Skip to content
TagSentry

Legal

Data processing agreement

Last updated October 1, 2026. Written to be read.

TagSentry is a product of Orbit Metrics Inc., 1776 N Scottsdale Rd #1182, Scottsdale, AZ 85252, USA ("TagSentry", "we", "us").

This agreement applies whenever TagSentry processes personal data on your behalf: the consent choices and tag events of the visitors to your websites. It forms part of our terms of service. You are the controller; TagSentry is the processor.

What we process, and why

  • Consent records: when a visitor answered your banner, what they were shown, what they chose, how, and a random consent ID. No IP address, user agent or fingerprint.
  • Tag events: the shape of what your tags sent (field names and types), and the host and path of each request. Not the values. Event names are kept: your dataLayer event names and the name a known tracker sends. Each event carries the visitor's random consent ID.

We process this only to provide the service to you: showing the right banner, keeping records you can export, and monitoring your tags. We process it only on your documented instructions, which are these terms, your settings in the dashboard, and your use of our API.

How long we keep it

Consent records are kept for 24 months, then deleted, including our audit copy. Tag events are kept for 14 to 365 days depending on your plan, then deleted.

Where it's stored

In the region you choose for each site when you create it: the EU (Belgium) or the US (Iowa). It isn't moved to the other region. Our application servers run in the US. For EU and UK data, transfers to the US rely on the European Commission's standard contractual clauses and the UK addendum, which are incorporated into this agreement by reference.

Our commitments

We will:

  • keep the data confidential, and make sure everyone who can access it is bound to confidentiality;
  • protect it with appropriate security, including encryption in transit and at rest, access limited to people who need it, and per-customer separation in our databases;
  • help you answer requests from your visitors (our dashboard lets you find a visitor's records by consent ID);
  • tell you without undue delay, and within 72 hours, after becoming aware of a breach affecting your data;
  • return your data on request (you can export it any time), and delete it within 30 days when you close your business in Settings or ask us in writing, consent records included, except the locked audit copy of consent records, which is deleted when its 24 months are up;
  • give you the information you reasonably need to show you've met your obligations, and answer reasonable audit questions in writing.

Subprocessors

You agree that we may use these subprocessors:

SubprocessorWhat forWhere
Google CloudHosting, databases, deliveryEU and US
StripeBillingUS
ResendEmailUS
GoHighLevel (LeadConnector)Managing our relationship with you: your team's names and emails, your business name and first site. Never visitor dataUS
AnthropicSorting your trackers by purpose and suggesting which events to track. Receives tag details, never visitor dataUS

We'll give you notice of new subprocessors on our trust page at least 30 days before we use them. You can object by emailing us, and if we can't address it, you can cancel.

Contact

Data protection questions: hello@tagsentry.ai.