Last Updated: 7/16/2025 | Effective Date: 7/16/2025
Introduction
ContactCloak ("we," "us," or "our") is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
Data Controller: ContactCloak, operated by Peter Sillen
Contact: privacy@contactcloak.com
Data Protection Officer: dpo@contactcloak.com
Legal Basis for Processing
Contract Performance (Article 6(1)(b) GDPR)
Processing necessary to provide our contact page services, user authentication, and account management.
Legitimate Interest (Article 6(1)(f) GDPR)
Essential security measures, fraud prevention, and service improvement based on anonymous analytics.
Consent (Article 6(1)(a) GDPR)
Optional analytics cookies and enhanced functionality features. You may withdraw consent at any time.
Information We Collect
Personal Information
Information you provide when registering and using our services:
- Account Data: Name, email address, password (encrypted)
- Contact Information: Details you choose to display on your contact page
- Payment Data: Processed by Paddle (PCI DSS compliant) - we don't store payment details
Analytics Data (with your consent)
Anonymous usage statistics to improve our service:
- Page Views: Which pages are visited and when
- Geographic Data: Country-level location (no precise location)
- Referrer Information: Where visitors come from
- Browser Data: Browser type, device type (no device IDs)
- Usage Patterns: How features are used (anonymized)
Technical Data
Automatically collected for security and functionality:
- Security Logs: Failed login attempts, suspicious activity
- Error Logs: Technical issues for debugging (no personal data)
- Session Data: Temporary data for your login session
Detailed Cookie Information
Essential Cookies (Always Active)
Cookie Name | Purpose | Duration |
---|---|---|
better-auth.session_token | User authentication | 7 days |
better-auth.csrf_token | CSRF protection | Session |
better-auth.session_data | Session caching | 5 minutes |
contactcloak-cookie-consent | Your cookie preferences | 1 year |
cf_* | Cloudflare security & DDoS protection | Session |
Analytics Cookies (Requires Consent)
These cookies help us understand how visitors use ContactCloak to improve our service:
- Anonymous page view tracking for dashboard insights
- Country-level geographic data (no precise location)
- Referrer sources to understand traffic patterns
- Browser/device statistics for compatibility
- Bot detection and spam prevention metrics
Functional Cookies (Optional)
These cookies remember your preferences to enhance your experience:
- Dashboard layout and sorting preferences
- Theme settings (dark/light mode)
- Language and timezone preferences
- Page builder settings and customizations
Data Retention Periods
Data Type | Retention Period | Reason |
---|---|---|
Account Information | Until account deletion | Service provision |
Analytics Data | 2 years maximum | Service improvement |
Security Logs | 6 months | Fraud prevention |
Payment Records | 7 years | Legal compliance |
Support Communications | 3 years | Customer service |
Your GDPR Rights
Right to Access (Article 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Article 16)
Correct any inaccurate or incomplete personal data.
Right to Erasure (Article 17)
Request deletion of your personal data ("right to be forgotten").
Right to Restrict Processing (Article 18)
Limit how we process your personal data in certain circumstances.
Right to Data Portability (Article 20)
Export your data in a structured, machine-readable format.
Right to Object (Article 21)
Object to processing based on legitimate interest or for direct marketing.
Right to Withdraw Consent
Withdraw consent for analytics or functional cookies at any time.
Right to Complain
Lodge a complaint with your local data protection authority.
Response Time: We will respond to your requests within 30 days. For complex requests, we may extend this to 60 days and will inform you of any delay.
International Data Transfers
Cloudflare (DDoS Protection & CDN)
Adequacy Decision: Cloudflare operates under the EU-U.S. Data Privacy Framework and maintains adequate safeguards for EU data transfers.
Better Auth (Authentication)
Data Location: Authentication data is processed within the EU/EEA region to ensure GDPR compliance.
Paddle (Payments)
Standard Contractual Clauses: Payment processing follows GDPR-compliant data transfer mechanisms.
Data Security Measures
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access with multi-factor authentication
- Regular Audits: Security assessments and vulnerability scanning
- Data Minimization: We only collect necessary data
- Incident Response: 72-hour breach notification procedures
- Staff Training: Regular privacy and security awareness training
- Secure Development: Privacy by design principles
- Third-party Assessments: Vendor security evaluations
Data Breach Procedures
Our Commitment
- Detection: Continuous monitoring and automated breach detection
- Assessment: Risk evaluation within 24 hours of discovery
- Notification: Authorities notified within 72 hours if required
- User Communication: Affected users notified without undue delay if high risk
- Remediation: Immediate steps to contain and resolve the breach
- Review: Post-incident analysis and security improvements
Contact Information
General Privacy Inquiries
Email: privacy@contactcloak.com
Response Time: 48 hours
Data Protection Officer
Email: dpo@contactcloak.com
For GDPR rights requests
Security Issues
Email: security@contactcloak.com
For vulnerability reports
EU Representative
Email: eu-rep@contactcloak.com
For EU-specific inquiries
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will:
- Post the updated policy on this page with a new "Last Updated" date
- Notify you via email for material changes affecting your rights
- Provide notice through our service for significant updates
- Maintain previous versions for reference upon request