Privacy Policy

Document ID: MR-PRIV-2025-V3 • Effective: December 30, 2025

🔒 Zero-Knowledge Promise

MetricRig operates on a client-side architecture. Your business data, calculations, manifests, and financial models are processed entirely in your browser and are never transmitted to our servers. We cannot see, access, or recover your work.

1Introduction

MetricRig ("we," "us," or "our") operates the MetricRig platform and related services (the "Service"). We are committed to protecting your privacy and handling your personal information in an open and transparent manner.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at metricrig.com and use our calculation tools. This policy applies to users worldwide and addresses requirements under:

  • PIPEDA (Personal Information Protection and Electronic Documents Act) — Canada
  • GDPR (General Data Protection Regulation) — European Union & UK
  • CPRA/CCPA (California Privacy Rights Act / California Consumer Privacy Act) — California, USA
  • Other applicable provincial, state, and international privacy laws

By accessing or using the Service, you consent to the data practices described in this Privacy Policy.

2Our Client-Side Architecture (Zero-Knowledge)

MetricRig is fundamentally different from most SaaS applications. We operate on a client-side, zero-knowledge architecture:

  • No Server-Side Data Processing: All calculations performed by our tools (Container Loader, DIM-Rig, Warehouse-Rig, Burn Rate, Unit Economics, Churn, AdScale, A/B Test, Cap Rate, Commission, Employee Cost, EOQ, Landed Cost, Lease vs. Buy, Valuation, Engagement, and Freight Class calculators) are executed entirely within your web browser using JavaScript.
  • No Data Transmission: Your User Data — including manifests, dimensions, weights, financial figures, scenarios, and business metrics — is never transmitted to our servers.
  • Browser-Based Storage: If you choose to "save" your work or inputs, this data is stored in your browser's localStorage. This storage exists only on your specific device and browser instance.
  • No Recovery: We do not have access to your localStorage data. If you clear your browser cache or switch devices, we cannot recover your saved work.

What this means for you: Your sensitive business data (container loads, cash flow projections, customer metrics, commission structures) stays on your device. We literally cannot see it, even if we wanted to.

3Information We Do Collect

While we do not collect your User Data (calculation inputs), we do collect certain metadata and usage information to operate and improve the Service:

3.1 Automatically Collected Information

When you visit our website, we automatically collect:

  • Device Information: Browser type, browser version, operating system, screen resolution, and device type (desktop/mobile/tablet).
  • Usage Data: Pages visited, time spent on pages, features used, click patterns, and navigation paths.
  • Referral Data: The website or source that referred you to MetricRig, search terms used, and campaign parameters.
  • Approximate Location: City and country-level geolocation derived from your IP address. We do not collect precise GPS coordinates.
  • Technical Logs: Server access logs including IP addresses, timestamps, and HTTP request details for security and debugging purposes.

3.2 Cookies and Tracking Technologies

We use cookies and similar tracking technologies to operate and improve the Service:

  • Essential Cookies: Required for basic website functionality, including theme preferences (dark/light mode) and session management.
  • Analytics Cookies: We use Google Analytics 4 (GA4) to understand how visitors interact with our website. GA4 collects aggregated, anonymized usage data.
  • Advertising Cookies: We use Google AdSense to display advertisements. Google may use cookies to serve personalized ads based on your prior visits to this website or other websites.

3.3 Information You Provide Voluntarily

We may collect information you voluntarily provide when you:

  • Contact us via email at [email protected]
  • Submit feedback, bug reports, or feature requests
  • Subscribe to any newsletter or notification service (if offered)

4How We Use Your Information

We use the information we collect for the following purposes:

  • Service Operation: To provide, maintain, and improve the functionality of our tools and website.
  • Analytics: To understand usage patterns, identify popular features, and make data-driven improvements.
  • Security: To detect, prevent, and address technical issues, fraud, and security threats.
  • Advertising: To display relevant advertisements and sustain the free nature of our Service.
  • Communication: To respond to your inquiries, feedback, and support requests.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.

5Third-Party Services & Data Sharing

We do not sell your personal data to data brokers or third parties. However, we work with the following third-party services that may collect information as described:

5.1 Google Analytics 4 (GA4)

We use Google Analytics 4 to collect anonymized usage statistics. Google Analytics uses cookies to track user interactions. Data collected includes pageviews, session duration, and user demographics (in aggregate). For more information, see Google's Privacy Policy.

5.2 Google AdSense

We use Google AdSense to display advertisements on our website. Google may use cookies and web beacons to serve personalized ads based on your browsing history. Under the California Privacy Rights Act (CPRA), this may constitute "sharing" of personal information for cross-context behavioral advertising.

You can opt out of personalized advertising by:

5.3 Cloudflare

We use Cloudflare for content delivery (CDN), security, and DDoS protection. Cloudflare may process your IP address and other technical data to provide these services. See Cloudflare's Privacy Policy.

6International Data Transfers

MetricRig is operated from Canada. Our third-party service providers (Google, Cloudflare) may process data in the United States and other jurisdictions.

By using our Service, you acknowledge and consent to the transfer of your information to countries outside of your country of residence, including Canada and the United States, which may have different data protection rules than your country. We take steps to ensure that your information receives an adequate level of protection in the jurisdictions in which we process it.

7Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

7.1 Canadian Residents (PIPEDA)

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:

  • Access your personal information held by us
  • Request correction of inaccurate personal information
  • Withdraw consent to the collection, use, or disclosure of your personal information

Note: Because of our client-side architecture, we do not hold your User Data. We only hold aggregated analytics data and any information you voluntarily provide via email.

7.2 EU/UK Residents (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access: Request access to your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Request restriction of processing
  • Portability: Request a copy of your data in a portable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time

Legal Basis for Processing: We process your data based on: (a) legitimate interests (analytics, security); (b) consent (advertising cookies); and (c) contractual necessity (providing the Service).

7.3 California Residents (CPRA/CCPA)

Under the California Privacy Rights Act (CPRA) and California Consumer Privacy Act (CCPA), California residents have the right to:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising
  • Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights

Do Not Sell/Share My Information: While we do not "sell" personal information in the traditional sense, our use of advertising cookies may constitute "sharing" under CPRA. You may opt out by enabling Global Privacy Control (GPC) in your browser or using the opt-out links provided above.

8Global Privacy Control (GPC)

We recognize and honor Global Privacy Control (GPC) signals. If your browser sends a GPC signal, we will treat this as a valid request to opt out of the "sale" or "sharing" of personal information for advertising purposes, and we will suppress non-essential tracking cookies where technically feasible.

9Data Retention

We retain different types of information for different periods:

  • User Data (Your Calculations): We do not retain this data as it never leaves your device.
  • Analytics Data: Google Analytics data is retained according to Google's retention policies (typically 14-26 months).
  • Server Logs: Retained for 90 days for security and debugging purposes.
  • Email Correspondence: Retained as long as necessary to respond to your inquiry and for potential legal requirements.

10Data Security

We implement appropriate technical and organizational security measures to protect against unauthorized access, alteration, disclosure, or destruction of information. These measures include:

  • HTTPS encryption for all website traffic
  • Cloudflare DDoS protection and Web Application Firewall
  • Regular security assessments and monitoring

However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

11Children's Privacy

Our Service is not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at [email protected], and we will take steps to delete such information.

12Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by updating the "Effective Date" at the top of this page. We encourage you to review this Privacy Policy periodically for any updates.

13Contact Us

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have a privacy-related complaint, please contact us at:

Email: [email protected]

Subject Line: "Privacy Inquiry"

We will respond to privacy-related inquiries within 30 days (or sooner if required by applicable law).