Skip to content

Masking and replays

Quomerce is built to keep personal data out. Most of it happens with no work from you.

  • What visitors type. Values of inputs, text areas and selects are never recorded, on any page, in events or in replays.
  • Request and response bodies and headers. Network events carry only the method, host, path, status and duration.
  • IP addresses. Quomerce turns the IP address into a country and throws it away. No IP is stored.
  • All text on checkout, thank-you and account pages, in replays. This depends on the page type, so make sure those pages get the right one. It also covers client-side navigation into checkout.
  • Email addresses and phone numbers in URLs, error messages, click text, search terms and custom event props. Quomerce filters them again when the data arrives.
  • Query parameters other than the ones you keep. See URLs, requests and cookies.

Use two HTML attributes on any page:

<!-- The text is replaced in the replay; the layout stays. -->
<span data-qm-mask>Jan Kowalski</span>
<!-- Not recorded at all; the replay shows an empty box of the same size. -->
<div data-qm-block>…</div>

Use data-qm-mask where personal data shows outside checkout, such as a customer name in the header or an address in a “My orders” widget. Use data-qm-block for things that should not be seen at all, such as an embedded chat.

Can’t change the HTML? Add CSS selectors in Analytics settings → Session replay: Mask text in works like data-qm-mask, Leave out entirely works like data-qm-block.

A session is recorded only when all of these are true:

  • Record replays is on for the website;
  • the visitor allowed replays (or consent is set to Not required), see Consent;
  • the browser shows no sign of being automated (driven by a test tool, or headless);
  • the session is at least 3 seconds old. Shorter sessions upload nothing.

A recording lasts up to 6 hours per session. Replays are kept for 30 days by default (Keep replays in Analytics settings).