Privacy Policy

ConsentMonitor — Tagstack SASU · Last updated: 17/03/2026 · Version 1.0

Courtesy translation — This English version is provided for convenience only. In the event of any discrepancy, the French version shall prevail.

1. Data controller

The data controller for personal data collected through consentmonitor.com and the ConsentMonitor service is:

Tagstack SASU, share capital 100 €

Registered office: 17 rue Paul Bert, 94160, Saint-Mandé

SIREN: 100419340

Contact: privacy@consentmonitor.com

2. Personal data collected

2.1 User account data

When you register and use the service, we collect:

DataPurposeLegal basis
NameAccount management and commercial relationshipPerformance of contract (Art. 6.1.b GDPR)
Email addressAuthentication, communication, notificationsPerformance of contract
Organisation nameMulti-user management, billingPerformance of contract
IP addressSecurity, fraud prevention, loggingLegitimate interest (Art. 6.1.f GDPR)
Browsing data (pages viewed, clicks)Service improvement, usage analysisConsent (Art. 6.1.a GDPR)
Payment dataBilling and payment collectionPerformance of contract

2.2 Data collected during website checks

When ConsentMonitor analyses a user's website, the following data is collected:

DataWhat IS storedWhat is NOT stored
Detected cookiesCookie name, domain, path, expiration, attributes (Secure, HttpOnly, SameSite)Cookie value
Network requestsDomain name and request pathURL parameters, request body, transmitted cookies
ScreenshotsImage of the page at the time of the checkN/A

ConsentMonitor does not store any personal data of end users visiting its users' websites. Checks are performed by an automated browser (headless browser) without any real user session.

3. Cookies and trackers on consentmonitor.com

The consentmonitor.com website uses the following cookies and trackers:

ServicePurposeTypeDurationLegal basis
Session cookiesAuthentication, session managementEssentialSessionPerformance of contract
Google Analytics 4Audience measurement, usage analysisAnalytics14 months max.Consent
AxeptioCookie consent managementEssential12 monthsLegal obligation
StripeSecure paymentEssentialSessionPerformance of contract

Essential cookies are placed without prior consent as they are strictly necessary for the service. Analytics cookies (Google Analytics 4) are only placed after your explicit consent via our consent banner (Axeptio).

Tag management is handled by Cloudflare Zaraz, which operates server-side, thereby limiting the exposure of data to third-party scripts executed client-side.

4. Sub-processors and data transfers

Personal data may be processed by the following sub-processors:

Sub-processorServiceDataLocationSafeguards
Cloudflare, Inc.Hosting (Pages), database (D1), CDN, ZarazAll service dataEU / USSCCs, Cloudflare DPA
Google LLCGoogle Analytics 4Anonymised browsing dataEU / USSCCs, EU data region enabled
Stripe, Inc.Payment processingBilling and payment dataEU / USPCI DSS certified, SCCs
Axeptio (Agilitation SAS)Consent management (CMP)Visitor consent choicesFrance / EUEU hosting
QontoBanking servicesBilling dataFrance / EUACPR regulated, EU hosting

For transfers to the United States, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission and, where applicable, the EU-US Data Privacy Framework when the sub-processor is certified.

5. Data retention periods

Data categoryRetention period
Account data (name, email, organisation)Duration of contract + 3 years (commercial limitation period)
Billing data10 years (accounting obligation, Art. L.123-22 French Commercial Code)
Check results (cookies, requests, screenshots)According to the subscribed plan (7 days to 12 months), then deleted
Connection logs12 months (Article 6 of the LCEN)
Analytics data (GA4)14 months maximum

Once these periods expire, data is deleted or irreversibly anonymised.

6. Your rights

Under the GDPR and the French Data Protection Act, you have the following rights over your personal data:

RightDescription
Right of access (Art. 15 GDPR)Obtain confirmation that your data is being processed and receive a copy
Right to rectification (Art. 16)Have inaccurate or incomplete data corrected
Right to erasure (Art. 17)Request deletion of your data within legal limits
Right to restriction (Art. 18)Request the freezing of data processing
Right to portability (Art. 20)Receive your data in a structured, machine-readable format
Right to object (Art. 21)Object to processing based on legitimate interest
Right to withdraw consentWithdraw consent at any time for consent-based processing
Right to lodge a complaintFile a complaint with the CNIL (www.cnil.fr)
Post-mortem directivesDefine instructions regarding the fate of your data after death

To exercise your rights, send your request by email to: privacy@consentmonitor.com. We commit to responding within one month. This period may be extended by two months for complex requests, in which case you will be informed.

7. Data security

Tagstack implements the following technical and organisational measures to protect your data: encryption of data in transit (TLS/HTTPS), encryption at rest on Cloudflare D1, secure authentication with session management, role-based access control (RBAC) within organisations, hosting on Cloudflare infrastructure (ISO 27001, SOC 2 certified), and regular data backups.

8. Children's data

ConsentMonitor is a B2B service intended exclusively for professionals. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that a minor has provided us with personal data, we will delete it promptly.

9. Changes to this privacy policy

This policy may be modified at any time. In the event of a substantial change, we will inform you by email or by notification in the service interface at least thirty (30) days before the changes take effect.

10. Contact

For any questions about this policy or the processing of your personal data:

Email: privacy@consentmonitor.com

Tagstack SASU — 17 rue Paul Bert, 94160, Saint-Mandé

You may also lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr