Skip to content

Legal

Privacy policy

Last updated August 24, 2026.

Overview

OptinStack LLC ("we", "us", "our") operates OptinStack, a consent management platform that helps website operators present consent notices, manage visitor preferences, and enforce tracker choices.

Registered address: 30 N Gould St, STE R, Sheridan, WY 82801, USA.

This privacy policy describes how we handle personal data when you visit https://optinstack.com/, create an account, or use our services. For privacy questions, contact OptinStack hello@optinstack.com.

The roles we play

Depending on the context, OptinStack acts in two different roles. Understanding which applies to you matters for your rights and for who responds to your requests.

As a controller, we decide the purposes of processing for our own marketing site visitors, our account holders, and our newsletter subscribers. This policy covers that activity.

As a processor, we process your visitors' consent data on your behalf when you deploy OptinStack on your website. You are the controller of that data. We handle it according to your instructions and our Data Processing Agreement. Requests from your website visitors about their consent data should be directed to you, the controller.

Data we collect

When you interact with us as a controller (for example as a visitor to optinstack.com or an account holder), we collect information in these categories:

  • Account data: name, email address, and authentication identifiers when you sign up via our identity provider.
  • Customer account and configuration data we handle as controller: project names, domain names, user roles, subscription state, and the configuration actions account users take. Scan results include public URLs and tracker metadata observed during customer-initiated discovery; scans are not security assessments.
  • End-user consent data we process as your processor: when a visitor to your site interacts with your consent banner, we store a consent record that includes a salted hash of their IP address (never the raw IP), the full browser user agent string, a server-derived region code, the page URL and domain, the consent action and mode, selected consent categories, the Global Privacy Control signal if present, a banner text snapshot, runtime version metadata, and optional legislation or framework fields (for example TCF or GPP strings when those features are enabled for your project). We do not receive a device identifier or precise location.
  • Billing data: subscription tier, domain billed, and payment references. Card details are collected and processed by Paddle, our Merchant of Record and authorized reseller, and are not stored on OptinStack servers.
  • Usage data: product analytics, support correspondence, and technical logs needed to operate and secure the service.
  • Website data: standard server logs and cookies or similar technologies when you browse our marketing site.
  • Anonymous website measurement: Cloudflare Web Analytics (including related Real User Monitoring beacons such as beacon.min.js and /cdn-cgi/rum) may run on the marketing site without setting cookies or localStorage and without fingerprinting visitors for analytics reporting, according to Cloudflare’s product documentation. We use this to understand aggregate traffic and performance.

Lawful basis for processing (GDPR)

Where the GDPR applies to data we process as a controller, we rely on the following lawful bases. Where you process visitor data through OptinStack, you determine and are responsible for the lawful basis for that processing as the controller.

  • Consent (Article 6(1)(a)): for non-essential cookies and similar client-side storage technologies on our marketing site (for example Google Analytics cookies after you accept analytics in the consent banner), and for newsletter subscriptions.
  • Contract (Article 6(1)(b)): to provide your account and the services you sign up for.
  • Legitimate interests (Article 6(1)(f)): to secure, monitor, and improve the service, prevent abuse and fraud, detect and resolve bugs, maintain service integrity, and operate cookieless aggregate website measurement (Cloudflare Web Analytics) where we do not set non-essential cookies for that purpose. You may object to processing based on legitimate interests where applicable.
  • Legal obligation (Article 6(1)(c)): to retain billing and tax records where required by law.

How we use data

We use personal data to:

  • Provide, maintain, and improve the consent management platform.
  • Authenticate users and enforce role-based access.
  • Process subscriptions and communicate about billing.
  • Respond to support requests and security incidents.
  • Comply with legal obligations and enforce our terms.

When you deploy OptinStack on your website, you act as the controller of visitor consent data collected through your configuration. We process that data on your behalf as a processor according to your instructions and applicable agreements.

You are responsible for presenting accurate privacy notices to your visitors and linking to your own policies from your consent banner and consent preferences surfaces. Requests from your visitors to access, correct, or delete their consent data should come through you; we will assist you where feasible as described in our Data Processing Agreement.

Tracker scan results and automatic category assignments are automated estimates that may be incomplete or incorrect. As the controller, you remain responsible for reviewing those outputs and determining the correct legal category of every tracker used on your properties.

Business and Enterprise customers, including eligible Workspace Business projects, may make a one-time selection of a preferred Cloudflare R2 location hint for authoritative consent records, regional cold consent-analytics archives, and temporary CSV export artifacts. Available hints are Western Europe, Eastern Europe, Western North America, Eastern North America, Asia-Pacific, and Oceania. Free and Pro projects use Western Europe by default.

A location hint is a best-effort placement preference. It is not a promise of country-specific storage, data residency, jurisdiction, or exclusive processing in that region. Cloudflare edge processing, queues, Pipelines, Analytics Engine, service logs, transient processing, support, security, and administration may remain global. Analytics Engine is a disclosed global hot-analytics and fair-use system with a maximum three-month window.

The selection applies to future records after it becomes effective. Records created under an earlier assignment remain in their prior region and are included in authorized reads, exports, retention, and deletion. Automated historical migration is not included; contact support to discuss exceptional migration needs.

On a Pro, Business, Enterprise, or Workspace Business hostname, you may optionally configure Consent Forwarding so that each saved consent record is also sent to an HTTPS endpoint you control. You choose the endpoint URL and credentials; you remain the controller of data delivered there, and the endpoint operator is your processor or service provider, not an OptinStack sub-processor.

Forwarding is intended for operational copies, internal reporting, warehouse ingestion, or long-term archives beyond OptinStack storage. OptinStack plan retention and automatic deletion still apply to records stored in OptinStack even when forwarding is enabled. If a forward delivery fails, you remain responsible for monitoring your endpoint; OptinStack does not guarantee that your archive is complete.

You can disable forwarding or change the endpoint in your workspace settings. Disabling forwarding does not delete records already delivered to your endpoint.

OptinStack is designed to record consent activity while minimizing the personal data stored in consent records.

We do not retain a visitor's raw IP address in the consent record. Before the event is stored, the address is transformed into a project-specific salted hash designed not to be directly reversible to the original address.

Consent records also contain information needed to document the consent event, including the consent action, selected consent categories, page URL, server-derived region, banner content snapshot, and browser user agent string.

These records are intended to document what consent activity occurred on a website. They are not designed to identify a visitor by name, email address, account, or other direct identifier.

As the website operator, you can review consent activity and download individual consent evidence PDFs from your workspace on every plan. CSV export of consent records is available on Pro and above. However, OptinStack does not provide functionality that allows a consent record to be used to directly identify or contact an individual visitor.

Service providers and subprocessors

We use trusted infrastructure and service providers to operate OptinStack. We do not sell personal data or personal information.

A current, categorized list is published at Subprocessors and Service Providers. That page distinguishes (1) Customer Data Subprocessors we engage when we process Customer Personal Data as your processor, from (2) other service providers and independent controllers that support OptinStack in our own controller capacity or sell subscriptions as Merchant of Record.

Customer Data Subprocessors. When we act as your processor, the categories of personal data we share with each sub-processor are limited to what is necessary to provide the Service:

  • Cloudflare (hosting, CDN, storage, edge compute): consent records, account and configuration data, and related operational data processed to deliver the Service.
  • OpenAI (optional AI-assisted tracker classification and AI banner design on entitled plans): limited tracker metadata, public-page observations, and styling context submitted for the requested feature. Tracker classification may use hosted web search. AI output is a draft that requires editor review before it is saved to a project. These features are not intended to receive visitor consent records, raw IP addresses, payment information, or account credentials.
  • Google Cloud Translation (optional banner translations on Business and Enterprise plans): banner and preferences text you choose to translate. Does not receive visitor consent records, raw IP addresses, payment information, or account credentials.

Other service providers and independent controllers

The following providers process personal data as independent controllers or as service providers supporting OptinStack when we act as controller (for example account authentication, product analytics, and billing). They are not Customer Data Subprocessors under our DPA for your website visitors’ consent data:

  • Clerk (authentication): email address, authentication identifiers, and role metadata for OptinStack account holders. Credentials are held by Clerk, not OptinStack.
  • Paddle (Merchant of Record and authorized reseller): buyer name, email, billing address, and payment card data as needed to complete checkout. Card details are held by Paddle and not stored on OptinStack servers. Paddle acts as an independent controller for buyer personal data in connection with the purchase transaction.
  • Product analytics (where used in the operated platform): customer product events, diagnostics, and aggregated consent counts. Visitor-level consent events and salted visitor hashes are not sent to our product-analytics provider.

Retention

Account, workspace, and billing data is retained while your account is active and for a reasonable period afterward to comply with legal obligations and resolve disputes.

Consent records collected through your configuration are retained according to the plan for each project, unless you request earlier deletion: three (3) years on Free, Pro, Business, and Workspace site-pack plans, and five (5) years or a custom period on Enterprise. Records that pass the end of the applicable window are scheduled for deletion from OptinStack’s active consent-record store, following a short technical buffer after that window. Archiving a project stops runtime activity but does not pause or extend the applicable retention window. You may delete individual consent records from your workspace; verified project-wide erasure requires a support request. Enterprise customers may agree a different retention period in writing. Other logs, backups, exports, and forwarded copies follow separate lifecycles.

We do not retain raw IP addresses in consent records. Visitor identifiers in those records are salted hashes designed not to be directly reversible to an address. A browser user agent string is retained with a consent record to document the technical context of the event and may appear in an event export.

Operational logs, analytics, billing records, and security records follow separate schedules based on record type and legal or operational need.

Security

We apply administrative, technical, and organizational measures designed to protect personal data. These include encryption of personal data in transit (TLS), encryption at rest as provided by our infrastructure providers for hosted storage and databases, application-level encryption for selected secrets (for example OAuth tokens and Consent Forwarding credentials we store on your behalf), role-based access controls following least-privilege principles, multi-factor authentication available through our identity provider for account access, audit logging of sensitive actions, and ongoing monitoring of production systems.

No method of transmission or storage is completely secure. You are responsible for securing access to your account credentials and workspace permissions.

Your privacy rights

Depending on your location, you may have rights in relation to the personal data we hold about you. Where the GDPR applies, these include the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object to processing, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects; we do not carry out such processing.

We do not sell personal data or personal information.

Residents of the EEA, UK, or Switzerland may lodge a complaint with the supervisory authority in their country of residence, place of work, or place of the alleged infringement. Residents of other jurisdictions may contact their local data protection or consumer authority.

Submit privacy requests to OptinStack hello@optinstack.com. We will respond within the timeframe required by applicable law.

Children

OptinStack is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe we have collected personal data from a child, contact us at the address above and we will take steps to delete it.

California consumer rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you rights to know, access, delete, and correct your personal information, and to opt out of its sale or sharing.

Sale and sharing. OptinStack does not sell personal information. We do not share personal information for cross-context behavioral advertising as a controller of our own site and account data.

Sensitive personal information. OptinStack is not designed for customers to submit sensitive personal information through ordinary account and configuration fields. If applicable law treats data we hold as sensitive, any non-waivable rights under that law remain available.

Global Privacy Control. The OptinStack runtime detects the Global Privacy Control signal on customer websites and applies the configured sale-or-sharing opt-out behavior. Advanced GPC configuration is available on Business and Enterprise. Customers remain responsible for configuring and testing the behavior required for their properties.

Exercising your rights. To exercise your California privacy rights, contact OptinStack hello@optinstack.com. We respond to verified requests within 45 days. We do not discriminate against consumers who exercise privacy rights, and we do not offer financial incentives for the sale of personal information.

International transfers

We may process data in countries other than your own, including the United States. Our infrastructure runs on a global edge network with no region pinning by default. Where required, the transfer terms in our DPA make the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) and applicable UK and Swiss adaptations available to affected customers on Free and paid self-serve plans as well as Enterprise.

Changes

We may update this policy from time to time. Material changes will be posted on this page with an updated "Last updated" date.