Privacy Policy
Last updated: 28 July 2026
Open Identity Platform is a community-run, open-source project. Its website, openidentityplatform.org, is a static site hosted on GitHub Pages. It has no user accounts, no login, no contact forms, and no advertising. We aim to collect as little data as possible, and analytics stay switched off until you explicitly consent.
This policy explains what data is involved when you visit the site, the cookies and third-party services we rely on, and the choices and rights you have.
At a glance
- The site is static — we don't ask you to register or submit personal data to us.
- We use Google Analytics to understand usage, but only after you accept the cookie notice. Until then the Google Analytics script is never loaded, so no data at all is sent to Google.
- You can change or withdraw your choice at any time from cookie settings.
- We run no advertising and never enable advertising or personalization tracking.
- A few third parties (a hosting provider, content delivery networks, and an optional translation widget) load as part of delivering the site and can see your IP address.
- Commercial-support vendors listed on the site are independent companies; contacting them is directly between you and them.
Who we are
"Open Identity Platform" is an open-source community organization, hosted on GitHub. The website is maintained by community members and served through GitHub Pages. It is not a commercial product, and there is no separate company operating it.
What data is collected, and why
Data you actively provide
The site does not collect personal data from you directly — there are no accounts and no forms. If you email a listed support vendor using the links on the Support & Services page, that email goes directly to that independent company; we do not receive, store, or broker it. See "Commercial-support vendors" below.
Analytics (only with your consent)
With your consent, we use Google Analytics 4 (measurement ID
G-Q5PEKRFRH8), a service provided by Google. The Google Analytics script is only
downloaded once you accept the cookie notice — if you decline, or simply ignore it, your browser
never requests it and no measurement data of any kind is sent to Google Analytics. (The optional
translation widget described under "Third-party services" is separate and unaffected.) It helps
us understand, in
aggregate, which pages and resources people find useful. When enabled, it may collect information
such as your device and browser type, an approximate location derived from your IP address, the pages
you view, referring links, and interactions on the page. Google Analytics 4 does not store your
IP address.
Beyond page views, we record a small number of non-identifying interaction events so we can see which content is helpful:
support_cta_click— when a "Support" call-to-action is clicked, with alocationlabel (for examplehome_commercialorproduct_openam).generate_lead— when a vendor email button is clicked, with avendorlabel and aregionlabel.
These labels are fixed categories, not personal data. Analytics data is processed by Google under Google's Privacy Policy; retention is governed by our Google Analytics settings.
Hosting and server logs
The site is delivered by GitHub Pages (GitHub, Inc., part of Microsoft). As with any web server, GitHub may process technical request information such as your IP address and user-agent to deliver the site and for security. This is described in the GitHub Privacy Statement.
Cookies and similar technologies
We do not set analytics cookies until you accept the cookie notice. The cookies involved are:
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
cookie-notice-dismissed |
This site (first-party) | Remembers your answer to the cookie notice — true if you approved, false if you declined — so it isn't shown again. |
~31 days |
Google Analytics cookies (e.g. _ga) |
Set only after you consent; used to measure site usage. | Up to ~2 years (per Google) | |
Google Translate cookies (e.g. googtrans) |
Set only if you use the optional page-translation widget, to remember your chosen language. | Session / short-lived |
You can clear or block cookies through your browser settings. You can also install the Google Analytics opt-out browser add-on. Blocking cookies may affect some functionality.
Consent (how analytics is turned on and off)
The cookie notice offers Approve and Decline, and your choice takes effect immediately — no page reload, no dark patterns:
- Until you approve, the Google Analytics script is not loaded at all. Declining it, or ignoring the notice entirely, means no request is made for it and no measurement data — not even a cookieless one — is sent.
- When you approve, Google Analytics loads and Google Consent Mode v2 is set with analytics storage granted.
- Advertising storage, ad personalization, and ad user data are always denied — this site runs no ads and never enables them.
To change or withdraw your choice at any time, open cookie settings to bring the notice back. Choosing Decline there stops further measurement and deletes the Google Analytics cookies already set in your browser. Clearing this site's cookies has the same effect and makes the notice appear again on your next visit.
Third-party services
To deliver the site, a few third-party services load in your browser. As a normal part of serving their content, these providers can receive your IP address and basic request information. We do not control their processing; their own privacy policies apply.
| Service | Provider | Purpose | Privacy policy |
|---|---|---|---|
| Google Analytics / Tag (gtag.js) | Usage analytics — the script is downloaded only after you approve the cookie notice | policies.google.com/privacy | |
| Google Translate widget | Optional on-page translation. If you use it, the page text is sent to Google to translate. | policies.google.com/privacy | |
| jsDelivr CDN | jsDelivr | Serves the Bootstrap stylesheet/scripts used for layout | jsdelivr.com privacy |
| cdnjs (Cloudflare) | Cloudflare | Serves the Font Awesome icon fonts | cloudflare.com/privacypolicy |
| GitHub Pages / avatars | GitHub (Microsoft) | Hosts the site and serves some images | GitHub Privacy Statement |
Commercial-support vendors
The Support & Services page lists independent companies that offer paid support. They are separate businesses, not part of this project. Vendor email links open your own email program with the address pre-filled; the message is sent directly from you to that vendor. Any personal data you share with a vendor is handled under that vendor's privacy policy, not this one. We do not receive a copy of your message and do not track whether you send it.
Links to other websites
The site links to external resources such as GitHub, project documentation, OpenCollective, Wikipedia, YouTube, and vendor websites. Once you follow a link, you are subject to the privacy policy of that destination. We are not responsible for the content or practices of external sites.
International data transfers
Some third parties above (for example Google and GitHub) are global providers and may process data in countries outside your own, including the United States. Those transfers are governed by the providers' own safeguards and privacy policies.
Your rights and choices
Depending on where you live, you may have rights over your personal data — including the right to access, correct, delete, restrict, or object to its processing, and to data portability. Because this site itself does not create user accounts or hold a personal profile about you, most choices are exercised directly:
- Analytics: decline the cookie notice (or simply ignore it) to keep Google Analytics off; open cookie settings to withdraw a consent you gave earlier; or use the Google Analytics opt-out add-on.
- Google-held data: exercise rights over Analytics/Translate data with Google, under their privacy policy.
- Hosting logs: exercise rights relating to server logs with GitHub, under their privacy statement.
- Everything else: contact us (below) with any privacy question or request.
Children's privacy
This site is intended for a technical, professional audience and is not directed at children. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy as the site or the services it uses change. The "Last updated" date at the top reflects the most recent revision. Material changes will be reflected on this page.
Contact
Questions about privacy or this policy? Reach the maintainers through the Open Identity Platform community on GitHub — open a topic in GitHub Discussions or via the project organization.