2bigthink
How it works Pricing Get your free snapshot

2bigthink Privacy Policy

Effective date: September 14, 2026
Last updated: September 14, 2026

2bigthink is a privacy-compliance service operated by 1bigthink LLC, a Delaware limited liability company ("2bigthink," "we," "us," or "our"). This Privacy Policy explains what personal information we collect through 2bigthink.com (and any successor domain that links to this policy), why we collect it, how we use and share it, how long we keep it, and the rights that visitors, prospects, and subscribers have under United States federal and state law, Canadian law, the EU General Data Protection Regulation, and the UK General Data Protection Regulation.

This policy is consistent with, and supplements for 2bigthink-specific processing, the parent 1bigthink Privacy Notice. Where the two overlap, this policy governs personal information collected through 2bigthink.

This policy applies to our public marketing website, the free Cookie and Tracking Risk Snapshot intake, the paid Privacy Compliance Subscription, and any email or account interactions related to those services. It does not apply to third-party websites we link to or to services operated by our clients.

If you are located in the European Economic Area, the United Kingdom, or Switzerland, please also review the Notice for EEA, UK, and Swiss users. If you are located in Canada, please also review the Notice for Canadian users. If you are a resident of a U.S. state that grants consumer privacy rights, please review the Notice for U.S. state residents.

1. Who we are and how to reach us

Controller / business: 1bigthink LLC, a Delaware limited liability company, doing business as 2bigthink

Privacy contact: [email protected] (2bigthink service) or [email protected] (parent)

General contact: [email protected]

Contact form: 1bigthink.com/contact

For GDPR and UK GDPR purposes, 1bigthink LLC is the controller of the personal data described in this policy. We have not designated a Data Protection Officer and are not required to do so under Article 37 GDPR, but the privacy contacts above are the intake points for all privacy inquiries, data-subject requests, and complaints. Where an EU representative or UK representative is required under Article 27 GDPR, we will identify one in this policy before commencing regular monitoring of, or offering paid services to, individuals in those regions; until then we do not knowingly offer services to individuals as consumers in the EEA or UK, and our processing of business-contact data from those regions is on the legal basis described in Section 4.

2. Information we collect

We collect personal information in three ways: information you provide directly, information we collect automatically when you use the website, and information we obtain from publicly available sources to build a regulatory profile of the company you represent.

2.1 Information you provide directly

Snapshot and subscription intake form. When you request a free Cookie and Tracking Risk Snapshot or begin a subscription signup, you submit:

  • Your name
  • Your job title
  • Your business email address
  • Your company URL

We check that the company URL matches the domain of your business email so the request is a real business signal. We use the email to verify you and to deliver the report.

Additional questionnaire. To generate the full regulatory profile, we ask you to answer questions about your company's expansion plans, whether you process sensitive data, and how you use AI.

Account information. If you become a subscriber, we collect the credentials and profile information needed to operate your account (for example, password hash held by our authentication provider, multi-factor-authentication settings, and communication preferences).

Payment information. Subscription payments are processed by our payment processor, Stripe, Inc. 2bigthink does not receive or store your full card number, CVV, or bank-account credentials. We receive limited billing metadata from Stripe (for example, name, billing email, country, last four digits of the card, and transaction status).

Documents and inputs you submit for processing. If you upload a Data Processing Agreement (DPA), a URL, or other material for evaluation, we process the contents of that material to produce the requested output.

Correspondence. If you email us, respond to a survey, or contact us through a form, we collect the message, your contact details, and any files you attach.

Data Subject Access Requests (DSARs) directed to 2bigthink. If you exercise a privacy right by using our DSAR intake form or by emailing [email protected], we collect the identifiers you provide (name, email, and any details needed to verify your identity and locate your data) and retain the request and our response as required by law.

2.2 Information collected automatically

Server and security logs. Our hosting provider (Cloudflare Pages, with Cloudflare's edge network) automatically logs information about each request, including IP address, user-agent string, referrer, timestamp, and the resource requested. We use these logs to operate, secure, and troubleshoot the site.

Cookies and similar technologies. We use a small number of cookies and browser-storage keys, as described in Section 6. Analytics cookies load only if you affirmatively accept them through our consent banner.

Analytics. If you accept analytics cookies, Google Analytics 4 (measurement ID G-MHYW1276RD) is loaded. Google Analytics collects information about your interaction with the site, including pages viewed, session duration, approximate location derived from IP address (IP addresses are truncated / anonymized by Google Analytics 4 before storage), device and browser characteristics, and a randomly generated client identifier stored in first-party cookies.

Web fonts. Our pages request typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Google may receive your IP address and user-agent as part of this request. No cookies are set by Google Fonts.

Do Not Track and Global Privacy Control. We honor the Global Privacy Control (GPC) signal as a valid opt-out of "sale" and "sharing" for cross-context behavioral advertising for U.S. state law purposes and as a request to reject non-essential cookies. Because we do not sell personal information and do not use cross-context behavioral advertising, the practical effect of GPC on our site is that non-essential cookies remain off. We do not currently respond to legacy "Do Not Track" browser headers.

2.3 Information from public and third-party sources

To produce the Regulatory Relevance Analysis, we read publicly available information about the company you represent, including your public website, your company's LinkedIn presence, and other publicly available sources (for example, corporate registries, SEC EDGAR filings, and public business-information databases). We use this to build a jurisdictional footprint (industry, offering, customer base, offices, workforce, jurisdictions of operation, and likely regulatory exposure). We do not collect personal information about individual employees from these sources beyond what is reasonably necessary to identify the company's operational geography.

3. How we use personal information

We use personal information for the following purposes:

  • To provide the free Cookie and Tracking Risk Snapshot and deliver the resulting PDF report to you.
  • To provide the Privacy Compliance Subscription, including the Regulatory Relevance Analysis, Cookie Compliance Monitoring, Privacy Policy Compliance, DPA Evaluator, and Bulletins and Updates features.
  • To create and administer subscriber accounts, including authentication, multi-factor authentication, password recovery, and account settings.
  • To take payment through Stripe and to send invoices, receipts, and renewal notices.
  • To communicate with you about your account, service changes, security alerts, and support requests.
  • To send you optional marketing communications about 2bigthink and 1bigthink services, from which you may unsubscribe at any time using the link in the email or by writing to [email protected].
  • To operate, secure, monitor, and improve the website and services, including detecting and preventing fraud, abuse, and unauthorized access.
  • To generate aggregated, de-identified analytics that we may use and share without restriction.
  • To comply with applicable law, respond to lawful requests from public authorities, enforce our Terms, and defend legal claims.
  • To evaluate potential business transactions such as a merger, acquisition, financing, or sale of assets.

We do not use your personal information, and we do not use inputs you submit for processing (for example, uploaded DPAs), to train third-party general-purpose AI models. We do use large language models operated by our AI service providers to generate the reports you request, and those providers are contractually restricted from using your inputs to train their public models.

4. Legal bases for processing (EEA / UK / Switzerland)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

Processing activity Legal basis
Delivering the Snapshot report or subscription features to a business contact who requested them Performance of a contract (Article 6(1)(b)) or, where you are not the counterparty, our legitimate interests in providing the requested service to the business you represent (Article 6(1)(f))
Billing, invoicing, and financial record-keeping Performance of a contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c))
Site operation, security, fraud prevention, and troubleshooting Legitimate interests in operating a secure service (Article 6(1)(f))
Analytics cookies and any other non-essential cookies Your consent (Article 6(1)(a)), given through our consent banner
Marketing emails to a business contact Legitimate interests (Article 6(1)(f)) for B2B soft opt-in where permitted, otherwise your consent (Article 6(1)(a))
Responding to data-subject requests and legal claims Legal obligation (Article 6(1)(c)) and legitimate interests (Article 6(1)(f))
Reading public sources to build a company's regulatory footprint Legitimate interests (Article 6(1)(f)) in providing an accurate compliance service; the information used is already public and relates primarily to the company rather than to individuals

Where we rely on legitimate interests, we have carried out a balancing test that considers the limited nature of the personal data processed, the business context in which it is submitted, and the reasonable expectations of the individuals involved. You have the right to object to that processing as described in Section 8.

We do not process special-category personal data (as defined by Article 9 GDPR) as part of the Snapshot or subscription features. Please do not submit special-category data to us through free-text fields or file uploads unless it is strictly necessary. If the DPA or other document you upload for processing incidentally contains special-category data, we process it only to produce your requested output, in reliance on your explicit consent (Article 9(2)(a)) evidenced by your voluntary upload.

5. How we share personal information

We share personal information only in the ways described below and never sell it for monetary consideration.

Service providers acting on our behalf. We use vendors that provide hosting, edge networking, email delivery, authentication, payment processing, analytics, AI-model inference, customer support, and monitoring. Each vendor is bound by a written agreement that limits their processing to the purposes we authorize and requires appropriate security. Our current core categories include:

  • Hosting and edge network: Cloudflare, Inc. (Cloudflare Pages)
  • Payment processing: Stripe, Inc.
  • Email delivery for outbound service and marketing mail: Amazon Web Services (Amazon SES) and Microsoft (Microsoft 365 / Outlook for individual staff mail)
  • Analytics: Google LLC (Google Analytics 4)
  • Web fonts: Google LLC (Google Fonts)
  • AI model providers used to generate reports on your behalf

Affiliates. We share information with our parent, 1bigthink LLC, and may share it with future affiliates that agree to comply with terms consistent with this policy. This includes routing upgrade or consulting inquiries generated from the Snapshot to 1bigthink's professional services.

Professional advisers. We may share information with lawyers, auditors, accountants, and insurers when reasonably necessary.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred to the counterparty or successor entity subject to standard confidentiality protections.

Legal and safety disclosures. We may disclose personal information when we believe in good faith that disclosure is required by law, is necessary to comply with a lawful request from a public authority, is needed to enforce our Terms, or is necessary to protect the rights, property, or safety of 2bigthink, our clients, our users, or others.

With your direction. We share information when you ask us to (for example, when you direct us to send a report to a specific colleague).

We do not sell personal information for monetary consideration and we do not share personal information for cross-context behavioral advertising, as those terms are defined by U.S. state privacy laws.

6. Cookies and similar technologies

We keep the site's cookie footprint deliberately small. On first visit we display a consent banner that lets you accept or reject non-essential cookies.

Strictly necessary cookies and storage. We use a first-party browser-storage key (2bt_cookie_consent) to remember your cookie choice so the banner does not reappear on every page load. This is essential to honor your choice and does not require consent under GDPR, UK GDPR, or the EU e-Privacy Directive.

Analytics cookies (opt-in). If you click Accept, Google Analytics 4 loads and sets first-party cookies (typically _ga and _ga_<container>) to distinguish visitors and sessions and to measure aggregate site usage. Analytics cookies do not load if you click Reject or if you ignore the banner.

Third-party subresources without cookies. Our pages fetch typefaces from Google Fonts. This request exposes your IP address and user-agent to Google but does not set cookies.

You can change your cookie choice at any time by clicking the Cookie settings control that appears on the site or by clearing site data in your browser. You can also block or delete cookies directly through your browser settings; the site will continue to function without analytics.

7. International data transfers

We are based in the United States and our service providers are located in the United States, the European Union, the United Kingdom, and other countries. When we transfer personal information out of the EEA, the UK, or Switzerland, we rely on one of the following transfer mechanisms:

  • The European Commission's Standard Contractual Clauses (2021/914) and, for UK transfers, the UK International Data Transfer Addendum or the UK IDTA, together with additional safeguards where appropriate.
  • The EU-U.S. Data Privacy Framework, UK Extension to the DPF, and Swiss-U.S. DPF, where our recipient is self-certified.
  • Your explicit consent for a specific transfer, or another derogation under Article 49 GDPR, where appropriate.

We have carried out transfer impact assessments for our core vendors and apply supplementary measures (for example, encryption in transit and at rest, and vendor commitments to challenge disproportionate government-access requests) where warranted. You may request a summary of the safeguards that apply to a specific transfer by writing to [email protected].

8. Your rights

Depending on where you live, you have some or all of the following rights over your personal information:

  • Access, a copy of the personal information we hold about you.
  • Correction, correction of inaccurate or incomplete personal information.
  • Deletion, deletion of your personal information, subject to legal exceptions.
  • Portability, a copy of certain information in a structured, commonly used, machine-readable format, and where technically feasible, transmission to another controller.
  • Restriction, restriction of certain processing.
  • Objection, objection to processing based on legitimate interests, including direct marketing.
  • Withdraw consent, withdrawal of any consent you previously gave (including cookie consent), without affecting the lawfulness of prior processing.
  • Opt out of "sale" or "sharing", opt out of any activity that qualifies as a sale or sharing of personal information under U.S. state law. We do not sell or share personal information as those terms are defined, but you may still submit a request.
  • Opt out of profiling / targeted advertising / significant automated decisions, opt out of processing that produces legal or similarly significant effects about you. We do not carry out automated decision-making that produces legal or similarly significant effects on individuals.
  • Limit use of sensitive personal information, limit our use of sensitive personal information to what is necessary to provide the service. We do not solicit sensitive personal information; if you provide it in a free-text or upload field, it is used solely to produce the report you requested.
  • Non-discrimination, you have the right not to receive discriminatory treatment for exercising any of these rights.
  • Appeal, if we deny a request, you may appeal our decision by writing to [email protected] with "Privacy Appeal" in the subject line. We will respond within the period required by applicable law.
  • Complaint to a regulator, you may lodge a complaint with your local data-protection authority (for EEA users), the UK Information Commissioner's Office (for UK users), the Office of the Privacy Commissioner of Canada (for Canadian users), or the attorney general or other regulator of your state (for U.S. state residents).

How to exercise your rights. Email [email protected] (or [email protected]) with the request, your identity information, and the state, province, or country of residence relevant to the request. You may also use the 1bigthink contact form. Where required by law, we will verify your identity before responding. You may designate an authorized agent to submit a request on your behalf; we will require reasonable proof of authorization and, in most cases, direct confirmation from you. We respond within the timeframe required by the law that applies to your request (typically 45 days for U.S. state requests, extendable by 45 days when reasonably necessary; 30 days for Canadian PIPEDA requests; and one month for EEA and UK GDPR requests, extendable by two months for complex requests).

9. Data retention

We keep personal information only as long as necessary for the purposes described in this policy, or as long as required by law:

  • Snapshot intake and generated report: 24 months from the date of the request, then deleted or de-identified.
  • Subscriber account and generated deliverables: for the life of the account and for 12 months after account closure, then deleted or de-identified. Billing records are retained for the period required by tax, accounting, and anti-money-laundering law (typically 7 years in the United States).
  • DPA and other files you upload for evaluation: processed for the duration needed to generate the requested output and deleted from active systems within 90 days after delivery, subject to short-term backup retention.
  • Server and security logs: typically 90 days, longer where needed for a security investigation.
  • Cookie-consent record: stored in your browser until you clear it.
  • DSAR intake and correspondence: for the period required by law and by our record-keeping obligations, typically 3 years.

We may retain aggregated or de-identified information indefinitely.

10. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including transport encryption (TLS 1.2 or higher), encryption at rest for stored data, multi-factor authentication for administrative access, role-based access controls, logging and monitoring, and vendor due diligence. No system is completely secure; if you believe your account has been compromised or you have found a vulnerability, please write to [email protected] or [email protected].

11. Children

The 2bigthink service is a business-to-business offering. We do not knowingly collect personal information from children under 16 (or under the equivalent minimum age in the individual's jurisdiction, including 13 in the United Kingdom under the UK Data (Use and Access) Act 2025). If you believe a child has provided personal information to us, please contact [email protected] or [email protected] and we will delete it.

12. Automated decision-making

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Reports produced by our AI features are drafts intended for use by trained privacy professionals and by you; they are not final legal determinations.

13. Changes to this policy

We may update this policy from time to time. When we do, we will change the "Last updated" date at the top and, where the change is material, we will notify subscribers by email or through the account before the change takes effect. Continued use of the service after a change takes effect indicates acceptance of the updated policy.


Notice for U.S. state residents

This notice supplements the policy above for residents of U.S. states that grant consumer privacy rights, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Delaware (DPDPA), Iowa (ICDPA), Indiana (INCDPA), Kentucky (KCDPA), Maryland (MODPA), Minnesota (MCDPA), Montana (MCDPA), Nebraska (NDPA), New Hampshire (NHDPL), New Jersey (NJDPA), Oregon (OCPA), Rhode Island (RIDTPPA), Tennessee (TIPA), Texas (TDPSA), Florida (FDBR), and Oklahoma (OCDPA), and to any additional U.S. state comprehensive privacy law that comes into force during the term of this policy.

Categories of personal information collected in the last 12 months. Identifiers (name, email, IP address, client identifier from analytics), professional information (job title, employer, company domain, business address), commercial information (subscription plan, transaction history), internet or other electronic network activity information (pages viewed, session characteristics), inferences drawn from the above (for example, jurisdictional footprint of the represented company), and audio, electronic, visual, or similar information (files you upload, such as DPAs).

Sources. Directly from you, automatically from your device, and from publicly available sources about the company you represent.

Business or commercial purposes. As described in Section 3 above.

Categories of recipients. As described in Section 5 above.

Sensitive personal information. We do not solicit sensitive personal information. If you voluntarily include it in a free-text field or file upload, we use it only to provide the service you requested. You have the right to limit our use of sensitive personal information for other purposes; we do not use it for any other purposes.

Sale, sharing, and targeted advertising. We do not sell personal information, we do not share personal information for cross-context behavioral advertising, and we do not process personal information for targeted advertising. We do not knowingly sell or share the personal information of consumers under 16.

Global Privacy Control. We treat a valid GPC signal received from your browser as an opt-out of any sale or sharing that might otherwise occur and as a request to reject non-essential cookies. Because we do not sell or share, the observable effect is that analytics cookies remain off.

Profiling and automated decisions. We do not carry out profiling that produces legal or similarly significant effects.

Financial incentives. We do not offer financial incentives in exchange for personal information.

Right to appeal. If we deny your request, you have the right to appeal as described in Section 8. In Virginia, if the appeal is denied you may also submit a complaint to the Virginia Attorney General; similar rights apply in other states.

Shine the Light (California only). California Civil Code Section 1798.83 permits California residents to request certain information about our disclosure of personal information to third parties for their direct-marketing purposes. We do not disclose personal information to third parties for their own direct-marketing purposes.

Notice at collection. This policy serves as our notice at collection for California residents under CCPA/CPRA. The categories collected, purposes, retention periods, and rights are all set out above.


Notice for EEA, UK, and Swiss users

If you are located in the EEA, the UK, or Switzerland, you have the rights and legal-basis protections summarized in Sections 4 and 8. In addition:

  • Your data-protection authority is the supervisory authority of your country of residence (for the UK, the Information Commissioner's Office at ico.org.uk). You may lodge a complaint at any time.
  • Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Where we rely on legitimate interests, you may object at any time on grounds relating to your particular situation. For direct marketing, you may object at any time without needing to give reasons.
  • For international transfers, we use the mechanisms described in Section 7. You may request a summary of the safeguards that apply to a specific transfer.

If we appoint an Article 27 GDPR representative in the EU or UK, we will update this policy with the representative's name and contact details.


Notice for Canadian users

If you are located in Canada, we process your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the substantially similar provincial laws of Alberta (PIPA), British Columbia (PIPA), and Quebec (Law 25). We will update this policy as Canada's federal Consumer Privacy Protection Act (CPPA) comes into force.

  • Consent. We rely on your express or implied consent to collect, use, and disclose your personal information for the purposes identified in this policy. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by writing to [email protected]. Withdrawing consent may prevent us from providing certain services.
  • Access and correction. You may request access to your personal information and correction of inaccuracies. We will respond within 30 days.
  • Automated decision systems (Quebec Law 25). We do not use personal information exclusively to make an automated decision that produces legal or similarly significant effects. Reports produced by our AI features are drafts for human review.
  • Cross-border transfers (Quebec Law 25). Personal information may be processed outside your province, including in the United States. Before transferring personal information outside Quebec, we assess whether the receiving jurisdiction affords adequate protection and enter into contractual protections where appropriate.
  • Privacy Officer. Our Privacy Officer for Canadian purposes is reachable at [email protected].
  • Complaints. You may lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca or with your provincial commissioner.
2bigthink
How it works Pricing 1bigthink Privacy Policy Terms & Conditions

© 2026 2bigthink. All rights reserved.