
Squarespace and GDPR
CertReports found no public GDPR evidence for Squarespace as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 10 Nov 2016
- Expires or valid through
- 24 Aug 2027
- Scope
- Squarespace provides online tools that our customers use to design and host their websites, register domains, send marketing emails, create and publish marketing materials, manage their online businesses, and conduct online transactions (including appointment scheduling). The purposes for our data collection vary by product, but include without limitation account registration and support; providing various web design, web hosting, domain, email marketing, and eCommerce support services; data analytics to improve products and services; enabling online transactions; and sustaining marketing relationships. Squarespace uses certain trusted third parties to help us provide, improve, promote and protect our services. For example, we use third parties to help us provide customer support or assist with data storage. These third parties may access, process or store data we collect to perform tasks only for the purposes we've authorized, and we require them to provide at least the same level of protection described in our privacy policies. We also maintain human resources data, for the purpose of administering and carrying out our employment or personnel relationships with our employees.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Squarespace, Inc.: Active: UK Extension Certification, EU-US Certification, SW-US Certification | Live pagesha256 627596c6e6 |
- Kind
- listing
- Issued or listed
- 24 Jan 2019
- Expires or valid through
- 9 Dec 2026
- Scope
- The A-ISAC collects information about a person when they request information regarding our services, inquire about membership, or sign up to attend an A-ISAC event. The A-ISAC only collects and uses data as described in our Privacy Policy Statement. Except as noted in our Privacy Policy, personal data collected by the A-ISAC via our website or through our services is not shared with third parties without a person's consent. The personal data we may collect from a person might include, by way of example: Email address; Domain name and Internet Protocol (IP) address; Contact information (including, name, phone number(s), business, address, zip code, and country); User-specific and aggregate information on areas of the Site accessed and the Services used; and Other information you volunteer to the site or via other means of communication, such as responses, registrations, surveys, reviews, comments, confirmations, emails, messages, telephone calls, written correspondence or other electronic submissions and communications sent by you to the Site or through a registration or contact initiated by you. Our external facing public website is managed by a third-party provider which is Data Privacy Framework compliant. The A-ISAC does not collect cookies from our external facing web site hosting service. We use cookies on our external, private-access portals to improving the browser experience and authentication. The A-ISAC will retain personal data for the period necessary to fulfill the purposes outlined in our Privacy Policy unless a longer retention period is required or permitted by law. Agents and Third-Party Service Providers. To provide the A-ISAC’s Services , we may sometimes use other businesses to perform certain specialized services such as bulk emailing, event planning or other technology services. In such instances, we may provide some or all of a member's personal data to those businesses, but they are not permitted to retain or use your information for any other purpose. Members will utilize 3rd party services for information sharing and communications.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | A-ISAC: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 e4da52d883 |
- Kind
- listing
- Scope
- Ignite collects online identifiers when an end consumer accesses an offer by one of our clients. Ignite also collects personal data (name, email address) from end users that reach out to us for support, or that are potential clients or employees. For more details on why we collect data, including personal data, please visit our privacy policies.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Ignite: Inactive | Live pagesha256 19a12195a9 |
- Kind
- listing
- Issued or listed
- 30 Mar 2017
- Scope
- Pinsight® is a leadership simulation assessment operating on a cloud-based platform. We do not sell, trade, share, or rent personal information to third parties to use for their own marketing purposes. We use user contact information to deliver our services. For example, we use usernames and passwords to authenticate users when logging in and to identify as a user on our system, we use contact information to provide customer support, we use time zone information when scheduling assessments, we use email addresses to deliver quiz results and newsletters and depending on notifications preferences, we send administrative notifications. We also use information to inform of new features or products. Marketing communications can be controlled via the “Unsubscribe” link in an email and user notifications can be adjusted by using notification preferences in user profiles. We use the data that we collect when a user participates in an assessment or uses the Leader Habit app to create a Pinsight report. When a user participates in an assessment, completes a learning efficiency test, a personality questionnaire, and a live simulation. The results from these assessments are all used to create a Pinsight report. If a user uses the Leader Habit app, we track when information is entered and use this information to estimate improvement. We may create anonymous data records by excluding information (such as a user’s name) that makes the data personally identifiable to the user. We use this anonymous data to analyze request and usage patterns to enhance the content of our services and improve site navigation. We may also use anonymous data for research and development purposes, such as scientific articles and presentations, assessor training, and to enhance our services. We may use information to comply with legal obligations, as part of our general business operations, and for other business administration purposes.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Pinsight: Inactive | Live pagesha256 7cfeaa4d64 |
- Kind
- listing
- Issued or listed
- 6 Jan 2017
- Scope
- Cantel Medical Corp. and its United States incorporated subsidiaries (collectively, “Cantel”) transact business with companies in the European Union. Though Cantel engages primarily in business-to-business transactions, personal information may be transmitted from the European Union to the United States as a result of such interactions. Additionally, Cantel maintains an internet presence and does not restrict access based on location. Accordingly, Cantel may receive emails and other electronic communications in the United States from individuals located in the European Union. Moreover, Cantel may indirectly collect an individual's personal information through the use of network, internet, and email servers that are physically located in the United States or incidentally from other sources in the ordinary course of business. With respect to such information, Cantel will only use and retain personal information to the extent appropriate to meet the purposes for which it was provided and to advance the legitimate business purposes of Cantel (including, but not limited to, marketing, server maintenance, and security). Lastly, Cantel Medical Corp. has subsidiaries located in the European Union. With respect to the employees of such subsidiaries, Cantel may process personal information for human resources functions, management purposes, training and education programs, compliance with legal and regulatory requirements, and fulfillment of corporate security and compliance functions. Cantel may engage third party agents for the processing of such personal information.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Cantel Medical Corp.: Inactive | Live pagesha256 92de077238 |
- Kind
- listing
- Issued or listed
- 22 Oct 2018
- Scope
- Providing information about our products, services and events Providing products, services and support to our customers Communicating with business partners, vendors, agents and contractors about business matters Analysis of information in order to improve business practices, products and services Conducting related tasks for legitimate business purposes Other purposes disclosed at the time of collection Compliance with legal requirements
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Raxar Technology Corporation: Inactive | Live pagesha256 eb1ec515c9 |
- Kind
- listing
- Issued or listed
- 5 Aug 2019
- Scope
- Our organization collects the name, address, email address, phone number, login name, and password of individual clients to provide professional career services directly to the client under an agreement with the client, and to enable the client to access our online services, such as applying for career opportunities and contacting potential employers. Our organization also collects the business contact information of the contact person at our corporate clients, including name, business email address, position at the company, business phone number, and business address, in order to provide professional services to the corporate client. Such services include introducing corporate clients to job candidates and providing career counseling to employee's of corporate clients.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Volta Talent Strategies, LLC: Inactive | Live pagesha256 4c92e42d22 |
- Kind
- listing
- Issued or listed
- 16 Dec 2019
- Scope
- The iGo Figure Software manages fitness and wellness clubs in the EU and around the world. Go Figure is a Processor that processes data on the instruction of a Controller (our customers). One function of the software is to set employee schedules and track employee hours and commissions earned, which an iGo Figure Software user can print locally. No other HR function is performed. Go Figure does not disclose the information to third parties.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | iGo Figure Software: Inactive | Live pagesha256 6fe2bfc559 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Squarespace GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the E-commerce category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No E-commerce vendor has GDPR evidence in the index yet.