This Privacy Policy applies to https://theadminstack.com and its tool sections — theadminstack.com/grc, theadminstack.com/itops, theadminstack.com/secops, and theadminstack.com/osint (together, the "Site"). All are operated by TheAdminStack. By using the Site you agree to the practices described below. If you don't agree, please don't use the Site.

1. Information We Collect

We try to collect as little as possible. What we do collect falls into three categories:

a. Information you provide directly

If you use the contact form, we collect your name, email address, company (optional), and message so we can reply. This is stored in our database and is never sold or shared with third parties.

b. Information collected automatically

Like most websites, our server and the tools hosted on it automatically log standard technical data when you visit: IP address, browser/device type, referring page, pages viewed, and timestamps. Some of our IT Ops and OSINT tools (for example, reverse-DNS and network-recon lookups) also process domain names and IP addresses you submit, and a first-party index records IP/domain pairs to power "co-hosted domain" lookups. This data is used to operate, secure, and improve the tools — it is not used to build advertising profiles and is not shared with ad networks.

c. Cookies, local storage, and similar technologies

We use a small number of cookies:

  • Strictly necessary: remembers your light/dark theme preference and your cookie-consent choice. These don't track you and can't be disabled without breaking basic site behavior.
  • Advertising (only after you accept): as described in Section 5, if you accept cookies we may load third-party advertising scripts that set their own cookies to show and measure ads.

Some tools — such as the Risk Register, Vendor Risk Assessment, and Control Mapper — save your work using your browser's local storage (localStorage) so it's still there when you come back. This data stays on your device: it is never transmitted to our servers, and we cannot see it. You can erase it at any time using the tool's clear/reset option or by clearing site data for theadminstack.com in your browser.

You'll see a cookie banner the first time you visit any theadminstack.com subdomain. Your choice (accept or reject) is remembered across all subdomains for 12 months, so you won't be asked again on every page. You can change your mind at any time by clearing cookies for theadminstack.com in your browser.

2. How We Use Information

  • To operate, maintain, and secure the Site and its tools (rate limiting, abuse prevention, debugging).
  • To respond to messages sent through the contact form.
  • To understand aggregate usage (which tools are popular) so we can prioritize what to build next.
  • To show advertising, where you have consented to it (see Section 5).

We do not sell your personal information, and we do not use it to make decisions that have a legal or similarly significant effect on you.

3. Analytics

We use Cloudflare Web Analytics to understand aggregate traffic (page views, referrers, countries, and browser types). Cloudflare's measurement script is loaded from static.cloudflareinsights.com and reports to cloudflareinsights.com. It is a privacy-first analytics service: it does not use cookies, does not fingerprint your device, and does not track you across other websites. Because our Site is served through Cloudflare's network, Cloudflare also processes standard request data (such as your IP address) as our infrastructure provider — see Cloudflare's privacy policy for details.

4. Tool Inputs & Third-Party Lookups

Many of our tools work by querying public data sources about the value you enter (a domain, IP address, email header, or DNS record). When you run such a lookup, the value you submit is forwarded to the relevant third-party service — sometimes directly from your browser, sometimes via our server. Depending on the tool, these sources include:

  • Public DNS resolvers — DNS-over-HTTPS queries to Cloudflare (cloudflare-dns.com) and Google (dns.google), and, for the DNS Propagation checker, direct queries from our server to public resolvers around the world.
  • Certificate Transparency logscrt.sh and Cert Spotter, for certificate and subdomain lookups.
  • Domain/IP registries — RDAP endpoints operated by IANA, ARIN, Verisign, Nominet, DENIC, and other registries.
  • Recon data providers — HackerTarget and AlienVault OTX, for passive-DNS and host lookups.
  • Map tiles — the DNS Propagation world map loads tiles from CARTO's CDN.

These services receive only the query itself (plus standard request metadata such as an IP address) and are governed by their own privacy policies. Don't submit confidential values — for example, use the Token Decoder only with test or non-production tokens. The Token Decoder itself parses tokens entirely in your browser; nothing you paste is sent to our servers, and the only network request it can make is an optional signature-verification fetch of the token issuer's public keys (JWKS), made directly from your browser to that issuer.

5. Advertising & Third-Party Vendors

We plan to display ads on the Site through Google AdSense. Google and its advertising partners may use cookies, device identifiers, and similar technologies to serve ads based on your prior visits to this and other websites, and to measure ad performance.

  • Advertising cookies are only set after you click "Accept" on the cookie banner. If you click "Reject," ad scripts won't load and only strictly-necessary cookies are used (you may still see non-personalized ads in regions where that's the default, or no ads at all, depending on how ad serving is configured at the time).
  • Google's use of advertising cookies enables it and its partners to serve ads based on your visits to this site and/or other sites on the Internet. You can opt out of personalized advertising by visiting Google Ads Settings.
  • You can also opt out of many third-party vendors' use of cookies for personalized advertising via aboutads.info (US) or youronlinechoices.eu (EU).
  • Most browsers also let you block or delete cookies entirely in their settings, though this may affect site functionality.

We will update this section with the specific vendors in use and links to their own privacy policies once advertising goes live.

6. Data Sharing

We share data only with:

  • Service providers who host the Site, deliver it through a CDN, and send email on our behalf (e.g., our hosting provider, Cloudflare, and SMTP/email delivery service), bound by confidentiality obligations.
  • Third-party lookup services described in Section 4, which receive only the query values you choose to submit to a tool.
  • Advertising partners (Google AdSense and its network), but only for users who have consented to advertising cookies, and only to the extent necessary to serve and measure ads.
  • Law enforcement or legal process, if required to comply with a valid legal request.

We do not otherwise sell, rent, or trade your personal information.

7. Your Rights

If you're in the EU/EEA or UK (GDPR)

Our legal basis for strictly-necessary cookies and cookieless analytics is legitimate interest in operating and improving the Site; for advertising cookies, it's your consent, which you can withdraw at any time. You have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Contact us using the details in Section 10 to exercise these rights.

If you're in California (CCPA/CPRA)

You have the right to know what personal information we collect, to request deletion of it, and to opt out of the "sale" or "sharing" of personal information — which can include the use of advertising cookies for cross-context behavioral advertising. Rejecting the cookie banner opts you out of this. We do not sell personal information for money.

Everyone

Regardless of location, you can always reject advertising cookies via the banner, clear cookies and site data in your browser, or contact us with questions or requests.

8. Data Retention

Contact form messages are retained as long as needed to address your inquiry and for a reasonable period afterward for our records, then deleted or anonymized. Server logs are retained for a limited period for security and debugging purposes. Cookie-consent choices are retained for 12 months, after which you'll be asked again. Data saved by tools in your browser's local storage stays on your device until you clear it.

9. Children's Privacy

The Site is intended for IT, security, and compliance professionals and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.

10. Contact

Questions about this policy or your data? Email [email protected] or use the contact form.

11. Changes to This Policy

We'll update the "Last updated" date above whenever this policy changes, and post material changes (such as advertising going live) prominently on the Site. Continued use of the Site after changes take effect means you accept the updated policy.