Legal
Privacy Policy
Last updated: September 29, 2026
This Privacy Policy explains how Color Match (“we,” “us”) treats information when you use colormatchfinder.com, related pages, and the Color Match API (together, the “Site”). It is written for visitors in the United States and also covers rights under Brazil’s LGPD (Lei nº 13.709/2018) and, where they apply, GDPR and similar laws.
We designed the Site so that you can look up paint colors without creating an account. We do not run advertising pixels, we do not sell personal information, and we do not build marketing profiles.
Who is responsible
The controller of personal data processed for Color Match is the independent operator of this Site. We are not a paint brand and not part of any manufacturer listed in the catalog.
Contact: contact@colormatchfinder.com.
What we collect
Unique daily visits
To count unique visitors per calendar day (timezone America/New_York), the Site may:
- Send a first-party cookie named
statzwith a random identifier (UUID). The cookie isHttpOnly,SameSite=Lax, set for up to 400 days, and is used only to recognize the same browser for visit counting. - Store in our database only the calendar date and that visitor token. We do not store your name, email, or paint searches in that database.
- Store in your browser’s
localStoragea key namedstatzwith today’s date so we do not send a duplicate count the same day.
Known bots (from User-Agent) are not counted. The summary of visit counts is available only with a private access token; it is not a public profile of you.
Colors saved in this session
If you heart a color, the list is kept in your browser’s sessionStorage under colormatch:favorites. It stays on your device for that browsing session. We do not receive that list on our servers.
Search, picker, and matching in the browser
Name search, HEX input, the color picker, and the eyedropper run in your browser against a public catalog file (/catalog.json). We do not operate a user database of queries. The address bar may contain a search term (for example /search/?q=...); that is normal web behavior and may appear in hosting logs as described below.
API
If you call the authenticated API (for example /api/v1/match?hex=...), we process the parameters you send (such as HEX, limit, and brand filters) to return matches. Use of the API is also governed by the Terms of Use.
What we do not collect
- No user accounts, passwords, or profiles.
- No payment card data — we do not sell paint or subscriptions on this Site.
- No newsletter or marketing list.
- No advertising cookies, no Google Analytics, no social-login SDKs.
Cookies and similar storage
statzcookie — first-party, visitor token for unique daily counts, up to 400 days, HttpOnly.statzlocalStorage — today’s date, to skip a repeat hit.colormatch:favoritessessionStorage — colors you save this session.- Hosting / security — Cloudflare, which delivers the Site, may set technical or bot-management cookies or process IP address, User-Agent, and request URL as part of operating a CDN and Worker. That processing is by a service provider, not for our advertising.
You can block or delete cookies in your browser. If you block statz, the Site still works; we may simply fail to de-duplicate your visits. Clearing site data removes localStorage and sessionStorage values.
Fonts and other third parties
We load typefaces from Bunny Fonts (fonts.bunny.net). Your browser requests those files directly; the font provider may see your IP address and User-Agent. We chose a privacy-oriented font CDN rather than a advertising network. We do not control that provider’s independent practices.
The Site is hosted on Cloudflare (Worker and static assets, with a D1 database used only for visit tokens and dates). Cloudflare may process request metadata (including IP address) in the United States and other regions to deliver, cache, and protect the Site.
How we use information
- Operate, secure, and debug the Site and API.
- Count unique visitors per day.
- Remember colors you save in the current session (on your device only).
- Respond if you email us (we will see your email address and whatever you write).
- Comply with law or a binding legal request.
We do not use this information to serve ads, to score you, or to sell lists.
Legal bases (LGPD / GDPR)
Where those laws apply, we rely on:
- Legitimate interests (LGPD art. 7º, IX; GDPR art. 6(1)(f)) — unique visit counts, security, and running a public reference site.
- Performance of a request / contract — if you email us or use the API with a key we issued.
- Legal obligation — if we must keep or disclose information under law.
We do not require consent for the essential operation of the Site. You may object to visit counting by blocking the statz cookie or by contacting us.
Sharing; we do not sell personal information
We do not sell personal information. We do not share it for cross-context behavioral advertising (California CPRA “sharing”). We do not disclose visit tokens to paint brands.
We use processors that help us run the Site (currently Cloudflare for hosting, database, and delivery; Bunny Fonts for typefaces). They may process data only to provide those services.
We may disclose information if required by law, court order, or to protect the Site, our users, or others from fraud or security threats.
Retention
- Visit date + token: kept to produce unique-visitor counts (we typically look at about the last 90 days in summaries) and may be deleted when no longer needed for that purpose.
statzcookie: up to 400 days unless you delete it earlier.- sessionStorage favorites: until the browser session ends.
- Email you send us: as long as needed to handle your request and any legal duties.
- Hosting logs: according to the provider’s default log retention for security and operations.
Your rights
Depending on where you live, you may have the right to access, correct, delete, anonymize, or port personal data, to learn about sharing, to restrict or object to processing, and to withdraw consent where processing was based on consent. Brazilian users have the rights in LGPD arts. 18 and 9. California residents have rights to know, delete, and correct personal information, to opt out of sale/sharing (we do not sell or share in that sense), and to non-discrimination. EU/UK users may have GDPR rights, including lodging a complaint with a supervisory authority.
To exercise these rights, email contact@colormatchfinder.com. We may need enough information to identify the relevant visitor token or message. Because we do not keep names or accounts, some requests (for example “delete my search history”) cannot apply — we do not store that history in our visit database.
We do not offer a financial incentive related to personal information.
Children
The Site is a general paint-reference tool. It is not directed at children under 13 (or under 16 where that higher age applies). We do not knowingly collect personal information from children. If you believe a child provided data to us, contact us and we will delete what we can identify.
International processing
If you visit from outside the country where our hosting infrastructure runs, your information may be processed in the United States and other locations used by Cloudflare. Where a transfer law requires safeguards, we rely on the provider’s published transfer mechanisms and on the fact that the Site only stores a random visit token and date in our own database.
Changes
We may update this Policy. The “Last updated” date will change. Material changes will be posted on this page. Continued use of the Site after an update means you accept the revised Policy, except where a law requires a different rule.
Contact
Privacy questions or requests: contact@colormatchfinder.com.
Related: Disclaimer and Terms of Use.