For Admin users only
Please note that only users with Admin access can change Data Masking settings.
Introduction
This article provides information about personal data masking in Contentsquare and how to manage it, so you can protect your user’s personal data.
Personal data refers to any information that identifies, relates to, or can directly, or indirectly, be linked to an individual. GDPR and other privacy laws around the globe regulate the collection and storage of personal data.
Our Data Masking controls help you to manage what your visitors' personal data looks like inside the Contentsquare platform. This page will help you choose a global masking level for your entire website, then create exceptions to override it on specific pages.
Before you begin
- Masking settings are configured per project.
- Only users with Admin access can access and change Data Masking settings.
How to access Data masking settings
- Click on your profile icon.
- Click 'Projects and users'.
- Select ‘Data Masking’.
Website-level masking
Automatic Personal Data Redaction: What's always protected?
Regardless of your settings, the Contentsquare tag automatically redacts
form field values, email addresses, credit card-like numbers, phone-like
strings, numbers greater than or equal to (≥) 9 digits, and JWT tokens.
This is called Automatic Personal Data Redaction. It
is
always active and
cannot be turned off.
Website-level masking sets the default masking level for your entire website.
There are three modes:
- Full masking : All text, numbers, and media are masked (this is the default setup)
- Partial masking : Text and numbers are masked. Media is visible.
- No masking : All text, numbers, and media are visible. Form fields and sensitive numbers remain masked (See Automatic Personal Data Redaction above).
To set website masking:
- Under ‘Website-level masking’, select ‘Full masking’, ‘Partial masking’, or ‘No masking’.
- Click ‘Save’.
⚠ Important
Switching from Full masking to Partial masking or No masking means more
of your users’ content will be visible in the Contentsquare platform.
Make sure you've reviewed what data your pages display before reducing
your masking level.
Page rules exceptions
Page-level exceptions override your global masking setting on specific pages. Use them when you need a different masking level on certain URLs — for example, to unmask pages that don't contain personal data, or to add extra masking on pages that do.
Step 1 - Choose what to mask or unmask on exception pages
Before creating your URL rules, define what type of content should be masked or unmasked on those pages. These settings apply to all your exceptions, not to individual rules.
Under ‘Page-level exceptions’, tick the content types you want to apply to your exceptions:
- Text
- Numbers
- Media
What does "media" include?
Note that checking media will include these html tags:
["picture", "img", "video", "audio"]
Step 2 - Create URL rules
You can create up to 20 rules per project.
URL rules define which pages your exceptions apply to.
- Select a condition from the dropdown in the first field (for example, "URL contains" or "URL starts with", or “Regex”).
- Enter a value in the second field.
- Click the more options (three vertical dots) for additional settings for this rule:
- Ignore query string
- Ignore URI fragments
- Ignore case sensitivity
- Enter a URL in the ‘URL tester’ field and click ‘Test’ to validate your rule.
- Click ‘Save’.
To delete a rule, simply click on the 🗑️ (trash) icon and click ‘Save’.
Refine your setup with Element masking rules
Having your pages’ UI content masked by default can make it difficult to analyze your website’s interface during a session replay. Therefore, you have the capacity to selectively mask and unmask targeted elements across your site.
This helps you improve visibility of the user experience when analyzing session replays, while still maintaining masking throughout your pages as necessary.
Using the ‘Element rules’ panel
You can configure Element masking/unsmasking directly from the ‘Element rules’ panel, targeting HTML elements thanks to CSS selectors.
Follow the instructions detailled in this article.
AI-assisted PII detection
Users with access to Sense can utilize AI-assisted detection to identify potential PIIs on the webpages and configure targeted CSS selectors in our tool. Please refer to this section for further details about Sense in Contentsquare.
Masking specific elements in your code
Beyond Data Masking configuration options, Contentsquare provides javascript APIs and HTML attributes to mask or strip Personal Data from specific channels.
You can refer to our Technical Implementation Documentation for details.
FAQs
Does Page Masking retroactively mask pages?
No, changes are not applied retroactively.
Does changing my Data Masking settings apply to historical data?
No. Changes apply only to data collected after you save. They are not applied retroactively.
Can I use different content types (Text, Numbers, Media) for different rules?
No. The Text, Numbers, and Media checkboxes apply to all your page-level exceptions, not to individual rules.