Privacy Policy
Last updated: August 1, 2026
Moonira Agency (“Moonira”, “we”, “us”) operates the website moonira.com. This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have.
1. What we collect
a) Product analytics (PostHog)
We use PostHog to understand overall site traffic and how pages perform. It records page views and the engagement events listed in (d) below, tied to the visitor identifier described in (f). We use it in aggregate, to see which pages work and which do not.
PostHog also records replays of site sessions: the pages you view, your mouse movement, clicks and scrolling, and the text you type into our forms, including where you start filling a form and do not submit it. We use replays for two things: finding where pages and forms break, and reading back an enquiry that was started but never sent so we can respond to it. Password fields are never recorded, and we do not ask for payment details anywhere on this site. You can stop replay recording with a tracking blocker, and the site works normally without it.
b) Form submissions
When you fill out a qualification form, we collect the information you provide: name, email address, company website, team size, and any message you write. This data is used solely to respond to your inquiry, assess fit, and provide our services.
c) Cal.com booking data
When you book a discovery call through our Cal.com integration, we receive your name, email, and scheduling details via a webhook. This data is stored alongside your form submission to connect your inquiry to the booked meeting.
d) Engagement tracking
We collect anonymous engagement signals to understand how visitors interact with our site. This includes:
- Scroll depth (how far you scroll on a page)
- Time spent on page
- Which sections of a page you view
- CTA button clicks
- Form submission events
This data is tied to a random session identifier stored in your browser's sessionStorage (not a cookie). The session ID is generated fresh each visit and cannot be used to identify you personally unless you submit a form during that session.
e) UTM parameters
If you arrive via a marketing link, we capture campaign parameters (source, medium, campaign, term, content) to understand which outreach efforts are effective. These are stored in your browser's sessionStorage and sent with your form submission. Personal information (email, name) is stripped from the URL immediately after capture.
f) Visitor and session identifiers
We generate random visitor and session IDs to connect page views and engagement events. The session ID lives in your browser's sessionStorage and is discarded when you close the tab. The visitor ID is stored in a cookie named _moonira_vid, set by our server and readable only by our server, and it lasts 400 days. It lets us tell a returning visitor from a new one. It contains no name, email address or other personal detail, and on its own it does not identify you. If you later submit a form, we connect that identifier to the details you gave us.
g) Advertising measurement (Meta Pixel)
Our paid-advertising landing pages under /get-started run the Meta Pixel, a tool provided by Meta Platforms. It tells us which advertisements produced enquiries, so we can stop paying for the ones that do not work. It does not run on the rest of the site.
When it runs, Meta receives:
- The address of the page you are viewing, including any campaign parameters in it, and the page you arrived from
- Your IP address, browser type, device type and screen size
- Two identifiers stored in your browser as cookies:
_fbp, set on this domain and valid for 90 days, and_fbc, which records which advertisement you clicked - Four events, and no others: InitiateCheckout when you enter your name and email address and continue to the next step, Lead if you complete the application and meet our qualification criteria, LeadDisqualified if you complete it and do not, so that we stop showing you advertisements, and Schedule if you book a call. Each carries only a short label naming which form it came from. We do not send your name, email address, phone number, company details, team size or revenue with any of them, and we do not send the reason an application did not qualify.
We also send the Schedule event to Meta from our own server when a booking is confirmed, so that a booking is still counted if your browser blocks the pixel. It carries the same identifiers listed above and no additional personal data.
Meta acts as an independent controller for its own use of this data. We and Meta are joint controllers for the collection and transmission step. Meta describes its handling in its Business Tools Terms and Data Policy. We do not currently ask for consent before the pixel runs; if you would rather it did not, browser tracking protection and content blockers stop it, and doing so does not affect your ability to use the site or submit a form.
2. Legal basis for processing (GDPR Art. 6)
- Consent (Art. 6(1)(a)): When you voluntarily submit a form or book a call, you consent to us processing that data to respond to your inquiry.
- Legitimate interest (Art. 6(1)(f)): Analytics and engagement tracking serve our legitimate interest in understanding site performance and improving user experience. This processing uses the identifiers described in 1(f). Session replay is covered by this basis only for diagnosing broken pages and forms; it can capture what you type into a form before you submit it, as described in 1(a). The advertising measurement described in 1(g) is separate and is not covered by this basis.
- Contract (Art. 6(1)(b)): If you engage us for services, we process data necessary to fulfill our contractual obligations.
3. What we do not do
- We do not sell your data to third parties.
- We do not share your information with data brokers.
- We do not run advertising technology on our content pages. The one exception is our paid-advertising landing pages under
/get-started, which run the Meta Pixel. Section 1(g) sets out exactly what that collects. Analytics and session replay, described in 1(a), do run across the site. - We do not send your name, email address or company details to any advertising platform.
4. Sub-processors and data sharing
We use the following services to operate moonira.com. Each processes data on our behalf and under our instruction:
| Service | Purpose | Data location |
|---|---|---|
| Vercel | Website hosting and edge delivery | Global (edge network) |
| Supabase | Database for form submissions and engagement data | United States |
| Cal.com | Meeting scheduling | EU / United States |
| PostHog | Website analytics, engagement tracking and session replay | United States |
| Meta Platforms | Advertising measurement on our paid landing pages (see 1(g)) | United States / Global |
| Cloudflare | Spam and bot protection on our forms | Global (edge network) |
| Mux | Video hosting and playback | United States |
| Sanity | Content management system | United States |
5. International data transfers
Some of our sub-processors are located in the United States. Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) adopted by the European Commission, or the service provider's participation in recognized data protection frameworks.
6. How we store and retain your data
Form submissions and associated attribution data are stored in Supabase (PostgreSQL), hosted in the United States. Data is retained for the duration of our business relationship and for up to 24 months afterward for follow-up and record-keeping purposes. After this period, data is deleted or anonymized.
Anonymous engagement data (scroll depth, time on page) is retained for up to 12 months for analytical purposes.
Session replays are stored by PostHog in the United States and are retained for up to 12 months. A replay recorded before you submitted a form can be linked to you once you do submit one, because we identify you to PostHog by email address at that point.
7. Your rights
Under the GDPR and applicable data protection laws, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure:Request deletion of your personal data (“right to be forgotten”).
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Portability: Request your data in a structured, machine-readable format.
- Object: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@moonira.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
8. Data protection measures
We implement appropriate technical and organizational measures to protect your data, including encrypted connections (TLS/HTTPS), access controls, rate limiting on all endpoints, and input validation. Sensitive credentials are stored as encrypted environment variables and are never exposed to the client.
9. Data Processing Agreement
If you require a Data Processing Agreement (DPA) for your organization, contact us at privacy@moonira.com and we will provide one.
10. Changes to this policy
We may update this policy from time to time. Material changes will be noted with a revised “last updated” date at the top of this page. Continued use of the site after changes constitutes acceptance.
11. Contact
For privacy-related questions, reach out to privacy@moonira.com.