Report URI

Privacy Policy

This Agreement was last modified on 8th October 2026
1. The TL;DR version
2. Data related to logging in

When you sign up for an account at Report-URI you need to provide your email address and a password.

The email address you provide is stored and is used as a unique identifier for you to login. It is also used to send you emails in relation to your use of the service, ask for your feedback, and inform you of changes and enhancements to our services.

The password you choose is salted, hashed and stored. This hash is used every time you login to authenticate that the person logging in and claiming to be you, really is you.

We also create a unique UserID (think GUID) for your account. This is used to reference your account and for internal administration.

Data related to logging in is retained until your account is deleted.

By signing up for an account at Report-URI, you agree that we can use this information relating to you for these purposes. No other information is required for you to use the service.

3. Data related to payments

When you enter your payment card information we require the following data.

To enter your payment card information your browser will be redirected to Stripe Payment Europe. Report-URI never sees this data, instead Stripe send us a reference.

This information, along with your payment history, is necessary for us to process payments in accordance with our terms of service. It is retained as long as you continue to use Report-URI.

In addition to Stripe Payments Europe acting as our payment processor, Stripe also uses the data provided for their own purposes which include the prevention and detection of fraud and their own regulatory obligations. You can find out more about how Stripe uses your data in their privacy policy at https://stripe.com/gb/privacy.

4. Data related to your engagement with us

If you email us to ask about our services or require to be invoiced before paying, then we will process the data you provide to us in emails which may include your name, telephone number(s), job title, company and physical address. We use this information to communicate with you and to send invoices to you.

This information may be retained as long as you use our service and as required by law (e.g. accounting records).

If you sign up for a webinar, we'll use your email address to provide access to the webinar and to follow-up. You can unsubscribe from our emails at any time.

5. Third-party service providers

As a cloud-based service, we rely on the use of third-party service providers.

Name Services Provided Personal Data Processed
Cloudflare Edge computing, CDN, WAF. Email address.
DigitalOcean Core application processing on Report-URI administered systems, hosted on Digital Ocean hypervisor plane. Email address.
Fastmail Email services. Email address, and other information shared with us via email.
Microsoft Azure Core application storage. Database services. Email address.
Sendgrid Core application. Email sending and receipt (SMTP servers). Email address - automated emails sent by the system.
Xero (UK) Limited Accounting SaaS. Invoicing and accounting information for Enterprise customers. May include contact information.
Stripe Payments Europe Payment Services. Payment card data. Payment card billing address. Billing history.
Hubspot Customer Relationship Management tool. Email address, and other information shared with us via email.
Google (Google Ireland Limited, Google LLC) Google Analytics and Google Ads. Online identifiers (cookie IDs and the Google Ads click ID), IP address, pages visited, and device and browser information. Cookies are only set with your consent. See sections 7 and 8.
LinkedIn (LinkedIn Ireland Unlimited Company) LinkedIn advertising. Online identifiers (cookie IDs and the LinkedIn click ID), IP address, pages visited, and device and browser information. Cookies are only set with your consent. See sections 7 and 8.
Reddit (Reddit, Inc.) Reddit advertising. Online identifiers (cookie IDs and the Reddit click ID), IP address, pages visited, and device and browser information. Cookies are only set with your consent. See sections 7 and 8.
OpenAI AI services. No personal data is processed.

Other than Stripe Payments Europe and Xero, all these third-parties operate outside the UK or EEA. For EU-based customers, we have executed agreements that incorporate the European Commission’s revised Standard Contractual Clauses (SCCs) with all third-parties to provide the necessary protection for personal data relating to you. For UK-based customers, the previous Commission SCCs approved by the ICO are still effective.

We have undertaken a Transfer Impact Assessment in respect of the transfer of personal data to the US and assessed that the risk of US authorities’ lawful access to this data is negligible. Most of these third parties process only your email address and the other data related to logging in. Google, LinkedIn and Reddit receive the online identifiers and browsing information described in sections 7 and 8, and never your email address or password. Google and LinkedIn are certified under the EU-US Data Privacy Framework and its UK Extension.

6. Security of data

As you'd expect from a company run by Scott, we're pretty serious about security. Although the systems we run process minimal personal data -- just your email address, password hash and a payment token -- our systems are designed, built, and operated securely.

Our security is regularly tested by independent parties and you can read about our latest penetration test here.

7. Cookies

We use three kinds of cookie. Essential cookies are always set, because the site cannot run securely without them. Analytics and advertising cookies are only set if you agree to them in the cookie banner. Until you choose, none of their scripts load. This applies to every visitor, wherever you are. If your browser sends a Global Privacy Control signal, we treat it as a refusal of advertising cookies.

You can change your choice at any time from the Cookie settings link at the foot of every page that can use them. Withdrawing consent deletes the analytics and advertising cookies set on our domain. Cookies set on Google's, LinkedIn's or Reddit's own domains are managed in those services' settings.

No analytics or advertising cookies are used in your account, or on our login, registration, password reset, billing, email unsubscribe and error pages.

Essential cookies
Party Cookie Purpose
1st _nss Set to prevent CSRF, expires at the end of the session.
1st __Host-report_uri_sess Session cookie, expires in 24 hours.
1st __Host-report_uri_dbsc Device Bound Session Credentials cookie, expires in 5 minutes.
1st __cf_bm Cloudflare Bot Management - The __cf_bm cookie supports Cloudflare Bot Management by managing incoming traffic that matches criteria associated with bots. The cookie does not collect any personal data, and any information collected is subject to one-way encryption. This encrypted file contains Cloudflare's proprietary bot score and helps manage incoming traffic that matches specific criteria. This cookie is a session cookie that lasts for up to 30 minutes from the time you connect with our site.
1st __Host-report_uri_consent Remembers your cookie choice, and when you made it, so we don't ask again. Expires after 180 days.
Analytics cookies (only with your consent)
Provider Cookie Purpose
Google Analytics _ga, _ga_D8BTB16DGW Distinguishes visitors so we can count visits and see which pages are read. Expires after 2 years.
Advertising cookies (only with your consent)
Provider Cookie Purpose
Google Ads _gcl_au, _gcl_aw Measures visits from our Google ads and lets us show our ads to people who have visited. _gcl_aw is only set when you arrive from one of our Google ads. Expires after 90 days.
LinkedIn li_fat_id Measures visits from our LinkedIn ads. Only set when you arrive from one of our LinkedIn ads. Expires after 30 days. LinkedIn's other cookies (such as bcookie, lidc and li_gc) are set on linkedin.com.
Reddit _rdt_uuid Measures visits from our Reddit ads and lets us show our ads to people who have visited. Expires after 90 days.

These providers may also set cookies on their own domains (for example google.com, linkedin.com and reddit.com) when their scripts load. For pixel data, Google, LinkedIn and Reddit act as controllers alongside us. Their privacy policies explain how they use it: Google, LinkedIn, Reddit.

8. Measuring our advertising

When you click one of our ads, the ad platform adds a click ID to the link (for example gclid from Google, li_fat_id from LinkedIn, rdt_cid from Reddit), along with campaign tags (utm_source, utm_medium, utm_campaign). We keep these in your session. If you start a trial, they are saved with your subscription. When the trial starts, and when your first payment is made, we send the click ID back to the platform that issued it, so we can tell which ads lead to customers. The platform already holds the click ID. We send nothing else about you, and never your email address. The click ID and campaign tags are also recorded in our CRM (HubSpot) against your account.

We do this on the basis of our legitimate interest in measuring whether our advertising works. It does not use cookies on your device beyond our essential session cookie. You can object at any time by emailing info@report-uri.com, and we will remove the click ID from your subscription.

9. Your rights
Getting a copy of your data

You can see the data we process about you related to logging in, in your account.

If you have registered a payment card and want a copy of the data you provided, please email info@report-uri.com.

If you are an enterprise customer and require a copy of any personal data, please email info@report-uri.com.

Your cookie choices

Use the Cookie settings link at the foot of any page that can use them to give or withdraw consent for analytics and advertising cookies. Withdrawing consent is as easy as giving it, and takes effect straight away.

Correcting your data

If you believe any data we hold relating to you is incorrect, please email info@report-uri.com

Deleting your data

The processing of your personal data is necessary for your use of the service. If you delete your account this will also delete all the data related to you. This is a one-way process; it is not reversible.

10. Complaints?

We provide this service and process the minimum amount of personal data that we can. If you have questions or complaints, please address them to info@report-uri.com.

If you are not happy with how we have dealt with your questions or complaints in relation to how we process personal data, you can contact the UK Information Commissioner. The best place to start is https://ico.org.uk/make-a-complaint/.

11. Changes to this Privacy Policy

Although changes are likely to be minor, we may change our Privacy Policy from time to time, at our sole discretion. We'd encourage you to frequently check this page for any changes to this Privacy Policy.

12. Personal data received by Report-URI in telemetry and violation reports

The data that we receive from your customers' browsers and email gateways in telemetry and violation reports may constitute the personal data of your users or customers. Only you are able to make this determination, and you should seek professional advice, we are not able to advise you.

There are two questions you need to consider:

  1. Does the UK or EU GDPR apply to you?
  2. Is the data received by Report-URI personal data that relates to identified or identifiable people who visit your website?

Typically, there are five types of data that are received by Report-URI which, for you, may be the personal data of visitors to your website. These are:

From a security and privacy perspective we would discourage anyone from including Personal Data in a URI, Fragment or Query String.

If you determine that Report-URI processes the personal data of your customers, and that therefore in GDPR terms, you are the Controller for this data, and Report-URI will act as your Processor, you must agree to amending our Terms of Service by incorporating our Data Processing Agreement after you upgrade from a free account.

You should determine that the reporting and data management functionality provided by Report-URI allows you to fulfil your obligations as a Controller.

Further information about the privacy implications of telemetry and violation reporting is available in the following detailed technical standards and RFC documents.

Standard RFC Document
General W3C Reporting API https://www.w3.org/TR/reporting/#privacy
Content Security Policy (CSP) https://www.w3.org/TR/CSP3/#security-considerations
Network Error Logging (NEL) https://www.w3.org/TR/network-error-logging/#privacy-considerations
Domain-based Message Authentication, Reporting, and Conformance (DMARC) https://tools.ietf.org/html/rfc7489#section-9
Transport Layer Security for Simple Mail Transport Protocol (SMTP over TLS) https://tools.ietf.org/html/rfc8460#section-8
Certificate Transparency (CT) https://tools.ietf.org/html/rfc6962

The forensic reporting option in DMARC (ruf) will expose the private information contained in an email. Report-URI does not support this option.

We have detailed further observations about a Controller's use of Report-URI as a Processor which is available in this document Report-URI and Data Protection.

This Privacy Policy is also available as a PDF download.

This policy was last updated on 8th October 2026 (1v16):