Privacy Statement
Effective Date: March 22, 2026
1. Introduction
This Privacy Statement ("Statement") explains how rrweb, a private limited liability company organised under the laws of the Netherlands, with its registered office in Amsterdam ("rrweb", "we", "our", or "us"), collects, uses, shares, and protects personal data in connection with:
(a) our website at rrweb.com and related subdomains (the "Website");
(b) the rrweb Cloud hosted session replay service (the "Service"); and
(c) our interactions with customers, prospects, and community members.
The rrweb open-source library is distributed under its applicable open-source or commercial licence and does not transmit data to rrweb unless the library is configured to connect to the Service. This Statement does not apply to data processed entirely within self-hosted environments.
2. Roles and Responsibilities
rrweb operates in two distinct data-processing roles depending on the context:
2.1 rrweb as Controller
When you visit our Website, create an account, contact us, subscribe to our communications, or interact with our community channels, rrweb is the data controller. We determine the purposes and means of processing your personal data in these contexts.
2.2 rrweb as Processor
When customers use the Service to record, store, and replay end-user sessions within their own applications, rrweb acts as a data processor on the customer's behalf. The customer is the data controller and determines what data is captured through the rrweb SDK, including what masking, redaction, or anonymisation controls are applied. rrweb processes this data solely in accordance with the customer's instructions and the Terms & Conditions. The Data Processing Agreement (Annex A to this Statement) governs this processing relationship.
Customers who embed the Service into their own products are responsible for providing appropriate privacy disclosures to their end users, obtaining any necessary consents, and configuring the rrweb SDK's privacy controls to prevent the collection of data they do not wish to capture.
3. Personal Data We Collect
3.1 Data We Collect as Controller
Account Data: when you register for the Service, we collect your name, email address, company name, and billing information (payment details are processed by our payment provider and are not stored on our systems).
Communication Data: when you contact us by email, through support channels, or via community platforms, we collect the content of your communications and associated metadata.
Website Usage Data: we collect standard server log data (IP address, browser type, referring URL, pages visited, timestamps) and may use analytics tools to understand how visitors use the Website. We use cookies and similar technologies as described in Section 8.
Marketing Data: if you subscribe to our newsletter or attend our events, we collect your name, email address, and preferences.
3.2 Data We Process as Processor (Customer Data)
When customers use the Service, the rrweb SDK embedded in their applications captures session replay data from their end users. The scope and content of this data is determined by the customer's SDK configuration. It may include:
(a) DOM snapshots and mutations (the visual content of the page);
(b) user interaction events (mouse movements, clicks, scrolls, keyboard input);
(c) network request metadata;
(d) console log output;
(e) browser metadata (user agent, viewport size, URL);
(f) any identifiers or attributes the customer passes to the SDK (e.g. user IDs, email addresses).
rrweb does not determine what data the SDK captures. Customers are responsible for configuring privacy controls (text masking, input blocking, element exclusion) to ensure compliance with their own privacy obligations. rrweb provides extensive SDK-level privacy configuration options documented at docs.rrweb.com.
4. How We Use Personal Data
4.1 As Controller
We use Account Data and Website Usage Data to: operate, maintain, and improve the Website and Service; manage your account and provide support; process payments; send transactional communications; send marketing communications (where you have opted in or where we have a legitimate interest); detect and prevent fraud and security incidents; comply with legal obligations; and generate Aggregate Data for analytics, benchmarking, and publication.
4.2 As Processor
We process Customer Data solely to operate and provide the Service in accordance with the customer's instructions, our Terms & Conditions, and the Data Processing Agreement. We do not access, use, or analyse Customer Data for our own purposes, except to generate de-identified, aggregated Aggregate Data as described in our Terms & Conditions. We do not sell Customer Data. We do not use Customer Data for advertising.
5. Legal Bases for Processing (GDPR)
Where the GDPR applies, our legal bases for processing personal data as controller are:
Contract performance: processing necessary to perform our contract with you (e.g. managing your account, providing the Service).
Legitimate interest: processing necessary for our legitimate interests, including improving our products, securing our systems, and direct marketing to existing customers, provided these interests are not overridden by your rights.
Consent: where you have given specific consent, such as for newsletter subscriptions. You may withdraw consent at any time.
Legal obligation: processing necessary to comply with applicable laws.
Where we act as processor, the customer (as controller) is responsible for establishing the appropriate legal basis for processing end-user data through the Service.
6. Data Sharing and Transfers
6.1 Service Providers
We share personal data with third-party service providers who assist us in operating the Website and Service, including cloud infrastructure providers, payment processors, analytics providers, customer support tools, and email delivery services. These providers are contractually bound to process personal data only on our instructions and to maintain appropriate security measures. A list of sub-processors is maintained and available upon request.
6.2 Legal Requirements
We may disclose personal data where required by applicable law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, the safety of our users, or the public.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the successor entity.
6.4 International Transfers
The Service is hosted in the European Union by default. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) as set out in Implementing Decision (EU) 2021/914, or an adequacy decision where applicable. Customers on an Order Form may specify data residency requirements.
7. Data Retention
Account Data: retained for the duration of the customer relationship and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
Customer Data (session replays): retained for the retention period specified in the customer's account settings or Order Form (default: thirty (30) days from ingestion). Upon termination, Customer Data is available for export for thirty (30) days, after which it is deleted.
Website Usage Data: retained in aggregated form. Individual-level log data is retained for no more than ninety (90) days.
Marketing Data: retained until you unsubscribe or request deletion.
8. Cookies and Tracking Technologies
We use cookies and similar technologies on the Website for the following purposes:
Essential cookies: necessary for the Website and Service to function (e.g. authentication, session management). These cannot be disabled.
Analytics cookies: help us understand how visitors use the Website. We use PostHog, Google Analytics for this purpose.
You can manage your cookie preferences through the cookie banner presented on your first visit, or by adjusting your browser settings. Disabling certain cookies may affect the functionality of the Website.
9. Your Rights
Depending on your jurisdiction, you may have the following rights in relation to personal data we hold about you as controller:
Access: request a copy of the personal data we process about you.
Rectification: request correction of inaccurate or incomplete personal data.
Erasure: request deletion of your personal data, subject to legal retention requirements.
Restriction: request that we restrict processing of your personal data in certain circumstances.
Portability: receive your personal data in a structured, machine-readable format.
Objection: object to processing based on legitimate interest, including for direct marketing purposes.
Withdraw consent: where processing is based on consent, withdraw that consent at any time.
To exercise any of these rights, please contact us at legal@rrweb.com. We will respond within thirty (30) days, or within the period required by applicable law.
If you are an end user of a customer's application and wish to exercise your rights regarding session replay data, please contact the customer directly. rrweb processes this data on the customer's behalf and will redirect any end-user requests to the relevant customer.
10. Security
We maintain reasonable and appropriate administrative, physical, and technical safeguards designed to protect personal data against unauthorised access, disclosure, alteration, and destruction. These include encryption of data in transit (TLS 1.2+) and at rest (AES-256), access controls, regular security assessments, and incident response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
The Service is not directed at individuals under the age of sixteen (16). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that data. Customers are responsible for ensuring that their use of the Service complies with applicable age-related requirements.
12. Changes to This Statement
We may update this Statement from time to time. We will notify you of material changes by posting the updated Statement on our Website and, where appropriate, by email. The "Effective Date" at the top indicates the date of the most recent revision. Your continued use of the Website or Service after the effective date constitutes acceptance of the updated Statement.
13. Contact
If you have questions about this Statement, our data practices, or wish to exercise your rights, please contact:
rrweb
Herengracht 551, 1017 BW Amsterdam
Email: legal@rrweb.com
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority of your country of residence.
Annex A - Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the rrweb Cloud Terms & Conditions ("Terms") between rrweb ("Processor") and the Customer identified in the Terms or applicable Order Form ("Controller"). Capitalised terms not defined in this DPA have the meanings given in the Terms.
1. Definitions
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including the GDPR, the EU e-Privacy Directive (2002/58/EC), the California Consumer Privacy Act ("CCPA"), and any implementing or successor legislation.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
"Personal Data" means any personal data (as defined in the GDPR) contained within Customer Data that is processed by the Processor on behalf of the Controller in connection with the Service.
"Restricted Transfer" means a transfer of Personal Data from the EEA, the United Kingdom, or Switzerland to a country that does not benefit from an adequacy decision.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision (EU) 2021/914.
"Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
2. Subject Matter and Scope
2.1 Purpose
The Controller engages the Processor to process Personal Data for the purpose of providing the Service, including the recording, storage, retrieval, playback, and deletion of session replay data.
2.2 Nature of Processing
Collection (via the rrweb SDK embedded in Controller's application), storage, retrieval, display, analysis (for the purpose of playback and Service functionality only), and deletion of Personal Data.
2.3 Categories of Data Subjects
End users of the Controller's application whose sessions are recorded through the Service; Controller's employees and authorised users who access the Service dashboard.
2.4 Types of Personal Data
The types of Personal Data processed depend on the Controller's SDK configuration and may include: DOM content and mutations (which may contain text visible on screen), user interaction events, browser metadata (user agent, viewport, URL), IP addresses, session identifiers, and any custom attributes or identifiers passed by the Controller to the SDK.
2.5 Duration
Processing continues for the duration of the Terms plus the post-termination data retention and deletion period specified in Section 11.7 of the Terms (default: thirty (30) days).
3. Obligations of the Processor
3.1 Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, unless required to do so by Applicable Data Protection Law. The Terms, this DPA, and the Controller's configuration of the Service (including SDK settings) constitute the Controller's documented instructions. If the Processor believes an instruction infringes Applicable Data Protection Law, the Processor shall promptly notify the Controller.
3.2 Confidentiality
The Processor shall ensure that persons authorised to process Personal Data are subject to obligations of confidentiality, whether contractual or statutory.
3.3 Security
The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing, including as appropriate: (a) encryption of Personal Data in transit and at rest; (b) measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems; (c) a process for regularly testing, assessing, and evaluating the effectiveness of such measures; and (d) the ability to restore access to Personal Data in a timely manner in the event of a physical or technical incident.
3.4 Assistance with Data Subject Rights
The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to data subject requests. If the Processor receives a request from a data subject directly, the Processor shall promptly redirect the data subject to the Controller and notify the Controller of the request.
3.5 Assistance with Compliance
The Processor shall assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, impact assessments, and prior consultation), taking into account the nature of processing and the information available to the Processor.
3.6 Data Breach Notification
The Processor shall notify the Controller without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a personal data breach affecting Personal Data. The notification shall include: (a) a description of the nature of the breach, including the categories and approximate number of data subjects affected; (b) the name and contact details of the Processor's point of contact; (c) a description of the likely consequences; and (d) a description of measures taken or proposed to address the breach.
3.7 Deletion and Return
Upon termination of the Terms or upon the Controller's written request, the Processor shall, at the Controller's election, delete or return all Personal Data and delete existing copies, unless Applicable Data Protection Law requires retention. The Processor shall provide written confirmation of deletion upon the Controller's request.
4. Sub-processors
4.1 General Authorisation
The Controller grants the Processor general authorisation to engage Sub-processors for the processing of Personal Data. The Processor shall maintain a current list of Sub-processors, which shall be made available to the Controller upon request.
4.2 Notification of Changes
The Processor shall notify the Controller in writing (email is sufficient) of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance. If the Controller has a reasonable objection to the new Sub-processor, the Controller shall notify the Processor in writing within fifteen (15) days of receiving the notification. The parties shall discuss the objection in good faith. If the parties cannot resolve the objection within thirty (30) days, the Controller may terminate the affected Order Form or, if no Order Form is in effect, the affected subscription, and shall receive a pro-rata refund of any prepaid Fees for the unused portion of the Subscription Term.
4.3 Sub-processor Obligations
The Processor shall impose on each Sub-processor data protection obligations substantially equivalent to those in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-processor's obligations.
5. International Transfers
The Processor shall not transfer Personal Data outside the EEA, the United Kingdom, or Switzerland unless one of the following safeguards is in place: (a) the destination country is subject to an adequacy decision by the European Commission or the UK Secretary of State, as applicable; (b) Standard Contractual Clauses have been executed between the relevant parties; or (c) another valid transfer mechanism recognised under Applicable Data Protection Law applies. Where SCCs are required, Module Two (Controller to Processor) shall apply, with the Controller as data exporter and the Processor as data importer. The annexes to the SCCs are deemed completed with the information in Section 2 of this DPA.
6. Audits
6.1 Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
6.2 Conditions
Audits shall be conducted upon at least thirty (30) days' written notice, during normal business hours, and shall not unreasonably interfere with the Processor's operations. The Controller shall bear the costs of any audit. The auditor may not be a competitor of the Processor and must be bound by appropriate confidentiality obligations. The Processor may satisfy audit requests by providing relevant certifications, audit reports (such as SOC 2 reports), or completed industry-standard questionnaires.
7. CCPA Provisions
To the extent the CCPA applies to Personal Data processed under this DPA:
(a) The Processor acts as a "Service Provider" as defined in the CCPA.
(b) The Processor shall not sell or share Personal Data.
(c) The Processor shall not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Terms and this DPA, or as otherwise permitted by the CCPA.
(d) The Processor shall not combine Personal Data with personal information received from other sources, except as permitted by the CCPA.
(e) The Processor certifies that it understands and will comply with these restrictions.
8. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms. This DPA does not limit either party's liability to data subjects under Applicable Data Protection Law.
9. Term and Termination
This DPA takes effect on the date the Terms become effective and continues until the later of: (a) the termination or expiration of the Terms; or (b) the date on which the Processor ceases to process Personal Data on behalf of the Controller. The Processor's obligations under Sections 3.2, 3.7, and 6 survive termination of this DPA.
10. Precedence
In the event of any conflict between this DPA and the Terms, this DPA prevails with respect to the processing of Personal Data. In the event of any conflict between this DPA and the SCCs, the SCCs prevail.
Appendix - Processing Details
The following table summarises the processing activities covered by this DPA.
| Element | Details |
|---|---|
| Controller | The Customer identified in the Terms or Order Form |
| Processor | rrweb, Amsterdam, the Netherlands |
| Purpose | Provision of the rrweb Cloud session replay service, including recording, storage, retrieval, playback, and deletion of session data |
| Nature of processing | Collection, storage, retrieval, display, and deletion |
| Data subjects | End users of the Controller's application; Controller's employees and authorised users |
| Types of personal data | DOM content and mutations, interaction events, browser metadata, IP addresses, session identifiers, custom attributes passed by Controller to the SDK |
| Sensitive data | None intentionally. Controller is responsible for masking or excluding sensitive data via SDK privacy controls |
| Retention period | Default: 30 days from ingestion. May be extended per Order Form |
| Data location | EU by default. Custom regions available per Order Form |
| Sub-processors | List available upon request at legal@rrweb.com |