Privacy Policy
How Tripticode collects, uses, and protects personal data across tripticonsent.tripticode.com, the console, and the Tripticonsent API.
Effective date: September 13, 2026. This policy covers tripticonsent.tripticode.com, the console (console.tripticonsent.tripticode.com), and the API (api.tripticonsent.tripticode.com), together "the Service".
Who we are
Tripticonsent is a product of Tripticode, S.L., registered at C/ Júcar 36B, 41012, Sevilla, Spain ("Tripticode", "we", "us"). You can reach us on data protection matters, including to exercise your rights, at dp@tripticode.com.
Two distinct roles: controller and processor
This is the single most important distinction in this document, because it determines who you should contact to exercise your rights.
- When you visit
tripticonsent.tripticode.com, sign up as a customer, or a member of your team signs into the console, Tripticode is the data controller: we decide what those data are used for, and you can exercise your rights directly with us. - When a customer organization uses the Tripticonsent API or SDK to capture consent or preferences from its own end users (the people visiting that organization’s site or app), Tripticode acts as a data processor on that organization’s behalf — the organization is the controller. In that case, we are not your point of contact: you should reach out to the organization that captured your consent — Tripticode only provides them the tools (including export, rectification, and erasure) to handle your request.
console.tripticonsent.tripticode.com, you’re the latter — contact the organization whose site or app you were using.What data we collect
As a controller (customers, team members, site visitors)
| Category | Data | Source |
|---|---|---|
| Account | Name and email. To sign in we use only "Continue with Google" (we verify Google’s token directly — no Firebase Authentication, and no user database of our own at Google) or a single-use email magic link — we never store passwords. MFA (TOTP) status, if you enable it. | You provide it when signing up or signing in |
| Console usage | Audit logs of your actions (site creation, keys, configuration changes) | Generated automatically as you use the console |
| Communications | Email address, message content | If you write to support or sales |
| Site visits | IP address (exposed to the Google Fonts CDN when the typeface loads) | Automatic on loading any tripticonsent.tripticode.com page |
tripticonsent.tripticode.com uses no first-party cookies and no analytics (Google Analytics, Plausible, or similar) — no cookie banner is needed to browse the marketing site.As a processor (our customers’ end users)
On behalf of each customer organization, the API stores, for every person whose consent or preferences that organization manages:
- An identifier (email, phone, a customer-owned id, or a
cookie_idfor anonymous visitors), always encrypted at rest (AES-256-GCM) — never stored as plain text. - The state of every decision (granted, denied, withdrawn…), the exact version of the legal text shown at that moment, the date, and, where applicable, the IP address it was issued from, as evidence against a claim.
- A signed receipt (Ed25519) for every decision, verifiable offline and without depending on our servers.
This data belongs to the relevant customer organization and is used only to provide the Service they contracted — it is never combined across customers or used for Tripticode’s own purposes.
Legal basis for processing
- Performance of a contract (GDPR Art. 6(1)(b)): to sign you up as a customer, deliver, and bill for the Service.
- Legitimate interest (Art. 6(1)(f)): for the security of the Service (abuse detection, audit logs) and to respond to your inquiries.
- Legal obligation (Art. 6(1)(c)): to retain evidence of consent where the law requires it.
- When we act as a processor, the underlying legal basis (typically the end user’s consent, Art. 6(1)(a)) is determined and documented by the customer organization, not by us.
Who we share data with — sub-processors
We use the following providers to operate the Service. None of them is permitted to use the data for its own purposes; all of them operate under a data processing agreement (DPA) with Tripticode.
| Provider | Role | Data it can touch | Location |
|---|---|---|---|
| Vercel | Hosting for the API, console, marketing site, and AI connector | All HTTP traffic; logs including IP address | EU — Frankfurt (fra1) |
| Neon | PostgreSQL database | All persistent data: accounts, encrypted consent data, lookup hashes | EU — eu-central |
| Upstash | Caching, request rate limiting, and the delivery queue for webhooks and transactional email (QStash) | Cached consent state (pseudonymous, 1-hour TTL), short-lived IP counters, and queued messages, which are encrypted before they leave our servers | EU (region is configurable; ours is pinned to the EU) |
| Resend | Transactional email delivery (data-subject-request verification, double opt-in preference confirmation) | Recipient email address, a single-use link | US, DPF-certified |
| Groq | Automatic classification of unknown cookies found by the scanner, and optional machine translation of banner and legal-document copy | Technical cookie metadata (name, domain, the scanned site’s URL) and customer-authored text; never end-user or subject data | US — classification runs only for cookies our reference data can’t place; translation only if the customer uses it |
| Stripe | Payment processing and billing for your organization's subscription | The email of whoever starts the subscription, and the payment details you enter directly into Stripe — these never pass through our servers or get stored in our database. It never receives your end users' consent data. | US (Stripe, LLC) or EU/UK (Stripe Payments Europe/UK) depending on your location, with an active DPF certification |
| Sentry | Error tracking for our own servers | Technical error reports. User info, cookies, request bodies and query strings are never collected, and emails, identifiers and keys are masked before sending. No telemetry from visitors’ browsers | EU — Frankfurt (de.sentry.io) |
| Cloudflare | Bot protection (Turnstile) on the console login form and the hosted data-subject-request form | The IP address and browser signals of whoever solves the challenge on those two forms | Global network; US entity, DPF-certified |
Each provider’s DPA: Vercel · Neon · Upstash · Resend · Groq · Stripe · Sentry · Cloudflare.
International transfers
Persistent data storage (database, cache) is pinned to the EU. A few sub-processors operate from the US for specific functions; those transfers rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission’s standard contractual clauses where it is not — per that provider’s current DPA, linked above. Groq offers no EU data residency for inference; what it receives from Tripticonsent is technical metadata (cookie names, domains, UI and legal-document text), not identifiers or subject data. Cloudflare only sees who solves a bot challenge on two forms. Stripe maintains an active Data Privacy Framework certification for the entities that process payments outside the EU/UK.
Security
- AES-256-GCM encryption at rest for any stored identifier or personal data, with key rotation.
- Identifier lookups use a deterministic HMAC-SHA256 hash with a pepper separate from the encryption key — lets us find a record without decrypting anything.
- Append-only vault: no consent record is ever modified or deleted; a change always creates a new row referencing the previous one.
- Hash-chained audit log of every configuration action, to detect tampering.
- Multi-factor authentication (TOTP) available for every console account.
Retention & erasure
Account data is kept for as long as the organization maintains its subscription, and afterward for whatever period applicable tax or corporate law requires.
For data we process on a customer’s behalf: when a customer organization fulfils an erasure request from one of its end users, we apply crypto-shredding — we destroy the encryption key for that person’s identifier, making them permanently and irreversibly unfindable. The already-anonymized historical event log is kept for legal defensibility (for example, to prove a consent was correctly requested and handled at the time), but with no data that could identify the person.
A photo or scan of an ID document, where a customer organization requires one to verify a data-subject request, is deleted automatically 7 days after upload, regardless of whether the request was approved or rejected.
Connected AI agents (MCP)
If your organization connects an AI agent such as Claude through our MCP connector, that agent acts with exactly the same permissions and limits as an authorized member of your team — never with expanded access. The full detail of what it can and cannot touch is in AI agents (MCP).
Your rights
If you are a customer, team member, or site visitor (Tripticode is the controller): you can request access, rectification, erasure, restriction, portability, and object to processing by writing to dp@tripticode.com, and lodge a complaint with the Spanish Data Protection Agency (AEPD) or your own supervisory authority.
If you are an end user whose consent is managed by one of our customer organizations through Tripticonsent (Tripticode acting as processor): direct your request to that organization, not to us — you will typically find a preference link or a rights-request form on their own site.
Children
The Service is aimed at organizations and the people acting on a company’s behalf; it is not directed at children, and we do not knowingly collect data from them.
Changes to this policy
If we materially change how we handle your data, we will reflect it on this same page with a new "last updated" date and, where the change significantly affects you, notify you by email.
Contact
Tripticode, S.L. · C/ Júcar 36B, 41012, Sevilla, Spain · dp@tripticode.com