LAST UPDATED 12 FEBRUARY 2026
If you submit the contact form: your name, email address, the URL you asked about and anything you typed in the notes field. If you request the checklist: your email address. We set no advertising cookies and run no ad networks or cross-site ad tracking.
This site uses Google Analytics 4 to count visits and see which pages get read. It sets first-party cookies (_ga and _ga_*, up to two years) and sends your IP address, page URL, referrer, approximate location and device and browser details to Google, who process it on our behalf with IP anonymization on. We use it to understand traffic, not to identify you, and we never join it to anything you send us through the forms. We set no advertising cookies and run no ad networks — the advertising and personalization consent signals stay switched off whatever you choose.
A banner asks before we count you. In the UK, EU and Switzerland no analytics cookie is set until you accept; everywhere else it starts on and the same banner turns it off. Being precise about what “off” means: declining stops all cookies and strips any identifier, but Google still receives an anonymous, cookieless signal that a page was viewed — it cannot be tied to you, your device or a previous visit. Your answer is remembered in this browser and you can change it at any time from Cookie settings in the footer; declining also deletes any _ga cookie already set. If your browser sends Global Privacy Control or Do Not Track we treat that as a decline automatically and never show you the banner. Declining costs you nothing: no part of this site depends on analytics.
To reply to you, to scope an engagement, and — for the checklist — to send the file once. We do not add contact-form submissions to a mailing list. Checklist subscribers receive the file and nothing further unless they separately opt in.
During an engagement we necessarily encounter data belonging to you and your users. It is held encrypted at rest, accessible only to the tester assigned, never copied outside our systems, and destroyed at the end of the engagement plus the agreed re-test window. Evidence in reports is redacted to the minimum that proves the finding.
Our email provider and our form endpoint provider, as processors. No advertising networks, no data brokers, no resale — ever. Subprocessor list available on request.
Inquiries: 24 months, then deleted. Engagement evidence: engagement plus re-test window. Scope documents and closure records: seven years, because they are the record that testing was authorized.
Ask us for a copy of what we hold, a correction, or deletion, by emailing contact@earthshakersecurity.com. We respond within 30 days. If you are in the UK or EU you may complain to your supervisory authority; we would rather you told us first.
Earthshaker SecurityWe find the cracks before they do. Automated and human-verified security testing for web applications.
earthshakersecurity.com · contact@earthshakersecurity.com
Earthshaker Security