What we collect, in plain sight.
Last updated: 9 July 2026
Who we are. PlainConsent is a cookie consent product made by Bart Knijnenberg, the Netherlands. For anything in this policy, contact info@bartknijnenberg.com. This policy covers the website plainconsent.com and the PlainConsent script.
The short version. PlainConsent is built to collect as little as possible. The website is a set of static pages. The consent script itself makes zero third-party calls and stores each visitor's choice in a first-party cookie on the website that uses it, so that data does not come to us.
What we process on plainconsent.com
- Server and CDN logs. When your browser loads a page or the script, our hosting/CDN provider records the request (IP address, user-agent, timestamp). We use this to deliver the files and keep the service secure. For these delivery logs PlainConsent is the controller (not a processor acting for the website owner). Legal basis: our legitimate interest in security and delivery.
- If you contact us. Your email address and message. Legal basis: legitimate interest in answering you, or steps prior to a contract.
- If you start a trial or subscribe. Billing details are handled by our payment provider (Stripe); we receive the information needed to manage your subscription. Legal basis: performance of a contract.
- Cookies on this site. plainconsent.com uses its own consent banner. Non-essential cookies load only after you agree; your choice is stored in a first-party cookie.
What the PlainConsent script does with visitor data
Nothing leaves the page by default. The consent choice is stored in a first-party cookie on the customer's own domain. An audit record (a unique consent ID, timestamp, version and the per-category choices) is created only for the website owner and is sent only to an endpoint they choose. There is an optional hosted consent log; where a customer switches it on, we process those consent records as a processor on their behalf, under a Data Processing Agreement.
Recipients and sub-processors
Hosting and delivery (GitHub Pages and its CDN), payments (Stripe), and email (ImprovMX and Google for info@bartknijnenberg.com). Some of these are outside the EEA; such transfers rely on appropriate safeguards (Standard Contractual Clauses or an adequacy decision).
Retention
Logs are kept only as long as needed for security and then deleted or aggregated. Contact emails are kept as long as needed to help you. Billing data is kept for as long as the law requires.
Your rights
You can ask for access, correction, deletion, restriction, objection and portability, and you can withdraw consent at any time. Email info@bartknijnenberg.com. You may also complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Changes
We will update this page when the product or our tools change, with a new date at the top.