Privacy Policy
Last updated: 6 August 2026
Who this covers
Consently is an agreement- and consent-capture app for OpoShop stores, published by Found. This policy covers the Consently admin app, the agreement checkbox or confirmation the merchant shows on their storefront, and the website at getconsently.com. If you are a shopper who agreed to a policy on a store, the merchant running that store is the controller of your data; Consently processes it on their behalf, and this describes exactly what that amounts to.
What we read from a merchant's store
When a merchant installs Consently, OpoShop grants it access we use for three things:
- Verifying who is asking. When the app loads inside the OpoShop admin we confirm, with the caller's own credential, that they really own the store they claim to. No session exists until that check passes.
- Your store name and owner email, so the agreement can be brand-matched and so we can reach you.
- Order events, via an OpoShop webhook, for the single purpose of linking a recorded agreement to the order it belongs to (the thing that makes a receipt "chargeback-ready"). We do not read, store or export your customer list, your products or your revenue, and Consently never writes anything to your store.
What we record about shoppers
This is the heart of the app, so we will be exact. When a shopper accepts an agreement, Consently records a receipt containing:
- The exact agreement text they saw — a snapshot of the wording and its version at the moment they accepted, taken on our server so it cannot be altered afterward.
- A positive-acceptance flag and the timestamp.
- An anonymous session id the shopper's own browser generated, and their email address if it is known at checkout.
- The page and product(s) the agreement was shown on, and the cart or order id it is tied to.
- The IP address and browser (user agent) the acceptance was made from. A consent receipt exists to prove who agreed and when — unlike an analytics cookie, that proof is the whole point, so this context is recorded deliberately and only for that.
Consently also keeps plain daily counters per store — how many agreements were shown and accepted — as simple integers bucketed by day. It records no advertising identifier, builds no cross-site profile, and never uses a receipt for marketing.
Where data lives, and for how long
Store configuration, daily counters and agreement receipts are held in Consently's own MongoDB database, scoped per store and hosted in the United States. One store's data is never visible to another, even when the same person owns both.
Because a receipt's entire job is to be available if a payment is disputed — which can happen many months after the sale — receipts are kept for as long as they may be needed for chargeback or refund-dispute defense and are not auto-purged. A merchant can delete a receipt, or ask us to erase a store's data, at any time (see below). Merchant configuration is kept while the app is installed so a reinstall restores it.
Browser storage the agreement uses
-
consently_sid— a random session id in the shopper's browser, so a receipt can be tied to their session and they are not asked to re-agree on every page. -
consently_cfg_<store>— a cached copy of the store's public agreement configuration, so the agreement paints instantly instead of waiting on a network round trip.
Neither is used for advertising, profiling or analytics, and neither travels to another site. The Consently admin uses browser storage only to keep a merchant signed in.
Uninstalling
Removing Consently from a store immediately stops the agreement rendering — OpoShop calls our uninstall endpoint and the public configuration endpoint starts answering "off" straight away, so even a cached copy in a shopper's browser goes inert. Existing receipts are retained (a merchant may still need them to defend a dispute); to have a store's stored data erased instead, email brandon@tryfound.io and we will delete it.
Third parties
- OpoShop — the platform the app is installed on, and the source of the order events used to link receipts.
- Fly.io — hosting.
- MongoDB Atlas — the database.
- PostHog — product analytics for the merchant-facing admin only, never on a storefront and never about a shopper's acceptance.
We do not sell data, we do not share it for advertising, and we run no advertising of our own.
Payments
Consently does not take payments and never sees a card number, a bank detail or a billing address. Linking a receipt to an order uses only the order's identifier — never its payment information.
Your rights
If you are in the EU, UK, California or another region with a privacy law, you have rights of access, correction, deletion and objection over data we hold. In almost every case the merchant whose store you bought from is the right first contact, since they are the controller — but you can always write to us directly at brandon@tryfound.io and we will help. Note that a merchant may retain an agreement receipt where it is needed to establish a legal claim, such as defending a payment dispute.
Changes
If this policy changes materially we will update the date at the top and, where the change affects merchants, note it in the app's What's New page.
Contact
Found · brandon@tryfound.io