Privacy PolicyGDPR Compliant

Last Updated: 7/16/2025 | Effective Date: 7/16/2025

Introduction

ContactCloak ("we," "us," or "our") is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

Data Controller: ContactCloak, operated by Peter Sillen
Contact: privacy@contactcloak.com
Data Protection Officer: dpo@contactcloak.com

Legal Basis for Processing

Contract Performance (Article 6(1)(b) GDPR)

Processing necessary to provide our contact page services, user authentication, and account management.

Legitimate Interest (Article 6(1)(f) GDPR)

Essential security measures, fraud prevention, and service improvement based on anonymous analytics.

Consent (Article 6(1)(a) GDPR)

Optional analytics cookies and enhanced functionality features. You may withdraw consent at any time.

Information We Collect

Personal Information

Information you provide when registering and using our services:

  • Account Data: Name, email address, password (encrypted)
  • Contact Information: Details you choose to display on your contact page
  • Payment Data: Processed by Paddle (PCI DSS compliant) - we don't store payment details

Analytics Data (with your consent)

Anonymous usage statistics to improve our service:

  • Page Views: Which pages are visited and when
  • Geographic Data: Country-level location (no precise location)
  • Referrer Information: Where visitors come from
  • Browser Data: Browser type, device type (no device IDs)
  • Usage Patterns: How features are used (anonymized)

Technical Data

Automatically collected for security and functionality:

  • Security Logs: Failed login attempts, suspicious activity
  • Error Logs: Technical issues for debugging (no personal data)
  • Session Data: Temporary data for your login session

Detailed Cookie Information

Essential Cookies (Always Active)

Cookie NamePurposeDuration
better-auth.session_tokenUser authentication7 days
better-auth.csrf_tokenCSRF protectionSession
better-auth.session_dataSession caching5 minutes
contactcloak-cookie-consentYour cookie preferences1 year
cf_*Cloudflare security & DDoS protectionSession

Analytics Cookies (Requires Consent)

These cookies help us understand how visitors use ContactCloak to improve our service:

  • Anonymous page view tracking for dashboard insights
  • Country-level geographic data (no precise location)
  • Referrer sources to understand traffic patterns
  • Browser/device statistics for compatibility
  • Bot detection and spam prevention metrics

Functional Cookies (Optional)

These cookies remember your preferences to enhance your experience:

  • Dashboard layout and sorting preferences
  • Theme settings (dark/light mode)
  • Language and timezone preferences
  • Page builder settings and customizations

Data Retention Periods

Data TypeRetention PeriodReason
Account InformationUntil account deletionService provision
Analytics Data2 years maximumService improvement
Security Logs6 monthsFraud prevention
Payment Records7 yearsLegal compliance
Support Communications3 yearsCustomer service

Your GDPR Rights

Right to Access (Article 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Article 16)

Correct any inaccurate or incomplete personal data.

Right to Erasure (Article 17)

Request deletion of your personal data ("right to be forgotten").

Right to Restrict Processing (Article 18)

Limit how we process your personal data in certain circumstances.

Right to Data Portability (Article 20)

Export your data in a structured, machine-readable format.

Right to Object (Article 21)

Object to processing based on legitimate interest or for direct marketing.

Right to Withdraw Consent

Withdraw consent for analytics or functional cookies at any time.

Right to Complain

Lodge a complaint with your local data protection authority.

Response Time: We will respond to your requests within 30 days. For complex requests, we may extend this to 60 days and will inform you of any delay.

International Data Transfers

Cloudflare (DDoS Protection & CDN)

Adequacy Decision: Cloudflare operates under the EU-U.S. Data Privacy Framework and maintains adequate safeguards for EU data transfers.

Better Auth (Authentication)

Data Location: Authentication data is processed within the EU/EEA region to ensure GDPR compliance.

Paddle (Payments)

Standard Contractual Clauses: Payment processing follows GDPR-compliant data transfer mechanisms.

Data Security Measures

  • Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based access with multi-factor authentication
  • Regular Audits: Security assessments and vulnerability scanning
  • Data Minimization: We only collect necessary data
  • Incident Response: 72-hour breach notification procedures
  • Staff Training: Regular privacy and security awareness training
  • Secure Development: Privacy by design principles
  • Third-party Assessments: Vendor security evaluations

Data Breach Procedures

Our Commitment

  • Detection: Continuous monitoring and automated breach detection
  • Assessment: Risk evaluation within 24 hours of discovery
  • Notification: Authorities notified within 72 hours if required
  • User Communication: Affected users notified without undue delay if high risk
  • Remediation: Immediate steps to contain and resolve the breach
  • Review: Post-incident analysis and security improvements

Contact Information

General Privacy Inquiries

Email: privacy@contactcloak.com
Response Time: 48 hours

Data Protection Officer

Email: dpo@contactcloak.com
For GDPR rights requests

Security Issues

Email: security@contactcloak.com
For vulnerability reports

EU Representative

Email: eu-rep@contactcloak.com
For EU-specific inquiries

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will:

  • Post the updated policy on this page with a new "Last Updated" date
  • Notify you via email for material changes affecting your rights
  • Provide notice through our service for significant updates
  • Maintain previous versions for reference upon request