Who we are
ConsentCook is operated by Arched (arched.dev). Consentcook operates a multi-tenant consent management platform on behalf of website operators ("Customers"). This policy covers data we process about our Customers and the visitors to their sites.
Data we collect and why
We store consent receipts containing an HMAC-derived anonymous subject key (never a raw visitor identifier), the configuration and policy versions shown, the jurisdiction resolved, the language, and the purpose/vendor choices made. We do not store full IP addresses by default. Each field exists to provide auditable evidence of a consent decision and is retained only for the configured retention window.
Legal basis and roles
For consent receipts collected on a Customer site, the Customer is the controller and Consentcook is the processor. For our own account and billing data, Consentcook is the controller. See the DPA for the full breakdown.
Retention
Consent receipts are retained for the period configured by the Customer (default 365 days) and then permanently deleted by an automated retention job. Customers may request earlier erasure of a subject's receipts via the deletion workflow described in the DPA.
Your rights and erasure
Site visitors may exercise access and erasure rights through the Customer (controller). Consentcook, as processor, supports erasure of a subject's receipts keyed by the anonymous subject key. Full cross-system DSAR orchestration is out of scope for this release.
Contact
Privacy enquiries: privacy@consentcook.com.