How Visual Visitor Handles Privacy and Data Compliance

How Visual Visitor Handles Privacy and Data Compliance

Privacy and data compliance questions come up often, especially when your legal or procurement team is doing due diligence on a new vendor. We would rather give you a real answer than a one-line assurance. Below is the full picture of how we manage data privacy and compliance, in enough detail that you can forward it directly to your team or attach it to your own review.

The short version: we handle privacy compliance by partnering with Superset, a compliance platform built specifically for companies that handle consumer data at scale. Here's what that covers.

Why This Question Matters for Our Data

Our WebID +Person and WebID +Employee identification engines identify anonymous website visitors at the person level, often before anyone fills out a form, surfacing name, email, company, and dozens of additional attributes. Our Licensed Custom Audiences, used in Person-Level Advertising, also pull in third-party behavioral, demographic, and interest data so you can reach in-market individuals who haven't visited your site yet.

That combination, first-party visitor identification plus licensed third-party audience data, is exactly what a growing list of state privacy laws was written to regulate. If your team wants more background before your own review, we've published an Information Security FAQ covering our encryption and data-handling practices, and a breakdown of how we respond to client CCPA questions about visitor identification. What follows is how we put that guidance into practice on our end, day to day.

Our Compliance Partner: Superset


Info
Superset makes legal compliance as simple and hands-off as possible for businesses of all sizes.

We wanted a partner built for exactly this problem, not a generic legal tool retrofitted for it. Superset is a New York-based compliance platform, founded and led by Zane Witherspoon, CIPP/US, a Certified Information Privacy Professional. Its mission statement is "to make legal compliance as simple and hands-off as possible for businesses of all sizes". It is built around independently validating data privacy practices for data brokers and similar businesses.

Superset connects to our existing systems and adds a compliance layer on top of them rather than replacing anything. Here's what that covers, point by point, in case your team needs to check off specific items.

State Data Broker Registrations

A growing number of states require companies that collect and transfer consumer data to register annually or face steep fines. Four states currently require this: California, Texas, Vermont, and Oregon. California alone has issued fines totaling nearly $70,000 to data brokers for registration failures, and the California Privacy Protection Agency (CPPA) continues to bring new enforcement actions on a rolling basis, with recent individual fines ranging from roughly $45,000 to over $62,000.

Connecticut just joined this group. On May 27, 2026, it became the 5th state to require data broker registration, with registration obligations phasing in starting January 1, 2027.

Superset files directly with the CPPA on our behalf, with a stated turnaround of about 11 minutes for a completed filing, plus ongoing monitoring of what's been filed. Superset's own case study walks through everything that goes into a single registration, from assessing which laws apply, to filing with the CPPA, to supplying compliant privacy policy language, to confirming certification once it's done.

California's DROP System

If your team has heard about California's Delete Request and Opt-Out Platform, DROP, and is wondering whether it affects data you receive through Visual Visitor, here's the relevant detail:

  1. DROP is a state-run database where California residents can request that every registered data broker stop selling or delete their information in one place.

  2. It opened for consumer signups on January 1, 2026, with a sandbox for broker testing in April 2026 and full production for brokers going live August 1, 2026.

  3. Registered data brokers have to pull DROP requests and process them at least every 45 days. The penalty for missing that is $200 per day, per consumer, or per deletion request once the platform is in full production.

We track this shift closely because it affects the sales prospecting workflows our clients run on top of Visual Visitor data, not just our own compliance obligations. We use Superset to set up and maintain our DROP account so that 45-day cycle gets processed on schedule, without any manual tracking on our end.

How We Handle Consumer Privacy Requests

If a consumer contacts us asking what data we hold on them, or asking to have it deleted, that's legally a Data Subject Request (DSR), sometimes called a DSAR when it's specifically an access request. Most privacy laws require us to offer at least two ways to submit a request, and to respond within roughly 30-45 days, sometimes with a possible extension.

Consumers can already reach us through our Do Not Sell My Personal Information page, by calling us toll-free at (888) 586-7730, or by emailing support at visualvisitor dot com, as outlined in our Privacy Policy. Behind the scenes, we run that privacy inbox through Superset's Privacy Inbox Automation, which connects to the inbox, flags valid requests, responds to invalid ones, and pulls the information needed to process legitimate ones automatically. Superset's founder has described this feature as monitoring a privacy inbox around the clock and automating both detection and response.

One detail worth flagging for your legal team specifically: over-verifying identity can create its own liability. Requiring something like a government ID for a simple request has led to real penalties elsewhere, including a $275,000 CPPA fine against Charles Schwab for exactly that. We keep our verification steps proportionate to the request for that reason.

Data Mapping

Superset integrates with more than 6,000 business systems to map where customer data is stored, and runs automated agents that watch for new code and system changes so that map stays current. Superset markets this data mapping and inbox automation combination as "PrivacyOps 10x Faster," which is the piece that's saved us the most manual triage time.

AI Tools for Policy Review and Research

Superset also runs a set of AI agents at ai.trustsuperset.com that we lean on for spot checks between full reviews. That includes a Privacy Policy Review Agent that analyzes an uploaded privacy policy for compliance issues, and a RAG-based compliance research chatbot trained on data privacy laws. Superset also runs a separate compliance agent, at agent.trustsuperset.com, that compares documents against applicable regulations and our own internal policies, flagging anything out of compliance.

Coverage Beyond U.S. Data Broker Laws

Most of our identification products, WebID +Person and WebID +Employee, are U.S.-only, so GDPR does not directly apply to that data. WebID +Company, which does work internationally, is built to be GDPR-aligned, and this is where Superset's international coverage matters most for our clients with European traffic.

If your compliance review touches that international data, here's the relevant piece: Superset's EU Representative Agent service appoints a physical representative within an EU member state on our behalf and monitors incoming communications from EU regulators or data subjects, which GDPR requires for companies serving European users. Superset has done the same for itself, appointing its own EU representative under Article 27 of the GDPR, and its company page lists GDPR representation, privacy policy review, and DSAR email triage among the areas it automates for clients like us.

Independent Certification

Superset also runs a Data Broker Compliance Certification program, auditing a company's practices across five categories: registrations, notices, DSR handling, procedural documentation, and security, and issuing a certification badge once a business passes. It's a useful external benchmark if your team wants a third-party point of reference beyond what we've outlined here.

If Your Team Needs More

If your legal or procurement team needs anything beyond this, our Security & Privacy Compliance page and our Privacy Policy cover the rest of our data handling and contractual terms. For anything specific to your account, a security questionnaire, or documentation you need for your own review, reach out to us at support at visualvisitor dot com or (888) 586-7730 and we'll get you what you need directly.

If Your Team Needs More on Superset

Zane Witherspoon
CEO
URL:  trustsuperset.com