Privacy Policy
Last updated: 17 February 2026
Who we are
CookieChest is a trading name of Tailor Made Analytics. We provide cookie consent management and compliance monitoring services. Contact us at [email protected].
What data we collect
We collect the following personal data:
- Name and email address (via contact form or checkout)
- Website URL (when you sign up for monitoring)
- Payment information (processed securely by Stripe — we never store card details)
- Usage data via Google Analytics 4 and Google Tag Manager (anonymised, consent-gated)
Data collected during monitoring scans
When we monitor your website, our automated scans collect:
- Network requests made before and after consent (to detect pre-consent data leakage)
- Consent Mode v2 signal states
- GTM container contents and configuration
- Third-party scripts loaded on the page
- CMP banner state (presence, accept/reject behaviour)
This data relates to your website's technical configuration, not to your visitors' personal data.
RUM (Real User Monitoring) data
Where you install our RUM script, it collects anonymised performance metrics from your site visitors, including page load times, core web vitals, and basic page view data. No personally identifiable information is collected. The script does not set cookies or use local storage.
You are responsible for disclosing the RUM script in your own privacy policy and cookie banner where required by applicable law.
How we use your data
- To provide and manage your CookieChest subscription and monitoring service
- To send compliance alerts and transactional emails (via SendGrid)
- To respond to enquiries submitted through our contact form
- To improve our website and services through anonymised analytics
Legal basis for processing
We process your data under the following lawful bases (UK GDPR Article 6):
- Contract: To deliver the services you have purchased
- Legitimate interest: To improve our website and respond to enquiries
- Consent: For analytics cookies (managed via our cookie banner)
Agency data handling
Where you use CookieChest under an agency or reseller arrangement, CookieChest acts as a data processor on your behalf. You remain the data controller for your end clients. You are responsible for ensuring appropriate data processing agreements are in place with your clients.
Third-party processors
We use the following sub-processors:
- Stripe — payment processing
- SendGrid — transactional email and compliance alerts
- Google Analytics / GTM — anonymised website analytics
- Cookie-Script — cookie consent management
- Cloudflare — website hosting, CDN, and Workers (checkout and RUM endpoints)
- GitHub — monitoring scan execution (GitHub Actions) and snapshot storage
- Formspree — contact form processing
Data retention
- Account data: retained for the duration of your subscription
- Monitoring scan snapshots: retained for subscription duration plus 90 days
- RUM data: aggregated, anonymised, retained for 12 months
- Contact form submissions: retained for 12 months
- You may request deletion at any time
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability
- Lodge a complaint with the ICO (ico.org.uk)
Contact
For any privacy-related requests, email [email protected].