Back

Privacy Policy

Last updated: September 14, 2026

1. Who We Are

We are the team behind Consentify (consentify.app), a cookie consent platform. We follow GDPR and do our best to protect your privacy.

The data controller is Aareskjold Consulting, org.nr 936 584 535 MVA, Norway.

Contact Us: support@consentify.app

2. What Data We Collect

2.1 Your Account Data (You = Customer)

When you create an account, we collect:

  • Email address - to identify your account and contact you
  • Password - encrypted with bcrypt, we can't see your actual password
  • Name (optional) - if you choose to add it
  • Payment info - processed by Stripe (we never see your full card number)

2.2 Usage Data

  • How you use the dashboard - which features you use, to improve the product
  • Technical info - IP address, browser type, device (for security and debugging)
  • Error logs - if something breaks, so we can fix it

2.3 Your End-Users' Consent Data

When someone interacts with your cookie banner, we store:

  • Consent choices - which cookie categories they accepted/rejected
  • Timestamp - when they gave consent
  • A hashed IP address - the IP is hashed with a secret salt the moment the request arrives and only the hash is stored, so a returning visitor updates their existing record instead of creating a new one. The hash is pseudonymised personal data, not anonymous data.
  • User agent - Browser and device information for analytics and debugging.
  • Anonymous ID - a random identifier (not their IP or email)
  • Banner ID - which of your banners it was

Important: For your end-users' data, YOU are the data controller and WE are the data processor. This means you're responsible for your compliance. See the DPA for details.

3. Why We Collect This Data

  • To provide the service - Consentify can't work without storing your account and consent data
  • To process payments - so you can upgrade to paid plans
  • To give you support - when you email us with questions
  • To improve the product - understanding which features are used helps us build better tools
  • To fix bugs - error logs help us troubleshoot issues

Legal basis (GDPR): Contract performance (Art. 6(1)(b)) for core features, Consent (Art. 6(1)(a)) for analytics, and legitimate interest (Art. 6(1)(f)) for security.

4. Where Your Data Is Stored

Your account data and all end-user consent data is stored with Supabase in London, United Kingdom

The UK is covered by the European Commission's adequacy decision, renewed in December 2025, which means data can move there from the EEA under the same protection it had at home, with no extra safeguards needed. Two further services sit outside that, and neither touches end-user consent data: payment handling at Stripe, and the internal Slack notification carrying your name and email when you sign up. Both are covered by EU Standard Contractual Clauses.

Services We Use:

  • Supabase (UK - London) - Database and authentication. They handle encryption, backups, and security.
  • Stripe - Payment processing. They have their own strict security standards.
  • Vercel (EU - Stockholm) - Hosting and content delivery, plus cookieless traffic and performance measurement on our own marketing site. Our server code runs in Stockholm.
  • Sentry (EU - Germany) - Error and performance monitoring. Configured not to send IP addresses or user identifiers.
  • Browserless (EU - Amsterdam) - the headless browser that loads a site when you run a scan.
  • Zoho Mail (EU) - the mail service that sends our transactional email.
  • Slack (US, with SCCs) - internal notifications. Your name and email reach it when you sign up. Your end-users' consent data never does.

These are called "sub-processors" in GDPR terms. They all have proper data protection agreements in place.

For services that transfer data to the US (like Stripe), we ensure protection through EU Standard Contractual Clauses (SCCs) or the Data Privacy Framework (DPF).

5. How Long We Keep Data

  • Your account data: Until you delete your account
  • Consent logs: 13 months from the visitor's last decision
  • Payment records: 7 years (required by Norwegian accounting law)
  • Support emails: Up to 3 years
  • Error logs: 90 days

When you delete your account: We delete your data within 30 days, except for payment records we are legally required to keep.

6. Your Rights (GDPR)

You have the right to:

  • ✓ Access your data - Export everything via the dashboard
  • ✓ Correct your data - Update your email/name in settings
  • ✓ Delete your data - Delete your account anytime (settings → danger zone)
  • ✓ Export your data - Download as JSON from the dashboard
  • ✓ Object to processing - Email us to discuss
  • ✓ Complain - Contact the Norwegian Data Protection Authority (Datatilsynet)

How to exercise these rights: Most things you can do yourself in the dashboard. For anything else, email us at support@consentify.app and we'll help you out.

7. Security

Here's what we do to keep your data safe:

  • HTTPS everywhere - All data encrypted in transit (TLS 1.3)
  • Encrypted passwords - Hashed with bcrypt, we can't see your password
  • Supabase handles encryption at rest - They use industry-standard AES-256
  • Regular updates - We keep dependencies up to date
  • Access logs - We can see who accessed what, when

Realistic expectations: We follow best practices, but we rely on trusted providers (Supabase, Vercel) for infrastructure security. No system is 100% secure, but we do our best.

8. Data Breaches

If there's a security breach that affects your data, we will:

  • Notify you as soon as we become aware of it (aiming for within 72 hours, as required by GDPR)
  • Explain what happened and what data was affected
  • Tell you what we're doing about it

We'll be honest and transparent if something goes wrong. That's a promise.

9. Cookies

10. Third-Party Links

If we link to other websites (like Supabase docs or Stripe), those sites have their own privacy policies. We're not responsible for their practices.

11. Children

Consentify is not for anyone under 18. We don't knowingly collect data from children. If you're a parent and think your child has created an account, please contact us and we'll delete it immediately.

12. Changes to This Policy

We may update this privacy policy occasionally (like when we add new features or change providers). If we make significant changes, we'll email you at least 30 days in advance.

13. Contact Us

Questions about privacy? Want to exercise your rights? Just want to say hi?

Email us: support@consentify.app

We're a real team and we read every email. We'll get back to you as soon as we can!

TL;DR

  • We only collect data needed to run the service
  • Everything stored safely in the EU (Supabase)
  • You can export or delete your data anytime
  • We never sell your data to anyone
  • We're transparent and honest about what we do with your data
← Terms of Service→ Data Processing Agreement

© 2026 Consentify