Consentinel Privacy Policy
Last updated: August 12, 2026
This Privacy Policy explains how SLI Studios Web Development, LLC, a Florida limited liability company doing business as Consentinel ("Consentinel," "we," "us," or "our"), handles personal information through consentinel.co, app.consentinel.co, the Consentinel hosted service, and the optional Cloud connection in the Consentinel WordPress plugin.
Consentinel is designed to minimize personal information. We do not sell personal information or share it for cross-context behavioral advertising.
1. The public WordPress plugin and local mode
The free Consentinel Plugin can operate entirely on the WordPress site where it is installed. In local mode:
- scanner results, settings, consent choices, timestamps, truncated and salted-hashed IP addresses, hashed user-agent strings, and related consent records remain in the site operator's WordPress database;
- the Plugin's scanner requests pages only from that same WordPress site;
- no account is required and the Plugin makes no outbound connection to Consentinel; and
- Consentinel does not receive or control this local data and is not the controller, business, processor, or service provider for it.
The WordPress site operator is responsible for its own privacy notice, lawful basis, retention, security, data-subject requests, and use of the Plugin. Site visitors should direct requests about locally stored Plugin data to that site operator.
Plugin branding and public-site links are off by default. If a site operator enables a Consentinel link, no information is sent to us unless a visitor clicks it. The destination URL may identify the referring site's domain and link placement, and ordinary web-server data such as the visitor's IP address and browser information may then be processed when our site loads.
WordPress.org independently processes directory, account, download, and update information under its own privacy terms. We do not control WordPress.org.
2. Public website scans
Anyone may request a free scan of a publicly accessible website from consentinel.co without creating an account. For a public scan, Consentinel fetches the submitted domain's public home page once, server-side, and reads the returned HTML without executing page JavaScript. The public scan is not a deep crawl and does not verify that the requester owns or controls the domain.
For each completed public scan, we may store:
- the normalized domain, scan date and time, detected platform, result or verdict, number of tracker matches, and tracker-catalog findings; and
- a random scan identifier used to display and, if requested, claim the result.
We do not store the requester's email address, IP address, or user-agent string in the public scan record. We process the requester's IP address transiently to rate-limit and secure the scanner, and our hosting and security providers may process ordinary request information, including IP address, browser or device information, requested URL, and timestamps, in operational logs as described in Section 4. An unclaimed scan is not associated with a Consentinel account, although a domain or scan content may itself relate to an identifiable individual or sole proprietor and therefore may constitute personal information in context.
We retain an unclaimed public scan for up to 90 days and then schedule it for deletion. If a person creates an account and uses the scan's claim link, we associate the scan with that person's Customer organization so authorized organization members can view, print, and use the full result. Claiming a scan does not establish ownership or control of the scanned domain and does not authorize a deep crawl. DNS-based domain verification remains required before a deeper multi-page crawl.
Claimed scans are retained while associated with an active Customer organization and afterward only for the limited periods described in Section 10, subject to deletion requests, backup cycles, security needs, disputes, legal requirements, and documented legal holds. We do not sell or share public scan records for cross-context behavioral advertising.
The operator of a scanned website may receive an ordinary server request from Consentinel's scanner and may record that request under its own logging and privacy practices. The public scan stores tracker-catalog findings, not a copy of the fetched page HTML. Scan results are automated technical observations, may be incomplete, and are not proof of ownership, legal compliance, or a legal violation.
3. When a WordPress site is connected to Consentinel Cloud
Connection is optional and must be initiated by a site administrator. During connection and operation, we may process:
- the site's domain, WordPress return URL, one-time PKCE challenge and verifier, authorization code, Plugin version, site-scoped access token, connection status, and configuration-sync events;
- blocking configuration and site-crawl results associated with the Customer account; and
- when the connected hosted banner is published, visitor consent-event data described in Section 4.
Routine configuration and status requests from the connected Plugin do not send page content, local consent records, or visitor data. Consentinel may call the site's documented challenge and configuration-notification endpoints while connected. If a connected Plugin is uninstalled with local deletion selected, it may make one status request to determine whether a legal hold requires preservation, as described in the Plugin documentation.
Disconnecting removes the remote script and restores local Plugin operation. Data already held in the Hosted Service remains subject to the Customer's plan, deletion requests, legal holds, and our retention rules.
4. Our roles and the personal information we process
Customer and account data - we are a controller/business. We process account email address and authentication data (including a password hash handled by our authentication provider), organization name, invite information, site domains, configurations, support communications, access and audit events, plan and subscription information, and Stripe customer or subscription identifiers. Stripe processes payment-card details; Consentinel does not store full card numbers.
Connected-site visitor data - we are a processor/service provider. When a Customer publishes the hosted consent interface, we process on that Customer's behalf:
- consent choice by category, choice method, Global Privacy Control signal, timestamp, banner-configuration version, and SDK version;
- a one-way salted hash of a truncated IP address (IPv4 /24 or IPv6 /64); the raw IP address is processed transiently to deliver and secure the request but is not stored in the consent record;
- a salted hash of the browser user-agent string; and
- a coarse jurisdiction tag, such as EEA or California, derived from available network-location information.
These identifiers are pseudonymous, not anonymous. We generally cannot identify a visitor from a consent record alone. The Customer remains responsible for the underlying site and determines the purposes and legal basis. Visitors should direct requests to the site operator; we assist under the DPA.
Website and service-use data - we are a controller/business. Our servers and providers may process IP address, browser and device information, requested URLs, timestamps, authentication events, error and security logs, and communications needed to deliver, secure, troubleshoot, and support our properties.
5. California notice at collection
Depending on how a person uses Consentinel, we may collect the following CCPA/CPRA categories: identifiers; customer-record information; commercial information; internet or other electronic-network activity; approximate geolocation; professional or employment-related information supplied for an organization account; and sensitive personal information consisting of account log-in credentials used only to authenticate and secure the account.
We collect these categories from users, Customers, connected WordPress sites, site visitors interacting with a hosted banner, service providers, and automatically from use of our properties. We use and retain them only for the purposes and periods described in this Policy. We do not use sensitive personal information to infer characteristics.
6. Purposes and lawful bases
For EEA, UK, and similar privacy laws, our lawful bases depend on the processing:
| Purpose | Typical information | Lawful basis when we are controller |
|---|---|---|
| Create accounts, connect sites, provide features, billing, and support | Account, organization, domain, configuration, subscription, communications | Performance of a contract or steps requested before contract |
| Secure the service, prevent abuse, troubleshoot, and maintain audit records | Network, authentication, error, and access events | Legitimate interests in security, reliability, and protecting users; legal obligation where applicable |
| Accounting, tax, legal claims, and required disclosures | Billing and relevant account or service records | Legal obligation and legitimate interests in establishing, exercising, or defending legal claims |
| Optional marketing communications or non-essential cookies on our properties | Contact details and cookie/device data | Consent where required; otherwise legitimate interests subject to opt-out rights |
When we process connected-site visitor data for a Customer, the Customer determines the lawful basis. We process that data on documented instructions under the DPA and do not independently use it for advertising, profiling, or marketing.
7. How we disclose information
We disclose information only as needed to provide and protect the service, complete transactions, comply with law, or carry out a transaction involving our business. Recipients may include:
| Provider or category | Purpose | Typical processing location |
|---|---|---|
| Supabase, Inc. | Hosted database, authentication, and edge functions | United States |
| Vercel, Inc. | Application, dashboard, and API hosting | United States and provider infrastructure |
| Stripe, Inc. | Subscription and payment processing; no Visitor Consent Data | United States and provider infrastructure |
| Cloudflare, Inc., if enabled | CDN delivery, network security, and domain verification | Global |
| Google Public DNS | DNS-over-HTTPS fallback for domain verification; receives the queried domain | Global |
| Professional advisers and authorities | Legal, accounting, insurance, security, and legally required disclosures | As required |
We may disclose information in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and continued legal obligations. Our current subprocessors for Customer Personal Data are identified in the DPA.
8. No sale or sharing; opt-out signals
Consentinel does not sell personal information and does not share it for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA. We do not use Customer data or connected-site visitor consent records for targeted advertising.
Because we do not engage in those practices on our own properties, there is currently no sale/share opt-out to exercise against Consentinel. If that changes, we will provide the required notice and opt-out mechanism and honor legally recognized opt-out preference signals.
The Plugin and Hosted Service provide tools for Customers to detect and record Global Privacy Control on their own sites. The Customer remains responsible for configuring its site and honoring all applicable opt-out rights. California law requires affirmative authorization before a business knowingly sells or shares personal information of a consumer under 16; Consentinel does not provide a mechanism to bypass that rule.
9. Cookies on our properties
The dashboard uses cookies or similar storage necessary for authentication, security, and the active-organization preference. We do not currently run advertising trackers in the dashboard. If we introduce optional analytics or marketing technologies, we will provide notice and obtain consent where required.
Cookies and storage used by a Customer's site, including the local Plugin consent cookie and Customer-selected trackers, are controlled by that Customer and should be described in the Customer's privacy and cookie notices.
10. Retention and deletion
- Hosted visitor consent records: 90 days on the Free Hosted plan or up to 24 months on paid plans, then scheduled for deletion.
- Published hosted configuration history: while the connected site exists, because it supports consent evidence, subject to legal holds and legal requirements.
- Account and organization data: while the account or organization remains active and for a limited period afterward as needed for security, disputes, backup cycling, and legal obligations.
- Billing and transaction records: for the period required by tax, accounting, and legal rules.
- Security, access, support, and diagnostic records: only as long as reasonably necessary for the purpose, risk, and applicable legal requirements.
Deleting a hosted site or organization initiates deletion of associated hosted data, ordinarily within 30 days from active systems, subject to backup cycles, legal requirements, fraud prevention, dispute resolution, and documented legal holds. Deleting a Cloud account does not delete data stored locally in an independently operated WordPress site.
11. International transfers
Consentinel is established in Florida, and the Hosted Service processes information in the United States and in locations used by our providers. Where required for transfers from the EEA, we use an adequacy decision or the European Commission's Standard Contractual Clauses, together with appropriate supplementary measures and transfer assessments. The DPA supplies the processor terms and transfer details for Customer Personal Data.
12. Security
We use measures designed to protect hosted data, including tenant isolation through row-level security, least-privilege access, TLS in transit, provider encryption at rest, pseudonymization of consent identifiers, server-side salts, append-only consent records, immutable published configurations, credential separation, and scheduled retention controls. No method of transmission or storage is completely secure.
Customer is responsible for security of its WordPress installation, administrators, database, hosting, backups, Plugin updates, and local-mode records.
13. Privacy rights and requests
Depending on location and applicable law, a person may have rights to know or access, correct, delete, or port personal information; restrict or object to processing; withdraw consent; opt out of sale, sharing, or targeted advertising; limit certain uses of sensitive personal information; appeal a denied request; and complain to a regulator or supervisory authority.
For Consentinel account or website data, contact privacy@consentinel.co. We may verify identity and authority before acting. Authorized agents may submit requests where permitted. We will not unlawfully discriminate or retaliate for exercising a privacy right.
For consent records created on a Customer's connected site, contact that site operator first. We will assist the operator under the DPA. For records stored only by the local Plugin, Consentinel has no access and cannot fulfill the request.
14. Children and parental rights
Consentinel accounts and the Hosted Service are intended for adults and organizations, not for children. We do not knowingly permit a person under 18 to create a Consentinel account.
The public Plugin can be installed by unrelated site operators, including on sites that may serve children. In local mode, Consentinel does not receive those visitors' data. A Customer that connects a child-directed or mixed-audience site is responsible for determining whether children's data will be processed, providing age-appropriate notices, selecting a lawful basis, obtaining and verifying parental or guardian authorization where required, and enabling parent or guardian access, correction, deletion, and withdrawal rights.
Under GDPR Article 8, the age at which a child may consent to an information-society service varies by Member State from 13 to 16. Under the CCPA/CPRA, a business with actual knowledge that a consumer is under 16 may not sell or share that consumer's personal information without the required affirmative authorization. Consentinel does not sell or share connected-site visitor data.
If you believe a child provided account information directly to Consentinel, contact privacy@consentinel.co. For a child's consent record on a Customer's site, contact the site operator; we will assist as legally required.
15. Automated decision-making
Consentinel does not use account or connected-site visitor data to make decisions that produce legal or similarly significant effects about individuals. Geographic and Global Privacy Control signals may automatically select or record a consent posture according to the Customer's configuration; the Customer controls that configuration.
16. Changes
We may update this Policy to reflect legal, technical, or business changes. We will post the revised date and give account holders reasonable notice of material changes. We will obtain consent where a new use legally requires it.
17. Contact
- Privacy requests: privacy@consentinel.co
- Legal contact: legal@consentinel.co
- Mailing address: SLI Studios Web Development, LLC, 1688 Meridian Avenue, Suite 700, Miami Beach, Florida 33139, USA