Understand where CookieShift processes data, retention, and workspace privacy controls.
CookieShift stores consent records, scan results, and configuration to operate the product. Use this guide with your Data Processing Agreement (DPA) and legal team.
What data CookieShift processes
| Data type | Examples | Used for |
|---|---|---|
| Account | Email, name, auth provider | Login, billing |
| Property config | Banner JSON, categories, laws | Serving consent UI |
| Scan results | URLs, cookie names, vendors | Inventory & compliance |
| Consent logs | Timestamp, categories, pseudonymous IDs | Audit & analytics |
| AI payloads | Prompts derived from your site context | Assistant, translations |
Data residency
Settings may display a processing region label (for example European Union (Frankfurt)). Workspace owners can open Data residency configuration when enabled.
Consent log retention
On Consent logs:
- Set retention period and Save retention when supported
- Older records purge per policy—verify before regulatory holds
- Export audit packages before shortening retention if litigation is possible
Privacy toggles in AI Settings
| Toggle | Purpose |
|---|---|
| Anonymize payloads | Reduce PII sent to models |
| Zero-Retention Mode | Minimize provider retention where supported |
| Auto-classify unknown trackers | Runs on new scans—review classifications |
BYOK sends data to your provider under their terms.
Cross-domain consent sync
Implementation (advanced) supports cross-domain consent sync with cookie domain and allowed origins. Use when subdomains should share one consent state—misconfiguration can leak consent state; test carefully.
Your responsibilities
- Maintain accurate privacy policy and cookie disclosures
- Honor opt-out and deletion requests per applicable law
- Configure categories to match actual processing
- Restrict dashboard access to authorized staff