Privacy Policy

Effective date: to be confirmed · Last updated: August 8, 2026

This Privacy Policy explains how Forge Frameworks Inc. (“Cookies Privacy Manager”, “we”, “us”, “our”), a corporation based in Edmonton, Alberta, Canada (exact registered legal name and address to be confirmed), collects, uses, shares, and protects personal information. It forms part of, and is incorporated by reference into, our Terms of Service. Where this policy and the Terms conflict on how personal data is handled, this policy controls for that subject.

1. Who we are & what this policy covers

Cookies Privacy Manager is a business-to-business platform for cookie-consent management. Our business customers install an embeddable consent banner and script on websites they own or control; the platform records the consent choices made by visitors to those websites, and provides scanning, reporting, and account tools around them.

This policy covers:

  • personal information about our customers and their authorized users — the people who hold accounts with us;
  • personal information about visitors to our customers' websites, which we process on our customers' behalf; and
  • personal information about visitors to our own website, cookiesprivacymanager.com, including people who submit the contact form.

2. The two roles we play

Which rules apply to a given piece of data depends on whose data it is. There are two distinct situations, and it matters which one you are in.

We are the controller for account data

For personal information about our own customers and their authorized users — your name, email address, company details, billing information, support history, and login activity — we act as the data controller (or, under Canadian law, the organization responsible for that information). We decide why and how it is processed, and the rest of this policy describes those decisions.

We are the processor for website-visitor data

For personal information about the visitors to our customers' websites — consent records, page-view records, and the technical data attached to them — our customer is the data controller and we act as their processor (a “service provider” under US state privacy laws). We process that data only to provide the Service, on our customer's instructions, and as described in Section 4.

If you are a website visitor and you want to exercise rights over a consent record we hold, the organization that operates the website you visited is the one responsible for it. See Section 12.

A Data Processing Addendum governing our processing of visitor personal data on our customers' behalf is available on request (availability and form of DPA to be confirmed).

3. Account data we collect about you

When you create an account, subscribe to a plan, contact support, or simply use the Service, we collect and store:

4. Website-visitor data we process on our customers' behalf

When our script runs on a customer's website, we record the following on that customer's behalf. Our customer — not us — decides that this collection happens and is responsible for telling their visitors about it.

Consent records

Every time a visitor makes or updates a consent choice, we store: a consent identifier (a randomly generated UUID that stays stable across re-consents so the audit trail links up), the consent version in force at the time, the site or location the banner was serving, the website domain and the page URL, the visitor's choice for each cookie category, the time it happened, the visitor's IP address, their browser user-agent string, and a country derived from the IP address.

Page-view records

We record page views on our customers' sites: domain, URL and path, referring URL, IP address, user-agent, device type (mobile, tablet, or desktop), country code, a session identifier, and — if one exists — the consent identifier described above.

Page views are recorded on every page load, including before a visitor has answered the banner and where a visitor has declined all optional categories. They are recorded on the basis of our customers' legitimate interest in measuring traffic to their own site and in applying their plan's allowances, rather than on consent. The privacy-exclusion check described below applies to them in the same way it applies to consent records.

Whether page-view measurement should instead be gated on consent, and whether the session identifier described in Section 5 is strictly necessary, is under review before launch (to be confirmed with counsel).

Banner delivery records

Each time our banner script is requested, we log the site identifier, IP address, user-agent, referring page, and origin. These records exist to operate and protect the delivery of the script — measuring load, diagnosing failures, and detecting abuse or unauthorized use of a customer's embed code.

How we determine country

We resolve an approximate country from the IP address using a MaxMind GeoLite2 database file that is downloaded and stored on our own servers. The lookup happens locally: the visitor's IP address is not transmitted to MaxMind in order to perform it. We resolve country only — not city, region, or precise location. If the lookup fails, the consent record is still stored, without a country.

US “Do Not Sell” privacy exclusions

Before any geolocation is attempted, we check the visitor's IP address against MaxMind's privacy-exclusions list, which identifies individuals who have exercised their right to opt out of the sale or sharing of their personal information. If a visitor's IP address is on that list, we skip geolocation entirely and store the IP address and user-agent as empty — the consent decision itself is still recorded, so the audit trail survives, but the identifying technical data is not retained.

5. Cookies and similar technologies we use

We build cookie-consent software, so we hold ourselves to the same standard we help our customers meet. This is everything we set.

On our customers' websites (set by our banner)

Our banner sets nothing else. It does not set advertising cookies, does not set third-party cookies, and does not share anything with an advertising network.

On our own website and application

  • Session cookie — keeps you signed in and maintains your session. Strictly necessary.
  • CSRF token cookie — protects forms against cross-site request forgery. Strictly necessary.
  • Language preference — the site language you select is held in that same session, so the site stays in the language you chose. Strictly necessary for that feature.
  • Google reCAPTCHA — our sign-in, registration, password-reset, contact, and scan forms use Google reCAPTCHA to block automated abuse. Google sets and reads its own cookies and receives data about the request, including your IP address, under Google's privacy policy.

6. How and why we use this information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your data, or your visitors' data, to train machine-learning models, and we do not use it to advertise to you or to anyone else.

7. Sharing & sub-processors

We do not sell personal information. We share it only in the situations below.

Service providers (sub-processors). We rely on a small number of providers to run the Service. Each is bound by a contract limiting them to processing data on our instructions. This is the current list:

We will update this list when it changes. Customers who require advance notice of sub-processor changes should ask about our Data Processing Addendum.

Other disclosures. We may also disclose personal information: where we are legally required to, or to respond to a valid legal process; to establish, exercise, or defend legal claims; to protect the rights, safety, or property of any person; and, if we are ever involved in a merger, acquisition, or sale of assets, to the party involved — in which case we will give notice before your information becomes subject to a different privacy policy.

8. Where your data is stored and international transfers

We are based in Canada, and the Service is operated from servers in a hosting region to be confirmed. Some of our providers — notably Stripe and Google — operate globally and may process personal information in the United States or elsewhere.

This means personal information may be transferred to, and stored in, a country other than the one you live in, where privacy laws differ from your own, and where courts and public authorities may in some circumstances be able to access it. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (the specific mechanism relied on for each provider is to be confirmed).

Whether an EU/UK representative under Article 27 of the GDPR is required, and who it would be, is to be confirmed before launch.

9. How long we keep data

We keep personal information only as long as we need it for the purpose it was collected for. These windows are enforced automatically by scheduled deletion jobs, not by hand.

We may keep information for longer where we are required to by law — for example, invoices and other financial records kept for tax purposes — or where it is needed to establish, exercise, or defend a legal claim. Where a customer asks us to erase their account, we act on that request directly rather than waiting for a scheduled window; see Section 11.

10. How we protect data

  • All traffic to the Service is encrypted in transit using TLS.
  • Passwords are stored only as one-way cryptographic hashes. Two-factor secrets and recovery codes are encrypted at rest.
  • Two-factor authentication is available to every account, and we require it before sensitive billing actions can be carried out.
  • Access to production data is limited to personnel who need it, and administrative areas are separated by role.
  • Public endpoints are rate-limited, sign-in attempts are throttled and locked out after repeated failures, and both are logged.
  • Our application sends browser security headers that limit how our pages can be embedded and how content is interpreted.
  • The consent endpoint verifies a server-issued token for the site it claims to be reporting for, so consent records cannot be forged against another customer's account.

No system can be guaranteed completely secure. If we become aware of a breach affecting personal information, we will notify affected parties and the relevant supervisory authorities where the law requires it and within the time limits it sets.

11. Your rights over your own data

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you, and know how we use it;
  • Correct information that is inaccurate or incomplete;
  • Delete your personal information — we operate a deletion procedure that permanently removes an account and the data attached to it, rather than merely hiding it;
  • Export your data, or receive it in a portable format — consent records can be exported from your dashboard at any time;
  • Object to or restrict processing based on our legitimate interests;
  • Withdraw consent where we rely on it, without affecting processing already carried out; and
  • Not be discriminated against for exercising any of these rights.

These rights come from laws including the EU and UK General Data Protection Regulation, Canada's Personal Information Protection and Electronic Documents Act and Alberta's Personal Information Protection Act, Quebec's Law 25, and the California Consumer Privacy Act as amended by the CPRA. Which ones apply to you depends on where you are.

To exercise any of them, email privacy@cookiesprivacymanager.com. We will verify your identity before acting on a request, and we will respond within the period the applicable law sets. There is no charge for a reasonable request.

If you are in the EEA, the UK, or Switzerland, you also have the right to complain to your local data protection authority. In Canada, you may complain to the Office of the Privacy Commissioner of Canada or your provincial equivalent. We would ask that you raise the matter with us first so we have a chance to resolve it.

12. If you are a visitor to one of our customers' websites

If you saw a cookie banner powered by Cookies Privacy Manager and want to change or delete the consent record attached to it, the organization that operates that website is responsible for that data — not us. Contact them directly, using the privacy notice on their site.

We support our customers in honouring those requests: they can locate and delete an individual consent record, or every record they hold, through our platform, and each such deletion is logged. If you contact us directly, we will pass the request to the relevant customer where we can identify them, but we cannot act on it ourselves without their instruction.

You can also withdraw or change your consent at any time from the website itself, using the consent icon our banner leaves on the page.

13. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from children in connection with an account. You must be at least 16 years old to hold an account, as set out in our Terms of Service. If you believe a child has provided us with personal information, contact us and we will delete it.

14. Automated decision-making

We do not use automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile you. The automated processing we do perform is operational — applying your plan's limits, sending usage warnings, deleting data past its retention window, and detecting abuse.

15. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, give additional notice by email or an in-app notice before the change takes effect. If a change would materially expand how we use personal information we already hold, we will seek consent where the law requires it.

16. Contact us

Forge Frameworks Inc., Edmonton, Alberta, Canada (registered address to be confirmed):

Whether we are required to appoint a Data Protection Officer, and an EU/UK representative under Article 27 of the GDPR, is to be confirmed before launch.