SolidCookie
  • How it works
  • Pricing
  • Docs
Get early access

Legal

Privacy policy

Last updated 2026-08-27

This page explains what SolidCookie does with personal data. It is written to be read, not to be waved at. If anything here is unclear, or wrong, write to [email protected].

SolidCookie is operated from Ireland. Where this page says “we”, it means the operator of solidcookie.com. We wear two different hats, and they are described separately below: we are the controller for what happens on this website, and a processor for the consent records our customers’ websites write through us.

1. Visiting this website

When you load a page on solidcookie.com, our hosting provider and the network in front of it see your IP address, the page you requested, your browser’s user-agent string and the time. That is the normal business of serving a web page. Server logs are kept for a short operational period and are not used to profile anyone.

There is no analytics on this website. No tag manager, no advertising pixel, no session recording, no hotlinked fonts. The scanner we sell reports exactly those things, and this site has to pass its own scan.

Legal basis: our legitimate interest in running a website that works and is not being attacked.

2. The consent cookie

This site runs its own consent banner. When you answer it, one cookie is set: gdprs_consent. It records what you chose, so you are not asked again on every page, and it is strictly necessary in the legal sense — a consent tool that could not remember your answer would have to keep asking. It contains a random identifier and your choices; nothing about you. Details are on the cookie policy.

Your answer is also written to our own consent store as a record, in the same form our customers’ records take — see section 4 for what a record contains and what it deliberately does not.

3. The early-access list

If you leave your email address on the “Get early access” form, we store the address, which page you left it on, and the date. Nothing else: no user-agent, no IP hash. Your IP address is used once, hashed, to slow down automated submissions, and is not written anywhere.

Why: to tell you when there is a dashboard to log in to. Legal basis: your consent, given by submitting the form. How long: until you ask to be removed, or until we launch and you decide not to sign up — after which the list is deleted. To be removed: email [email protected] from the address in question.

4. Consent records we hold for customers

When a website that uses SolidCookie asks its visitor about cookies, the visitor’s answer is written to our database as a consent record. For those records, the website owner is the controller and we are their processor: we hold the record for them, produce it when they need it, and delete it when its retention period ends.

A record contains:

  • a random visitor identifier, minted in the browser and derived from nothing about the person;
  • the exact published version of the banner and cookie declaration the visitor saw, by number and content hash;
  • what they chose, and when;
  • the page path (never the query string, which is where names, order numbers and search terms live);
  • a truncated user-agent string;
  • a hash of the visitor’s IP address, taken after the address has been truncated to /24 (IPv6: /48) and salted. The full address is never stored.

Records are kept for the period the website owner sets — 12 months by default — and then deleted by a scheduled job. We do not use them for anything except holding them for the customer.

5. Who else sees data

Three companies sit between a visitor and our database, all under contract and all processing within the EU or under EU-approved safeguards. They are listed, with what each one handles, on the sub-processors page. That page is the complete list; if it changes, it changes there first.

We do not sell personal data and we do not share it with anyone for their own purposes.

6. Your rights

You can ask for a copy of the personal data we hold about you, ask us to correct or delete it, object to or restrict its processing, and take it elsewhere. Email [email protected]. For consent records held for a customer’s website, contact that website; we will help them answer.

If you think we have got something wrong, you can complain to the Data Protection Commission, Ireland’s supervisory authority, at dataprotection.ie, or to the authority in your own EU country.

7. Changes

When this page changes, the date at the top changes with it. Changes that matter — a new sub-processor, a new use of data — will be announced to customers before they take effect.

© 2026 SolidCookie · solidcookie.com · Made in Ireland
  • Privacy
  • Cookies
  • Terms
  • Sub-processors