Skip to main content
Last updated: 1 July 2026

Privacy Policy

ConsentSignals is built by a privacy compliance company — we hold ourselves to the standard we help customers achieve.

Who we are

ConsentSignals is operated by Rivoryn Limited, incorporated in Ireland (Limerick). We provide automated child-privacy, consent-differential, and accessibility compliance scanning for websites. We are the data controller for personal data collected through consentsignals.com and our API. Contact: privacy@consentsignals.com Postal: Rivoryn Limited, Limerick, Ireland

What data we collect

When you use ConsentSignals, we may process: • URLs you submit for scanning (stored to deliver results and audit history) • Account data if you sign up via Clerk (name, email, authentication identifiers) • Payment metadata via Stripe (we never store card numbers) • Usage analytics — only with your cookie consent • Contact form submissions (name, email, message) • Scan outputs linked to your account (scores, tracker domains, classifications) We do not intentionally collect personal data from third-party websites you scan. Scans run in isolated browser sessions; we store technical metadata and compliance indicators, not page content for unrelated purposes.

Legal basis (GDPR Article 6)

• Contract (Art. 6(1)(b)): account data and scan results to provide the service you requested • Legitimate interests (Art. 6(1)(f)): security, fraud prevention, abuse detection on free tier — balanced against your rights • Consent (Art. 6(1)(a)): non-essential cookies and optional marketing — withdraw anytime • Legal obligation (Art. 6(1)(c)): retaining billing records under Irish/EU tax law

Children's data

ConsentSignals is a B2B compliance tool for organisations. We do not knowingly offer services directly to children under 16. If you believe a child has provided personal data to us without appropriate consent, contact privacy@consentsignals.com and we will delete it promptly. Where our customers scan sites that may be child-directed, our outputs are technical indicators for the customer's compliance programme — not parental suitability ratings.

International transfers

We prioritise EU/EEA hosting for customer data (Supabase EU, Vercel EU edge, Railway EU regions where configured). Where a sub-processor transfers data outside the EEA, we rely on Standard Contractual Clauses (SCCs) and supplementary measures. See our DPA (/dpa) and sub-processor list (/subprocessors).

Retention

See /data-retention for tier-specific scan retention. Summary: • Scan results: per your plan (30–90 days or unlimited on Agency) • Account data: subscription period + 30 days after deletion request • Billing records: 7 years (Irish tax law) • Contact enquiries: 2 years Anonymous scans without an account may expire after 30 days unless claimed.

Your rights (GDPR & Irish DPA)

You have the right to access, rectify, erase, restrict, object, and port your data, and to withdraw consent where processing is consent-based. Contact privacy@consentsignals.com — we respond within 30 days (extendable by 60 days for complex requests as permitted by law). You may lodge a complaint with the Irish Data Protection Commission (DPC): www.dataprotection.ie · Lo Call 1800 437 737

Security

• TLS 1.2+ in transit; encryption at rest with our database provider • HMAC-SHA-256 signing for audit PDFs • API keys stored as hashes • SSRF guards on all scan targets • Minimal collection — scanned page content is not retained for unrelated purposes

Automated decision-making

Scan outputs include automated risk scores and regulatory mappings. These are technical indicators for human review — not legal verdicts. You should have qualified counsel review findings before regulatory submissions.

Changes

Material changes will be notified by email to account holders at least 14 days before they take effect.
Questions?
Email privacy@consentsignals.com or use the contact form.