Privacy
The site has one form and one analytics script. This page lists what each collects, where it goes, and how long we keep it. There are no accounts, no advertising pixels and no third-party cookies.
The report form
The report form asks for a vendor URL. A note and an email address are optional. When you submit, the form sends those fields to our server, which forwards them to a private message channel read by the audit team. The submission also carries your IP address, which the server uses for a rate limit of 5 submissions per minute and does not store beyond that minute.
The email address reaches the same private channel as the rest of the submission and is used only to reply to you about it. It is never shown to the vendor, never added to a mailing list, and never passed to anyone else. The note is read by a person and is not published. The vendor URL becomes part of the audit record if an audit is opened.
The form contains a hidden field that people do not see or fill. Submissions that fill it are discarded without being read.
Analytics
The site uses Vercel Analytics to count page views. It records the page path, the referrer, the country derived from the request, and the browser and device category. It does not set cookies, does not fingerprint, and does not follow you to other sites. We see aggregate counts, never an individual visit.
Vendor and laboratory data
Vendor cards contain information the vendor published on its own site: its domain, the reports it posted, and the contact address it lists. Company responses are published because the company sent them for that purpose, and the card says so. Laboratory entries contain information the laboratory publishes about its verification path.
We do not publish the names of individuals, and we redact personal names from exhibits where a report names a private client rather than a business. A person named on a published exhibit can ask for redaction under the corrections policy.
Retention
| Item | Where | Kept |
|---|---|---|
| Report form submission (URL, note) | Private audit queue | Until the audit is closed, then 12 months |
| Report form email address | Private audit queue | Until the card publishes and the link is sent, then deleted |
| IP address on a submission | Rate-limit counter in server memory | 60 seconds |
| Analytics page views | Vercel Analytics | Per Vercel's retention, aggregated |
| Email to audits@coawatchdog.com | Mailbox | As long as the related card exists |
Your requests
To see, correct or delete anything you sent us, write to audits@coawatchdog.com from the address you used. We answer within 7 days. Deleting a report submission does not remove a vendor card that was opened because of it; the card rests on the vendor’s public documents, not on your message.
Changes to this page are made with a new effective date at the top. The rules for the register itself are in the methodology.