> For the complete documentation index, see [llms.txt](https://docs.getuntitled.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.getuntitled.ai/misc/privacy-and-consent-management.md).

# Privacy & Consent Management

The Untitled ID Tag is designed to support compliance with applicable privacy requirements, including the California Consumer Privacy Act (CCPA/CPRA) and applicable GDPR requirements, when implemented and used appropriately. The Untitled Identity Tag and identity resolution services are designed exclusively for U.S. records and U.S.-based audiences and do not resolve EU/EEA resident identity records.

Privacy and appropriate disclosures are critical components of the Untitled ID Tag implementation process. **Before installing or activating the Untitled ID Tag, customers must maintain two core privacy mechanisms on any website where the Untitled iframe or JavaScript tag is deployed:**

1. An appropriate and publicly accessible Privacy Policy
2. A Consent Management Platform (CMP), consent string, or cookie consent banner

The Untitled ID Tag should only be permitted to fire after the appropriate consent has been obtained from the website visitor through the customer's consent management solution.

For Client Personal Data processed through the Untitled Platform, the customer generally acts as the business or data controller and Untitled acts as its service provider or data processor. Customers remain responsible for ensuring that their collection, use, disclosure, and activation of personal information complies with applicable privacy laws and that their website disclosures and consent practices accurately describe their use of the Untitled ID Tag.

For more information about Untitled's own privacy practices, please review our Privacy Policy:

<https://getuntitled.ai/privacy-policy/>

### Privacy Policy Requirements

A customer's Privacy Policy must be globally accessible from the website where the Untitled ID Tag is installed.

The Privacy Policy should accurately disclose the website's use of cookies, tags, pixels, or similar technologies for applicable marketing, advertising, remarketing, analytics, identity resolution, and related purposes. It should also describe the categories of information collected, how that information may be used or disclosed, and the methods available to consumers to exercise applicable privacy rights.

Untitled provides a [Privacy Policy template](/misc/privacy-and-consent-management/sample-privacy-policy.md) as a reference. However, each customer is responsible for ensuring that its Privacy Policy accurately reflects its own data collection, usage, disclosure, and retention practices. **We strongly encourage customers to review their policies and implementation with qualified legal counsel.**

### Consent Management

In addition to maintaining an appropriate Privacy Policy, Untitled requires customers to deploy a consent management solution on websites where the Untitled ID Tag is installed.

The consent solution should notify new website visitors about the use of cookies and similar technologies, provide appropriate choices regarding data collection, and direct users to the website’s Privacy Policy, which should more comprehensively describe applicable data collection, use, and disclosure practices. The Untitled ID Tag should be configured so that it does not fire unless the visitor has provided the consent required for the applicable processing.

Many website and publishing platforms provide consent-management functionality directly. Customers may also use a third-party Consent Management Platform.

Examples include:

* Osano
* CookieYes
* Cookiebot

This list is provided for convenience and is not exhaustive. Customers are responsible for selecting and configuring a consent management solution appropriate for their website, users, and applicable legal requirements.

### Consumer Privacy Requests and Opt-Outs

Customers must provide consumers with appropriate methods to exercise privacy rights required under applicable law.

To support California consumer privacy rights, customers should include access to Untitled's [**Do Not Sell or Share My Personal Information**](https://getuntitled.ai/do-not-sell-or-share-my-info/) request mechanism within their Privacy Policy or otherwise make the applicable opt-out mechanism available where required.

When Untitled receives a valid deletion or applicable opt-out request concerning Untitled Personal Data, Untitled will process the request in accordance with applicable privacy requirements and will prevent affected records from being provided where the request prohibits further disclosure or use.

Customers are also responsible for honoring privacy choices communicated directly through their own websites or systems. When a consumer has opted out of applicable advertising, sharing, sale, or other processing, customers should maintain appropriate suppression and preference-management controls across their marketing and advertising systems so that the consumer's privacy choices continue to be honored.

## Data Landscape and Privacy <a href="#frequentlyaskedquestions-datalandscapeandprivacy" id="frequentlyaskedquestions-datalandscapeandprivacy"></a>

<details>

<summary>Is the Untitled ID Tag compliant in the USA?</summary>

**Yes, when implemented correctly.** The Untitled ID Tag is designed to operate within applicable U.S. data privacy frameworks and is built around a first-party and second-party data model. This means the data originates from a direct interaction between a visitor and your website, rather than third-party tracking across sites.

However, compliance is not automatic. It depends on how you configure and use the tag within your broader privacy and consent framework. To remain compliant, you should:

* Clearly disclose data collection and usage practices in your website’s privacy policy, including marketing use cases
* Implement a consent management platform (CMP) that allows users to opt out of non-essential data collection
* Honor user preferences and opt-out signals in accordance with applicable laws and standards
* Avoid misrepresenting how data is collected, processed, or activated

For a more detailed overview of how consent and compliance should be handled, please review our [Privacy and Consent Management article](/misc/privacy-and-consent-management.md).

</details>

<details>

<summary>Is the Untitled ID Tag GDPR compliant?</summary>

Yes - the Untitled ID Tag services does not collect or store any data from individuals in the EU. Only within the United States/for U.S.-based contacts.

</details>

<details>

<summary>Is any personally-identifiable information (PII) transmitted to 3rd-parties via the Untitled ID Tag?</summary>

No. We do not transmit any PII to third parties in order to resolve your website visitors. Instead, we leverage joint first-party and second-party data through a consent-based framework, collecting information from the visitor’s browser and matching those signals against data sources through out-of-band or offline processes.

If you have any questions about how this works, or would like to confirm compliance before enabling the ID Tag feature, feel free to reach out. We’re happy to help.

</details>

<details>

<summary>Are visitors captured even if they don’t hit “Accept All” to my consent policy?</summary>

Whether a visitor is captured depends on how your consent management platform (CMP) is configured and implemented on your website. For clarity, a "Cookie Consent Banner" is the user-facing feature of a CMP.

In the United States (an “opt-out” jurisdiction), many CMPs allow tags to fire by default unless a user explicitly rejects non-essential cookies. This means a visitor may be included if they continue browsing without interacting with the consent banner, depending on your CMP’s settings. However, some CMPs provide more granular controls, allowing users to selectively disable certain categories of cookies, which can impact whether data is collected.

Ultimately, capture behavior is determined by how your consent framework is set up and whether it accurately enforces the user’s preferences. Untitled’s tag will follow the consent signal provided by your CMP and will not fire where a user has explicitly opted out of applicable data collection.

For a more detailed overview, we recommend reviewing our [Privacy and Consent Management article](/misc/privacy-and-consent-management.md), which covers implementation considerations and consent handling in greater depth.

</details>

<details>

<summary>Why would someone who accepted my Cookie policy NOT be resolved?</summary>

Even with consent, not every visitor can be resolved. Common reasons include:

* **Not in our dataset:** The individual may not exist in our data.
* **Geography:** We exclusively resolve U.S.-based visitors only.
* **Age:** Our data covers individuals 18 and older.
* **Insufficient signal:** We require high-confidence, deterministic matches. If signals are weak or conflicting, we will not resolve the visitor.
* **Browser limitations:** Resolution is strongest on Chrome; other browsers may have lower match rates.
* **Private browsing:** Incognito or similar modes reduce the ability to resolve users.
* **VPNs or proxies:** These can obscure device signals and prevent accurate matching.

If you have questions about specific edge-cases, your Customer Success Manager can help review.

</details>

<details>

<summary>If a website visitor opts out of the cookie policy, will their visit to the site still be tracked in other tools such as Google Analytics?</summary>

Whether a visitor's site visit is tracked in tools like Google Analytics after opting out of the cookie policy depends on your cookie consent tool settings. In the U.S., you can inform visitors about the use of cookies for marketing and tracking, and allow them to opt in or out. Tools like Osana and CookieYes offer options to customize this.&#x20;

</details>

<details>

<summary>Can I email my website visitors, even if they didn’t ask to be contacted?</summary>

**Yes, with conditions.** You can email your website visitors, but you must comply with the requirements of the CAN-SPAM Act. This includes (but is not limited to) providing clear identification of the sender, an accurate subject line, a physical mailing address, and a clear, functioning opt-out mechanism in every message. Recipients must be able to unsubscribe easily, and those requests must be honored promptly.

We also encourage users to conduct their own research to develop a more complete understanding of CAN-SPAM requirements and how they apply to their specific use case.

</details>

<details>

<summary>Can I text or call my website visitors?</summary>

Having a phone number in Untitled does **not** constitute consent for marketing phone calls or SMS messaging. Under the Telephone Consumer Protection Act (TCPA), SMS requires a higher standard of consent than most other marketing channels. This includes explicit opt-in requirements and compliance with restrictions such as “quiet hours” (generally 9 PM–8 AM in the recipient’s local time zone).

SMS consent must be collected and managed deliberately, and requirements can vary by state. If you are already using platforms like Klaviyo or Mailchimp, their built-in SMS tools and consent workflows are often the most straightforward way to stay compliant. Alternatively, you can implement third-party consent management solutions on your website to capture and store proper opt-ins.

Additional Resources:

[Untitled Messaging Policy Agreement](https://getuntitled.ai/messaging-policy/)

[SMS Compliance and Consent Overview from Klaviyo](https://help.klaviyo.com/hc/en-us/articles/360035056972)

</details>

<details>

<summary>What does the JavaScript code send Untitled?</summary>

IP Address, Time Stamp, Cookies, Browser Details, Page URL(s) and the referring URL.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.getuntitled.ai/misc/privacy-and-consent-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
