# Data Collection

> The limits on this page are enforced **server-side as well as in the SDK**: the ingest API
> rebuilds every payload from a strict allowlist and rejects sensitive-looking values (raw
> emails, phone numbers, card patterns, password-like fields), so bypassing the SDK cannot store
> undocumented data. Raw request payloads are never persisted.
>
> Free Preview sites also contribute pseudonymized, infrastructure-level sightings to the
> [FindIP Threat Network](https://www.findip.net/docs/shield/threat-network.md) — network-level data only, identical in every
> privacy mode, never including anything from the sections below.

## What the SDK Collects

### Always (all modes)

- Event name and timestamp
- Page URL, path, title, referrer
- UTM parameters
- Session ID
- SDK version

### balanced / advanced

- Visitor ID (cookie)
- Browser language, timezone, screen/viewport
- Form metadata (field types, counts, button text category)
- Customer-provided context (allowlisted fields only)

### advanced only

- Extended device consistency signals
- Touch support detection

## What the SDK Never Collects

- Passwords or payment card numbers
- Full form input values
- Raw email addresses or phone numbers
- Names or physical addresses
- Keystrokes, mouse movements, screenshots
- Full DOM content

## Form Metadata Example

```json
{
  "field_count": 5,
  "has_email_field": true,
  "has_password_field": true,
  "has_phone_field": false,
  "has_payment_field": false,
  "has_message_field": false,
  "submit_text_type": "signup"
}
```

Input **values** are never read or transmitted.

## Customer Context

Only these fields are accepted via `FindIP.track()`:

- `user_id_hash`, `email_hash` — hashed identifiers
- `email_domain` — domain only (e.g. `gmail.com`)
- `plan`, `currency`, `transaction_amount`
- `form_name`, `lead_source`
- `custom` — object with safe string/number/boolean values

## Backend Enrichment

The FindIP backend adds (not collected by SDK):

- Visitor IP, ASN, geolocation
- VPN/proxy/Tor/hosting/malicious flags
- Risk score and recommendation

---

Canonical page: https://www.findip.net/docs/shield/data-collection · Markdown: https://www.findip.net/docs/shield/data-collection.md · All Shield docs in one file: https://www.findip.net/llms-full.txt
