CoSt ("we", "us", "our") is operated by COTR Global Group Ltd, a company registered in the United Kingdom. This Privacy Policy explains what personal data we collect when you use costdecision.com and the CoSt application, how we use it, who we share it with, and the rights you have under the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
For the purposes of GDPR, COTR Global Group Ltd is the data controller of personal data processed through CoSt.
Data We Collect
What we collect.
1. Information you give us
Email address — used to deliver your report, send receipts, and respond to support requests.
Website URL submitted for analysis — the public URL you ask us to diagnose. We fetch the page contents from that URL to run the pipeline.
Optional context — any free-text notes you provide on the intake form (e.g. current conversion rate, prior tests).
Payment information — processed entirely by Stripe. We do not see or store full card numbers; we receive only a billing reference and the transaction outcome.
2. Information we collect automatically
Log data — IP address, browser, device type, and request timestamps, used for security, abuse prevention, and debugging.
Cookies — a single first-party cookie records your cookie-banner choice. We do not use third-party advertising cookies.
3. Information we generate
Analysis output — the report produced by the CoSt pipeline (ICP model, diagnosis, primary bet, kill list, execution assets). This is generated from the URL you submit and is stored against your run ID.
How We Use It
Why we process your data.
To deliver the service — running the 11-stage analysis pipeline against the URL you submit, generating the report, and emailing the result. Legal basis: performance of a contract.
To process payment — sending a charge to Stripe and reconciling completed orders. Legal basis: performance of a contract.
To send transactional email — receipts, delivery notifications, and replies to support requests at hello@costdecision.com. Legal basis: performance of a contract.
To prevent abuse and secure the service — rate-limiting, fraud screening, log retention. Legal basis: legitimate interests.
To meet legal and accounting obligations — VAT records, tax filings, regulator requests. Legal basis: legal obligation.
We do not sell your data, and we do not use your submitted URL or the contents of your report to train third-party AI models beyond what is required to generate your specific report.
Third Parties
Who we share data with.
CoSt runs on a small stack of vetted sub-processors. Each receives only the data it needs to perform its specific function:
Payments
Stripe
Processes card payments. Receives your email, billing address, and card details (handled directly in Stripe's checkout — we never see the card). Stripe is PCI-DSS compliant and acts as an independent controller for fraud-prevention purposes.
Authentication
Clerk
Manages account sign-in for the dashboard. Receives your email and session identifiers. Acts as a data processor.
AI Pipeline
Anthropic
Powers the 11-stage analysis. Receives the URL contents and intermediate prompts needed to generate your report. Anthropic does not train its models on data sent through the API. Acts as a data processor.
Storage
Upstash Redis
Stores run state, report data, and rate-limit counters. Hosted in the EU. Acts as a data processor.
We may also share data when legally required (court order, lawful regulator request) or to protect the rights, property, or safety of CoSt, our users, or others.
Retention
How long we keep your data.
Report data and submitted URL — retained for 24 months from the date of your run, so you can revisit the report from the dashboard. You can request earlier deletion at any time.
Email address (account) — retained while your account exists, then deleted within 30 days of account closure.
Payment records — retained for 7 years to meet UK accounting and tax obligations.
Support correspondence — retained for 24 months from last contact.
Server logs — retained for 90 days for security and debugging, then deleted or anonymised.
Your Rights
Rights you can exercise.
Under GDPR (EU/UK) and CCPA (California), you have the following rights:
Access — request a copy of the personal data we hold about you.
Rectification — ask us to correct inaccurate or incomplete data.
Deletion ("right to be forgotten") — ask us to delete your account, reports, and associated data, subject to legal retention obligations.
Restriction — ask us to limit how we process your data.
Portability — receive your data in a structured, machine-readable format.
Objection — object to processing based on legitimate interests.
Withdraw consent — where processing relies on consent, withdraw it at any time.
Non-discrimination (CCPA) — we will not deny you service or charge you a different price for exercising your CCPA rights.
Lodge a complaint — with your local supervisory authority (in the UK, the Information Commissioner's Office at ico.org.uk).
To exercise any of these rights, email hello@costdecision.com with the subject line "Privacy request". We will respond within 30 days.
International Transfers
Where your data is processed.
CoSt is operated from the United Kingdom. Some of our sub-processors (notably Stripe, Clerk, and Anthropic) are based in the United States. Transfers outside the UK/EEA are protected by the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
Changes
Updates to this policy.
We may update this Privacy Policy from time to time. Material changes will be communicated by email to active account holders or by a prominent notice on this page. The "Last updated" date at the top reflects the most recent revision.
Contact
Get in touch.
For any privacy question, data request, or complaint, contact the controller directly: