Privacy Policy
CookiesRegTech (Cookies Regulatory Technology) — a product of SKYNET TECHNOLOGIES USA LLC, 9045 SW 79th Avenue, Gainesville, FL 32608, United States ("we", "us").
Effective date: August 5, 2026
This policy explains what personal data the CookiesRegTech service collects, why, and what rights you have. It covers the dashboard at www.cookiesregtech.com, the public cookie checker, our platform plugins, and the consent script that our customers install on their websites.
1. Two roles: controller and processor
- For our customers (people who create a CookiesRegTech account) we are the data controller of account and billing data.
- For visitors of our customers' websites, the website owner is the controller; CookiesRegTech acts as a processor, storing consent records on the owner's behalf. If you are such a visitor, please direct privacy requests to the website you visited — we support the owner in fulfilling them.
2. Data we collect
Account data (customers): account name, email address, hashed password, team member emails and roles, sign-in timestamps.
Billing data (customers): handled by our payment processor Stripe. We store your plan, billing interval, and Stripe references — we never see or store card numbers.
Website data (customers): the domains you add, scan results (cookies, scripts, categories), banner configurations, and languages.
Consent records (visitors of customer sites): when a visitor makes a cookie choice, we store the consent ID, chosen categories, banner version and shown text, jurisdiction, timestamp, country/region (derived from the IP address at request time), and one-way hashes of the IP address and browser user-agent. We do not store visitors' raw IP addresses with consent records, and the derivation of country happens on our own server — visitor IPs are not sent to any third party.
Public cookie checker: when someone scans a website on our free checker page we log the scanned URL, the requesting IP address, derived country, and timestamp, to prevent abuse and understand usage.
Emails: if you contact us or receive service emails (welcome, invoices, scan results), we process your email address and the message content.
3. Cookies and local storage we use ourselves
- Dashboard: a browser localStorage entry keeps you signed in. No advertising or cross-site tracking cookies.
- On customer websites: the consent script stores the visitor's own consent choice (a
cookiestar_consent_…localStorage entry and a matching cookie) so the choice is remembered. This storage is strictly necessary for the consent function itself.
4. Why we process data (legal bases)
- To provide the Service under our contract with you (account, billing, scans, banners, consent storage).
- Legitimate interests: service security, abuse prevention (rate limits, checker logs), and improving the product.
- Legal obligations: tax and accounting records for payments.
- Consent, where required (e.g., optional communications).
5. Who we share data with (subprocessors)
We share data only with providers needed to run the Service: Stripe (payments), our hosting provider (server infrastructure in the United States), and our email delivery provider (transactional emails). We do not sell personal data and we do not share it for advertising.
6. International transfers
Our servers are located in the United States. If you use the Service from another region, your data is processed in the USA with the safeguards described in this policy.
7. Retention
Account data is kept while your account exists. Consent records are kept for as long as the website owner's account requires them as proof of consent. Deleting a site deletes its scans, banner configurations, and consent records; deleting an account deletes everything associated with it. Checker logs and server logs are kept for a limited operational period.
8. Your rights
Depending on your location (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to object to certain processing. To exercise these rights, contact us using the details below. Website visitors should contact the owner of the website they visited (see Section 1); we assist owners in responding.
9. Security
Passwords are stored as strong one-way hashes, visitor IPs in consent records are hashed, secrets are kept outside the code repository, access to production systems is restricted, and all traffic to the Service is encrypted in transit (HTTPS).
10. Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect children's data.
11. Changes to this policy
We may update this policy; material changes are announced by email or in the dashboard. The effective date above always reflects the current version.
12. Contact
SKYNET TECHNOLOGIES USA LLC 9045 SW 79th Avenue, Gainesville, FL 32608, United States Email: support@skynettechnologies.com