Effective date: to be confirmed · Last updated: August 8, 2026
This Privacy Policy explains how Forge Frameworks Inc. (“Cookies Privacy Manager”, “we”, “us”, “our”), a corporation based in Edmonton, Alberta, Canada (exact registered legal name and address to be confirmed), collects, uses, shares, and protects personal information. It forms part of, and is incorporated by reference into, our Terms of Service. Where this policy and the Terms conflict on how personal data is handled, this policy controls for that subject.
Cookies Privacy Manager is a business-to-business platform for cookie-consent management. Our business customers install an embeddable consent banner and script on websites they own or control; the platform records the consent choices made by visitors to those websites, and provides scanning, reporting, and account tools around them.
This policy covers:
cookiesprivacymanager.com, including people who submit the contact form.Which rules apply to a given piece of data depends on whose data it is. There are two distinct situations, and it matters which one you are in.
For personal information about our own customers and their authorized users — your name, email address, company details, billing information, support history, and login activity — we act as the data controller (or, under Canadian law, the organization responsible for that information). We decide why and how it is processed, and the rest of this policy describes those decisions.
For personal information about the visitors to our customers' websites — consent records, page-view records, and the technical data attached to them — our customer is the data controller and we act as their processor (a “service provider” under US state privacy laws). We process that data only to provide the Service, on our customer's instructions, and as described in Section 4.
If you are a website visitor and you want to exercise rights over a consent record we hold, the organization that operates the website you visited is the one responsible for it. See Section 12.
A Data Processing Addendum governing our processing of visitor personal data on our customers' behalf is available on request (availability and form of DPA to be confirmed).
When you create an account, subscribe to a plan, contact support, or simply use the Service, we collect and store:
| Category | What it includes | Source |
|---|---|---|
| Identity & contact | Name, email address, company name, and the role and subscription plan attached to your account. | You, at registration or in your profile. |
| Credentials | Your password, stored only as a one-way cryptographic hash — we never hold it in a readable form. If you enable two-factor authentication, your TOTP secret and recovery codes, stored encrypted. | You. |
| Billing | Your billing address and subscription, invoice, and add-on records, plus an identifier linking your account to your customer record at Stripe. We do not receive or store your full card number — card details are captured and held by Stripe. | You, via Stripe; Stripe, via billing webhooks. |
| Support | Support tickets and replies, including anything you choose to put in them. | You. |
| Email delivery log | A record of the transactional emails we send you: recipient address, subject line, message type, and timestamp. We log that a message was sent; we do not retain its body. | Generated by us. |
| Authentication & security logs | Sign-ins, sign-outs, failed sign-in attempts, registrations, and account lockouts, together with the IP address involved. We keep these to detect and investigate unauthorized access. | Generated by us. |
| Configuration & usage | Your banner settings, registered domains, scan results for sites you scan, and the volume counters we use to apply your plan's limits. | You and the Service. |
| Enquiries | If you use our contact form: name, email, phone, company, address details, your message, the page you submitted from, and your IP address. | You. |
When our script runs on a customer's website, we record the following on that customer's behalf. Our customer — not us — decides that this collection happens and is responsible for telling their visitors about it.
Every time a visitor makes or updates a consent choice, we store: a consent identifier (a randomly generated UUID that stays stable across re-consents so the audit trail links up), the consent version in force at the time, the site or location the banner was serving, the website domain and the page URL, the visitor's choice for each cookie category, the time it happened, the visitor's IP address, their browser user-agent string, and a country derived from the IP address.
We record page views on our customers' sites: domain, URL and path, referring URL, IP address, user-agent, device type (mobile, tablet, or desktop), country code, a session identifier, and — if one exists — the consent identifier described above.
Page views are recorded on every page load, including before a visitor has answered the banner and where a visitor has declined all optional categories. They are recorded on the basis of our customers' legitimate interest in measuring traffic to their own site and in applying their plan's allowances, rather than on consent. The privacy-exclusion check described below applies to them in the same way it applies to consent records.
Whether page-view measurement should instead be gated on consent, and whether the session identifier described in Section 5 is strictly necessary, is under review before launch (to be confirmed with counsel).
Each time our banner script is requested, we log the site identifier, IP address, user-agent, referring page, and origin. These records exist to operate and protect the delivery of the script — measuring load, diagnosing failures, and detecting abuse or unauthorized use of a customer's embed code.
We resolve an approximate country from the IP address using a MaxMind GeoLite2 database file that is downloaded and stored on our own servers. The lookup happens locally: the visitor's IP address is not transmitted to MaxMind in order to perform it. We resolve country only — not city, region, or precise location. If the lookup fails, the consent record is still stored, without a country.
Before any geolocation is attempted, we check the visitor's IP address against MaxMind's privacy-exclusions list, which identifies individuals who have exercised their right to opt out of the sale or sharing of their personal information. If a visitor's IP address is on that list, we skip geolocation entirely and store the IP address and user-agent as empty — the consent decision itself is still recorded, so the audit trail survives, but the identifying technical data is not retained.
We build cookie-consent software, so we hold ourselves to the same standard we help our customers meet. This is everything we set.
| Name | Purpose | Lifetime |
|---|---|---|
cookieConsent |
Stores the visitor's own consent decision — the consent identifier, the consent version, and the choice made for each category — so the banner is not shown again and the site can honour those choices. Strictly necessary; it exists only to remember the visitor's preference. | Until the visitor clears it, or until the site's consent version changes and consent is requested again. |
| Local storage entry | A copy of the same consent record, so the preference survives if the cookie is unavailable. | Same as above. |
cc_session |
A randomly generated session identifier, held in the browser's session storage, used to group the page views described in Section 4 into a single visit. It contains no name, email, or other directly identifying information, and it is not used for advertising. | Cleared when the browser tab is closed. |
Our banner sets nothing else. It does not set advertising cookies, does not set third-party cookies, and does not share anything with an advertising network.
| Purpose | Legal basis (where the GDPR or a similar law applies) |
|---|---|
| Providing the Service, including recording consents on our customers' behalf | Performance of our contract with you. For visitor data, we act on our customer's instructions and their legal basis applies. |
| Billing, invoicing, and collecting payment | Performance of our contract, and compliance with tax and accounting obligations. |
| Transactional and service email — verification, password reset, receipts, usage warnings, failed-payment notices, alerts | Performance of our contract. |
| Applying plan limits and measuring usage | Performance of our contract, and our legitimate interest in operating the Service sustainably. |
| Support, and responding to your enquiries | Performance of our contract, or our legitimate interest in answering people who contact us. |
| Security, fraud prevention, abuse detection, and diagnosing faults | Our legitimate interest in keeping the Service and its users safe. |
| Complying with legal obligations and responding to lawful requests | Legal obligation. |
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your data, or your visitors' data, to train machine-learning models, and we do not use it to advertise to you or to anyone else.
We do not sell personal information. We share it only in the situations below.
Service providers (sub-processors). We rely on a small number of providers to run the Service. Each is bound by a contract limiting them to processing data on our instructions. This is the current list:
| Provider | Function | Data handled |
|---|---|---|
| Stripe | Payment processing and subscription billing | Your name, email, billing address, and payment method. Stripe holds card details; we do not. Governed by Stripe's own terms and privacy policy. |
| Linode / Akamai (hosting region to be confirmed) | Server hosting and infrastructure | All data stored by the Service resides on infrastructure we operate at this provider. |
| Proton Mail (provider at launch to be confirmed) | Transactional email delivery | Recipient email address and message content for the emails we send you. |
| MaxMind | IP geolocation database and privacy-exclusions list | We download their database and exclusions list to our servers and query them locally. Visitor IP addresses are not sent to MaxMind. |
| reCAPTCHA bot protection on our public forms | Your IP address and interaction signals, collected directly by Google when you use a protected form. |
We will update this list when it changes. Customers who require advance notice of sub-processor changes should ask about our Data Processing Addendum.
Other disclosures. We may also disclose personal information: where we are legally required to, or to respond to a valid legal process; to establish, exercise, or defend legal claims; to protect the rights, safety, or property of any person; and, if we are ever involved in a merger, acquisition, or sale of assets, to the party involved — in which case we will give notice before your information becomes subject to a different privacy policy.
We are based in Canada, and the Service is operated from servers in a hosting region to be confirmed. Some of our providers — notably Stripe and Google — operate globally and may process personal information in the United States or elsewhere.
This means personal information may be transferred to, and stored in, a country other than the one you live in, where privacy laws differ from your own, and where courts and public authorities may in some circumstances be able to access it. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (the specific mechanism relied on for each provider is to be confirmed).
Whether an EU/UK representative under Article 27 of the GDPR is required, and who it would be, is to be confirmed before launch.
We keep personal information only as long as we need it for the purpose it was collected for. These windows are enforced automatically by scheduled deletion jobs, not by hand.
| Data | Retention period |
|---|---|
| Consent records | According to the subscription plan of the customer they belong to: Starter 12 months, Growth 24 months, Business 36 months. Enterprise accounts are retained for the period set in their contract. A customer may have a different window negotiated for their account, which replaces the plan default. Records older than the applicable window are deleted automatically. |
| Page-view records | The same window as that customer's consent records, so a customer makes one retention promise rather than two. Where no customer can be resolved, 12 months. |
| Banner delivery records | 12 months. These are keyed to a site rather than a customer, so no plan window can apply. |
| Contact-form submissions | 24 months from submission. |
| Generated exports and reports | 2 hours. The download link expires at the same moment, and the file itself is deleted from storage. |
| Account data — closed accounts | Deleted 90 days after the subscription ends. Deletion removes the account, its consent records, page views, scan results, and pending exports. |
| Account data — never verified | If an account is created but the email address is never confirmed, we send one reminder after 5 days, disable the account after 7 days, and delete it permanently 30 days after that. |
| Security and email logs | Retained for security and audit purposes and rotated on a routine schedule (exact log-rotation window to be confirmed). |
We may keep information for longer where we are required to by law — for example, invoices and other financial records kept for tax purposes — or where it is needed to establish, exercise, or defend a legal claim. Where a customer asks us to erase their account, we act on that request directly rather than waiting for a scheduled window; see Section 11.
No system can be guaranteed completely secure. If we become aware of a breach affecting personal information, we will notify affected parties and the relevant supervisory authorities where the law requires it and within the time limits it sets.
Depending on where you live, you may have the right to:
These rights come from laws including the EU and UK General Data Protection Regulation, Canada's Personal Information Protection and Electronic Documents Act and Alberta's Personal Information Protection Act, Quebec's Law 25, and the California Consumer Privacy Act as amended by the CPRA. Which ones apply to you depends on where you are.
To exercise any of them, email privacy@cookiesprivacymanager.com. We will verify your identity before acting on a request, and we will respond within the period the applicable law sets. There is no charge for a reasonable request.
If you are in the EEA, the UK, or Switzerland, you also have the right to complain to your local data protection authority. In Canada, you may complain to the Office of the Privacy Commissioner of Canada or your provincial equivalent. We would ask that you raise the matter with us first so we have a chance to resolve it.
If you saw a cookie banner powered by Cookies Privacy Manager and want to change or delete the consent record attached to it, the organization that operates that website is responsible for that data — not us. Contact them directly, using the privacy notice on their site.
We support our customers in honouring those requests: they can locate and delete an individual consent record, or every record they hold, through our platform, and each such deletion is logged. If you contact us directly, we will pass the request to the relevant customer where we can identify them, but we cannot act on it ourselves without their instruction.
You can also withdraw or change your consent at any time from the website itself, using the consent icon our banner leaves on the page.
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from children in connection with an account. You must be at least 16 years old to hold an account, as set out in our Terms of Service. If you believe a child has provided us with personal information, contact us and we will delete it.
We do not use automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile you. The automated processing we do perform is operational — applying your plan's limits, sending usage warnings, deleting data past its retention window, and detecting abuse.
We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, give additional notice by email or an in-app notice before the change takes effect. If a change would materially expand how we use personal information we already hold, we will seek consent where the law requires it.
Forge Frameworks Inc., Edmonton, Alberta, Canada (registered address to be confirmed):
Whether we are required to appoint a Data Protection Officer, and an EU/UK representative under Article 27 of the GDPR, is to be confirmed before launch.