Effective August 26, 2026Version 1.0

Privacy Policy

How 1Consent collects, uses, discloses, retains, and protects personal data across our website and Consent Management Platform.

The short version

We use personal data to operate and secure 1Consent, manage accounts and subscriptions, respond to you, and provide features you choose to use. We do not sell personal data or use customer end-user data for advertising. When customers use our CMP on their sites, they normally decide why that visitor data is processed and 1Consent processes it on their instructions.

Who is responsible

For the website, accounts, billing relationship, support, and our own business operations, the controller is:

1Consent UG (haftungsbeschränkt)

Ernst-Vogler-Weg 9

83607 Holzkirchen

Germany

Represented by Artur Przemyslaw Wachelka

Commercial register: Amtsgericht München, HRB 315682

We have not appointed a data protection officer because the statutory appointment criteria currently do not apply. Privacy requests go directly to the privacy contact listed below.

Scope and our different roles

This Policy applies when you visit 1consent.app, join the waitlist, create or use an account, subscribe, contact us, or otherwise interact directly with 1Consent.

When a customer deploys 1Consent on its own website or app, that customer generally acts as controller for its visitors' consent records and related CMP measurements. 1Consent acts as processor under Section 11 of the Terms. We use that data only to provide, secure, and support the service on the customer's instructions.

A customer's own privacy and cookie notice governs its use of the CMP. If your request concerns a consent choice made on a customer's site, contact that customer first; we assist the customer with verified requests.

Personal data we process and where it comes from

The categories depend on how you interact with us. We collect data from you, your organization, your browser or device, the customer that deployed our CMP, and the service providers identified below.

Website and security data

IP address, approximate country or region, request date and time, requested URL and query string, referrer, browser and device information, language, protocol and response data, security signals, and error or performance traces.

Account and organization data

Name, email address, authentication identifiers, organization and role, invitation and access status, account preferences, audit events, and support or security history.

Configuration and customer content

Domains, projects, app and framework settings, service and vendor catalog choices, consent text, translations, themes, uploaded assets, API and deployment metadata, scan targets and results, detected cookies or requests, screenshots of public pages, and audit records. A scan of a public page can incidentally capture personal data shown on that page.

Subscription and transaction data

Selected plan and add-ons, billing interval and status, usage totals, transaction and subscription identifiers, invoices, tax and country information, and limited payment status returned by Stripe/Link. 1Consent does not receive full card numbers.

Waitlist, contact, and support data

Name, email address, subject, message, support attachments, correspondence, delivery status, and technical information needed to diagnose a request.

Customer end-user CMP data

Pseudonymous consent identifiers, action and timestamp, encoded consent string and its SHA-256 hash, framework and notice/configuration versions, app and tenant identifiers, plus sampled or aggregated CMP metrics such as totals by day, country, device, framework, experiment variant, and consent time.

Sources

We receive data directly from you or your organization, automatically from browsers and systems, from customer websites using 1Consent, and from providers such as Clerk and Stripe/Link. We do not buy consumer profiles from data brokers.

Purposes and legal bases

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Article 6(1)(b): create and administer accounts, deliver the service, provide support, process subscriptions, and take requested steps under a contract.
  • Article 6(1)(b): respond to product inquiries, waitlist requests, and steps requested before entering a contract.
  • Article 6(1)(c): keep tax and commercial records, respond to lawful requests, and meet other legal duties.
  • Article 6(1)(f): protect the website, service, customers, and others; prevent fraud and abuse; investigate incidents; and establish or defend legal claims.
  • Article 6(1)(f): maintain, debug, measure, and improve the service using proportionate operational data and aggregated statistics.
  • Article 6(1)(a): optional website analytics and any other processing for which we specifically request consent. Consent can be withdrawn at any time for the future.
  • Article 6 does not give 1Consent a separate purpose for customer end-user data processed as processor. The customer determines and discloses its legal basis.

For legitimate interests, we consider necessity, reasonable expectations, data minimization, safeguards, and the impact on individuals. You may object as described below.

Website storage, analytics, and security services

Necessary storage and our CMP

Our own CMP stores your privacy choice in browser storage and may use a first-party cookie so the site can remember and apply that choice. This is necessary to provide the privacy settings you request and is used under Section 25(2)(2) TDDDG where German law applies.

Optional PostHog and Google Analytics 4

On this website, PostHog and the Google tag load only after you allow the respective service in Cookie Settings; Google Consent Mode is configured in Basic mode. PostHog receives a manual page-view event containing the current page URL, including its query string, plus a pseudonymous browser identifier and browser/device data; autocapture, session recording, and automatic page-leave capture are disabled. Google Analytics 4 measures page views, engagement, browser/device characteristics, approximate location, referrers, and campaign attribution using its own identifiers. Google advertising storage and personalization remain denied unless you separately consent to a configured advertising service. Do not put personal or confidential information in URLs.

Cloudflare Turnstile

The contact form uses Turnstile to distinguish legitimate requests from automated abuse. Cloudflare processes connection, device, browser, interaction, and verification data. We treat this as necessary security processing under Article 6(1)(f) GDPR and Section 25(2)(2) TDDDG.

Sentry diagnostics

Production server and edge errors and a limited sample of performance traces are sent to Sentry's EU ingest endpoint. They can include IP address, request headers, URL, stack trace, and technical context. Client-side website reporting is disabled by default and, if enabled, excludes default personal data and tracing.

Use Cookie Settings in the footer to revisit each optional service. Withdrawing consent for PostHog or Google Analytics 4 stops future collection by that service. It does not affect processing already performed lawfully.

How customer end-user CMP data is handled

The customer chooses the applicable framework, purposes, vendors, wording, and deployment rules. 1Consent supplies and operates the configured CMP as processor.

  • A raw consent receipt contains a pseudonymous consent ID, event ID, action, received time, encoded consent string and hash, framework identifiers, and version evidence. Raw receipts are kept on a rolling 24-calendar-month basis unless earlier deletion is required.
  • The consent receipt table does not store the visitor's IP address or user-agent string. Identifiers are still treated as pseudonymous personal data, not as anonymous data.
  • CMP analytics are stored as tenant/app-level hourly or daily rollups. They are not keyed by consent ID, but small groups can still be personal data where singling out remains reasonably possible, so we protect them accordingly.
  • If a customer enables session measurement and its visitor grants the Analytics purpose, a first-party session identifier measures visits. It expires in the browser after 30 minutes of inactivity; the server deduplication marker lasts 60 minutes. Daily sampling counts last 14 days before being reduced to plan-level analytics.

Requests about this data should be sent to the customer that deployed the CMP. We provide deletion and assistance workflows to that customer, including deletion of subject-linked raw receipts and tenant data.

AI-assisted features

AI features run only when an authorized account user asks for them, for example to generate or refine a theme or translate authored CMP content.

  • Depending on the feature, inputs can include the user's instruction, current theme tokens, a screenshot or uploaded image, or the authored text selected for translation.
  • Requests pass through Cloudflare AI Gateway to OpenAI. Cloudflare handles gateway metadata and OpenAI processes the prompt and output to generate the requested result.
  • 1Consent disables prompt and response payload storage in Cloudflare AI Gateway; limited request metadata remains. OpenAI states that API inputs and outputs are not used to train models by default and may be retained for up to 30 days for abuse monitoring unless a shorter retention control applies.
  • Outputs are suggestions. An authorized user reviews and decides whether to save or publish them.

Do not submit special-category data, secrets, or third-party personal data that is not needed for the requested AI feature.

Recipients and service providers

We disclose data only as needed for the purposes above, under contracts and access controls appropriate to the provider's role:

  • Cloudflare — CDN, DNS, edge Workers, queues, object storage, email delivery, Turnstile, security, location signals, and AI Gateway.
  • Vercel — website, dashboard, and API hosting, deployment, logs, and file/blob hosting.
  • Clerk — authentication, sessions, account identity, organization access, and waitlist management.
  • Neon — managed PostgreSQL databases for platform, content, and consent data.
  • Stripe and Link — merchant of record, checkout, billing, taxes, fraud prevention, disputes, receipts, order management, and transaction support.
  • Google Cloud — isolated scanner execution and processing of customer-requested site scans and artifacts.
  • Google Ireland Limited — optional, consent-based Google Analytics 4 measurement for the public website.
  • Trigger.dev — orchestration and execution of durable background workflows.
  • Upstash — short-lived Redis storage for session deduplication and service coordination.
  • Sentry — error monitoring and sampled performance diagnostics.
  • PostHog US Cloud — optional, consent-based analytics for the public website.
  • OpenAI — generation for AI-assisted themes, suggestions, and translations requested by an authorized user.
  • Professional advisers, auditors, insurers, authorities, courts, or transaction counterparties where reasonably necessary and legally permitted.

We do not sell personal data, share it for cross-context behavioral advertising, or allow providers to use customer end-user data for their own advertising.

International transfers

We prefer EEA processing where available, but our provider chain includes processing in the EEA, United Kingdom, United States, and other locations from which global infrastructure is operated. A global edge request may be processed near the visitor.

  • European Commission adequacy decisions, including the EU-US Data Privacy Framework for certified recipients where available.
  • The European Commission's 2021 Standard Contractual Clauses and, where relevant, the UK transfer addendum.
  • Encryption in transit and at rest, access controls, minimization, pseudonymization, transfer assessments, and contractual review of government-access requests.

Contact us to request more information or a copy of the relevant transfer safeguard, with protected confidential terms redacted where necessary.

Retention and deletion

We keep data for the shortest period needed for the stated purpose, then delete or irreversibly aggregate it. These are the current operational periods and criteria:

  • Website and application security logs and diagnostics: normally no more than 90 days, unless an incident requires a protected copy for investigation or claims.
  • Contact and support correspondence: normally 12 months after the matter closes, longer only where the relationship or a legal claim requires it.
  • Waitlist data: until access is granted, declined, or withdrawn, and in any event reviewed after 24 months of inactivity.
  • Account, configuration, assets, scans, and audit data: for the contract term, the 30-day retrieval period described in the Terms, and then deletion from active systems, subject to legal duties and backup cycles.
  • Invoices, transaction evidence, and tax or commercial records: 10, 8, or 6 years depending on the record under current German tax and commercial law.
  • Raw pseudonymous consent receipts and related event-ID tombstones: rolling 24 calendar months. Verified subject erasure removes subject-linked raw receipts earlier where required.
  • Daily CMP analytics: 7 days on Free, 90 days on Starter, and 548 days (18 months) on Pro. Hourly analytics last 7 days.
  • First-party session identifier: 30 minutes of inactivity in the browser; deduplication marker: 60 minutes; daily session sampling counts: 14 days.
  • Cloudflare does not store AI prompt or response payloads for our requests. OpenAI API payloads can be retained for up to 30 days unless a shorter control applies.
  • Evidence needed for legal claims: for the applicable limitation period, generally three years from the end of the relevant year, and longer only where a statutory maximum or active proceeding applies.

Deletion from backups follows protected provider rotation cycles and can take up to 180 days. Backup copies are isolated from ordinary use and restored only for continuity or security recovery.

Your privacy rights

Subject to the conditions and exceptions in applicable law, you may ask us to:

  • confirm processing and provide access to your personal data;
  • correct inaccurate or complete incomplete data;
  • delete personal data;
  • restrict processing;
  • provide data you supplied in a portable format where Article 20 applies;
  • object to processing based on legitimate interests;
  • withdraw consent at any time for future processing; and
  • complain to a competent data protection authority.

Send a request to the privacy email below. We may verify your identity and authority, and will respond within the period required by law. There is normally no charge. Authorized agents may act where applicable law permits and their authority can be verified.

Our lead local authority for private-sector processing is the Bavarian State Office for Data Protection Supervision (BayLDA)

What is required and what is optional

Account identity, organization details, essential configuration, and transaction information are required to enter or perform the service contract. Without them, we may be unable to create an account, deliver the service, or provide a paid plan.

Website analytics, optional profile fields, AI features, and the content of a voluntary inquiry are optional. Refusing optional analytics does not reduce website or service functionality.

Automated decisions

1Consent does not make decisions based solely on automated processing that produce legal or similarly significant effects about account users or website visitors. AI output is advisory and requires user action. Stripe/Link may independently use automated fraud and risk systems under its own privacy information.

United States privacy disclosures

This section supplements the rest of this Policy for residents of US states with applicable privacy laws. Some rights apply only if 1Consent meets that law's coverage thresholds.

  • Categories collected in the preceding 12 months: identifiers and contact information; internet, device, and network activity; commercial and subscription information; approximate geolocation; professional or employment-related organization information; customer content; and inferences limited to security, service configuration, or product use.
  • Sources and business purposes are described in Sections 3 and 4 above.
  • Recipient categories are infrastructure, authentication, database, payments, workflow, diagnostics, analytics, AI, security, and professional-service providers described in Section 8.
  • We do not sell personal information, share it for cross-context behavioral advertising, use sensitive personal information to infer characteristics, or offer financial incentives for personal information.
  • Where applicable, you may request access, correction, deletion, portability, a list of relevant third parties, or opt out of sale, targeted advertising, or certain profiling. We will not discriminate against you for exercising a right.
  • If we deny a request and your state grants an appeal right, reply to our decision within 45 days with 'Privacy appeal' in the subject line.

We do not currently interpret a browser's Do Not Track setting as a separate instruction because no uniform standard applies. We honor Global Privacy Control where legally required. On this website, our Basic Consent Mode configuration keeps each optional analytics service off unless you affirmatively allow that service in our CMP.

Children

1Consent is a business service and is not directed to children. We do not knowingly collect personal data from children through our direct account relationship. Customers must assess any child-specific duties for their own sites and must not enable unlawful processing through the service.

Security

We use technical and organizational measures appropriate to the risk, including encryption in transit and at rest where supported, tenant separation, role-based access, authentication controls, secrets management, logging, backups, vulnerability management, data minimization, and incident procedures.

No internet service is completely secure. Please report a suspected security issue promptly and do not send secrets through the contact form.

Changes to this Policy

We may update this Policy when the service, providers, or law changes. We will change the effective date and provide a prominent notice or direct account notice when a change materially affects your rights or our use of personal data. Earlier versions can be requested from us.

Contact us

Use the following privacy contact for questions, rights requests, transfer-safeguard requests, or concerns. If the matter involves a customer's CMP, identify the customer site and avoid sending unnecessary sensitive data.