Does Fathom use cookies or require a consent banner?
It may be hard to “fathom” (sorry, bad joke), but Fathom Analytics doesn’t use cookies or similar technologies in our analytics. Instead, we’ve pioneered collecting analytics data without invading anyone’s privacy or personal information.
Unlike Google Analytics, Fathom doesn’t use cookies or similar with our embed script. And while we’re not in a position to offer legal advice, we invest heavily in compliance and have a fantastic EEA-based privacy officer who keeps us up to date with all the latest changes.
GDPR and requiring consent banners
The intent of the GDPR is to protect the privacy of EU citizens, and we agree with that (our whole software product is built around accomplishing this goal).
We have a lawful basis for the processing we do. And we run privacy risk assessments whenever we need to make a significant change (e.g. when we had to enable basic, heavily redacted IP access logs after we were DDoS attacked).
We go into considerable detail on this on our Data journey page, but some key pieces for GDPR are as follows:
- We process personal data (IP Address and User-Agent) on your behalf.
- We use site-specific visitor signatures with a salt that rotates daily. Rotation changes the signatures used for new visits; it does not delete stored analytics records. See our data journey and DPA for processing and retention details.
What about international data transfers?
The EU–US Data Privacy Framework, adopted in July 2023, allows transfers to participating US organisations covered by the framework. It replaced Privacy Shield, which was invalidated in 2020; it does not remove other GDPR obligations. See our EU–US data transfer guide and data isolation.
Want to update your privacy policy?
We’ve added a sample paragraph example for your privacy policy to mention how you protect their privacy to your website visitors. The example is general information, not legal advice; adapt it to your website’s practices and applicable requirements.