Privacy & Data Residency

Understand where CookieShift processes data, retention, and workspace privacy controls.

CookieShift stores consent records, scan results, and configuration to operate the product. Use this guide with your Data Processing Agreement (DPA) and legal team.

What data CookieShift processes

Data typeExamplesUsed for
AccountEmail, name, auth providerLogin, billing
Property configBanner JSON, categories, lawsServing consent UI
Scan resultsURLs, cookie names, vendorsInventory & compliance
Consent logsTimestamp, categories, pseudonymous IDsAudit & analytics
AI payloadsPrompts derived from your site contextAssistant, translations

Data residency

Settings may display a processing region label (for example European Union (Frankfurt)). Workspace owners can open Data residency configuration when enabled.

On Consent logs:

  • Set retention period and Save retention when supported
  • Older records purge per policy—verify before regulatory holds
  • Export audit packages before shortening retention if litigation is possible

Privacy toggles in AI Settings

TogglePurpose
Anonymize payloadsReduce PII sent to models
Zero-Retention ModeMinimize provider retention where supported
Auto-classify unknown trackersRuns on new scans—review classifications

BYOK sends data to your provider under their terms.

Implementation (advanced) supports cross-domain consent sync with cookie domain and allowed origins. Use when subdomains should share one consent state—misconfiguration can leak consent state; test carefully.

Your responsibilities

  • Maintain accurate privacy policy and cookie disclosures
  • Honor opt-out and deletion requests per applicable law
  • Configure categories to match actual processing
  • Restrict dashboard access to authorized staff