5. TENANT ANALYTICS
A business using USLY may enable Tenant Analytics for its own public website. The business determines the limited measurement purpose and is generally the controller or business. USLY operates Tenant Analytics for that business as its processor or service provider. USLY keeps its separate account, billing, security, support, and Platform Analytics purposes outside this tenant-controlled analytics purpose.
Optional website measurement. Browser-based Tenant Analytics is off until a visitor selects Allow analytics. After permission, USLY may issue a pseudonymous handle limited to the exact tenant-site origin and record approved visit, page-area, campaign, booking-step, and purchase-step event keys. Approved website activity may be connected to an authoritative booking or purchase outcome for aggregate reporting.
Before a choice, a campaign link may place one opaque campaign code in the current tab's temporary session storage for no more than 30 minutes. It is not a visitor identifier or event, sends no analytics request, and is deleted on use, decline, withdrawal, expiry, or a tenant boundary.
Operational and money statistics. A business may use its ordinary booking, order, payment, and refund records to count completed outcomes even when browser analytics is off. When money reporting is enabled, Tenant Analytics may prepare aggregate statistics from successful payment and refund amounts, currency, and the approved transaction purpose. It does not connect an outcome to an unconsented browser journey, combine currencies, or provide accounting, tax, or financial advice.
Tenant Analytics is designed not to store names, contact details, form entries, message content, raw URLs or queries, raw referrers, IP addresses, user-agent strings, advertising click IDs, full payment-card or bank details, medical records, diagnosis or treatment information, or health histories. Excluding direct names does not make every record anonymous.
The exact-origin handle expires after 45 days without accepted activity or 90 days from issue, whichever happens first. An individual visit becomes inactive after 30 minutes without accepted activity and lasts no more than 24 hours. A pre-choice opaque campaign code remains only in the current tab for no more than 30 minutes. Raw minimized visits and events remain for no more than 90 days. Booking, purchase, payment, refund, consent, governance, and aggregate records remain for no more than 25 months under their applicable lifecycle. Detailed security rejection records remain for no more than 7 days, network tokens for no more than 24 hours, and minimized security counters for no more than 30 days.
Keeping analytics off does not affect browsing, booking, or purchasing. Global Privacy Control is a hard deny. Do Not Track keeps optional browser measurement off until an explicit choice; Allow analytics may enable this first-party measurement when no hard prohibition applies. If Do Not Track appears after a grant, collection stops and requires a new explicit choice. Withdrawal stops future browser collection; deletion is a separate verified request. The business is the first contact for tenant-controlled records, and USLY assists the business where appropriate.
USLY does not use Tenant Analytics for sale or sharing of personal information, cross-context behavioral advertising, cross-site tracking, cross-tenant or individual profiles, eligibility or pricing decisions, or AI/model training.
Tenant Analytics is limited to non-clinical beauty businesses. It is not a medical-record system, is not authorized for medical records, clinical workflows, diagnoses, treatments, or health histories, and is not offered under a HIPAA business associate agreement. USLY does not promise to continuously inspect or medically classify all customer content.