Legal

Privacy Policy

How Tripticode collects, uses, and protects personal data across tripticonsent.tripticode.com, the console, and the Tripticonsent API.

Effective date: September 13, 2026. This policy covers tripticonsent.tripticode.com, the console (console.tripticonsent.tripticode.com), and the API (api.tripticonsent.tripticode.com), together "the Service".

Who we are

Tripticonsent is a product of Tripticode, S.L., registered at C/ Júcar 36B, 41012, Sevilla, Spain ("Tripticode", "we", "us"). You can reach us on data protection matters, including to exercise your rights, at dp@tripticode.com.

Two distinct roles: controller and processor

This is the single most important distinction in this document, because it determines who you should contact to exercise your rights.

  • When you visit tripticonsent.tripticode.com, sign up as a customer, or a member of your team signs into the console, Tripticode is the data controller: we decide what those data are used for, and you can exercise your rights directly with us.
  • When a customer organization uses the Tripticonsent API or SDK to capture consent or preferences from its own end users (the people visiting that organization’s site or app), Tripticode acts as a data processor on that organization’s behalf — the organization is the controller. In that case, we are not your point of contact: you should reach out to the organization that captured your consent — Tripticode only provides them the tools (including export, rectification, and erasure) to handle your request.
Not sure whether you are our own customer or an end user of one of our customers? If you have never created an account at console.tripticonsent.tripticode.com, you’re the latter — contact the organization whose site or app you were using.

What data we collect

As a controller (customers, team members, site visitors)

CategoryDataSource
AccountName and email. To sign in we use only "Continue with Google" (we verify Google’s token directly — no Firebase Authentication, and no user database of our own at Google) or a single-use email magic link — we never store passwords. MFA (TOTP) status, if you enable it.You provide it when signing up or signing in
Console usageAudit logs of your actions (site creation, keys, configuration changes)Generated automatically as you use the console
CommunicationsEmail address, message contentIf you write to support or sales
Site visitsIP address (exposed to the Google Fonts CDN when the typeface loads)Automatic on loading any tripticonsent.tripticode.com page
tripticonsent.tripticode.com uses no first-party cookies and no analytics (Google Analytics, Plausible, or similar) — no cookie banner is needed to browse the marketing site.

As a processor (our customers’ end users)

On behalf of each customer organization, the API stores, for every person whose consent or preferences that organization manages:

  • An identifier (email, phone, a customer-owned id, or a cookie_id for anonymous visitors), always encrypted at rest (AES-256-GCM) — never stored as plain text.
  • The state of every decision (granted, denied, withdrawn…), the exact version of the legal text shown at that moment, the date, and, where applicable, the IP address it was issued from, as evidence against a claim.
  • A signed receipt (Ed25519) for every decision, verifiable offline and without depending on our servers.

This data belongs to the relevant customer organization and is used only to provide the Service they contracted — it is never combined across customers or used for Tripticode’s own purposes.

  • Performance of a contract (GDPR Art. 6(1)(b)): to sign you up as a customer, deliver, and bill for the Service.
  • Legitimate interest (Art. 6(1)(f)): for the security of the Service (abuse detection, audit logs) and to respond to your inquiries.
  • Legal obligation (Art. 6(1)(c)): to retain evidence of consent where the law requires it.
  • When we act as a processor, the underlying legal basis (typically the end user’s consent, Art. 6(1)(a)) is determined and documented by the customer organization, not by us.

Who we share data with — sub-processors

We use the following providers to operate the Service. None of them is permitted to use the data for its own purposes; all of them operate under a data processing agreement (DPA) with Tripticode.

ProviderRoleData it can touchLocation
VercelHosting for the API, console, marketing site, and AI connectorAll HTTP traffic; logs including IP addressEU — Frankfurt (fra1)
NeonPostgreSQL databaseAll persistent data: accounts, encrypted consent data, lookup hashesEU — eu-central
UpstashCaching, request rate limiting, and the delivery queue for webhooks and transactional email (QStash)Cached consent state (pseudonymous, 1-hour TTL), short-lived IP counters, and queued messages, which are encrypted before they leave our serversEU (region is configurable; ours is pinned to the EU)
ResendTransactional email delivery (data-subject-request verification, double opt-in preference confirmation)Recipient email address, a single-use linkUS, DPF-certified
GroqAutomatic classification of unknown cookies found by the scanner, and optional machine translation of banner and legal-document copyTechnical cookie metadata (name, domain, the scanned site’s URL) and customer-authored text; never end-user or subject dataUS — classification runs only for cookies our reference data can’t place; translation only if the customer uses it
StripePayment processing and billing for your organization's subscriptionThe email of whoever starts the subscription, and the payment details you enter directly into Stripe — these never pass through our servers or get stored in our database. It never receives your end users' consent data.US (Stripe, LLC) or EU/UK (Stripe Payments Europe/UK) depending on your location, with an active DPF certification
SentryError tracking for our own serversTechnical error reports. User info, cookies, request bodies and query strings are never collected, and emails, identifiers and keys are masked before sending. No telemetry from visitors’ browsersEU — Frankfurt (de.sentry.io)
CloudflareBot protection (Turnstile) on the console login form and the hosted data-subject-request formThe IP address and browser signals of whoever solves the challenge on those two formsGlobal network; US entity, DPF-certified

Each provider’s DPA: Vercel · Neon · Upstash · Resend · Groq · Stripe · Sentry · Cloudflare.

"Continue with Google" does not go through Firebase Authentication and does not create a user database of ours at Google: we verify, directly, the token Google issues in your browser. Google is involved only as the identity service you choose to sign in with — we send it no data of ours — so it is not listed as a sub-processor.

International transfers

Persistent data storage (database, cache) is pinned to the EU. A few sub-processors operate from the US for specific functions; those transfers rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission’s standard contractual clauses where it is not — per that provider’s current DPA, linked above. Groq offers no EU data residency for inference; what it receives from Tripticonsent is technical metadata (cookie names, domains, UI and legal-document text), not identifiers or subject data. Cloudflare only sees who solves a bot challenge on two forms. Stripe maintains an active Data Privacy Framework certification for the entities that process payments outside the EU/UK.

Security

  • AES-256-GCM encryption at rest for any stored identifier or personal data, with key rotation.
  • Identifier lookups use a deterministic HMAC-SHA256 hash with a pepper separate from the encryption key — lets us find a record without decrypting anything.
  • Append-only vault: no consent record is ever modified or deleted; a change always creates a new row referencing the previous one.
  • Hash-chained audit log of every configuration action, to detect tampering.
  • Multi-factor authentication (TOTP) available for every console account.

Retention & erasure

Account data is kept for as long as the organization maintains its subscription, and afterward for whatever period applicable tax or corporate law requires.

For data we process on a customer’s behalf: when a customer organization fulfils an erasure request from one of its end users, we apply crypto-shredding — we destroy the encryption key for that person’s identifier, making them permanently and irreversibly unfindable. The already-anonymized historical event log is kept for legal defensibility (for example, to prove a consent was correctly requested and handled at the time), but with no data that could identify the person.

A photo or scan of an ID document, where a customer organization requires one to verify a data-subject request, is deleted automatically 7 days after upload, regardless of whether the request was approved or rejected.

Connected AI agents (MCP)

If your organization connects an AI agent such as Claude through our MCP connector, that agent acts with exactly the same permissions and limits as an authorized member of your team — never with expanded access. The full detail of what it can and cannot touch is in AI agents (MCP).

Your rights

If you are a customer, team member, or site visitor (Tripticode is the controller): you can request access, rectification, erasure, restriction, portability, and object to processing by writing to dp@tripticode.com, and lodge a complaint with the Spanish Data Protection Agency (AEPD) or your own supervisory authority.

If you are an end user whose consent is managed by one of our customer organizations through Tripticonsent (Tripticode acting as processor): direct your request to that organization, not to us — you will typically find a preference link or a rights-request form on their own site.

Children

The Service is aimed at organizations and the people acting on a company’s behalf; it is not directed at children, and we do not knowingly collect data from them.

Changes to this policy

If we materially change how we handle your data, we will reflect it on this same page with a new "last updated" date and, where the change significantly affects you, notify you by email.

Contact

Tripticode, S.L. · C/ Júcar 36B, 41012, Sevilla, Spain · dp@tripticode.com