Skip to content
optoutwatch

Privacy Policy

This policy explains how optoutwatch (“we”, “us”) collects, uses and discloses personal information, and describes the rights California residents have under the California Consumer Privacy Act as amended by the CPRA (“CCPA”). It applies to this website and the optoutwatch service.

Your Privacy Choices

We do not sell or share personal information, and we have not done so in the preceding 12 months. We do not use advertising pixels, analytics scripts or any third-party code on this site. We have no actual knowledge of selling or sharing personal information of consumers under 16.

What we collect, why, and for how long

The table lists each category of personal information we have collected in the preceding 12 months, its sources, the purposes, the categories of recipients we disclose it to for a business purpose, and how long we keep it.

CategorySourcesPurposesDisclosed toRetention
Identifiers and account data: name, e-mail address, company name, password (stored only as a hash)You, when you create or update your accountProviding your account, authentication, service and security messagesHosting provider; e-mail delivery providerFor the life of your account, then deleted within 30 days of account deletion
Commercial information: plan, subscription status, invoices. Card data is entered directly with Stripe; we never receive full card numbersYou; Stripe, our payment processorBilling, accounting, tax obligations, fraud preventionStripe; hosting provider7 years from the end of the fiscal year, as required for tax and accounting records
Service data: site URLs you submit, your threshold self-declaration, scan reports, alert e-mail addresses and webhook URLYou; publicly available content of the websites you ask us to scanRunning scans and monitoring, sending alerts. The publicly available privacy policy text of scanned sites is analyzed with an AI modelHosting provider; Mistral AI (receives only the public privacy policy text of scanned sites, no account data); e-mail delivery providerFor the life of your account; a site’s scans and reports are deleted within 30 days after you remove the site
Shared report links: the recipient's e-mail address in masked form (for example “ma***@example.com”) and as a hash, a hashed access password, how often and when the link was openedThe account holder who shares a report; the recipient's browser when the link is openedGiving the recipient access to the report, letting the account holder see and revoke access, sending the invitation e-mailHosting provider; e-mail delivery provider (invitation only)For the life of the sharing account; the account holder can revoke a link at any time
Internet activity: IP address, browser user agent, request logsYour browser, automatically when you visitSecurity, abuse prevention, debuggingHosting provider30 days
Communications: support and privacy request e-mailsYouAnswering your request; keeping records of privacy requestsE-mail delivery provider24 months, the period required for records of consumer requests (11 CCR § 7101)

Sensitive personal information

Your account log-in (e-mail address and password) is sensitive personal information under the CCPA. We use it only to authenticate you and keep the service secure, purposes permitted by 11 CCR § 7027(m). We do not use sensitive personal information to infer characteristics about you, so there is no use for you to limit.

Cookies

We set two strictly necessary cookies. “ow_token” keeps you signed in after you log in and expires after 7 days. “ow_share” is set only when you open a password-protected report someone shared with you; it is limited to that report's address and expires after 12 hours. Neither can be read by scripts. We do not use analytics, advertising or third-party cookies.

Opt-out preference signals (Global Privacy Control)

We honor Global Privacy Control. Because we do not sell or share personal information, there is currently nothing for the signal to switch off. If that ever changes, we will treat a GPC signal as a valid request to opt out of sale and sharing for that browser and any account associated with it, without asking for additional information, and we will display whether the signal has been processed.

Your rights

If you are a California resident, you have the right to:

  • Know and access the personal information we have collected about you, including its categories, sources, purposes and recipients.
  • Delete personal information we have collected from you, subject to legal exceptions such as tax records.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your personal information. We do not sell or share it.
  • Limit the use and disclosure of sensitive personal information. We use it only for permitted purposes.
  • Not be discriminated or retaliated against for exercising any of these rights.

How to submit a request

You can submit a request in either of these ways:

  1. By e-mail to privacy@optoutwatch.com.
  2. By postal mail to: optoutwatch, Attn: Privacy Requests, c/o cassida.io.

Account holders can also update their name and company, remove sites and their scan data, and change alert recipients directly in the dashboard.

To protect your data, we verify requests by matching them against information we already hold — for account holders, by confirming the request from the e-mail address on the account. You may use an authorized agent; we will ask for your signed permission and may ask you to verify your identity directly.

We confirm receipt within 10 business days and respond within 45 calendar days. If we need more time, up to another 45 days, we will tell you why.

Children

The service is intended for businesses and is not directed to children under 16.

Changes to this policy

We update this policy at least once every 12 months and whenever our practices change. The date at the top shows the last update.

Contact

Questions about this policy: privacy@optoutwatch.com.