Privacy Policy

Last updated: 24 August 2026

This Privacy Policy describes how your personal information is collected, used, and shared when you visit surecookie.com, when you use the SureCookie plugin, and when you use the scanning service at library.surecookie.com.

Where SureCookie is installed on someone else’s website, that website’s owner decides what data their site collects and is responsible for their own privacy policy. This policy covers our own sites and the services we operate.

Who We Are

We are Brainstorm Force US LLC. You can find more information about us, including our full address, on our company website.

Contact for all privacy matters: [email protected]

What Personal Information We Collect

When you visit our website, we automatically collect information about your device, including your web browser type, IP address, and time zone. As you browse the Site, we also collect information about the individual web pages or products you view, what websites or search terms referred you to the Site, and how you interact with the Site.

Cookies and Similar Technologies

“Cookies” are small data files placed on your device, often including an anonymous unique identifier. We use cookies and similar technologies (such as pixels and tags) across our sites for the following purposes:

  • Essential — required for core site functionality, including security and load balancing
  • Functional — remember your preferences and settings, and run the support chat widget
  • Analytics — help us understand how visitors use our sites and test improvements to site design
  • Marketing — used for advertising measurement and remarketing

Our consent system is configured to prevent non-essential analytics and marketing technologies from running until the required consent has been provided. Functional technologies are handled according to their purpose and the applicable consent requirements. You can change your preferences at any time by clicking Cookie Preferences in the footer.

We honor the Global Privacy Control (GPC) signal where required by law. If your browser or extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information.

A list of the cookies and tracking technologies our scanner detects on this site is available on our Cookie Policy page, linked from the cookie preference banner. That list is updated when the scanner detects a change. A scanner sees what loads on the pages it visits, so a technology that appears only on a page it has not yet scanned may not be listed straight away.

Retention: Records of your cookie consent choices are retained for up to 365 days, or less if manually cleared sooner, so we can demonstrate compliance with applicable consent requirements and honor your prior preferences on return visits.

How SureCookie Handles Data

SureCookie is a WordPress plugin backed by a scanning service we operate. Most of what it does happens inside your own WordPress installation. The sections below cover the cases where information leaves your site, and who is responsible for what.

Who Is Responsible For What

You are the controller of your visitors’ consent information. When you install SureCookie on your website and your visitors interact with the consent banner, you decide what the banner asks, how it categorizes technologies, and how long records are kept. The consent records the plugin creates are held on your own site and belong to you. If one of your visitors wants to exercise their rights over that data, they should contact you, and you can act on it directly in your WordPress admin.

We act as your processor only for information that actually reaches services we operate on your instructions. That means the page URLs and scan results handled by the scanning service, and the site URL and license details used to verify your connection and plan. We process those on your behalf and under our data processing agreement with you.

We are the controller in our own right for the information described elsewhere in this policy that relates to our own website, our customers, our billing, and our support and marketing communications.

This allocation of roles reflects our data processing agreement. Where the agreement and this summary differ, the agreement governs.

The Scanning Service

SureCookie connects to library.surecookie.com to run real browser-based cookie scanning and categorization.

  • Before your first scan, the plugin performs a one-time registration handshake with the scanning service.
  • When you run a scan, the plugin sends us the page URLs you selected. A browser-based scanner then visits those pages the same way a visitor would.
  • The scanner records what it finds: cookies, scripts, embedded resources, and third-party domains. It does not log in to your site and does not read your database, your form entries, or your customers’ personal data.
  • We keep the scan results so they can be shown in your dashboard and so a repeat scan can build on what was already found.
  • The scanner also writes diagnostic logs about the scan itself, which can include the page URLs visited and technical details of each request. These are records about the scan, not about your visitors, and we keep them only for as long as they are useful for diagnosing scan failures, after which they are deleted. If you need to know how long that currently is for your account, write to us at [email protected].

If your page URLs themselves reveal something sensitive, be aware they are transmitted to us as part of running a scan, and may appear in the diagnostic logs described above.

Cookie Categorization and Our Service Catalog

We maintain a catalog of known third-party services and the cookies they set, so the plugin can declare and block a service without waiting to observe it.

Cookies found by a scan are categorized automatically, including by an automated classification step that assigns a confidence score. High-confidence results are applied directly and lower-confidence ones are held for review. A category you set by hand is kept and is not overwritten by a later scan.

Aggregated information about which cookies and domains are commonly seen helps us keep this catalog accurate. This concerns cookie names, domains, and purposes, not the identities of your visitors.

Consent Records

Consent records generated by the plugin are stored on your own website. We do not receive a copy of them. Where the banner loads an image or a font from surecookie.com in order to display itself, that request carries no consent record.

Those records typically include a timestamp, the categories the visitor accepted or declined, the version of the banner and text the visitor was shown, the geographic rule that applied, and the visitor’s IP address. Together these give you an audit trail you can use to demonstrate that consent was given, which is what data protection law asks of a controller. The law does not require an IP address specifically, and the record’s usefulness as evidence comes from the trail as a whole rather than from any single field. Retention of those records is a setting you control, defaulting to 365 days and configurable down to 30, 60, or 90 days.

Because the visitor’s IP address is recorded, tell your own visitors about it in your own privacy policy.

Geolocation

To apply region-specific consent rules, the plugin needs to know roughly where a visitor is. The visitor’s IP address is resolved to a country, and the resolution happens server-side so it cannot be altered by the visitor. The country result is what determines which rule applies, and it is stored against the consent record alongside the other details described under Consent Records above.

Site Verification and Licensing

The plugin verifies that the site connecting to our services is the site it claims to be, and checks your plan and scan quota. This sends us your site URL and license details.

Contact Forms

Information submitted through contact forms on our Site is sent to our self-hosted support desk.

We may collect information submitted through contact forms, including (but not limited to) your first and last name and email address. We use it to answer you and to manage your request, and it is stored in our self-hosted CRM for that purpose.

Our download form asks for your name and email so we can send you the plugin and the service messages that go with it, such as setup guidance, security notices, and important product changes. Downloading the plugin does not add you to our marketing list. We only send you product announcements and offers if you separately opt in, as described under Newsletter Emails below.

Support Chat

Our support chat and documentation assistant is provided by Powerful Docs. It loads only after you provide consent. If you start a conversation, we receive the messages you send along with any name or email address you provide during the conversation.

Support

To help with our products, we may ask for temporary access to your website, either your live site or a staging copy, whichever you prefer, such as an admin login or FTP or database credentials. We may also ask you to share a license key, name, or email address.

Troubleshooting typically takes place directly on your site itself, and in these cases we do not transfer, export, or store your site’s data on our own servers. We recommend a staging copy where practical, but understand this is not always feasible for every customer.

In some cases, particularly for more complex issues, we may create a copy of your website on our own servers to investigate the problem. Once the issue is resolved, we delete these copies from our systems.

A few important points about access shared with our support team:

  • We use any access you provide strictly for debugging your specific issue
  • We do not copy site data to our own systems, except where you authorize us to create a temporary troubleshooting copy as described above, which we delete once the issue is resolved
  • We do not share your access or your data with anyone outside the company, other than the service providers listed in this policy that host and operate our support systems
  • Where you are able to share a staging site rather than a live one, and to keep a working backup of anything shared with us, we recommend doing so

Retention: You are responsible for rotating or revoking any login, FTP, or database credentials you shared with us once your issue is resolved. We have no further use for them after the support ticket closes. Where we have created a copy of your site on our own servers for investigation, we delete that copy once the issue is resolved.

We retain support ticket records, including any screenshots, logs, or other materials shared as part of a ticket, for 3 years from the date the ticket is closed. We do this so we can refer back to how a past issue was resolved if it recurs, and to analyze recurring issues internally to improve our products.

If your site contains your own customers’ or visitors’ personal data that we may view while troubleshooting, we access that data only as necessary to resolve your issue and do not retain or use it beyond that purpose. You remain responsible for your own compliance obligations toward your site’s visitors and customers.

Purchase

If you purchase products or services from us, our payment gateway provider may require your credit card and billing information to process the transaction. Credit card details are not stored by us on any internal or external database accessible to us.

We use payment providers that state they maintain applicable PCI DSS compliance for their payment services. PCI DSS is administered by the PCI Security Standards Council.

When you make or attempt a purchase, we verify your card through a payment gateway and collect information including your name, billing address, payment information, email address, and phone number. Checkout and license management run through SureCart at my.surecookie.com.

Retention: Billing and transaction records are retained for as long as your account or license remains active, including to support plan renewals. Because we are subject to tax, accounting, and audit-related legal obligations, financial records are retained for the period required by applicable law even after account deactivation or a data deletion request. This is a standard, legally recognized exception to deletion rights, not a workaround, and applies specifically to financial and transaction records rather than personal information generally.

Information About Your Website and Server Configuration

When you use our WordPress products, and only if you have opted in to usage tracking, we may receive website and technical usage information about your site, including (but not limited to) whether SSL is installed, Curl, PHP and MySQL versions, PHP ini settings, server software, WordPress version and language, timezone, whether the site is a Multisite installation, debug settings, site URL, active plugins and theme, and BSF Updater version.

Most of this describes software and server configuration rather than a person. Some of it, such as your site URL, can be connected to you or to your account, so we do not treat this information as categorically non-personal and we handle it under this policy.

This is switched off unless you turn it on, and you can turn it off again at any time.

We collect it to develop better, more compatible software and serve our customers more effectively.

License Keys

A license key is required to validate your purchase and unlock benefits like automatic updates, developer support, and extra resources. When you activate a license key, we receive your website URL, name, and email address, and we keep records of every website URL where the key has been activated.

Retention: License activation records are retained while the license is active, and afterwards for the period reasonably necessary for account history, support, fraud prevention, tax and accounting obligations, and dispute handling.

Third-Party Services Loaded On Our Pages

Some pages on our Site load files from other companies. When your browser fetches one of those files, that company receives your IP address and basic details about your browser. These load only on pages that use the feature they belong to, and non-essential ones load only after you provide consent.

ServiceWhy it loadsWhen it loads
Google Fonts (fonts.googleapis.com)Supplies the typefaces used on our pagesOn pages using a webfont
Cloudflare Web Analytics (static.cloudflareinsights.com)Measures how quickly our pages loadWith the page. It sets no advertising or analytics cookie
Powerful Docs (app.powerfuldocs.com)Documentation assistant and support chatOn pages with the chat widget, after consent
iubenda (www.iubenda.com, cdn.iubenda.com)Third-party consent and policy toolingOn pages where it is embedded, after consent

Information We Send To Third Parties From Our Servers

Separately from the files your browser loads, our servers send a small amount of information to other companies or services while handling your visit or your use of the product. Because this happens on our side, it is not something your browser settings can control.

  • Site verification and scan quota. Your site URL and license details are sent to our scanning service to confirm the connection and your plan limits.
  • Scanning. The page URLs you select for a scan are sent to library.surecookie.com so the scanner can visit them.
  • Geolocation. A visitor’s IP address is resolved to a country so region-specific consent rules can be applied. This resolution happens on the server running the plugin.
  • Payments. Payment details you enter at checkout are sent to our payment provider, as described under Purchase above.
  • Email. Your email address is sent to our email delivery provider when we send you a transactional or marketing message.

Who We Share Your Data With

We do not sell or trade your personal information for money.

Where a tool below is marked as shared, that means the partner may use information about your activity on our site for cross-context behavioral advertising, as that term is defined under California law. Sharing only happens after you provide consent through our cookie preference banner, or is subject to your California opt-out rights described further down.

CategoryServiceWhat they receivePurposeSale / Share / Service Provider
Tag managementGoogle Tag Manager (googletagmanager.com)IP address, browser and device information, page URLLoads and manages our other scripts and tags, and reads your consent status to decide which may runService provider, not sold or shared. See the note below on how tags behave before you answer the banner
Website analyticsGoogle Analytics (region1.google-analytics.com)Page views, device and browser identifiers, cookiesUnderstand site usageShared for cross-context behavioral advertising, where linked to advertising audiences
Performance analyticsCloudflare Web Analytics (static.cloudflareinsights.com)IP address, request metadata, page URL, and page timing informationMeasure how quickly our pages load. It sets no advertising or analytics cookie and is not linked to advertising audiencesService provider, not sold or shared. Loads with the page
On-site experimentationSigmize (api.sigmize.com)Browsing behavior, page interactions, assigned test variantA/B testing to improve user experience and site designService provider, not sold or shared
Documentation and chatPowerful Docs (app.powerfuldocs.com)Chat messages, name, email if provided during the conversationDocumentation assistance and support chat, loads after consentService provider, not sold or shared
Consent and policy toolingiubenda (www.iubenda.com, cdn.iubenda.com)IP address, browser and device information, page URLThird-party consent and policy tooling loaded on parts of our siteService provider, not sold or shared
Payments and checkoutSureCart (js.surecart.com), Stripe, PayPalBilling and payment details, IP addressTake and process payments and manage your licenseService provider, not sold or shared
Typeface deliveryGoogle Fonts (fonts.googleapis.com)IP address, browser informationServe the typefaces used on our pagesService provider, not sold or shared
WordPress core servicesWordPress.org (s.w.org)Basic request metadataCore WordPress functionality such as emoji support and update checksService provider, not sold or shared
Content delivery and securityCloudflareIP address, request metadataSite performance and securityService provider, not sold or shared
Email deliveryAmazon SESEmail addressTransactional and marketing email, sent from our serversService provider, not sold or shared
Affiliate attributionAffiliateWP cross-domain trackerReferral and click identifiersTrack and pay affiliate referralsService provider, not sold or shared

How we classify these recipients: the last column reflects the written agreement and data-processing terms we have in place with each provider, and the way we have configured the service. It is our assessment rather than a guarantee about a provider’s own practices, and we review it when we add a provider or change a configuration.

How tags behave before you answer the banner: our consent tool controls when advertising and analytics tags may run. Depending on the page and the rules that apply where you are, either our tag container is not loaded at all until you answer the banner, or it loads with Google Consent Mode signalling that consent has not been given, which lets it read your choice while sending no identifiers and setting no advertising or analytics cookies.

As at the date of this policy, our scanning and consent configuration show no advertising pixels such as Meta Pixel or Google Ads conversion tags running on surecookie.com. If that changes, this policy and our cookie list will be updated before those tools are enabled.

Cross-BSF-product tracking: Because Brainstorm Force operates multiple distinctly branded product sites (SureCookie, Astra, SureCart, SureForms, and others), each site runs its own independent cookie consent tool. Your consent choice on one BSF site does not carry over to another. When you visit any BSF-operated site, you will see that site’s own cookie banner, and that site applies its own consent configuration, so technologies that require consent run according to the choice you make there. If you want to opt out across multiple BSF properties, you will need to do so on each site individually.

How Long We Keep Your Data

We keep personal information only for as long as we need it for the purpose we collected it, or for as long as the law requires. In practice:

  • Cookie consent records on our own site are kept for up to 365 days.
  • Consent records generated by the plugin on your site are stored by you, on your site, with a retention period you control. The default is 365 days, and it can be set to 30, 60, or 90 days.
  • Scan results are kept for as long as your site is connected to the scanning service, so your dashboard and cookie policy stay current.
  • Scanner diagnostic logs are kept only for as long as they are useful for diagnosing scan failures, and are then deleted.
  • Support ticket records are kept for 3 years from the date the ticket is closed.
  • Purchase and license records are kept for as long as you hold a license with us, and afterwards for the period our tax and accounting obligations require.
  • Newsletter subscriptions are kept until you unsubscribe.

You can ask us to delete your data sooner. See “What Rights You Have Over Your Data” below.

Where Your Data Is Processed

We are based in the United States, and several of the providers listed above process data in the United States and other countries. Where personal information is transferred out of the European Economic Area, the United Kingdom, or India, the safeguard we rely on depends on the destination and on the region the data came from:

  • From the EEA: an adequacy decision where one covers the destination, the European Commission’s Standard Contractual Clauses, or the EU-US Data Privacy Framework where the recipient is certified under it.
  • From the United Kingdom: the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it. EU Standard Contractual Clauses on their own do not cover a UK restricted transfer, which is why the Addendum or the IDTA is used.
  • From India: contractual safeguards with the recipient, and transfers are made consistent with the restrictions applying under the Digital Personal Data Protection Act, 2023 and the rules made under it.

You may ask us at [email protected] for details of the safeguards applying to a particular transfer.

California Privacy Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect, use, disclose, and if applicable sell or share, and to request a copy of it
  • Right to delete personal information we have collected from you, subject to certain exceptions
  • Right to correct inaccurate personal information we maintain about you
  • Right to opt out of the sale or sharing of your personal information. Based on the categorization above, this means opting out of analytics data that may be linked to advertising audiences. We do not treat the other recipients listed above as sales or shares of personal information: each is engaged under a written agreement that limits their use of personal information to providing their service to us
  • Right to limit the use and disclosure of sensitive personal information, where applicable
  • Right to non-discrimination for exercising any of the above rights

To opt out of the sale or sharing of your personal information, click Do Not Sell or Share My Personal Information or Cookie Preferences in the site footer. We also honor Global Privacy Control (GPC) signals as a valid opt-out request. We action opt-out requests as soon as feasible, and no later than 15 business days from receipt.

To exercise your other rights, contact us at [email protected]. We will verify your request and respond within 45 days, as required by law, with a possible 45-day extension for complex requests, in which case we will notify you of the extension and the reason.

You may also designate an authorized agent to make a request on your behalf, subject to our ability to verify the agent’s authority to act for you.

Your Rights Under India’s Digital Personal Data Protection Act (DPDP)

If you are located in India, you have the following rights as a Data Principal under the Digital Personal Data Protection Act, 2023:

  • Right to access a summary of the personal data we hold about you and how we process it
  • Right to correction and erasure of your personal data
  • Right to grievance redressal, as described below
  • Right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before your withdrawal

We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental consent, consistent with the DPDP Act’s requirements for children’s data.

Grievance Officer: Mohit Sharma, [email protected]

If you have a grievance regarding how we handle your personal data, you may contact our Grievance Officer at the address above, or write to us at [email protected] and ask for your message to be passed to the Grievance Officer. Either route starts the same process.

As our own service commitment, we aim to acknowledge your grievance within 72 hours of receipt, including a reference number and expected resolution timeline, and to resolve most grievances within 30 days and in any event within 90 days. These are timelines we set for ourselves rather than statutory deadlines. The Digital Personal Data Protection Rules, 2025 come into force in phases, with several provisions taking effect later than the date of this policy, and we will update this section as those provisions apply to us.

How Secure Is My Information

We maintain technical and organizational measures appropriate to the risk, in order to protect your personal information from being inappropriately lost, misused, accessed, disclosed, altered, or destroyed. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Card information, when provided, is encrypted in transit using TLS (also known as SSL).

What Rights You Have Over Your Data

To exercise the privacy rights available to you, including access, correction, deletion, objection, restriction, or withdrawal of consent, contact us at [email protected]. Some requests are subject to legal exceptions, and some processing must continue for legal, security, accounting, contractual, or other permitted purposes.

If you are a visitor to a website that uses SureCookie, and your request concerns that site’s consent records, contact that website’s owner. Those records are held by them, not by us.

You can also request information about the source of your personal data if it was not provided directly by you, or how long it will be retained. You have the right to request deletion of data no longer needed for its original purpose, or to cease its processing. Certain records, such as financial and transaction records, may be retained even after a deletion request, where retention is required by applicable tax, accounting, or audit obligations, consistent with the recognized legal exceptions to the right of deletion. You can request we stop using your data for direct marketing purposes, and you may withdraw consent at any time by clicking “unsubscribe” in our emails.

Legal basis for processing (EEA and UK visitors): Depending on the purpose, we process your data based on your consent (for example, non-essential cookies and marketing communications), the necessity of processing to perform our contract with you (for example, fulfilling a purchase or running a scan you requested), our legitimate interests (for example, improving our services, spam prevention, and fraud prevention), or compliance with a legal obligation.

If you believe we have not complied with applicable data protection laws, you have the right to lodge a complaint with your local data protection authority. Within technical limits, we will provide your personal data to you or your data protection authority upon request.

If we cannot provide requested data within a reasonable timeframe, we will let you know when it will be available. If we deny a request, we will explain why.

Children’s Online Privacy Protection Act Compliance

We do not knowingly collect personal information from children under the age of 13. If we determine we have collected personal information from a child under 13, we will take reasonable measures to remove it from our systems. If you are under 13, please do not submit personal information through the Site, service, or Software.

Third-Party Links

We may include or offer third-party products or services on our website. These third-party sites have separate, independent privacy policies, and we hold no liability or responsibility for their content or activities.

Affiliate Disclosure

Some third-party links on our store may be affiliate links. We earn a referral fee when you buy services from companies we recommend. We only recommend products we believe add value to our customers. If you purchase after clicking an affiliate link, we receive a commission.

These affiliate commissions help us generate free content on our blog and free courses on SkillJet.

Affiliate tracking cookies are subject to the same consent preferences described in the Cookies section above.

Remarketing and Targeted Advertising

We use Google Analytics to understand how visitors use our site, and that data may be linked to advertising audiences. This may include cross-context behavioral advertising as defined under California law. For more on how targeted advertising works, see the Network Advertising Initiative’s educational page.

As at the date of this policy, no Meta Pixel or Google Ads conversion tags run on this site.

You can opt out of targeted advertising through Google directly, or by clicking Cookie Preferences in the site footer, which applies to the advertising-related partners listed in this policy.

Newsletter Emails

We send product announcements, software updates, and special offers by email. You will receive these only if you ask for them, by signing up to our newsletter or by ticking the marketing option on a form, and you can stop them at any time via the “unsubscribe” link in our emails.

Becoming a site user, member, or customer does not by itself sign you up for marketing email, and neither does downloading or installing the plugin.

Marketing email is separate from the service email we need to send you about a purchase, a license, a security notice, or a support ticket. Unsubscribing from marketing does not stop those.

If you are in the EEA or the UK, we will only send you marketing email where you have given consent, and we will never make that consent a condition of buying or using our products.

Will This Privacy Policy Ever Change

We may update this Policy to keep pace with changes in our Site, Software, Services, business, and applicable laws. When we do, we will post the updated Policy here and change the date at the top. Where a change is significant, we will take reasonable steps to tell you about it. Where a change means we need your consent for something new, we will ask for that consent rather than treat your continued use of our products as agreement.

Contact Us

For questions about our privacy practices or to make a complaint, contact us by email at [email protected] or by mail:

Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States

If you are in India and want to raise a grievance under the DPDP Act, you can write to our Grievance Officer, Mohit Sharma, at [email protected], or use [email protected] and we will route it.

Scroll to Top