Configuration

Tunables live in the database, not in environment variables, so they change per site or per organisation at runtime with no redeploy.

KeyDefaultMeaning
retentionDays400Organisation-wide: how long raw events are kept. Set by your plan.
saltRetentionDays3How long visitor identity salts are retained for the legacy visitor metric.
sessionTimeoutMins30Inactivity gap that ends a visit.
monthlyEventQuota200,000Organisation-wide ceiling on events per month. Set by your plan.
maxEventsPerAddressPerHour1,000Events one address may send to one site in a clock hour. The rest of that hour's events from it are refused and not counted against your quota, so a script replaying your site id cannot spend your month. Raise it for a site whose events come from your own servers or one shared office connection.
collectCountrytrueSet false to store no geography at all.
visitorFingerprinttrueStore the device fingerprint and device details the tracker sends. Set false to drop them on arrival. To stop them being sent at all, add data-no-fingerprint to the script tag.
visitorCookietrueStore the random browser id from the tracker's cookie, which returning visitors are counted from. Set false to drop it on arrival. To stop the cookie being written at all, add data-cookieless to the script tag.
excludePaths[]Paths never recorded.
excludeIps[]Addresses never recorded, as single addresses or CIDR blocks no wider than /16 for IPv4 or /32 for IPv6. The organisation's list and a site's list add together rather than one replacing the other. A malformed entry is refused.
conversions[]Event names pinned to the conversions row, in order, shown even at zero. Unpinned custom events appear there on their own while they fire.

Going over quota returns a 429 and logs it. Events are rejected loudly rather than dropped on the floor. An address over its hourly allowance gets a 429 too, with the error address_rate_limited.