Privacy Policy

Last updated: January 15, 2024 · Effective: January 15, 2024

Data Controller: Hostao LLC, 30 N Gould St, Ste 4000, Sheridan, Wyoming 82801, USA
Grievance Officer: Reji Modiyil — [email protected]
Privacy Contact: [email protected]

1. Who We Are

CookieSeal is a cookie consent management service operated by Hostao LLC, a company incorporated in Wyoming, USA. This Privacy Policy explains how we collect, use, and protect personal data when you use our service at cookieseal.in.

2. Data We Collect

We collect the following categories of personal data: Account Data: Name, email address, billing information when you create an account. Usage Data: Pages visited, features used, session duration, IP address, browser type, device information. Consent Data (on behalf of your users): When your website visitors interact with a CookieSeal banner, we record: timestamp, IP country (not full IP), categories accepted/rejected, and a hashed visitor identifier. We do not collect full IP addresses of your website visitors. Payment Data: Processed by Stripe. We do not store card numbers.

3. Legal Basis for Processing

GDPR (EU/UK): We process your data based on: (a) Contract performance — to provide the CookieSeal service; (b) Legitimate interests — to improve our service and prevent fraud; (c) Consent — for marketing communications. DPDPA 2023 (India): We process data as a "Data Fiduciary" with explicit consent and for legitimate purposes as defined under the Act. CCPA (California): We do not sell personal data. California residents have rights to access, deletion, and opt-out of data sharing.

4. How We Use Your Data

To provide and maintain the CookieSeal service · To process payments and send receipts · To send service notifications and product updates · To prevent fraud and ensure security · To comply with legal obligations · To respond to support requests.

5. Data Sharing

We share data with: - Stripe — payment processing - Vercel — hosting and CDN - AWS — cloud infrastructure - Postmark — transactional email We do not sell your personal data. We do not share data with advertisers.

6. Data Retention

Account data: retained for the duration of your subscription plus 90 days · Consent logs: per your plan (Free: 30 days, Pro: 1 year, Business: indefinite) · Billing records: 7 years (legal requirement).

7. Your Rights

Depending on your jurisdiction, you have the right to: - Access the personal data we hold about you - Correct inaccurate data - Delete your data (right to be forgotten) - Port your data to another service - Object to processing - Withdraw consent at any time To exercise these rights, email: [email protected] Under DPDPA 2023, our Grievance Officer is: Reji Modiyil ([email protected]). Response time: within 30 days.

8. Cookies We Use

CookieSeal's own website uses: Necessary cookies (session management, CSRF protection) and Analytics cookies (usage analytics with anonymized IPs). See our Cookie Policy for details.

9. International Transfers

We are based in the USA. Your data may be processed in the USA, India, and EU data centers. All international transfers are covered by Standard Contractual Clauses (EU/UK) and equivalent safeguards.

10. Security

We use TLS 1.3 encryption in transit, AES-256 at rest, and follow OWASP security guidelines. We conduct regular security audits. In case of a data breach, we will notify affected users within 72 hours.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email. Continued use of the service after changes constitutes acceptance.

12. Contact

For privacy questions: [email protected]
Hostao LLC, 30 N Gould St, Ste 4000, Sheridan, Wyoming 82801, USA