DataCops Ltd Privacy Policy

Effective date: August 27, 2026

1. Introduction

This Privacy Policy explains how DataCops Ltd ("DataCops", "we", "us", or "our") collects, uses, shares, and protects information in connection with our website joindatacops.com and the services offered through it (together, the "Services").

DataCops Ltd is a private company limited by shares, registered in England and Wales under company number 16891252, with its registered office at 124 City Road, London, EC1V 2NX, United Kingdom.

DataCops helps businesses measure their advertising accurately by validating conversions, filtering bots and fraud, and honoring consent before any data is sent to an advertising or marketing destination. This policy is incorporated into our Terms of Use. If you have any questions, contact us at [email protected].

2. Our Two Roles: Controller and Processor

Data protection law distinguishes between the party that decides why and how data is processed (the "controller") and the party that processes it on the controller's instructions (the "processor"). DataCops acts in both roles depending on the data:

  • We are the controller of the account data of our own customers, the businesses that sign up for DataCops (for example, account and billing details). Sections 3 to 11 describe how we handle that data.
  • We are a processor of the visitor data we handle on behalf of a business that installs DataCops on its website. That business is the controller of its visitors' data and is responsible for having a lawful basis, providing notice, and obtaining consent. We process that data only on their instructions, as described in Section 4.

3. Information We Collect From Our Customers

When you sign up for and use DataCops as a business customer, we collect:

  • Account information: your name, email address, company name, company website, and password.
  • Billing information: the details needed to process your subscription. Card payments are handled by our third-party payment processor; we do not store full card numbers on our servers.
  • Communications: the content of messages you send us (for example, to [email protected]) and any attachments.
  • Product usage: how you interact with the DataCops dashboard, so we can operate, secure, and improve the Services.

4. Data We Process On Behalf of Our Customers

When a business installs DataCops on its website, we process data about that website's visitors on the business's behalf and under its instructions. This may include:

  • Identity data, only when a visitor provides it. A visitor is only ever identified when they themselves give their email address to the website operator, for example at sign-up, log-in, a form submission, or checkout. We store the email and a normalized version of it, and, where the operator chooses to send them, a phone number and name. We never identify an anonymous visitor, and we never build a profile of someone who has not provided their details.
  • Session and attribution data: a session identifier, page URL, referral information, device and browser information, and advertising click identifiers (such as Google, Meta, and TikTok click IDs) that the visitor arrived with. IP addresses are used for security and location risk and are not exposed as a marketing attribute.
  • Fraud and validation signals: an email-risk result and an IP-risk result (for example, whether an address is disposable or high-risk, or whether an IP is a VPN, proxy, or datacenter). These are produced by our own in-house detection service and are used solely to filter bots and fraud and to validate conversions, not for advertising or profiling.
  • A device fingerprint, used solely to detect fraud and repeat or multi-account abuse. It is never used to re-identify a person who has cleared their browser, and never to track a person across unrelated websites.
  • Conversion and order events that the operator sends for measurement, which we validate and, where consent allows, deliver to the operator's chosen advertising or marketing destinations.

We do not buy, license, or ingest third-party personal or consumer data, and we do not enrich profiles from outside data sources. All enrichment is our own fraud and validation scoring. The identity data above is siloed per business customer; it is never combined into a cross-customer or cross-site identity graph, and it is never a shared "supercookie".

5. Cookies and Identifiers

On our own website we use cookies to operate and secure the site, remember preferences, and measure our own performance.

On a customer's website, DataCops may set a first-party identifier stored on that customer's own domain, with a lifetime of up to 400 days. Where enabled, it is set only after consent is given and only when our fraud checks are clear. It is signed per customer, so it cannot be used to link a person across different businesses. Businesses that use DataCops are responsible for covering these identifiers in their own cookie notice and consent mechanism, in line with applicable law (such as the UK's PECR).

6. Consent

In the United Kingdom, the EEA, and Switzerland, our default is opt-in: nothing is shared with any advertising or marketing destination until the visitor gives consent. Events captured before consent are held and are only released once consent is recorded; a withdrawal of consent blocks all future delivery.

We operate our own consent management platform, built to the IAB TCF v2.2 framework and integrated with Google Consent Mode v2, so tags respect the visitor's choice. Because our consent layer is first-party and loads from the website's own domain, it is not blocked by ad blockers or browser tracking protection, so a visitor's choice reliably reaches the tags. Every consent decision and change is written to an append-only audit log (one immutable record per change) so the lawful basis for processing can be evidenced. Recording consent signals a visitor's choice; it does not replace each destination's own data processing terms, which remain the responsibility of the relevant parties.

7. How We Use Information

  • To provide the Services: create and manage accounts, process payments, and deliver measurement, validation, and reporting.
  • To secure the Services and prevent fraud: filter bots, detect abuse, and enforce our Terms of Use.
  • To improve the Services: understand how the product is used and develop new features.
  • To communicate with you: send service notices, security alerts, and support messages, and marketing messages only where you have opted in.
  • To meet legal obligations: comply with applicable laws and lawful requests.
  • To produce aggregate insights: we may aggregate and anonymize data to produce statistics that do not identify any individual.

8. How We Share Information

We do not sell personal data, and we never have. We share information only in these limited circumstances:

  • With the business that owns the data and, on that business's instruction, with the advertising or marketing destinations it has chosen to connect (for example Google, Meta, or an email platform), subject to consent.
  • With sub-processors that help us run the Services, including cloud hosting and content-delivery providers (including OVHcloud and Cloudflare), a payment processor, and email delivery. They may use the data only to perform services for us and are bound to protect it.
  • For legal reasons, where required by law or to protect our rights, our users, or the public.
  • In a business transfer, such as a merger, acquisition, or sale of assets, in which case we will notify affected users.

9. Data Retention

We keep personal data only for as long as needed for the purposes in this policy. Typical retention periods for data we process are:

  • Visitor sessions: 90 days
  • Attribution and click identifiers: 90 days
  • Conversion events held pending consent: 90 days
  • Lead form submissions: up to 24 months
  • Deduplication receipts: 48 hours
  • Order-to-session links: 7 days
  • First-party identifier (where enabled): up to 400 days
  • Data subject to a verified deletion request: purged within 30 days

Consent records are retained for as long as necessary to evidence the lawful basis for processing. Account and billing data is retained for the life of the account and thereafter only as required to meet our legal obligations.

10. Your Rights and How to Exercise Them

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. You can also withdraw consent at any time.

Requesting deletion of your data

You can ask us to delete your data at any time in either of these ways:

  • Using the data deletion form on this page. When you submit your email, we resolve it to its record, create a timestamped audit entry, erase the associated personal data across our systems and connected destinations, and send you a confirmation with a status link.
  • By emailing [email protected]. On a verified request we complete erasure within 30 days.

If DataCops processes your data on behalf of a business (as its processor), we will act on that business's instructions and will pass your request to them where appropriate. You can also contact the business directly.

If you are in the UK or EEA, you have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (www.ico.org.uk).

11. International Transfers

We are based in the United Kingdom and may process data on servers in other countries. Where we transfer personal data outside the UK or EEA, we put appropriate safeguards in place, such as the UK's International Data Transfer Agreement, Standard Contractual Clauses, or transfers to countries recognized as providing an adequate level of protection.

12. Security

We use appropriate technical and organizational measures to protect personal data. No method of transmission or storage is completely secure, so while we work to protect your data, we cannot guarantee absolute security.

13. Children's Privacy

Our Services are not intended for children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will take steps to remove it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the effective date above, and for material changes we may also notify you through your account or by email.

15. Contact Us

For any question about this policy or our data practices, or to exercise your rights, contact us:

By email: [email protected]
By mail:
DataCops Ltd
Company Number: 16891252
Registered in England and Wales
124 City Road
London, EC1V 2NX
United Kingdom

Submit a Data Deletion Request

Enter your email address to request erasure of your personal data under GDPR Article 17. We will create a timestamped record, delete the associated data across our systems, and email you a confirmation with a status link.