Overview
OptinStack LLC ("we", "us", "our") operates OptinStack, a consent management platform that helps website operators present consent notices, manage visitor preferences, and enforce tracker choices.
Registered address: 30 N Gould St, STE R, Sheridan, WY 82801, USA.
This privacy policy describes how we handle personal data when you visit https://optinstack.com, create an account, or use our services. For privacy questions, contact hello@optinstack.com.
The roles we play
Depending on the context, OptinStack acts in two different roles. Understanding which applies to you matters for your rights and for who responds to your requests.
As a controller, we decide the purposes of processing for our own marketing site visitors, our account holders, and our newsletter subscribers. This policy covers that activity.
As a processor, we process your visitors' consent data on your behalf when you deploy OptinStack on your website. You are the controller of that data. We handle it according to your instructions and our Data Processing Agreement. Requests from your website visitors about their consent data should be directed to you, the controller.
Data we collect
When you interact with us as a controller (for example as a visitor to optinstack.com or an account holder), we collect information in these categories:
- Account data: name, email address, and authentication identifiers when you sign up via our identity provider.
- Customer account and configuration data we handle as controller: project names, domain names, user roles, subscription state, and the configuration actions account users take. Scan results include public URLs and tracker metadata observed during customer-initiated discovery; scans are not security assessments.
- End-user consent data we process as your processor: when a visitor to your site interacts with your consent banner, we store a consent record that includes a salted hash of their IP address (never the raw IP), the full browser user agent string, a server-derived region code, the page URL and domain, the consent action and mode, selected consent categories, the Global Privacy Control signal if present, a banner text snapshot, runtime version metadata, and optional legislation or framework fields (for example TCF or GPP strings when those features are enabled for your project). We do not receive a device identifier or precise location.
- Billing data: subscription tier, domain billed, and payment references. Card details are collected and processed by Paddle (our Merchant of Record) and are not stored on OptinStack servers.
- Usage data: product analytics, support correspondence, and technical logs needed to operate and secure the service.
- Website data: standard server logs and cookies or similar technologies when you browse our marketing site.
Lawful basis for processing (GDPR)
Where the GDPR applies to data we process as a controller, we rely on the following lawful bases. Where you process visitor data through OptinStack, you determine and are responsible for the lawful basis for that processing as the controller.
- Consent (Article 6(1)(a)): for non-essential cookies and similar technologies on our marketing site, and for newsletter subscriptions.
- Contract (Article 6(1)(b)): to provide your account and the services you sign up for.
- Legitimate interests (Article 6(1)(f)): to secure, monitor, and improve the service, prevent abuse and fraud, detect and resolve bugs, and maintain service integrity.
- Legal obligation (Article 6(1)(c)): to retain billing and tax records where required by law.
How we use data
We use personal data to:
- Provide, maintain, and improve the consent management platform.
- Authenticate users and enforce role-based access.
- Process subscriptions and communicate about billing.
- Respond to support requests and security incidents.
- Comply with legal obligations and enforce our terms.
Consent records and customer sites
When you deploy OptinStack on your website, you act as the controller of visitor consent data collected through your configuration. We process that data on your behalf as a processor according to your instructions and applicable agreements.
You are responsible for presenting accurate privacy notices to your visitors and linking to your own policies from your consent banner and consent preferences surfaces. Requests from your visitors to access, correct, or delete their consent data should come through you; we will assist you where feasible as described in our Data Processing Agreement.
Preferred consent storage region
Business and Enterprise customers, including eligible Workspace Business projects, may make a one-time selection of a preferred Cloudflare R2 location hint for authoritative consent records, regional cold consent-analytics archives, and temporary CSV export artifacts. Available hints are Western Europe, Eastern Europe, Western North America, Eastern North America, Asia-Pacific, and Oceania. Free, Lite, and Pro projects use Western Europe by default.
A location hint is a best-effort placement preference. It is not a promise of country-specific storage, data residency, jurisdiction, or exclusive processing in that region. Cloudflare edge processing, queues, Pipelines, Analytics Engine, service logs, transient processing, support, security, and administration may remain global. Analytics Engine is a disclosed global hot-analytics and fair-use system with a maximum three-month window.
The selection applies to future records after it becomes effective. Records created under an earlier assignment remain in their prior region and are included in authorized reads, exports, retention, and deletion. Automated historical migration is not included; contact support to discuss exceptional migration needs.
Consent Forwarding
On an active Free or paid hostname, you may optionally configure Consent Forwarding so that each saved consent record is also sent to an HTTPS endpoint you control. You choose the endpoint URL and credentials; you remain the controller of data delivered there, and the endpoint operator is your processor or service provider, not an OptinStack sub-processor.
Forwarding is intended for operational copies, internal reporting, warehouse ingestion, or long-term archives beyond OptinStack storage. OptinStack standard-plan retention and automatic deletion still apply to records stored in OptinStack even when forwarding is enabled. If a forward delivery fails, you remain responsible for monitoring your endpoint; OptinStack does not guarantee that your archive is complete.
You can disable forwarding or change the endpoint in your workspace settings. Disabling forwarding does not delete records already delivered to your endpoint.
How we protect visitor privacy in consent records
OptinStack is designed to record consent activity while minimizing the personal data stored in consent records.
We do not store a visitor's raw IP address. Before a consent event is recorded, the IP address is transformed into a one-way salted hash that is specific to your project. The original IP address is not retained and cannot be recovered from the stored record.
Consent records also contain information needed to document the consent event, including the consent action, selected consent categories, page URL, server-derived region, banner content snapshot, and browser user agent string.
These records are intended to document what consent activity occurred on a website. They are not designed to identify a visitor by name, email address, account, or other direct identifier.
As the website operator, you can review consent activity and export consent records from your workspace. However, OptinStack does not provide functionality that allows a consent record to be used to directly identify or contact an individual visitor.
Subprocessors
We use trusted infrastructure and service providers to operate OptinStack. We do not sell personal data or personal information.
A current, categorized list of sub-processors, including the purpose of processing for each and where they operate, is published at our Subprocessors page (/legal/subprocessors). The categories of personal data we share with each sub-processor are limited to what is necessary to provide the Service:
- Cloudflare (hosting, CDN, storage, edge compute): all categories of data we process, including consent records, account data, and configuration.
- Clerk (authentication): email address, authentication identifiers, and role metadata. Credentials are held by Clerk, not OptinStack.
- Paddle (Merchant of Record for payments): buyer name, email, billing address, and payment card data. Card details are held by Paddle and not stored on OptinStack servers.
- Product analytics (where used in the operated platform): customer product events, diagnostics, and aggregated consent counts. Visitor-level consent events and salted visitor hashes are not sent to our product-analytics provider.
- Anthropic (Claude) (optional AI-assisted tracker classification and AI banner design on Business and Enterprise plans): tracker metadata only, including script URLs, cookie or storage names, domains, request URLs, and scanner observations, when an editor actively requests it. AI banner design receives only the styling context you provide in the dashboard. Neither service receives visitor consent records, raw IP addresses, payment information, or account credentials.
- Google Cloud Translation (optional banner translations on Business and Enterprise plans): banner and preferences text you choose to translate. Does not receive visitor consent records, raw IP addresses, payment information, or account credentials.
Retention
Account, workspace, and billing data is retained while your account is active and for a reasonable period afterward to comply with legal obligations and resolve disputes.
Consent records collected through your configuration are retained for twelve (12) months on standard plans, unless you request earlier deletion. Archiving a project stops runtime activity but does not pause or extend the standard retention window. You may delete individual consent records from your workspace at any time; verified project-wide erasure requires a support request. Enterprise customers may negotiate a different retention period under a separate written agreement.
We do not retain raw IP addresses. Visitor identifiers in consent records are salted hashes that cannot be reversed to an address. The full browser user agent string is retained with each consent record because it forms part of the evidence of the consent event and is reproduced in proof exports.
Operational logs and analytics are retained according to our internal schedules: subscription lifecycle audit logs for up to 730 days, administrator audit logs for up to 365 days, and payment idempotency records for up to 90 days. Aggregated analytics older than 60 days are moved to cold storage.
Security
We apply administrative, technical, and organizational measures designed to protect personal data. These include encryption of personal data in transit (TLS), encryption at rest as provided by our infrastructure providers for hosted storage and databases, application-level encryption for selected secrets (for example OAuth tokens and Consent Forwarding credentials we store on your behalf), role-based access controls following least-privilege principles, multi-factor authentication available through our identity provider for account access, audit logging of sensitive actions, and ongoing monitoring of production systems.
No method of transmission or storage is completely secure. You are responsible for securing access to your account credentials and workspace permissions.
Your privacy rights
Depending on your location, you may have rights in relation to the personal data we hold about you. Where the GDPR applies, these include the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object to processing, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects; we do not carry out such processing.
We do not sell personal data or personal information.
Residents of the EEA, UK, or Switzerland may lodge a complaint with the supervisory authority in their country of residence, place of work, or place of the alleged infringement. Residents of other jurisdictions may contact their local data protection or consumer authority.
Submit privacy requests to hello@optinstack.com. We will respond within the timeframe required by applicable law.
Children
OptinStack is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe we have collected personal data from a child, contact us at the address above and we will take steps to delete it.
California consumer rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you rights to know, access, delete, and correct your personal information, and to opt out of its sale or sharing.
Sale and sharing. OptinStack does not sell personal information. We do not share personal information for cross-context behavioral advertising as a controller of our own site and account data.
Sensitive personal information. We do not collect or process categories of sensitive personal information as defined by the CPRA. The right to limit the use of sensitive personal information therefore does not apply to the data we hold as a controller.
Global Privacy Control. For visitors to our customers' websites, OptinStack honors the Global Privacy Control signal and equivalent opt-out preference signals as requests to opt out of the sale or sharing of personal information, as configured by each customer for their properties.
Exercising your rights. To exercise your California privacy rights, contact hello@optinstack.com. We respond to verified requests within 45 days. We do not discriminate against consumers who exercise privacy rights, and we do not offer financial incentives for the sale of personal information.
International transfers
We may process data in countries other than your own, including the United States. Our infrastructure runs on a global edge network with no region pinning by default. Where required, the transfer terms in our DPA make the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) and applicable UK and Swiss adaptations available to affected customers on Free and paid self-serve plans as well as Enterprise.
Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated "Last updated" date.