Kopimore is designed from the ground up to work within US privacy law. We help you identify and reach potential customers while respecting every consumer's rights.
Every step of how visitor identity data is collected, matched, and delivered — and where your obligations apply.
A user visits your website. Our pixel fires and collects standard browser signals — no personal data yet.
Signals are matched against our licensed first-party data graph of opted-in US consumers.
Matched records — name, email, phone — are delivered to your dashboard or CRM in real time.
You contact the lead using your own platform. CAN-SPAM and TCPA obligations now rest with you as the sender.
When you use Kopimore to identify website visitors, you become a "business" under CCPA. You must update your Privacy Policy to disclose your use of visitor identification technology, provide a clear "Do Not Sell or Share My Personal Information" link, and honor any consumer requests for access or deletion that are forwarded to you. We make this easy — our platform includes template disclosures and a forwarding mechanism for consumer requests.
Kopimore identifies leads — it does not create TCPA consent on your behalf. Phone numbers delivered through our platform should be used for manual outreach only unless you have independently obtained proper written consent. We strongly recommend consulting legal counsel before running any automated SMS or robocall campaigns.
Kopimore's identity resolution service is built exclusively on US-sourced data and is intended for identifying US-based website visitors. Our data graph does not include EU/EEA resident records. If your website receives significant EU traffic, you should implement geo-based pixel suppression for EU visitors.
All data is encrypted with AES-256 at rest and transmitted over TLS 1.3. We never store raw match signals longer than necessary for delivery.
Lead records in your dashboard are retained for 12 months by default. You can adjust this in Settings, or request full deletion of your account data at any time.
The leads we identify for you belong to your account. We do not resell, share, or repurpose your identified visitor data to any third party.
We maintain an up-to-date list of sub-processors (cloud providers, data infrastructure). Enterprise clients receive a full sub-processor addendum.
Enterprise and Pro clients can request a signed DPA at any time. Our standard DPA is based on the IAPP Model Data Processing Agreement.
All access to identified lead records is logged with timestamp, user, and IP address. Audit logs are available to account admins in Settings → Security.
If you're a consumer and believe your information may be in our data graph, you have clear rights — and we make them easy to exercise.
You can request a summary of personal information we hold about you, including the categories of data and the sources it was collected from.
You can request deletion of your personal information from our data graph. We will process your request within 15 business days and confirm deletion in writing.
You can opt out of the sale or sharing of your personal information at any time using the form below. Your opt-out is permanent and honored globally across our platform.
Exercising any privacy right will never affect your ability to use products or services. We do not discriminate against consumers who exercise their rights.
Enter your email address below and we will remove you from our data graph and suppress your information from all future identity matches. Your request will be processed within 15 business days.
You may also email us directly at privacy@kopimore.com with the subject line "Opt-Out Request".
Legal Disclaimer: The information on this page is provided for general informational purposes and does not constitute legal advice. Privacy law is complex and jurisdiction-specific. We strongly recommend consulting qualified legal counsel before deploying any outreach campaign using identified visitor data. Kopimore's compliance posture reflects our own practices and does not guarantee that your specific use case will be legally compliant in every jurisdiction.