Legal & Compliance

Privacy Policy

How we collect, use, and protect your data — written in plain language, not legalese.

Effective
April 1, 2026
Last updated
April 30, 2026
Compliance
GDPR & CCPA compliant
01

Introduction

cmpstack.io (“we”, “us”, or “our”) operates a consent management platform designed to help businesses achieve and maintain privacy compliance across GDPR, CCPA, DMA, and related frameworks. This Privacy Policy explains what personal data we collect, why we collect it, and how we use it.

By using our platform, website, or services, you agree to the collection and use of information in accordance with this policy. If you are acting on behalf of an organization, you represent that you have authority to bind that organization to these terms.

02

Data Collection

We collect information when you interact with our platform. The categories and specific data points we collect depend on how you use cmpstack.io.

Account & Registration Data

  • Full name — used to personalize your account and communications.
  • Email address — used for authentication, support, and transactional notifications.
  • Company name and website URL — used to configure your compliance setup.
  • Billing information — processed via our payment provider; we do not store raw card data.

Usage & Platform Data

  • Log data — IP address, browser type, pages visited, and timestamps.
  • Feature usage events — which features you access, when, and how frequently.
  • API request logs — endpoint, response times, and error codes for debugging.
  • Consent records — anonymized aggregate consent logs generated by your visitors (not their personal data).

Communications Data

  • Support tickets and chat messages — stored to provide continuity of service.
  • Survey responses — collected on an opt-in basis to improve the platform.
Data TypeSourceRetention
Account detailsProvided by you at registrationDuration of account + 30 days post-deletion
Billing recordsGenerated on purchase7 years (legal requirement)
Usage logsAutomatically collected90 days rolling
Support historyYour communications with us3 years from last interaction
03

Data Usage

We use the data we collect to operate, maintain, and improve cmpstack.io. We will never sell your personal data to third parties for marketing purposes.

Primary Uses

  • Providing and improving the consent management platform and all associated features.
  • Processing payments and managing your subscription and billing cycle.
  • Sending transactional emails — account confirmations, invoices, and security alerts.
  • Responding to support requests, bug reports, and account inquiries.
  • Enforcing our Terms of Service and protecting platform integrity.

Secondary Uses

  • Analyzing aggregated, anonymized usage patterns to prioritize product improvements.
  • Sending product update emails and release notes — you may opt out at any time.
  • Conducting optional satisfaction surveys to measure service quality.
04

Cookies & Tracking

We use cookies and similar technologies on our marketing website and dashboard. As a consent management platform, we practice what we preach — our own cookie implementation is fully compliant with GDPR and ePrivacy requirements.

Cookie NameTypePurposeExpiry
cmp_sessionStrictly NecessaryMaintains your authenticated sessionSession
cmp_themeFunctionalRemembers your dark/light mode preference1 year
_plausibleAnalyticsPrivacy-first analytics (no fingerprinting)1 year
_stripe_midPaymentFraud prevention during checkout1 year

Managing Cookies

  • To change your choice, clear this site’s cookies in your browser, or email us at privacy@cmpstack.io.
  • Blocking strictly necessary cookies will prevent the platform from functioning.
  • Most browsers allow you to view, delete, and block cookies through their settings.
05

Third-Party Services

We work with a small number of trusted sub-processors to deliver our service. All sub-processors are contractually required to handle your data in compliance with GDPR and our data processing agreements.

  • Stripe— payment processing. Card data is processed under Stripe’s PCI-DSS Level 1 environment.
  • Amazon Web Services (EU-West-1) — cloud infrastructure hosting. All data is stored within the European Economic Area by default.
  • Postmark — transactional email delivery for account notifications and invoices.
  • Plausible Analytics — cookieless, privacy-first website analytics. No personal data is collected by this service.
  • Intercom— customer support and live chat. Chat history is subject to Intercom’s own privacy policy.
06

Your Rights

Depending on your location, you hold specific legal rights over your personal data. We honor all applicable rights and process requests within 30 days.

Rights Under GDPR (EEA & UK residents)

  • Right of access — request a copy of all personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data at any time.
  • Right to erasure — request deletion of your data, subject to legal retention obligations.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to restrict processing — limit how we use your data in certain circumstances.
  • Right to object — object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — revoke consent for optional processing at any time.

Rights Under CCPA (California residents)

  • Right to know — request disclosure of the categories and specific pieces of data collected.
  • Right to delete — request deletion of personal information we have collected.
  • Right to opt out — we do not sell personal information; this right does not apply.
  • Right to non-discrimination — exercising your rights will not affect service quality or pricing.
07

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how we handle your information, please reach out.

Data Controller

cmpstack.io Ltd.
Registered in England & Wales

Email: privacy@cmpstack.io

For enterprise DPA requests: legal@cmpstack.io

You also have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO). In the EU, contact your national Data Protection Authority.

Built by people who take privacy seriously

Start collecting consent the right way — GDPR, CCPA, and DMA ready out of the box.

GDPR · CCPA · DMA · Google Consent Mode v2