Privacy Policy
What we collect, why we collect it, and the rights you have over it.
Our Privacy Commitments
We're a company whose entire product is getting your personal information off other people's servers. It would be indefensible to be careless with it ourselves. So these are the commitments this policy is built around, stated up front rather than buried:
- We never sell your personal information. Not now, not as a "future business model," not in aggregate, not de-identified, not under any other name for the same thing. We have never sold personal data and we do not intend to build a business that does.
- We never share your personal information for advertising. We run no advertising, remarketing, or cross-site tracking tags. Nothing you submit is used to target ads to you or anyone else.
- Your identity data never leaves the removal pipeline. The name, date of birth, and address you give us are used to find and remove your listings — and for nothing else. They are never sent to our analytics provider, never used for marketing, and never disclosed to anyone except the specific data broker you have asked us to submit a removal to.
- We ask for the minimum that actually works. Data-broker records are indexed by name, age, and location, so name, date of birth, and address are what a search genuinely requires. We don't ask for a Social Security number, and we don't ask for financial account details.
- We tell you what isn't finished yet. Where a protection is planned rather than live, this policy says so plainly instead of implying more than is true.
Introduction
At Delist My Data, accessible from https://delistmydata.com, the privacy and security of our visitors is a top priority. This Privacy Policy describes what personal data we collect, why we collect it, how we use and protect it, and what rights and choices you have. We're pre-launch — some of what's described below (like the search-and-removal flow itself) isn't live yet, but we've written this policy to reflect what actually happens today and what will happen once it is, rather than generic language borrowed from other kinds of services.
This policy applies to information collected through our website only. It does not cover data collected offline or via third-party services that link to or from our site.
By accessing or using Delist My Data, you acknowledge that you have read and agree to this Privacy Policy. Questions or requests may be sent to contact@delistmydata.com.
Definitions
- Personal Data: Any information relating to an identified or identifiable person, including name, address, phone number, date of birth, email, IP address, and online identifiers.
- Processing: Any operation on personal data, including collection, storage, use, transfer, and deletion.
- Data Controller: Delist My Data, determining the purposes and means of processing personal data on Delist My Data.
- Sell / Share: Used as CCPA/CPRA defines them — disclosing personal information to a third party for money or other valuable consideration, or for cross-context behavioural advertising. We do neither.
- You / User: Any individual accessing or using Delist My Data.
Information We Collect
1. Information you provide directly
- Waitlist signups: your email address. That's the only field we store — the form's other input is an anti-spam honeypot whose contents are rejected, not saved. There is no account registration, no password, and no payment step today; the site currently operates as an email-only waitlist.
- Removal-search details, once that feature is live: your name, date of birth, and address (including previous addresses, which is how brokers index historical records). These three are the requirement, and they exist for a specific reason: broker listings are matched on name plus age plus location, so without a date of birth we cannot tell your record apart from a stranger who shares your name — which risks both missing your listing and requesting removal of someone else's.
- Optional contact details: phone number and email, if you choose to provide them. Some brokers' opt-out flows send a confirmation link or code to the email or phone on the listing; without them, those specific removals may not be completable. You can leave them blank.
- Government ID — only when a specific broker demands it. A minority of data brokers refuse to process an opt-out without a copy of a government-issued ID to verify the request is genuinely yours. Where that is the only route to removal, we will ask you for one. This is always a specific, per-broker request that we explain at the time — never a blanket signup requirement — and you can always decline, in which case we skip that broker and tell you so. See How We Handle Government ID below for the strict handling rules that apply.
2. Information we generate on your behalf
- Matches: records of data-broker listings that appear to match the identity you submitted, including the broker's URL and the raw listing text.
- Screenshots: images of the matching listing pages, captured as evidence of what was found and, later, of what was removed.
3. Automatically collected data
- IP address, browser type and version, operating system, and device type
- Pages visited, time and date of visit, duration, and referring URL
- HTTP request headers and server log data
Your IP address is also used transiently to rate-limit the waitlist form against automated abuse. It is held briefly in our own server-side cache for that check and is not written to a user profile.
4. Analytics
We use Google Analytics 4 to understand how people find and move through this site — which pages get read, which guides are useful, where visitors arrive from. This is measurement, not advertising. Details, including how to opt out, are in the next two sections.
Analytics and Advertising
We think you're entitled to know exactly what runs on this site, so here it is in full.
What we run: Google Analytics 4, loaded on every page in production. It records the automatically collected data described above — pages viewed, approximate location derived from IP, device and browser, referring source — and attributes them to a randomly generated identifier stored in a cookie on your device.
How we've restricted it: we configure the tag with Google Signals and ads-personalisation signals switched off. That means our analytics data is not fed into Google's advertising-personalisation systems and is not used to build cross-site advertising profiles from our traffic.
What we deliberately do not run: no advertising or remarketing tags, no conversion pixels, no Meta/Facebook Pixel, no Hotjar or other session-recording tools, no cross-site tracking of any kind. We previously carried a Google Ads tag on this site; we removed it, because a remarketing tag is difficult to reconcile with the commitments at the top of this page.
What analytics never sees: nothing you submit to the removal service. Names, dates of birth, addresses, phone numbers, ID documents, matches, and screenshots are never sent to Google Analytics or any other analytics provider.
How to opt out: install Google's official Google Analytics Opt-out Browser Add-on, block or delete analytics cookies in your browser settings, or use any content blocker — the site works fully without analytics. You can also write to contact@delistmydata.com and we will confirm the exclusion.
One more third party worth naming: our page fonts are loaded from Google Fonts (fonts.googleapis.com), which means your browser makes a request to Google to fetch them, transmitting your IP address and user agent as any web request does. No cookie is set by this and it is not used for tracking, but we would rather disclose it than have you discover it in a network tab. We intend to self-host these fonts to remove that request entirely.
How We Use Your Information
We process personal data for the following purposes:
| Purpose | Examples | Legal Basis (GDPR) |
|---|---|---|
| Service Delivery | Searching data-broker sites for your listings, generating and submitting removal requests, notifying you of the waitlist status | Contract / Legitimate Interests |
| Identity Verification | Supplying a government ID to a broker that will not otherwise process your opt-out | Consent (given per request) |
| Support | Responding to questions or requests sent to us directly | Legitimate Interests |
| Analytics | Measuring site traffic and which pages are useful, via Google Analytics 4 | Consent / Legitimate Interests |
| Security & Fraud Prevention | Rate-limiting forms, detecting malicious activity, protecting the service | Legitimate Interests |
| Legal Compliance | Meeting regulatory or court-ordered obligations | Legal Obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for marketing.
Cookies and Tracking Technologies
Delist My Data sets two categories of cookie, and no others. We set no advertising cookies and no cross-site tracking cookies.
| Category | Cookies | Purpose | Duration |
|---|---|---|---|
| Strictly Necessary | _hidemeonline_session | Core functionality, security, CSRF protection, session management. Cannot be disabled. | Session |
| Analytics | _ga, _ga_* | Google Analytics 4: distinguishes returning visitors and sessions so we can count traffic. No advertising use. | Up to 2 years |
You can control or delete cookies through your browser settings, and you can block the analytics cookies specifically using the opt-out methods above. Disabling strictly necessary cookies may impair website functionality; disabling analytics cookies has no effect on the site at all.
We do not currently display a cookie consent banner. If you are in a jurisdiction that requires prior consent for analytics cookies, we would rather tell you that plainly than pretend otherwise — adding a consent gate is on our list, and until it ships you can opt out using the methods above.
How We Share Your Information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There is no exception to this and no version of our business that depends on one. Data is disclosed only in these limited circumstances:
- Data Brokers, When You Ask Us To: when you request a removal, we submit the minimum information that particular broker requires to process an opt-out — often just a name and a link to the listing. This is the whole point of the service, it happens only at your direction, and we send the least the broker will accept.
- Infrastructure Providers: our servers and database run on Amazon Web Services (US region). AWS stores the data at rest on our behalf and may not use it for its own purposes.
- Analytics Provider: Google Analytics 4 receives site-usage data only — pages viewed, device, referrer, IP-derived approximate location. It receives none of your identity or removal data. Ever.
- Search Infrastructure, once removal search is live: broker sites block automated access, so our search pipeline may route requests through commercial proxy providers. These providers carry the outbound web request; they are not given your identity records as a dataset, and they are bound to process only as instructed.
- Email Delivery, when we begin sending mail: Amazon SES will deliver transactional email (such as waitlist and removal-status notifications). No mail is sent from the service today.
- Legal Requirements: where required by law, regulation, subpoena, or court order. We will notify you before disclosing where we are legally permitted to do so, and we will push back on requests that appear overbroad.
- Safety: to protect the rights, property, or safety of Delist My Data, our users, or the public.
- Business Transfers: in a merger, acquisition, or asset sale, your data may transfer — and any acquirer would be bound by the commitments in this policy for data collected under it. You will be notified via a prominent website notice and, where feasible, by email, with the opportunity to delete your data first.
- With Your Consent: for any other purpose, with your explicit prior consent.
We do not disclose personal information to advertisers, data brokers (other than to remove you from them), marketing partners, list vendors, or "data enrichment" services under any circumstances.
How We Handle Government ID
Because we ask for ID only in the hardest opt-out cases, we hold it to the strictest handling rules on this page:
- Only on request, only for one broker. We ask only when a specific broker refuses to process your opt-out without it, and we tell you which broker and why at the time we ask.
- Used for that submission and nothing else. An ID is never used to verify anything other than the removal request you asked us to make. It is never used for marketing, analytics, model training, or any secondary purpose.
- Deleted immediately after submission. Once the broker has confirmed or rejected the request, we delete our copy of the document. We do not keep an archive of customer IDs.
- Redaction encouraged. Brokers generally need to see your name, date of birth, and photo. You are welcome to black out everything else — licence number, document number, and any other field — before sending it, and we will submit the redacted version.
- Declining is always an option. If you would rather not supply an ID, say so. We skip that broker and tell you it remains outstanding, rather than pressing you for the document.
Data Security
Here's where things stand today, plainly:
- HTTPS/TLS encryption for all data in transit, enforced site-wide, with HSTS enabled.
- There is no customer-facing account system or admin panel today, so there's no login-based access path to your data to secure — see our Security page for more detail on how that changes as the product grows.
- Internal access to removal-search data is limited to the engineering team operating the service.
- Encryption of identity data (name, address, date of birth, phone number) at rest is planned but not yet implemented. We're not going to claim it before it's true — this section will be updated the moment it ships, and it will be in place before the removal service holds real submissions at scale.
- Screenshots and match data are currently stored on our application server's disk, not a separate encrypted store.
In the event of a personal data breach likely to result in risk to your rights, we will notify affected individuals and relevant supervisory authorities within the legally mandated timeframe (e.g. 72 hours under GDPR).
Data Retention
We keep personal data only as long as it serves the purpose you gave it to us for:
| Data | Retention |
|---|---|
| Waitlist email address | Until you ask us to remove it, or until the waitlist closes and you have not become a customer. |
| Government ID documents | Deleted as soon as the broker request they were supplied for is confirmed or rejected. Not archived. |
| Identity data (name, DOB, address, phone) | Retained while it is relevant to an active removal effort, including re-checking whether removed listings have reappeared. Deleted on request at any time. |
| Matches and screenshots | Retained as the evidence record of what was found and removed, for as long as the related removal effort is active. Deleted on request. |
| Google Analytics data | Retained by Google under our property's configured retention window; it contains no identity or removal data. |
| Server logs | Short-lived operational logs held within our own infrastructure. |
We do not yet enforce these windows with automated deletion jobs for removal-search data — that's an active area of work, not a finished mechanism, and we would rather say so than describe a scheduler that doesn't exist. You can request deletion of your data at any time and we will action it manually; see Your Privacy Rights below.
Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or transfer your personal data, and to withdraw consent at any time. You may exercise these rights by contacting us at contact@delistmydata.com. We will respond within the timeframe required by applicable law. You will never be penalised or discriminated against for exercising your privacy rights.
Because we hold very little about you, most requests are simple to honour — and we would rather delete your data than talk you out of it.
CCPA / CPRA — California Consumer Privacy Rights
The California Consumer Privacy Act (CCPA), as amended by the CPRA, grants California residents:
- Right to Know: disclosure of categories and specific pieces of personal information collected, sources, purposes, and third parties with whom data is shared.
- Right to Delete: request deletion of personal information, subject to narrow exceptions (completing an active removal request you asked for, security, legal obligations).
- Right to Correct: request correction of inaccurate personal information we hold.
- Right to Opt Out of Sale or Sharing: we do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We have not sold or shared personal information in the preceding 12 months. Because that is true, we are not required to post a "Do Not Sell or Share My Personal Information" link — and if it ever stopped being true, we would post one and say so here before the change took effect.
- Right to Limit Sensitive Personal Information: restrict use of sensitive personal information to necessary purposes only. We already limit it by default: a government ID is used solely for the broker request it was supplied for.
- Right to Non-Discrimination: we will not deny service, charge different prices, or provide lower quality because you exercised a CCPA right.
Personal information collected in the past 12 months: identifiers (name, email, IP address); internet or network activity (pages viewed, referring source, device and browser); and — once the removal feature is live — address, date of birth, phone number, and, where a broker requires it, government identification documents (a category of sensitive personal information).
Business or commercial purpose for collecting: operating the removal service you requested, verifying removal requests, supporting users, measuring site traffic, security, and legal compliance. Not advertising, profiling, or resale.
Submit CCPA requests to contact@delistmydata.com. We verify identity and respond within 45 days (extendable by 45 days). Authorised agents may submit requests on your behalf with proper documentation.
Other US State Privacy Rights: residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), and other states with similar privacy laws may exercise equivalent rights by contacting contact@delistmydata.com.
International Users and Data Transfers
Our infrastructure is located in the United States, so if you contact us or use the service from outside the US, your personal data is processed in the US. Where required for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. EEA and UK residents also have the right to lodge a complaint with their local supervisory authority.
Children's Privacy
Delist My Data is intended for adults. We do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted information to us, contact contact@delistmydata.com and we will delete it.
Links to External Websites
Delist My Data may contain links to third-party websites, including the data-broker sites our guides describe. Once you leave our site, this Privacy Policy no longer applies. We have no control over and accept no responsibility for external sites' content, privacy policies, or practices.
Do Not Track (DNT) Signals
Some browsers transmit "Do Not Track" signals to websites. There is currently no universally accepted standard for how websites must respond to DNT signals, and at this time Delist My Data does not automatically alter its data collection in response to a DNT or Global Privacy Control signal. We would rather state that accurately than claim a capability we haven't built. In the meantime, the analytics opt-out methods described above work immediately, and the practices a DNT signal is usually meant to prevent — advertising trackers and data sales — are things we don't do at all.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. When material changes are made, we will update the "Last Updated" date at the top and post a prominent notice on our website, and where feasible notify subscribers via email. If we ever proposed to use your data in a way materially less protective than this policy describes, we would seek your consent rather than rely on a silent update. Your continued use of Delist My Data after any modification constitutes acceptance of the revised policy. We encourage you to review this page periodically.
Contact Us
For questions, data subject requests, or privacy complaints, please contact us:
- Website: https://delistmydata.com
- Email: contact@delistmydata.com
We aim to respond to all enquiries within 5 business days, and within applicable legal deadlines for formal data subject requests.