This policy explains how miniconsent handles personal data — on this website (miniconsent.com), in our admin app, and within the consent platform we provide. We build a privacy tool, so we collect as little as we can.
Who we are
miniconsent operates this website and the consent platform. You can reach us at [email protected]. Full operator details are on our Imprint page. For consent data we process on behalf of our customers, see Consent data below.
This website
The marketing site is static. It runs no analytics, no advertising, and no third-party trackers, and fonts are self-hosted (no Google Fonts or third-party CDN). It sets no cookies of its own — see the Cookie Policy.
Our CDN and security provider (Cloudflare) processes technical request data such as your IP address transiently to deliver and protect the site, and standard access logs may be retained briefly for security and reliability. Legal basis: our legitimate interest in operating a secure website (GDPR Art. 6(1)(f)).
Waitlist
The waitlist “form” simply opens your email client and sends us your email address — there is no third-party form processor. We use that address only to contact you about early access and launch, and we delete it on request. Legal basis: steps taken at your request (Art. 6(1)(b)) / your consent (Art. 6(1)(a)).
Admin accounts
If you hold an account, sign-in is handled by our own authentication service. We store your email address and organisation to operate your account, and a strictly-necessary session cookie keeps you signed in (see the Cookie Policy). Legal basis: performance of our contract with you (Art. 6(1)(b)).
Consent data (our role as processor)
When you deploy miniconsent on your website, the banner records consent events — the visitor’s choice, a timestamp, the banner and policy version, and a coarse country. We never store a raw IP address or user-agent: both are SHA-256 hashed with a per-install salt before they are written to disk.
For this data, you (our customer) are the data controller and we are your processor. We process it only to provide the service and in line with our agreement with you. Consent logs are held on EU infrastructure, are not transferred outside the EU, and have a default retention of 13 months.
Where your data is processed
On EU-based infrastructure. Cloudflare provides CDN, DNS and security at the network edge. We do not use US-based sub-processors in the consent-logging path.
Sub-processors
- Cloudflare — CDN, DNS, and edge security.
- EU hosting provider — application and database hosting within the EU.
We keep this list deliberately short and will update it here if it changes.
How long we keep data
- Website logs: short-term, for security and reliability.
- Waitlist email: until launch, or until you ask us to delete it.
- Account data: for the life of your account.
- Consent logs: 13 months by default (configurable per site).
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority. To exercise any of these, email [email protected].
If your request concerns consent data collected on a site that uses miniconsent, please contact that site’s operator — they are the controller of that data.
Changes
We’ll post any changes here and update the “last updated” date above. Questions? [email protected].