PureStats documentation
Data destinations
Send privacy-safe PureStats events to signed webhooks, S3-compatible storage, BigQuery or ClickHouse.
Data destinations copy native PureStats pageviews and custom events to infrastructure you control. Open Site settings → Destinations to configure a signed webhook, S3-compatible object storage, Google BigQuery or ClickHouse.
Delivery guarantees
PureStats uses a transactional outbox and delivers each event at least once. Every envelope contains a stable event_id; destination consumers should use it as their deduplication key. Failed requests use exponential backoff. A delivery moves to the dead-letter queue after eight failed attempts and can be retried manually.
Credentials are encrypted at rest and are never returned to the browser. Pageview envelopes contain pseudonymous visitor and session identifiers, but never the visitor IP address or raw user agent.
Signed webhooks
Webhook requests include:
X-PureStats-Event-IdX-PureStats-TimestampX-PureStats-Signature
The signature is sha256= followed by the HMAC-SHA256 digest of <timestamp>.<raw body>. Reject stale timestamps and compare signatures in constant time.
Warehouses and object storage
S3 destinations receive one gzip-compressed NDJSON object per event. BigQuery uses the event ID as its stable insert ID. ClickHouse receives JSONEachRow requests. All providers use schema version 1 and expose connection status, delivery lag and failures in site settings.
Backfills
Backfills can export native pageviews and events still available inside the site's raw-data retention window. They are checkpointed and can be cancelled without affecting live delivery. Backfills never recreate data already removed by retention.
Privacy deletions
When a matching privacy delete request is processed, PureStats enqueues a privacy_tombstone. The tombstone identifies the site and privacy request but does not contain the lookup value. External destinations are separate data copies; you must consume tombstones and enforce deletion and retention there.