Privacy.
How Jourier handles personal data, cookies, and analytics. Last updated: 16 August 2026.
What we collect, in plain language.
Jourier is a Finnish technology consulting firm. We try to collect as little personal data as we reasonably can.
- If you book a meeting or send a message via the contact form, we receive your name, email, and the notes you provide.
- If you opt in to analytics or insights, we use a small set of tools to understand how the site is used. You control this from the cookie settings link in the footer.
- We do not sell your data, do not run ads on this site, and do not share your data with third parties beyond the processors listed below.
Booking a consultation.
When you book a meeting at jourier.com/contact, we collect:
- Name — to address you correctly in the meeting invite.
- Email — to send the calendar invite and follow-up correspondence.
- Topic + notes — so we come prepared.
Legal basis: Article 6(1)(b) GDPR — necessary to take steps at your request prior to entering into a contract.
Storage: meeting metadata is stored in our scheduling tool (Cal.com). Email correspondence is stored in our inbox provider for as long as the relationship is active, or until you ask us to delete it.
Retention: contact data is kept for 24 months from the last interaction, then deleted unless we have an active engagement.
Cookie-less measurement that runs without consent.
The tools below run on every visit. None of them writes anything to your device — no cookies, no local storage, no fingerprinting — so the consent rule in ePrivacy Article 5(3), which governs storing or reading data on your device, does not apply to them. They do process your IP address on the server, which is personal data, and our legal basis for that is legitimate interest under GDPR Article 6(1)(f): we need to know which of our pages are read. You can object at any time — either with the one-click control below, which takes effect immediately and needs nothing from us, or using the contact address above. Our full assessment, including the residual legal risk we have accepted, is written up in our internal Legitimate Interests Assessment and is available to clients on request.
Aggregate page-view counts and traffic sources. No cookies, no fingerprinting, no individual tracking — just anonymous numbers. IPs are hashed daily for de-duplication and discarded. Provided by Vercel Inc. (USA) under Standard Contractual Clauses.
Page views and interaction events, so we can see which content is read and where visitors stop. Runs in memory-only mode until you accept Insights: nothing is written to your device, the identifier lives in a JavaScript variable and is discarded the moment you move to another page, and no session recording takes place. Because it does not survive even a single navigation, we cannot follow you from one page to the next, let alone recognise you on a later visit. That is the deliberate trade for not asking permission. Hosted in the EU (Frankfurt) by PostHog. Accept Insights and it switches to persistent storage — see the section below.
A small amount of browser sessionStorage remembers whether you've already seen the entrance animation in this tab. Internal-only, never transmitted, cleared when you close the tab.
A link we send you may carry a short code, for example jourier.com/l/newsletter-august. Following one records the click on our server: the time, the country, the site that referred you, and a hashed version of your IP address. We never store the address itself. The click record writes nothing to your device. Most codes identify a campaign rather than a person — a newsletter, a conference, a post — and tell us only that someone arrived that way. Where we create a code for one named individual, the record is personal data about that person, and our basis is our legitimate interest in knowing whether our own outreach reached them. Please note that the opt-out below stops the analytics tools but not this server-side click record, because that is written before any code runs in your browser. To object to it, or to have the records deleted, email us at the address above and we will do it.
If you accept analytics or insights, we generate one random identifier, store it in your browser, and give the same value to Google Analytics, Clarity and PostHog. Without it each of those tools keeps its own separate identifier and the same visit looks like three unrelated strangers; with it we can see that one session recording, one funnel and one report describe the same person. The identifier is random and means nothing on its own — it is not derived from your name, your address, your device or anything you typed. It is created only after you accept, never before, and it is deliberately stronger than any single tool’s own cookie, which is why it is opt-in. Decline, or use the control below, and it is never created. Vercel Analytics does not receive it and cannot: it has no way to accept one.
Turn measurement off on this device
The tools above run on legitimate interest rather than consent, so you are entitled to object. This is that objection, as one click: it takes effect immediately and requires nothing from us. It stops Vercel Analytics and PostHog, and it also stops Google Analytics and Clarity even if you have already accepted those categories. The setting is stored in this browser, so repeat it on each browser and device you use. Clearing your site data removes it.
What loads only when you opt in.
Nothing in this category loads until you click Accept all or enable the relevant category in Manage preferences. If you reject, none of the tools below run.
Page views, traffic sources, and which content performs. Sets first-party cookies (_ga) to recognise returning visits. We use Google Consent Mode v2: the tag is not loaded at all until you opt in, and Google’s advertising signals (ad_storage, ad_user_data, ad_personalization) remain denied. We do not run advertising or remarketing, and Google Signals is switched off on our property. Provided by Google Ireland Limited; data may be processed in the USA under Standard Contractual Clauses and the EU-US Data Privacy Framework.
Heatmaps, scroll depth, click maps, and session recordings. Helps us see which content lands and where visitors get stuck. Sets first-party cookies. Provided by Microsoft Ireland Operations Limited.
Upgrades the memory-only PostHog described above to persistent storage. Sets first-party cookies and uses local storage, so we can recognise a returning visitor and connect their visits, and it enables session replays. Form fields are masked in recordings. Hosted in the EU (Frankfurt) by PostHog Inc. Decline and PostHog keeps running in memory-only mode, storing nothing.
What you can ask us to do.
Under GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct anything that's wrong.
- Erasure — ask us to delete your data ("right to be forgotten").
- Restriction & objection — limit or object to specific uses.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — at any time, via the cookie settings link in the footer or by emailing us.
- Lodge a complaint — with the Finnish Data Protection Ombudsman (tietosuoja.fi) or your local supervisory authority.
To exercise any of these, email aleksi.stenberg@jourier.com. We respond within 30 days.
Where data goes.
The site is hosted on Vercel (USA) with EU edge servers. PostHog is hosted in the EU. Microsoft Clarity processes data globally; Microsoft is certified under the EU-US Data Privacy Framework. Google Analytics is provided by Google Ireland Limited and may process data in the USA; Google is certified under the EU-US Data Privacy Framework. Where transfers outside the EEA occur, they're covered by Standard Contractual Clauses (SCCs).
Changes to this policy.
If we change anything material we'll update the "Last updated" date at the top and, if the changes are significant, ask for renewed consent through the banner.
Want to change your privacy preferences?