1. Who We Are
WebCookies is a cookie consent management plugin developed and operated by XMS Ai (Xperience Ai Marketing Solutions). When installed on a website, WebCookies helps site owners comply with cookie consent regulations such as GDPR, LGPD, and PIPEDA.
For questions about this policy, contact us at: aixmslead@xperienceusa.com
2. Information We Collect
When a visitor interacts with a WebCookies consent banner on a website, we may collect:
- A randomly generated anonymous user ID (stored in
localStorage) - The consent choice made (accept all, reject all, or custom preferences)
- The categories of cookies consented to (necessary, functional, analytics, marketing)
- The country or region detected via IP geolocation (used to apply the correct compliance mode)
- The website domain where the consent was recorded
- The timestamp of the consent action
We do not collect names, email addresses, or any personally identifiable information through the banner interaction.
3. How We Use This Information
The consent data collected is used exclusively to:
- Remember the visitor's cookie preferences so the banner is not shown again on return visits
- Provide website owners with a record of consent for compliance purposes
- Determine the correct legal framework (GDPR, LGPD, PIPEDA, or Basic) based on the visitor's location
We do not sell, rent, or share this data with third parties for advertising or marketing purposes.
4. Cookies and Local Storage
WebCookies uses localStorage to store consent preferences on the visitor's device. This is strictly necessary for the functionality of the plugin and does not require prior consent under most regulations.
The key stored is vc_cookie_consent and contains the consent record in JSON format. No tracking cookies are set by WebCookies itself.
5. Data Storage and Security
When a Supabase integration is configured by the website owner, consent records may be stored in a cloud database for audit and compliance purposes. This data is stored securely and access is restricted to authorized personnel only.
We implement appropriate technical and organizational measures to protect the data we process against unauthorized access, loss, or alteration.
- Encryption in transit (TLS 1.2 or higher) for all data sent to or from our servers
- Encryption at rest for all server-side consent records
- Role-based access controls, limiting access to authorized personnel with a documented business need
- Periodic security reviews and monitoring for unauthorized access or anomalies
- Vendor security assessments for any sub-processors involved in data storage or geolocation services
These measures are reviewed and updated periodically to align with recognized industry standards, including NIST guidelines.
6. Data Retention
Consent records stored in localStorage persist until the visitor clears their browser storage or the website owner expires them. Records stored server-side are retained for up to 24 months for compliance audit purposes, after which they are automatically deleted.
7. Your Rights
Depending on your location, you may have the following rights regarding your data:
| Regulation / Region | Rights |
|---|---|
| GDPR (EU / EEA / UK) | Access, rectification, erasure, restriction of processing, data portability, and objection to processing. |
| LGPD (Brazil) | Confirmation of processing, access, correction, anonymization, portability, deletion, and information about third-party sharing. |
| PIPEDA (Canada) | Access and correction of personal information held by us. |
| CCPA (California, USA) | Know what personal data is collected, delete, opt out of sale or sharing, and exercise these rights without discrimination. |
| Florida (FIPA / FDUTPA) | Notification in the event of a data breach affecting your personal information. |
To exercise any of the rights listed above, you may contact us by email at aixmslead@xperienceusa.com.
We will acknowledge your request within 5 business days and respond substantively within:
- 30 calendar days for GDPR requests, extendable to 90 days for complex cases with notice
- 45 calendar days for US state law requests, extendable by an additional 45 days with notice
- 30 calendar days for LGPD and PIPEDA requests
Appeals: If you are unsatisfied with our response to a rights request, you may submit an appeal by emailing aixmslead@xperienceusa.com with the subject line "Privacy Rights Appeal." We will respond to appeals within 60 days.
8. Third-Party Website Owners
Website owners who install WebCookies on their sites are independent data controllers. They are responsible for their own privacy practices and for updating their own privacy policies to reflect the use of WebCookies on their site. XMS Ai is not liable for how third-party website owners use or store the consent data provided by WebCookies.
XMS Ai acts as a data processor with respect to the consent records generated through WebCookies installations. In this capacity, we process data (including anonymous consent identifiers and preference records) strictly on behalf of and under the documented instructions of each website owner.
Website owners who require a Data Processing Agreement (DPA), for example, to satisfy GDPR Article 28 obligations, may request one by contacting us at aixmslead@xperienceusa.com.
9. Google Consent Mode
WebCookies is compatible with Google Consent Mode v2. When a visitor makes a consent choice, WebCookies automatically signals the updated consent state to Google services (such as Google Analytics and Google Ads) via gtag('consent', 'update', …). This signal is passed directly to Google and is governed by Google's Privacy Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page.
For material changes, including any change to the categories of data we collect, how we use data, who we share it with, or your rights, we will provide proactive notice by:
- Displaying a prominent notice within the WebCookies admin dashboard or plugin interface for at least 30 days prior to the change taking effect, and/or
- Sending an email notification to registered account holders at the address on file
Non-material changes, such as corrections of typographical errors or clarifications that do not affect your rights, may be made without prior notice.
Continued use of WebCookies after material changes are posted constitutes acceptance of the updated policy. We recommend bookmarking this page and reviewing it at least annually.
11. Data Breach Notification
XMS Ai maintains procedures to detect, investigate, and respond to data security incidents. In the event of a breach of security involving personal data we process, we will:
- Conduct an internal investigation to assess the nature, scope, and risk of the incident
- Notify affected individuals and relevant authorities within 30 calendar days of determining that a reportable breach has occurred, in accordance with the Florida Information Protection Act (FIPA, Fla. Stat. § 501.171)
- Notify the Florida Department of Legal Affairs within 30 days if the breach affects 500 or more Florida residents
- Notify all nationwide consumer reporting agencies if the breach affects 1,000 or more individuals
- Provide affected individuals with a description of the incident, the types of information exposed, our contact information, and recommended steps they can take to protect themselves
If XMS Ai reasonably determines, following investigation, that a breach is unlikely to result in harm to affected individuals, this determination will be documented in writing and maintained for a minimum of five (5) years, as required by Florida law.
Website owners (data controllers) who use WebCookies and experience a breach affecting end-user data stored via their own systems are independently responsible for their own breach notification obligations under applicable law.
12. Sub-Processors and Third-Party Services
In operating WebCookies, XMS Ai may engage the following categories of third-party sub-processors to support data storage, infrastructure, or location detection:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Supabase (optional) | Server-side consent record storage when configured by the site owner | United States (AWS us-east-1 by default) |
| ipapi.co | Country/region detection to apply the correct compliance mode | Processed by the provider according to its infrastructure and privacy practices |
We ensure that all sub-processors are bound by data processing agreements and provide sufficient guarantees regarding their data security practices.
13. Contact
If you have questions or concerns about this Privacy Policy or our data practices, please reach out:
- Email: aixmslead@xperienceusa.com
- Website: webcookies.xmsaibusinessapps.cloud