Privacy
ESGOS is built to hold as little personal data as possible. This page says exactly what exists. Draft pending counsel review.
What we store
- Organisation records — company-level facts only: names, websites, countries, certifications with their evidence. Registry sources that publish contact persons, emails or phone numbers are ingested without those fields.
- Ownership claims — when you claim a listing by work email, the address is used to send one confirmation link and to derive the domain match. Claim sessions are a signed cookie (esgos_session) holding only the organisation id, for 30 days. If you are signed in to an account when you complete a claim, the organisation is also attached to that account (see Accounts and payments below). There are no passwords.
- Dispute submissions — the text you write and the optional contact you choose to leave.
- Contact forms — an enhanced listing may show a contact form. What you type (your message and the reply address you give) is emailed once to the people who manage that organisation's listing, with your address as the reply-to, and only after you tick the consent box on the form. ESGOS keeps no copy of the message or the address. The only record is a rate-limit counter keyed by a one-way hash of your connection's IP address and the organisation — it holds no address, no text, and is deleted within about two days.
- Watchlist emails — when you watch an organisation, category or country, we store the email address, the watch(es) you've asked for, and timestamps (when you subscribed, when you confirmed, when the last digest was sent). The address is used only to send the one-time confirmation link and, once confirmed, the weekly digest for what you're watching — nothing else, ever. Unconfirmed watchers are purged automatically after 30 days. Unsubscribing deletes the email address and every watch immediately. Watching does not create an account and needs no password — identity is a secret token link, like the claim flow.
Accounts and payments
Reading ESGOS never needs an account. An account exists only to write: manage listings you have claimed, submit compliance declarations, and buy the product that allows those submissions. Nothing on the site or the machine interface is gated on being signed in.
- What an account stores — your email address, when the account was created, when you last signed in, and (if you have ever started a purchase) your Stripe customer id. Nothing else: no name, no password, no profile.
- Signing in — you enter your email and we send a one-time sign-in link. The link's token and the session token behind the esgos_account cookie are stored only as SHA-256 hashes; the cookie lasts 30 days from your last visit (rolling). Used and expired sign-in tokens are purged nightly. Signing out deletes the session.
- Organisations you manage — a record linking your account to each organisation you have proven control of (through the claim flow, or granted by staff on request), with when and how it was granted. Staff can see which accounts manage which organisations.
- Payments — payments are taken by Stripe through its hosted Checkout and Customer Portal pages. Card numbers and billing addresses are entered on Stripe's pages and never reach ESGOS. We store the Stripe customer, subscription and price ids, the entitlement's status and current period end, and the Stripe event records we need to process payment notifications reliably (with customer contact details removed before storage: the name, email, address, phone, shipping and tax-id fields Stripe attaches to sessions and invoices; the Stripe customer id is kept). Stripe's own handling of your data is described in Stripe's privacy policy.
- Compliance submissions — a declaration you submit is stored as pending and is visible only to you and to staff until a reviewer publishes it. Nothing you submit appears publicly without staff review; a rejected submission stays out of the public record, with the reviewer's note visible to you.
- Awards — the GREEN AWARDS are free editorial recognition. An entry is made by a manager of a claimed organisation from their account and holds the entry’s title, a summary of the achievement, the achievement year and an optional evidence link (a publicly reachable URL); it is visible to that organisation’s managers and to staff. If the entry is shortlisted or wins, the organisation’s name and the entry’s title — and, for the winner, the summary — become public at the announcement, with the jury’s written rationale; the evidence link is seen by staff only and is never published. Anyone may nominate an organisation without an account: we store the reason they write (up to 600 characters), the organisation named, and — if they choose to leave one — their email address as a SHA-256 hash only, so the address itself is never stored and the nominator is never identified; the reason is visible to staff and to the nominated organisation’s managers, nowhere else. Nomination submissions are rate-limited by a one-way hash of the connection’s IP address, deleted within about two days like the contact-form counter. Jurors’ names, role lines, short biographies, conflict-of-interest notes and photographs are professional facts entered by staff with the juror’s agreement and are published on the awards pages.
- Deleting an account — there is no self-serve deletion yet. Write to claims@esgos.org from the account's address and we will remove the account, its sessions and its manager records. Public directory records about an organisation are not personal data and remain; billing records are kept as long as required for accounting.
Portal partners
A portal is a co-branded view of the public directory that an institution (an exchange, ministry, chamber, development bank or agency) licenses so its own list of companies can be seen against ESGOS. Partner users are ordinary accounts, as above, with a role on the institution added; the workspace where they upload and review their list is the only page on the site that checks that role. Everything else about a portal — the page itself, the coverage counts, the line on an organisation’s page — is public and needs no account.
- What a partner uploads — a CSV of companies: for each row a name, and optionally a country, a website or domain, the partner’s own reference (an id or LEI, kept verbatim, never interpreted) and a contact email. The uploaded file is parsed and discarded; only the parsed rows are stored, against the institution. A “contact” cell that is not shaped like an email address (a person’s name, say) is dropped, not stored.
- Contact emails and their lifecycle — when a row carries a contact address we store it in two forms: the plaintext address, and a SHA-256 hash of the lowercased address. The plaintext exists for one purpose — so the partner can send that company one invitation — and lives only until the earlier of: the partner sends the invitation, or 30 days from when the address was stored (the clock restarts if a later upload supplies an address for that row). At that point the plaintext is removed by a nightly sweep and only the hash remains, used solely to de-duplicate rows and to stop the same partner mailing the same address again within 30 days; a row that has been invited never has its address re-populated by a later upload. Partners see and download only their own rows and the public match result — never a hash, never an internal id.
- The invitation — sent by the partner from the workspace, from notify@esgos.org, at most 200 per institution per day. It says which partner has listed which company, that ESGOS is a free public registry, and gives the get-listed link (tagged with the portal so a resulting listing records where it came from); it states that ESGOS keeps no copy of the address beyond the hash. No reply-to, no tracking, nothing else. Which companies a partner chooses to invite, and the lawful basis for holding and mailing those contacts, are the partner’s.
- What appears publicly — the portal page shows the institution’s own record (name, kind, country, logo, website, blurb), coverage counts (how many of the partner’s companies are on ESGOS, and of those how many are claimed, verified or have a compliance profile — all counts of public states), and the companies from the partner’s list that are already published on ESGOS, in the ordinary directory order. Rows that did not match anything on ESGOS are never shown, named or counted individually. On the page of a listed organisation a plain-text line reads “Listed on the … portal” naming the partner(s) whose lists it appears on; that is the whole of what a portal changes on an organisation’s page — not its tier, its verifications or its search position.
- The licence and the workspace — an institution’s licence is invoiced offline; no card, price or Stripe record is attached to it. Staff record the institution, its licence dates and its first partner user in the review area; partner administrators may add further users by their account email. When a licence ends the portal page returns not-found and the workspace becomes read-only; the rows are kept for the partner’s return, and their contact addresses keep ageing out on the same 30-day clock regardless.
What we deliberately do not do
- No analytics trackers, no advertising pixels, no fingerprinting.
- No marketing use of any address you give us, ever.
- No sale or sharing of data — everything public here is already free and public by design.
Third parties
The site runs on Cloudflare (hosting, bot protection via Turnstile, email delivery), which processes connection data such as IP addresses to serve and protect the site. Staff access to the review area authenticates through Cloudflare Access. Payments are processed by Stripe, as described above.
Your rights
To correct or remove data about your organisation, use the claim or dispute flow on any listing — corrections are public and timestamped. For anything else, write to claims@esgos.org.
What we publish, and to whom
Organisation records on ESGOS are published free and unauthenticated to everyone on identical terms — no account, no key, no contract, and no privileged feed to any related company; the distribution policy sets out exactly what is published and on what terms.