Skip to main content
Royalty Reporting

Privacy Policy

Last updated: May 13, 2026

1. Who we are

Royalty Reporting ("we," "us," or "our") is a product of RetailNorthstar, Inc., a Delaware corporation, operating the royalty-reporting.com website (the "Site") and the Royalty Reporting platform (the "Platform"; together with the Site, the "Service"). For purposes of EU and UK data-protection law, RetailNorthstar is the data controller for personal data collected on the Site and the data processor for personal data processed on the Platform on behalf of our customers. Our registered office address is available on written request via our privacy contact form.

2. Information we collect

Information you provide directly:

  • Name and work email address (when you request a free trial or a demo, request a template, or contact us)
  • Company name, job title, and role
  • Royalty and licensing data you upload to the Platform (licensor agreements, rate cards, sales data, advance schedules, royalty statements, audit responses)
  • Communications you send us (support requests, feedback)

Information collected automatically without storing anything on your device (no consent needed):

  • Page visited, page title, and referring source
  • Browser type, device type, and operating system
  • IP address, which Google uses to derive an approximate country or region and then discards or truncates

This is Google Analytics running in Consent Mode without cookies. It writes no identifier to your device, so it cannot recognise you across visits or build a profile, and it gives us aggregate counts only. Because nothing is stored on or read from your device, ePrivacy Article 5(3) does not require your consent for it. We are not claiming it is invisible to Google: a cookieless measurement request still reaches Google LLC and still carries your IP address and user agent.

Information collected only if you turn on the Analytics category:

  • A persistent analytics identifier stored in your browser, which links your visits together over time
  • Pages visited, time spent, scroll depth, and interaction patterns tied to that identifier
  • Session recordings and heatmaps from Microsoft Clarity (mouse movement, scrolling, clicks). Form fields are masked at the page level so typed values are not captured, and Clarity is not loaded at all unless you turn this category on.

3. Legal bases for processing (EU/UK)

For visitors and contacts in the EU, UK, or other GDPR-aligned jurisdictions, we rely on the following legal bases under GDPR Article 6:

  • Consent (Art. 6(1)(a)) — for non-essential cookies, analytics, marketing email subscriptions, and session-replay tooling. You may withdraw consent at any time.
  • Performance of a contract (Art. 6(1)(b)) — to provide the Platform under your Service Agreement, respond to demo requests, and deliver support.
  • Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the Service; to detect fraud; to maintain audit logs. Balanced against your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)) — to comply with applicable tax, accounting, audit-defense, and law-enforcement obligations.

4. How we use your information

  • To provide, operate, and improve the Royalty Reporting Service
  • To respond to free trial and demo requests and support inquiries
  • To send relevant royalty and licensing content (only if you opt in; unsubscribe anytime)
  • To count visits and see which pages get read (aggregate and cookieless); and, only if you turn on the Analytics category, to analyze usage and session recordings tied to a persistent identifier
  • To detect and prevent fraud or security issues
  • To comply with legal obligations and respond to lawful requests

5. Data sharing

We do not sell your personal information. We share information only with:

  • Service providers (sub-processors) — hosting (DigitalOcean), analytics (Google Analytics, which receives cookieless measurement requests from every visit and cookie-based analytics only with your consent; Microsoft Clarity, which is not loaded at all without your consent), and email delivery, each under contractual confidentiality and data-protection obligations and solely to operate the Service. A current list of sub-processors is available via our DPA — see DPA page.
  • Legal compliance — when required by law, regulation, valid legal process, or to defend our rights.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to equivalent protections.
  • Parent company — limited sharing with RetailNorthstar, Inc. for billing, support escalation, and security-incident response, under common data-protection standards.

6. Your royalty data and customer data

Royalty and licensing data uploaded by customers to the Platform (licensor agreements, rate cards, sales data, advance schedules, royalty calculations, statements, audit history, and any derived calculations, reports, or analytics generated from such data) belongs to the customer. We process this data only on the customer's instructions, under the terms of the applicable Service Agreement and Data Processing Addendum.

  • We do not use customer data to train AI/ML models, benchmark against other customers, or for any purpose other than delivering the Service to that customer.
  • We implement tenant isolation, role-based access controls, and engineering practices designed to prevent customer data from being accessed by other customers, including other licensees that may report to the same licensors. While we apply commercially reasonable safeguards, no multi-tenant system can guarantee zero risk of accidental exposure; our Service Agreement governs how any such incidents are handled.
  • We do not transmit customer data to third-party AI/ML services without the customer's prior written consent.

7. International data transfers

Our infrastructure is operated in the United States. If you access the Service from the EU, UK, or another jurisdiction with data-protection rules, your personal data is transferred to the United States for processing. We rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable to provide an adequate level of protection. Copies of the SCCs and our sub-processor commitments are available via our DPA.

8. Data security and breach notification

We implement commercially reasonable security measures including encryption in transit (TLS 1.2 or higher), encryption at rest, role-based access controls, multi-factor authentication for administrative access, tenant data isolation, and regular security reviews. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

In the event of a personal data breach affecting your data, we will notify affected customers without undue delay after becoming aware of the breach, consistent with our obligations under applicable law (including GDPR Art. 33 and Art. 34 where applicable). Security-research disclosures: see our security.txt.

9. Data retention

We retain personal data only as long as needed for the purposes described in this policy:

  • Free trial, demo and contact submissions — up to 24 months from last activity, then deleted or anonymized.
  • Marketing contacts — until you unsubscribe; we honor unsubscribe within 10 business days.
  • Customer Platform data — for the duration of your subscription; upon termination you have 30 days to export, after which we delete or anonymize the data, except where retention is required by law (e.g., tax records) or for audit-defense purposes specified in your Service Agreement.
  • Analytics data — Google Analytics retention is set to 14 months; Microsoft Clarity retention follows Microsoft's default (currently 13 months).
  • Server and security logs — up to 12 months for fraud, abuse, and incident-response purposes.

10. Cookies and tracking

We sort everything this website stores on, or reads from, your device into three categories. The consent bar lets you decide them separately, and you can change your mind at any time — see "Changing or withdrawing your choice" below.

Essential — always on, cannot be switched off. Each item here is either strictly necessary or stores nothing on your device, so ePrivacy Article 5(3) does not require consent for it:

  • rn_consent — a first-party cookie, 182 days, recording the choice you made on the consent bar. Storing your decision is what stops us asking again on every page. It holds only the category flags: no identifier, no profile, and it is never sent anywhere.
  • Theme preference — whether you chose the light or dark version of the site, kept in your browser's localStorage.
  • Security and anti-abuse — including the challenge on our free trial, contact, and download forms that blocks automated submissions.
  • Cookieless measurement — Google Analytics in Consent Mode with cookies switched off. It writes nothing to your device and produces aggregate page counts. As Section 2 says, the request still reaches Google LLC with your IP address and user agent; what keeps it in this category is that nothing is stored on or read from your device.

Analytics — off unless you turn it on. To be precise about what changes: Google Analytics runs for every visitor in the cookieless mode described above, but the storage listed below is written only once you switch this category on, and Microsoft Clarity is not loaded at all until you do:

  • _ga and _ga_<measurement-id> — Google Analytics, up to 2 years. A persistent identifier that links your visits together so we can distinguish new from returning readers.
  • _clck and _clsk — Microsoft Clarity first-party cookies, up to 1 year. Session recording and heatmaps: mouse movement, scrolling, and clicks. Form fields are masked at the page level so typed values are not captured.
  • _cltk — Microsoft Clarity again, but kept in your browser's session storage rather than as a cookie, so it goes when you close the tab. We clear it along with the cookies above when you switch this category off.
  • Cookies Microsoft sets on its own domains — turning this category on also allows Clarity to set CLID on clarity.ms, and MUID and ANONCHK on Microsoft domains. We are being plain about the limit here: we can stop sending you to Clarity, but a cookie set on someone else's domain cannot be expired by this website. Clear those from your browser settings.

If you turn this category off after having had it on, we expire the first-party cookies listed above, clear Clarity's session-storage key, and reload the page, because a tag your browser has already run cannot be unloaded in place. Stopping future collection alone would not be a real withdrawal. The cookies on Microsoft's own domains are the exception noted above, and only your browser settings can clear those.

Marketing — off unless you turn it on, and carrying nothing today.

We run no advertising pixel, no remarketing tag, and no cross-site tracker on this website. The category exists so the advertising consent signals (ad_storage, ad_user_data, ad_personalization) are managed correctly and your answer applies from the first moment if that ever changes. We are not asking you to consent to advertising we do not currently do.

Before you choose, and what closing the bar means.

Every non-essential category is off for every visitor, in every country, before you decide anything. The consent bar is shown to everyone, not only to visitors in Europe. Where you are affects only how the buttons are arranged, never what is switched on. Closing the bar with the X is treated exactly as declining everything optional, and that refusal is recorded so you are not asked again on the next page. Closing, scrolling, or continuing to browse is never read as acceptance.

Changing or withdrawing your choice.

Select Cookie settings in the footer of any page. The consent bar reopens with your current choices shown, and you can switch a category off, decline everything, or change your mind in either direction. Withdrawing is one click from anywhere on the site, as GDPR Article 7(3) requires. Deleting the rn_consent cookie in your browser has the same effect and makes the bar ask again on your next visit.

11. Your rights — EU/UK/EEA

If you are in the EU, UK, or EEA, you have the following rights under GDPR / UK GDPR:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure / "right to be forgotten" (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21), including to direct marketing
  • Right to withdraw consent at any time
  • Right to lodge a complaint with your local supervisory authority

To exercise any of these rights, contact our privacy team. We will respond within one month of receiving a verifiable request, as required by Art. 12(3).

12. Your rights — California (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) grants you the following rights:

  • Right to Know — what personal information we collect, the sources, the purposes, and with whom we share it.
  • Right to Delete — request deletion of personal information we have collected.
  • Right to Correct — request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing — we do not "sell" personal information as defined by the CCPA. We may "share" personal information for cross-context behavioral advertising via analytics cookies; you can opt out by declining on the consent bar, by switching the Analytics and Marketing categories off under Cookie settings in the footer, or by sending a Global Privacy Control (GPC) signal.
  • Right to Limit Use of Sensitive Personal Information — we do not use sensitive personal information for purposes that trigger this right.
  • Right to Non-Discrimination — we will not deny service, charge a different price, or provide a different level of service if you exercise any CCPA right.

Categories of personal information collected (CCPA enumeration):

  • Identifiers (name, email, IP address)
  • Commercial information (company, job title, role)
  • Internet/network activity (pages visited, referrals — aggregate and cookieless for every visitor; linked to a persistent identifier only if you turn on the Analytics category)
  • Geolocation (approximate, derived by Google from the IP address on each measurement request; see Section 10)
  • Professional or employment-related information (job title, employer)
  • Inferences drawn from the above

Sources: directly from you; automatically from your browser (cookieless measurement for every visitor; cookie-based analytics and session recording only with your consent); from our service providers acting on our behalf.

To exercise any California right, contact our privacy team. You may also designate an authorized agent.

13. Children

The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information, please contact us and we will delete it.

14. Third-party links

Our Site may link to third-party websites (including RetailNorthstar's primary site, licensor reference pages, and external resources). We are not responsible for the privacy practices or content of third-party sites. Review their privacy notices when visiting.

15. Changes to this Policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date for any change. For material changes, we will provide more prominent notice (e.g., banner notice or email to subscribers) and, where required by law, obtain affirmative re-acceptance before the changes apply to existing customers.

16. Contact

Questions about this Policy or to exercise your rights: contact our privacy team.