Trust and security

MIRA FIVE is made by a German company and hosted in Germany.

MIRA FIVE is made by Cloo GmbH in Auerbach, Germany, and your analytics data is stored and processed on servers in Germany. Collection is first-party: the script runs on your own site, and your data is never shared or sold.

Four facts about your data

Company
Cloo GmbH, a German company in Auerbach
Hosting
Germany; encrypted backups in Finland (EU)
Sub-processors
Hetzner for hosting, Google Workspace for support email
Collection
First-party, on your own site; never shared or sold

Where your data is hosted is one part of compliance. The rest depends on what you collect and why.

The full fact sheet

Where does my data live?

Your analytics data is received, stored and processed on Hetzner servers in Germany. Cloo GmbH, a German company, runs MIRA FIVE.

Hosting
Hetzner, Germany; encrypted backups in Finland (EU)
Company
Cloo GmbH, Reumtengrüner Str. 32B, 08209 Auerbach, Germany

What does the script collect?

The default setup counts visits without cookies or identifiers. Visitors who consent are followed as people across visits.

Default setup
Visits, pages, channels, campaigns, countries, devices and events
With consent
People across visits, their journeys, funnels and A/B tests
IP address
Used to look up country and region; never stored with your analytics data
Opt-outs and bots
Do Not Track and Global Privacy Control honoured; bots filtered

How do I answer a data request?

Access, erasure and objection are built into the app. Start from the person's page or the privacy page.

Access
Export what is stored about one person
Erasure
Erase one person's data in a project
Objection
Remove a person from every segment flags use and from every experiment result
Record
Every request is kept in the audit log

Who can see your numbers?

Team sign-in supports two-factor authentication and passkeys. Agents read by default, the API only reads, and every call is logged.

Sign-in
Two-factor authentication and passkeys
Roles
Owner, admin, member
Agents
Setup changes only after you allow them, flag switches behind a second permission; every call logged
API keys
Optional expiry after 30 days, 90 days or 1 year

Who else handles the data?

Two companies process customer data on our behalf. The public list names them and the place of processing.

Hosting
Hetzner Online GmbH, Germany
Support email
Google Workspace (Google Ireland); a transfer to the US is possible
Error tracking
Self-hosted in Germany
The full list
Sub-processors

Questions about your data

Does hosting in Germany make my setup compliant?
Not on its own. Where data is hosted is one part; the rest depends on what you collect and why.
Does MIRA FIVE set cookies?
Not in the default setup. It counts visits, pages and channels, and follows people across visits only after they consent.
Do you store IP addresses?
Not with your analytics data. The IP address is used to look up country and region; the access logs in front of our servers keep it for security, for at most 14 days.
Can an agent change or delete my data?
Agents are read-only by default and never delete anything. They can add setup, such as a goal, once you allow it for that connection; switching flags needs a second permission.

Ask us before you add the script

Write to hello@mirafive.io with questions about hosting, collection or access.