Last updated: 1 July 2026
Privacy Policy
ConsentSignals is built by a privacy compliance company — we hold ourselves to the standard we help customers achieve.
Who we are
ConsentSignals is operated by Rivoryn Limited, incorporated in Ireland (Limerick).
We provide automated child-privacy, consent-differential, and accessibility compliance scanning for websites. We are the data controller for personal data collected through consentsignals.com and our API.
Contact: privacy@consentsignals.com
Postal: Rivoryn Limited, Limerick, Ireland
What data we collect
When you use ConsentSignals, we may process:
• URLs you submit for scanning (stored to deliver results and audit history)
• Account data if you sign up via Clerk (name, email, authentication identifiers)
• Payment metadata via Stripe (we never store card numbers)
• Usage analytics — only with your cookie consent
• Contact form submissions (name, email, message)
• Scan outputs linked to your account (scores, tracker domains, classifications)
We do not intentionally collect personal data from third-party websites you scan. Scans run in isolated browser sessions; we store technical metadata and compliance indicators, not page content for unrelated purposes.
Legal basis (GDPR Article 6)
• Contract (Art. 6(1)(b)): account data and scan results to provide the service you requested
• Legitimate interests (Art. 6(1)(f)): security, fraud prevention, abuse detection on free tier — balanced against your rights
• Consent (Art. 6(1)(a)): non-essential cookies and optional marketing — withdraw anytime
• Legal obligation (Art. 6(1)(c)): retaining billing records under Irish/EU tax law
Children's data
ConsentSignals is a B2B compliance tool for organisations. We do not knowingly offer services directly to children under 16.
If you believe a child has provided personal data to us without appropriate consent, contact privacy@consentsignals.com and we will delete it promptly.
Where our customers scan sites that may be child-directed, our outputs are technical indicators for the customer's compliance programme — not parental suitability ratings.
International transfers
We prioritise EU/EEA hosting for customer data (Supabase EU, Vercel EU edge, Railway EU regions where configured).
Where a sub-processor transfers data outside the EEA, we rely on Standard Contractual Clauses (SCCs) and supplementary measures. See our DPA (/dpa) and sub-processor list (/subprocessors).
Retention
See /data-retention for tier-specific scan retention. Summary:
• Scan results: per your plan (30–90 days or unlimited on Agency)
• Account data: subscription period + 30 days after deletion request
• Billing records: 7 years (Irish tax law)
• Contact enquiries: 2 years
Anonymous scans without an account may expire after 30 days unless claimed.
Your rights (GDPR & Irish DPA)
You have the right to access, rectify, erase, restrict, object, and port your data, and to withdraw consent where processing is consent-based.
Contact privacy@consentsignals.com — we respond within 30 days (extendable by 60 days for complex requests as permitted by law).
You may lodge a complaint with the Irish Data Protection Commission (DPC):
www.dataprotection.ie · Lo Call 1800 437 737
Security
• TLS 1.2+ in transit; encryption at rest with our database provider
• HMAC-SHA-256 signing for audit PDFs
• API keys stored as hashes
• SSRF guards on all scan targets
• Minimal collection — scanned page content is not retained for unrelated purposes
Automated decision-making
Scan outputs include automated risk scores and regulatory mappings. These are technical indicators for human review — not legal verdicts. You should have qualified counsel review findings before regulatory submissions.
Changes
Material changes will be notified by email to account holders at least 14 days before they take effect.
Questions?
Email privacy@consentsignals.com or use the contact form.