Privacy Policy
How Finsweet handles personal data as a controller for Consent Pro customers, and as a processor for consent records captured on customer websites.
Last updated: September 17, 2026
1. What this policy covers, and the two roles we play
Consent Pro is a consent management platform. Businesses install it on their websites to present a consent banner to their visitors and to keep a record of the consent choices those visitors make.
That means Finsweet handles personal data in two different capacities, with different rules attached to each. This policy is split accordingly, and the split is not cosmetic — the rights available to you and the party you exercise them against depend on which part applies.
| Part A | Part B | |
|---|---|---|
| Whose data | Consent Pro customers — account holders, billing contacts, people who contact support | End Users — visitors to a website that has Consent Pro installed |
| Finsweet's role | Controller. We decide why and how this data is processed. | Processor. We process on the documented instructions of the customer operating the website. |
| Who you contact about your rights | Finsweet — see §2.6 | The operator of the website you visited — see §3.7 |
If you are a visitor to someone else's website and you are looking for who is responsible for your consent record: it is the operator of that website, not Finsweet. Part B explains what we hold on their behalf and how to reach them.
PART A — Where Finsweet is the controller
Applies to Consent Pro customers and prospective customers.
2.1 What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, organisation, account credentials | You |
| Billing data | Billing contact, address, subscription tier, transaction records | You / payment processor |
| Support data | Correspondence, tickets, forum posts, diagnostic detail you send us | You |
| Product usage data | Configuration, feature use, log and telemetry data from the Consent Pro dashboard | Automatic |
| Website usage data | IP address, device/browser information, pages visited, and identifiers stored via cookies and similar technologies on consentpro.com | Automatic — see the Cookie Declaration |
| Marketing data | Contact preferences, campaign engagement | You / automatic |
2.2 Why we process it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and operating the Consent Pro service | Contract — Art. 6(1)(b) |
| Billing, collections, tax and accounting records | Contract; legal obligation — Art. 6(1)(b), (c) |
| Support and service communications | Contract; legitimate interests — Art. 6(1)(b), (f) |
| Product security, identity verification, abuse and fraud prevention, integrity | Legitimate interests — Art. 6(1)(f) |
| Product improvement and analytics | Legitimate interests — Art. 6(1)(f) |
| Operating consentpro.com, including strictly necessary cookies | Legitimate interests — Art. 6(1)(f); where a cookie is strictly necessary to provide a service you requested, ePrivacy Art. 5(3) exemption |
| Analytics, functional and advertising cookies on consentpro.com | Consent — Art. 6(1)(a) and ePrivacy Art. 5(3). Categories, names and how to withdraw are in the Cookie Declaration |
| Marketing to business contacts | Legitimate interests or consent, depending on jurisdiction — Art. 6(1)(f) or (a) |
Where we rely on legitimate interests you may object; see §2.6.
2.3 Who we share it with
Service providers who process Part A data on our behalf, including hosting and infrastructure, payment processing, and email delivery. We also use Google Ads, Google Tag Manager and Google Analytics (GA4) on consentpro.com for advertising and analytics purposes, including conversion measurement and remarketing/retargeting. We do not use a separate dedicated tool for support or error monitoring — support is handled by email (§10) and error monitoring runs on our hosting provider's own built-in tooling, rather than through a distinct vendor. Our current service providers are listed at https://trust.finsweet.com/subprocessors.
We do not sell personal data. Our use of the advertising technology described above may, depending on how it is configured, constitute "sharing" personal information for cross-context behavioral advertising under the CCPA/CPRA and similar state laws — see §8 for how to opt out. We do not otherwise sell or share personal data.
2.4 How long we keep it
We generally retain Part A personal data for as long as necessary to provide and operate the Service. Closing your account does not by itself trigger automatic deletion: we may continue to retain data after closure until deletion or anonymisation is requested (see "Forget Me Finsweet," §2.6), except that individual systems we use may delete or anonymise data earlier, on their own technical or operational schedules — that is a matter of how those systems operate, not a retention commitment we make here.
We may also retain certain information for as long as necessary or permitted for legal, tax, accounting, security, fraud-prevention, dispute-resolution, or other legitimate business purposes, even after a deletion request. For example, billing and tax records are generally kept for seven years, as required by law.
2.5 Where it goes
Finsweet is US-based (Merrick, New York). If you are in the EEA, UK or Switzerland, your data is transferred to the US. See §5 for the mechanism.
2.6 Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to our processing of your personal data, and to withdraw consent where we rely on it. If you are a California resident, or a resident of another US state with a comprehensive privacy law, see §8 for the rights and response times specific to those laws.
To exercise these rights, use Forget Me Finsweet at finsweet.com/forget-me, or contact us at privacy@finsweet.com.
If you are in the EEA, UK or Switzerland, we will respond to a request within one month of receipt, extendable by a further two months for complex or numerous requests (three months in total), with notice to you if an extension applies.
Note. Forget Me Finsweet is Finsweet's general data-deletion mechanism — not specific to Consent Pro or to any one product — and reaches the range of current and archived systems Finsweet uses to operate its products, including the ones that support this Service (§2.1, §2.4). It does not delete consent records held under Part B; those are held on behalf of the website operator and are addressed in §3.7. It also does not guarantee erasure of every record: as described in §2.4, certain information may be retained where necessary or permitted for legal, tax, accounting, security, fraud-prevention, dispute-resolution or other legitimate purposes, and individual systems may complete deletion or anonymisation on their own timelines.
You may lodge a complaint with your supervisory authority. In the EEA, that is the authority in your country of residence, work or the place of the alleged infringement.
PART B — Where Finsweet is a processor
Applies to Consent Data about End Users of customer websites.
3.1 Our role
When a business installs Consent Pro on its website, that business decides what the banner says, which categories it offers, and how long records are kept in its configuration. It is the controller. Finsweet is a processor, acting only on that business's documented instructions and under a data processing agreement. The DPA is also available on request by emailing privacy@finsweet.com.
As part of providing the Service, Consent Pro may scan a website operator's Properties to detect cookies and similar tracking technologies in use, so the operator can categorise them and configure the banner accordingly. This scanning is performed on the operator's instructions and only for that purpose.
We do not decide the purposes of this processing. Other than the limited aggregated, de-identified uses described in §3.8, we do not use Consent Data for our own purposes.
3.2 What a consent record contains
| Field | Description |
|---|---|
| Record ID | A unique identifier for this consent record |
user_identifier | Pseudonymous identifier — see §3.3 |
| Consent state | The choice recorded (accept all, reject all, submit, or a granular preferences selection), and the resulting per-category state (essential, analytics, marketing, personalisation) |
| Timestamp | When the choice was recorded |
| Site / project | The website and Consent Pro project the choice was made on |
| Page URL | The page's origin and path where the choice was made (does not include the query string or URL fragment) |
| Consent mode | Which consent regime applied to the banner: opt-in, opt-out, informational, or "Do Not Sell" |
| Source | How the choice was captured: banner, preferences panel, or API |
| Runtime version | The version of the Consent Pro client script that captured the choice |
| Banner text | The literal text of the banner shown at the time, where captured |
| Region | Coarse, country-level signal used to determine the applicable regulatory framework — derived from the network edge, not GPS or IP geolocation beyond country |
| User agent | Browser and device information |
| Providers and trackers | The specific third-party providers and trackers active on the page at the time of the choice |
Consistent with our data processing agreement (§4.1), each record is maintained on an append-only basis — we do not correct or edit a record once it has been recorded (§3.7). Each consent interaction creates a new consent record rather than modifying an earlier one; an earlier record is not overwritten when an End User later changes their choice, and the separate records together preserve the sequence of choices made over time.
The Service does not implement the IAB Transparency and Consent Framework (TCF) or the IAB Global Privacy Platform (GPP), and does not store a TCF or GPP consent string.
Custom-endpoint forwarding. Where a website operator configures a custom storage endpoint, we also forward a subset of the consent record to that operator-controlled endpoint: the record ID, the action taken, the per-category consent choices, the literal banner text, the page URL, and the user agent string. We do not forward the pseudonymous user_identifier, the timestamp, the region signal, or the providers/trackers list to a custom endpoint — those fields stay only in Finsweet's own storage (§3.5). This is a real, separate data flow to a destination Finsweet does not control, and the operator — not Finsweet — determines what that endpoint does with the data once received.
3.3 The user_identifier is pseudonymous, not anonymous
We do not store the visitor's IP address. Instead, we derive an identifier by hashing the IP address together with a secret value we hold, and truncating the result.
This means the identifier cannot be reversed by anyone who obtains the record alone. It does not mean the data is anonymous. Because Finsweet holds the secret, the data remains pseudonymous personal data under the GDPR, and we treat it as such.
We state this plainly because the distinction is frequently blurred in this market, and because treating pseudonymous data as anonymous is the error that makes a consent log a liability rather than an asset.
The secret used to derive this identifier does not currently rotate. That is a narrower fact than it may first appear: because the identifier is derived from the visitor's IP address, it changes when that IP address changes — for example, when the visitor moves to a different network or their public IP address is reassigned. A non-rotating secret means only that the same IP address, hashed at two different times, still produces the same identifier — it does not mean any individual visitor is tied to one stable identifier for the full retention period described in §3.6.
3.4 Global Privacy Control
Consent Pro automatically detects the Global Privacy Control (GPC) signal transmitted by a visitor's browser. Where GPC communicates an opt-out from sale or sharing under applicable law, Consent Pro applies that opt-out to the applicable choices at runtime, including where an earlier stored choice would otherwise permit the affected activity. A website operator cannot disable detection of the signal. Other consent choices continue to be handled according to the banner mode configured by the operator and the visitor's valid choices.
The GPC signal is applied at runtime but is not written to the stored consent record, and Sec-GPC is not captured at server ingest. This means the record does not, on its own, evidence that a GPC signal was received or that it was applied — a limitation we state plainly rather than imply otherwise. This matches §4.2 of our data processing agreement. If the ingest path begins capturing GPC server-side, this section and the DPA will be updated together to describe the record field.
3.5 Where Consent Data is stored
Consent records are stored in Cloudflare object storage (R2) with Western Europe (WEUR) data residency, captured through our Cloudflare Workers-based ingest pipeline. Aggregated, de-identified statistics (domain, action, region, consent status, mode, device type — no user_identifier, no page URL) are separately written to Cloudflare Analytics Engine for customer dashboards.
3.6 How long Consent Data is kept
Our retention policy is to keep each consent record for five years from that record's own timestamp — the date of the consent interaction it reflects. Where a visitor later makes a new choice, that choice is captured as a separate consent record (§3.7) with its own five-year period; an earlier record's retention period is not extended or reset by a later one. We have not yet implemented an automated mechanism that deletes Consent Data once it reaches the end of this period — until we do, a record is not automatically deleted at the five-year mark. See §3.7 for how an operator's instruction regarding a record is currently carried out, and how we can remove an operator's data in full on request. On termination of the operator's contract, Consent Data is deleted or returned as set out in our data processing agreement.
The aggregated, de-identified statistics described in §3.5 are not tied to an identified consent record and are retained for as long as the operator's account with us remains open.
Retention is aligned with §8.5 of the Terms of Service and §4.3 of the data processing agreement; if those periods change, this section changes with them.
3.7 If you are an End User and you want your consent record accessed or deleted
Contact the operator of the website where you made the choice. They are the controller of that record and they decide whether and how it is actioned.
Finsweet does not offer visitors a self-service route to access, export, or delete a consent record. Where the website operator instructs us in accordance with our data processing agreement — identifying the record, including by its Consent ID — we action that instruction to access or export the specific record. We do not correct or edit a consent record once it has been recorded — each record reflects the choice made at the time, and a later change in choice is captured as a new record rather than an edit to an earlier one. Once a record has been exported, or forwarded to a destination the operator controls, any changes made to that copy are the operator's own and do not change the record we hold. We do not currently support deleting an individual consent record, a visitor's records, or an operator's consent logs, through Consent Pro or via our API. Where an operator needs all of its data removed before the retention period described in §3.6 otherwise applies, we can do so through Finsweet's existing account-level data-deletion process ("Forget Me Finsweet"), which removes all of that operator's data rather than a single record.
3.8 What we do not do with Consent Data
- We do not sell it or share it for cross-context behavioural advertising.
- We do not use it to train machine learning models. We may use aggregated, de-identified data that does not identify any visitor, customer or website to operate, secure and improve the Service — consistent with §3.4 of our data processing agreement.
- We do not combine one customer's Consent Data with another's.
- We do not use it to build profiles or to market to End Users.
3.9 Other individuals whose data we process for a website operator
When a website operator enters the name or contact details of its own data protection officer, EU or UK Article 27 representative, or privacy contact into the Consent Pro policy-generation tool, we process that information as a processor on the operator's instructions and render it into the Privacy Policy, Cookie Policy, or similar document the operator publishes on its own site. We process the operator's own company legal name, registered address and country for the same purpose.
If you are named in a policy document generated this way and want that information corrected or removed, contact the operator who published it — they control what is entered and published, the same way they control End Users' consent records (§3.7).
3.10 Government and third-party access requests
If we receive a legally binding request from a public authority or another third party for disclosure of Consent Data, our data processing agreement commits us to: notify the website operator without undue delay, unless the law prohibits it; tell the requesting party that we are a processor and are not authorised to disclose the data ourselves; direct the requesting party to the operator; and, where disclosure is legally compelled despite that, disclose only the minimum data required. We challenge requests we assess to be unlawful, and we do not voluntarily disclose Consent Data to any law enforcement or government agency.
As of the DPA Effective Date, Finsweet had not received a request from a government intelligence or security agency for access to Consent Data (DPA §13.4).
4. Sub-processors
Our current sub-processors are listed at https://trust.finsweet.com/subprocessors. Customers may subscribe to notifications of changes and may object to a new sub-processor as set out in the data processing agreement. Consent Pro uses OpenAI for AI-assisted configuration form-fill and tracker categorisation; OpenAI is named on that list.
5. International transfers
Finsweet is established in the United States. Consent Data is stored in Western Europe; Part A data is generally processed in the United States. If you are in the EEA, UK or Switzerland, this means some of your personal data is transferred to, or accessed from, the United States.
Finsweet is not currently certified under the EU–U.S. Data Privacy Framework (or its UK and Swiss extensions).
Where an international transfer of personal data is subject to applicable data-transfer restrictions, Finsweet uses appropriate safeguards as required by applicable law. Depending on the transfer, those safeguards may include the European Commission's Standard Contractual Clauses and the applicable UK transfer mechanism (such as the UK International Data Transfer Addendum), among others. Relevant third-party service providers we use may separately maintain their own lawful international-transfer mechanisms for their own processing. Where our data processing agreement with a customer addresses international transfers, that agreement governs the arrangements between us and that customer.
You may contact us at privacy@finsweet.com for more information about the safeguards that apply to a particular transfer.
6. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, and logging. We completed a SOC 2 Type II audit covering the 2025 reporting period.
7. Children
Consent Pro is a business tool and is not directed to children. Consent banners are served to whoever visits a customer's website, and we do not knowingly collect data from children through them. Where a customer's site is directed to children, the customer is responsible for the age-appropriate configuration of its banner and for any applicable parental consent requirements.
8. United States state privacy rights
Part A. If you are a California resident, or a resident of another US state with a comprehensive privacy law, you have the right to know/access, delete, correct and port your personal data, and to opt out of the sale or sharing of your personal data.
We do not sell personal data. We use advertising and analytics technology on consentpro.com — including Google Ads, Google Tag Manager and Google Analytics (GA4) — for purposes such as conversion measurement and remarketing/retargeting; depending on how that technology is configured, this can constitute "sharing" personal information for cross-context behavioral advertising under the CCPA/CPRA and similar state laws. You can opt out by emailing privacy@finsweet.com. We also recognize qualifying opt-out preference signals, including Global Privacy Control (GPC), as requests to opt out of sale or sharing where required by applicable law.
Response times differ by request type. For requests to know, delete, correct or port your personal data, we will respond within 45 days of receipt, extendable once by a further 45 days (90 days in total) where reasonably necessary, with notice to you of the extension. For requests to opt out of sale or sharing, we will comply as soon as feasibly possible and, in any case, within 15 business days of receipt.
Part B. Finsweet acts as a service provider (California) or processor (other states). We process Consent Data only for the business purposes specified in our agreement with the customer, we do not sell or share it, we do not retain, use or disclose it outside the direct business relationship, and we do not combine it with data from other sources except as permitted. End User requests should be directed to the website operator.
9. Changes to this policy
We will post any material change on this page and update the "Last updated" date. Where the change materially affects how we handle Consent Data, we will also notify customers as set out in the Terms of Service (§19.2).
10. Contact
Finsweet Inc.
1732 Pettit Avenue, Unit A, Merrick, New York 11566, USA
Data Protection Officer (GDPR Art. 37): Rohan Ganachari — rohan.ganachari@finsweet.com
EU representative (GDPR Art. 27): Alexandre Iglesias Piñol — Lleida, Catalonia, Spain — alex.iglesias@finsweet.com
UK representative (UK GDPR Art. 27): Rohan Ganachari — Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom — rohan.ganachari@finsweet.com