CONSENTCHECK

Privacy Policy

Last updated July 16, 2026

This is a plain-language description of what ConsentCheck actually collects and does with it — not legal boilerplate copied from a template. If something here is unclear, email us and we'll clarify it directly.

What we collect from you

Running a free scan needs nothing from you — no signup, just the URL you want scanned. Nothing about you is collected at that point.

If you ask us to email your report, or if you buy the full report or weekly monitoring, we store the email address you provide (via the report form, or from Stripe at checkout) so we can send the report or monitoring alerts. Payment itself is handled entirely by Stripe's hosted checkout page — we never see or store your card number.

Signing in to your dashboard

If you have an active monitoring or Agency subscription, you can sign in at /login to see your monitored sites. Sign-in uses a one-click link emailed to you — no password to create or for us to store. This is handled by Supabase (the same provider that stores scan/monitoring data), which manages the sign-in session via a cookie in your browser. Once signed in, the dashboard only ever shows sites tied to your own email address.

What the scan collects about the site you enter

When you scan a URL, a real headless browser loads that page and records what fires before any consent is given: which known tracker signatures matched (by name, e.g. "GA4" or "Meta Pixel"), which tracking cookies were set (by name and domain — not their values), and whether a consent banner and Google Consent Mode v2 signals were detected. This is technical information about the scanned site's behavior, not personal data about you as the visitor — unless the site you scan happens to be your own, in which case it's a technical report about your site, same as any audit tool.

How we store it

Scan results are stored in our database (Supabase/Postgres) keyed by a random, unlisted UUID — the link in your report URL. These links aren't indexed by search engines, aren't listed anywhere public, and aren't searchable. Nobody sees a report but you unless you share the link yourself.

Third parties we use

  • Stripe — payment processing for the $19 report unlock and $29/mo monitoring.
  • Resend — sends transactional email only (your report, monitoring alerts). No marketing list.
  • Supabase — database storage for scans/monitors, and (for monitoring/Agency customers) passwordless dashboard sign-in.
  • Vercel — hosting, plus Vercel Analytics, which is cookieless and doesn't track individual visitors.
  • Silktide Consent Manager — the cookie banner on this site. Yes, we use one too.

Retention

Honest answer: we don't currently delete scan or monitoring data automatically, so it's retained indefinitely today. If you want a report or your monitoring record deleted, email us and we'll remove it manually — we're a small operation and this is currently a human process, not a self-serve button.

Your requests

There's no self-serve deletion yet, even for dashboard accounts — any request (access, correction, deletion) goes through email. Send it to the address below and we'll handle it directly.

Cookies on this site

This site itself uses a cookie consent banner (Silktide Consent Manager) to gate its own cookies. You can change your choice at any time using the icon in the corner of the page.

Changes to this policy

If what we collect or how we use it changes, we'll update this page and the "last updated" date above.

Contact

support@getconsentcheck.com