Last updated: April 10, 2026
This Privacy Policy explains how CSP Warden collects, uses, discloses, and safeguards your information when you use our Content Security Policy monitoring platform at cspwarden.com. We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. Please read this policy carefully.
CSP Warden is the data controller for personal data collected through your account registration, platform usage, and direct communications with us.
When processing CSP violation reports submitted by your website visitors' browsers, CSP Warden acts as a Data Processor on your behalf. In this context, you (the CSP Warden customer) are the Data Controller for your visitors' data. See Section 10 for details.
For privacy-related enquiries, contact us at [email protected].
We collect the following categories of information:
When you register for an account, we collect:
When your website visitors' browsers detect a Content Security Policy violation, they automatically send a report to our servers. These reports contain:
Note: CSP reports are sent automatically by browsers and may inadvertently contain personal information embedded in URLs, such as user identifiers or session tokens in query strings.
CSP Warden does not store credit card numbers, bank account details, or other direct payment information. All payment processing is handled by Stripe, which is PCI DSS compliant.
We use the information we collect for the following purposes. The lawful basis for each is noted in parentheses.
Under the GDPR, we rely on the following lawful bases for processing your personal data:
We share personal data with the following third-party processors, solely to provide and operate the Service:
We do not sell, rent, or trade your personal data to third parties.
We may disclose information if required to do so by law, or if we believe in good faith that such action is necessary to comply with legal proceedings, a court order, or to protect our rights, property, or the safety of our users.
CSP Warden's infrastructure is hosted in the European Economic Area (EEA). Some of our third-party processors (including Stripe and Cloudflare) may process data in the United States or other countries outside the EEA.
Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions where applicable.
You may request further details about international transfers by contacting us at [email protected].
We retain personal data only for as long as necessary for the purposes described in this policy. Specific retention periods are:
| Data Type | Retention Period |
|---|---|
| CSP violation reports | Based on your subscription plan (Free: 15 days, Professional: 30 days, Business: 90 days, Enterprise: 365 days). Automatically deleted after the retention period. |
| User accounts | Retained until you delete your account |
| Audit logs | Retained indefinitely for security and compliance purposes |
| Verification tokens | Expire and are deleted automatically (email verification: 24 hours, password reset: 1 hour) |
| Billing records and invoices | Retained as required by applicable tax and financial regulations |
| Email communication logs | Retained for operational diagnostics |
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:
To exercise any of these rights, email us at [email protected]. We will respond within 30 days of receiving your request.
You may also delete your account at any time through your account settings, which will remove your personal data and associated domains in accordance with our retention policy.
When you configure your website to use CSP Warden as a reporting endpoint, your visitors' browsers will automatically send CSP violation reports to our servers. These reports may contain URLs, IP addresses, user agent strings, and referrer information belonging to your website visitors.
In this context:
As the Data Controller, you are responsible for:
Browsers apply cross-origin truncation to CSP reports, meaning the blocked URI is reduced to its scheme, host, and port when the violation originates from a different origin. This partially mitigates the amount of personal data included in reports.
CSP Warden does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Features such as security scores and readiness scores are informational tools designed to help you assess your website's CSP configuration - they are not automated decisions about individuals.
CSP Warden is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at [email protected].
We implement appropriate technical and organisational measures to protect your personal data. These include:
For more details about our security practices, visit our Security page.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
We encourage you to review this page periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
If you are unsatisfied with how we handle your personal data, we encourage you to contact us first at [email protected] so we can try to resolve the issue.
You also have the right to lodge a complaint with your local data protection supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO).
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us: