Privacy Policy
This policy explains how optoutwatch (“we”, “us”) collects, uses and discloses personal information, and describes the rights California residents have under the California Consumer Privacy Act as amended by the CPRA (“CCPA”). It applies to this website and the optoutwatch service.
Your Privacy Choices
We do not sell or share personal information, and we have not done so in the preceding 12 months. We do not use advertising pixels, analytics scripts or any third-party code on this site. We have no actual knowledge of selling or sharing personal information of consumers under 16.
What we collect, why, and for how long
The table lists each category of personal information we have collected in the preceding 12 months, its sources, the purposes, the categories of recipients we disclose it to for a business purpose, and how long we keep it.
| Category | Sources | Purposes | Disclosed to | Retention |
|---|---|---|---|---|
| Identifiers and account data: name, e-mail address, company name, password (stored only as a hash) | You, when you create or update your account | Providing your account, authentication, service and security messages | Hosting provider; e-mail delivery provider | For the life of your account, then deleted within 30 days of account deletion |
| Commercial information: plan, subscription status, invoices. Card data is entered directly with Stripe; we never receive full card numbers | You; Stripe, our payment processor | Billing, accounting, tax obligations, fraud prevention | Stripe; hosting provider | 7 years from the end of the fiscal year, as required for tax and accounting records |
| Service data: site URLs you submit, your threshold self-declaration, scan reports, alert e-mail addresses and webhook URL | You; publicly available content of the websites you ask us to scan | Running scans and monitoring, sending alerts. The publicly available privacy policy text of scanned sites is analyzed with an AI model | Hosting provider; Mistral AI (receives only the public privacy policy text of scanned sites, no account data); e-mail delivery provider | For the life of your account; a site’s scans and reports are deleted within 30 days after you remove the site |
| Shared report links: the recipient's e-mail address in masked form (for example “ma***@example.com”) and as a hash, a hashed access password, how often and when the link was opened | The account holder who shares a report; the recipient's browser when the link is opened | Giving the recipient access to the report, letting the account holder see and revoke access, sending the invitation e-mail | Hosting provider; e-mail delivery provider (invitation only) | For the life of the sharing account; the account holder can revoke a link at any time |
| Internet activity: IP address, browser user agent, request logs | Your browser, automatically when you visit | Security, abuse prevention, debugging | Hosting provider | 30 days |
| Communications: support and privacy request e-mails | You | Answering your request; keeping records of privacy requests | E-mail delivery provider | 24 months, the period required for records of consumer requests (11 CCR § 7101) |
Sensitive personal information
Your account log-in (e-mail address and password) is sensitive personal information under the CCPA. We use it only to authenticate you and keep the service secure, purposes permitted by 11 CCR § 7027(m). We do not use sensitive personal information to infer characteristics about you, so there is no use for you to limit.
Opt-out preference signals (Global Privacy Control)
We honor Global Privacy Control. Because we do not sell or share personal information, there is currently nothing for the signal to switch off. If that ever changes, we will treat a GPC signal as a valid request to opt out of sale and sharing for that browser and any account associated with it, without asking for additional information, and we will display whether the signal has been processed.
Your rights
If you are a California resident, you have the right to:
- Know and access the personal information we have collected about you, including its categories, sources, purposes and recipients.
- Delete personal information we have collected from you, subject to legal exceptions such as tax records.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information. We do not sell or share it.
- Limit the use and disclosure of sensitive personal information. We use it only for permitted purposes.
- Not be discriminated or retaliated against for exercising any of these rights.
How to submit a request
You can submit a request in either of these ways:
- By e-mail to privacy@optoutwatch.com.
- By postal mail to: optoutwatch, Attn: Privacy Requests, c/o cassida.io.
Account holders can also update their name and company, remove sites and their scan data, and change alert recipients directly in the dashboard.
To protect your data, we verify requests by matching them against information we already hold — for account holders, by confirming the request from the e-mail address on the account. You may use an authorized agent; we will ask for your signed permission and may ask you to verify your identity directly.
We confirm receipt within 10 business days and respond within 45 calendar days. If we need more time, up to another 45 days, we will tell you why.
Children
The service is intended for businesses and is not directed to children under 16.
Changes to this policy
We update this policy at least once every 12 months and whenever our practices change. The date at the top shows the last update.
Contact
Questions about this policy: privacy@optoutwatch.com.