Do Not Sell or Share My Personal Information
Last updated: August 14, 2026
01The Short Version
CueSync does not exchange your personal information for money. Nobody pays us for a list, and we do not run a data-broker business.
We do use advertising and measurement tags, and under California law that counts. When an advertising platform receives an identifier tied to you so that it can measure a campaign or show you an ad elsewhere, the CPRA calls that a "sale" or a "share"even though no money changes hands. So the honest answer is: yes, by California's definition, and here is exactly what goes where and how to switch it off.
To opt out right now: open the cookie preference centre and turn off the advertising category. It takes effect immediately on that device, with no page reload and no separate save step. If you would rather we handle it, email privacy@cuesync.live.
We never sell or share the personal information of anyone we know to be under 16.
02What “Sale” and “Share” Mean Here
These two words do not mean in the CPRA what they mean in ordinary speech, and the gap is where most privacy pages quietly mislead.
- Sale covers disclosing personal information to a third party for monetary or other valuable consideration. Better campaign measurement is valuable consideration.
- Share covers disclosing it for cross-context behavioural advertising — showing you an ad on another site based on what you did here — regardless of whether anything of value comes back.
Our Privacy Policy says we do not sell your personal information for money, and in that everyday sense it is true: we take no payment for it. It says the rest of this in the same breath, because under the wider California definitions our advertising tags and the conversion events we send when someone buys are a "share". This page is the disclosure and the opt-out that go with that. If you ever find the two pages disagreeing about this, the disagreement is the bug — tell us.
Not everything is a sale or a share. Sending your address to our payment processor so a payment can be taken, or to our email provider so your licence key can be delivered, is a disclosure to a service provider for a business purpose. Those providers are contractually barred from using your data for their own purposes, and opting out does not stop them — nor would you want it to, since that is how the product works. The full list is on the Sub-processors page.
03What We Actually Disclose
Two things happen, on two different paths. Both are gated on your advertising consent, and both fail closed: if we cannot positively confirm that consent was granted, nothing is sent.
In your browser, while you are on the site
Advertising tags load only after you accept the advertising category. Once loaded they see the pages you visit and set or read a platform cookie, and they receive any advertising click identifier that brought you here — the gclid from a Google ad, fbclid from Meta, and their equivalents. Like any web request they also see your IP address and browser user agent.
On our server, when you complete a purchase
When a purchase completes, our server sends a conversion event to the advertising platforms. This is the part most people do not expect, so it is worth stating plainly: it includes a SHA-256 hash of your email address, used as the key that matches the purchase to an advertising profile. A hashed email is not anonymous — being a stable match key is the whole reason it is sent — and we treat it as personal information accordingly.
The event also carries the purchase value, the currency, the edition and billing cycle, the transaction reference, and the country the buyer's billing address is in.
Your advertising choice is captured at checkout and travels with the transaction, so a purchase made after you declined sends nothing — including a purchase whose confirmation arrives days later. A checkout that carries no recorded choice at all is treated as a decline.
| Recipient | In the browser | On purchase, from our server |
|---|---|---|
| Google (Ads, Analytics) | Page views, events, click identifiers, cookie identifier, IP | Hashed email, purchase value, currency, transaction reference, country |
| Meta (Facebook, Instagram) | Page views, click identifiers, cookie identifier, IP | Hashed email, purchase value, currency, event identifier, country |
| Page views and interactions, cookie identifier, IP | Hashed email, purchase value, currency | |
| Microsoft (Bing Ads) | Page views and conversion events, cookie identifier, IP | Nothing — there is no server-side path for this one |
| X (Twitter) | Page views, cookie identifier, IP | Hashed email, purchase value, currency |
Product analytics and session replay (PostHog) are a separate category with a separate toggle. They are not an advertising disclosure and are not part of a sale or share, but you can switch them off in the same preference centre.
04How to Opt Out
1. The preference centre (fastest)
Open the cookie preference centre and turn the advertising category off. The change applies immediately on that device: the tags stop, the consent signal pushed to Google, Microsoft and Meta flips to denied, and the choice is carried to our server so the purchase-time conversion events stop too.
The choice is stored on the device you make it on. Opting out on a laptop does not opt out a phone, and clearing your browser storage clears the record of the choice along with everything else — the banner will ask again.
2. Email us (works across every device)
Send a request to privacy@cuesync.live with "Do Not Sell or Share" in the subject line. Include the email address on your CueSync account. We will record the opt-out against the account so it applies wherever you sign in, not just on one browser.
You do not need an account to send this request, and you do not have to create one to make it. If you have no account, tell us what identifier to act on.
3. Opt out at the platform
Each platform also runs its own controls, which apply across every site that uses them, not only ours: Google Ads Settings, Meta Ad Preferences, and LinkedIn's retargeting opt-out.
Opting out does not sign you out, degrade the product, or change what you pay. See non-discrimination below.
05Browser Opt-Out Signals
Global Privacy Control is honoured automatically.If your browser or an extension asserts GPC — the signal California's regulations name as a valid opt-out preference, and which Colorado and Connecticut adopted after — you do not need to do anything on this page. We treat it as a standing refusal of both advertising and analytics from the first page you load.
The deprecated Do Not Track header is treated identically. No law compels it, and we have honoured it for years; there was no honest reason to stop when GPC arrived.
What that means in practice
- No advertising or analytics tag is loaded, and the denied state is pushed explicitly to Google Consent Mode, the Microsoft tag and the Meta Pixel rather than left to a default.
- The consent banner does not interrupt you. Asking someone who has already answered at the browser level is precisely the interruption they set the signal to avoid.
- The check fails closed. If your browser storage is unreadable — private browsing modes throw rather than return empty — the refusal stands rather than being treated as absent.
Overriding it, and turning it on later
The signal can only be overridden by you, deliberately, in the preference centre, which stays fully usable while a signal is asserted — the toggles show the effective state, which is off, and switching one on is an explicit choice that wins.
An override applies only to the signals you were sending when you made it. If you switch on GPC later, that is a new request about something we never asked you, and an old Do Not Track override does not silence it: the refusal stands again until you say otherwise.
One limit worth knowing: a browser signal is per-browser and per-device, because that is where it is sent from. To have an opt-out recorded against your account so it applies everywhere you sign in, use the email route above.
06Your Other California Rights
If you are a California resident, the CPRA gives you the rights below. Exercise any of them at privacy@cuesync.live.
- Right to know. Ask what categories of personal information we have collected about you, where it came from, why we collected it, who we disclosed it to, and the specific pieces themselves.
- Right to delete. Ask us to delete what we hold, subject to the exceptions the law allows — principally records we must keep for tax and accounting, and records needed for a dispute in progress. The Data Retention Schedule names each one.
- Right to correct. Ask us to fix inaccurate personal information. Most of it you can correct yourself in your account dashboard, which is faster.
- Right to opt out of sale or sharing. Covered above.
- Right to limit the use of sensitive personal information. See the next section.
- Right to non-discrimination. We will not deny you the service, charge you a different price, give you a lower quality of service, or suggest that we might, because you exercised any of these rights. There is no loyalty programme or financial incentive tied to your data here, so there is nothing for an opt-out to cost you.
07Sensitive Personal Information
The CPRA defines a narrow category of "sensitive personal information", and gives you the right to limit its use to a specific list of permitted purposes.
The only thing in that category we hold is your account sign-in credential. We use it to sign you in and to keep your account secure — both squarely within the permitted purposes — and we do not use it to infer characteristics about you, do not disclose it to anyone for advertising, and do not sell or share it. On that basis the right to limit does not restrict anything we are actually doing.
We do not collect precise geolocation, racial or ethnic origin, religious beliefs, union membership, health data, biometric identifiers, or the contents of your mail, email or messages. Payment card details are collected by our payment processor and never reach us. If you would like the limitation recorded anyway, ask and we will record it.
08Authorised Agents
You can use an authorised agent to make any of these requests for you. The agent should email privacy@cuesync.live with:
- Written permission from you authorising them to act, or a valid power of attorney
- Enough information to identify the account or the identifier the request concerns
For a request to know, correct or delete, we may also contact you directly to confirm you gave the authorisation and to verify your identity. We do not do that for an opt-out request: an opt-out is low risk and the law does not permit us to make it burdensome.
09How We Verify a Request
Verification is proportionate to what the request could do if it were fraudulent.
- Opt-out requests are not verified. We act on them. The worst case is that someone stops advertising data flowing about a person who did not ask, which harms nobody.
- Requests to know, correct or deleteare verified, because acting on a fraudulent one would disclose or destroy someone's data. Normally this means sending the request from the email address on the account, or confirming a link we send to it. Where the request covers specific pieces of information rather than categories, we may ask for more.
Information you give us for verification is used only for verification and is not retained beyond it or used for any other purpose.
10Timing & Appeals
We confirm receipt within 10 business days and respond substantively within 45 calendar days. Where a request is genuinely complex we may extend once by a further 45 days, and we will tell you inside the first period, with the reason. Opt-out requests are actioned as soon as we receive them rather than at the end of that window.
If we decline a request in whole or in part we will say which exception we are relying on. If you think we got it wrong, reply and say so — a person will look at it again. You can also complain to the California Privacy Protection Agency or the California Attorney General.
11Contact
Privacy requests and questions about this page: privacy@cuesync.live.
Related documents: Privacy Policy, Cookie Policy, Sub-processors, and the Data Retention Schedule.