Version 1.1 · Effective 2026-07-09 · SHA-256 bebb723a1bb06979...

Sentinel Audits — Privacy Policy

Effective date: 2026-07-10 Version: 1.1 Owner: Willhite Strategy Group ("Sentinel," "we," "us," "our"), a California-based business.

This Privacy Policy explains what personal information we collect when you use Sentinel Audits (sentinelaudits.com and its subdomains, including api.sentinelaudits.com and sentinel.willhitestrategy.org), why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have — including specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). If you have questions, email [email protected].

Notice at Collection (CCPA § 1798.100(a))

This Privacy Policy is our Notice at Collection. A link to this Policy is presented at the point of every intake form (free basic scan, paid checkout, API key request) before you submit any personal information. The categories we collect, the purposes we use them for, and the retention period for each are set out below in Sections 1, 2, and 5. We do not sell or share personal information.

1. What we collect

When you request a free basic scan: - Your name - Your email address - The domain you asked us to scan - The IP address the request came from - The user-agent string of your browser - Your marketing-consent choice (yes / no) - The version number of the Terms of Service and Privacy Policy you accepted - The timestamp of your acceptance

When you purchase a paid scan or Monitor subscription: - All of the above, plus - Billing name and address (collected and stored by Stripe, our payment processor; Sentinel receives only the last 4 digits of your card and a customer identifier) - Purchase amount, tier, and page-count bucket - Delivery email for your report

When you use the API: - Bearer token identifier (not the token itself after issuance) - Timestamp of each request - The domains you submit - IP address of API caller

From your scanned domain: - The public HTML, response headers, cookies set by the target site, tracker categories, screenshots of specific page areas relevant to accessibility and privacy findings, and metadata about the site's public sitemap, robots.txt, structured data, and public search-console signals (where the scan is authorized by the domain owner via linked Google/Bing accounts).

Automatic / operational: - Log data (nginx access logs, worker logs) for security, fraud prevention, and debugging - Aggregated usage patterns (which categories are most-run, average page counts) — de-identified

2. Why we collect it

3. Legal bases (for GDPR-region users, if applicable)

Where GDPR applies to you, our legal bases are: performance of the contract (delivering the scan you paid for), our legitimate interest (fraud prevention, security, improvement of the Service), your consent (marketing), and legal obligation (tax records, subpoenas). You may withdraw consent for marketing at any time by clicking the unsubscribe link in any marketing email or emailing [email protected]. Withdrawal does not affect prior processing.

4. Who we share it with

We share personal information only with the third parties strictly necessary to deliver the Service:

Provider Purpose Data shared
Cloudflare CDN, DDoS mitigation, bot fight Request IP, headers, standard access logs
Stripe Payment processing Billing name, card details (Stripe holds directly; we receive last-4 + customer ID)
Resend Report + notification email delivery Recipient email, subject, body
Google (Search Console, PageSpeed Insights, Bing Webmaster Tools) Third-party SEO data sources — only for domains you have connected Domain name, OAuth token you granted
OpenRouter + LLM providers (Anthropic, Google, OpenAI, Perplexity, DeepSeek) AEO scan queries, legal-text linguistic analysis Public page text, brand name, prompt strings — no personal information about you

We do not sell your personal information. We do not "share" your personal information as that term is defined by the California Consumer Privacy Act (CCPA/CPRA) for cross-context behavioral advertising purposes. We do not participate in any advertising exchange or data broker network.

5. How long we keep it

CCPA statutory category mapping

Each Sentinel data point maps to a category under Cal. Civ. Code § 1798.140(v):

CCPA category Sentinel data points Sold? Shared? Retention
Identifiers (§ 1798.140(v)(1)(A)) Name, email, IP address, Stripe customer ID, bearer-token identifier No No 12 months (billing 7 years)
Customer records (§ 1798.140(v)(1)(B)) Billing name, address (held by Stripe) No No 7 years (tax law)
Commercial info (§ 1798.140(v)(1)(D)) Purchase amount, tier, page-count bucket No No 7 years (tax law)
Internet/network activity (§ 1798.140(v)(1)(F)) User-agent, log data, API request timestamps No No 30 days (security logs); 12 months (API request records)
Geolocation (§ 1798.140(v)(1)(G)) Approximate location inferred from IP No No 30 days
Professional info (§ 1798.140(v)(1)(I)) Company name (if you provide) No No 12 months
Inferences (§ 1798.140(v)(1)(K)) Sentinel score, category subscores, tier recommendation No No 12 months

Sensitive Personal Information (SPI) (§ 1798.140(ae)). We do not collect or process SPI as defined by CPRA. We do not require the "Limit the Use of My Sensitive Personal Information" link because we have no such use to limit.

6. Your California rights (CCPA/CPRA)

If you are a California resident, you have the following rights, which we will honor free of charge, twice per twelve-month period:

To exercise any right, email [email protected] with the subject line "California Privacy Request." We will verify your identity by matching the email address on file, and where necessary by asking one additional piece of information you supplied at scan time. We will respond within 45 days and may extend once by an additional 45 days as CCPA permits. If we deny a request, we will explain why in writing.

Authorized agents. You may designate an authorized agent to make a request on your behalf per CCPA § 1798.135(d). We will require written proof of the agent's authority and, in most cases, direct confirmation from you.

Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal on any page of sentinelaudits.com or any Sentinel Audits subdomain, we will treat it as a valid opt-out of sale/share, honored site-wide from the first request, consistent with California Attorney General regulations at Cal. Code Regs. tit. 11, § 7025. Since we do not sell or share personal information, this signal reinforces our default posture.

"Shine the Light" (Cal. Civ. Code § 1798.83). We do not share personal information with third parties for those third parties' direct marketing purposes. California residents therefore have no disclosure to request under § 1798.83.

Do Not Sell My Personal Information / Do Not Share My Personal Information. These links appear in our website footer as required. They confirm our no-sale/no-share posture; no additional action is needed on your part.

7. Requesting deletion

Email [email protected] with subject "Delete My Data." Include the email you used at scan time. We will:

  1. Verify your identity within 5 business days
  2. Delete or de-identify all scan inputs and outputs associated with your email within 30 days
  3. Retain a minimal record (email hash + deletion timestamp + billing history if you were a paying customer) for legal compliance
  4. Confirm completion in writing

Aggregated, de-identified benchmarking data that cannot be re-linked to you is not affected by a deletion request, consistent with CCPA § 1798.140.

8. Data security

We store personal information encrypted at rest (Postgres on an isolated dedicated VPS) and in transit (TLS 1.2+ only). Access is restricted to Sentinel personnel who need it for their work and is logged. We rotate credentials on a defined schedule. We do not maintain a public bug bounty at this time; please report security issues to [email protected].

Sentinel is a small business. In the event of a breach affecting your personal information, we will notify you and applicable authorities within the timeframes required by California Civil Code § 1798.82 (currently, "in the most expedient time possible and without unreasonable delay") and any other applicable law. Where a breach affects the personal information of 500 or more California residents, we will submit a sample notice to the California Attorney General as required by § 1798.82(f).

9. International transfers

Sentinel is based in California. Our servers are located in the United States and the European Union. If you are outside the United States, your information will be transferred to and processed in the United States. Where GDPR applies, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

10. Children

The Service is not directed to and we do not knowingly collect personal information from anyone under 18. If we learn we have collected information from someone under 18, we will delete it.

11. Cookies and analytics

Our marketing site (sentinelaudits.com) uses only functional cookies necessary to deliver the site and remember your Terms acceptance. We do not deploy advertising cookies. We use privacy-friendly self-hosted analytics (Umami) that does not track individual users across sites. See sentinelaudits.com/cookies for details.

12. Changes to this Policy

We may update this Policy. Material changes will be posted with a new Effective Date and Version. Where a change materially reduces your rights, we will notify you by email if we have your email, or by a prominent site notice, at least 30 days before the change takes effect.

13. Contact

Sentinel Audits / Willhite Strategy Group · [email protected] · sentinelaudits.com

Version 1.1 · Effective 2026-07-10

← HomeTermsPrivacyContact