Privacy Policy
Effective date: [EFFECTIVE DATE]
This Privacy Policy explains how [LEGAL ENTITY NAME](“we,” “us”) collects, uses, and shares information in connection with SiteKeep (the “Service”). For data you connect about your own clients, you are the controller and we act as your processor.
1. Information we collect
- Account data: your name, email, agency name, password (hashed), and settings.
- Client & site data you add: client names, website URLs, contacts, notes, requests, and branding assets.
- Metrics we collect on your behalf: website performance (Google PageSpeed Insights), analytics (Google Analytics 4), security/SSL checks, and uptime results for the sites you connect.
- Payment data: processed by Stripe; we receive limited billing metadata (e.g., subscription status), not full card numbers.
- Usage & technical data: log data, IP address, device/browser info, and error diagnostics.
2. How we use information
To provide, maintain, and improve the Service; generate dashboards, reports, and alerts; process payments; communicate with you; ensure security; and comply with law.
3. Legal bases (where applicable)
Where the GDPR/UK GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (securing and improving the Service), consent (where required), and legal obligation. [Confirm bases with counsel.]
4. Service providers & subprocessors
We share data with vendors who process it on our behalf, including:
- Supabase — database, authentication, storage.
- Vercel — application hosting.
- Stripe — payment processing.
- Resend — transactional and report emails.
- Google — Analytics Data API (GA4), PageSpeed Insights, Safe Browsing.
- [Sentry / error monitoring] — error diagnostics, if enabled.
[Maintain a current subprocessor list and update this section as vendors change.]
5. Sharing
We do not sell your personal information. We share it with the subprocessors above, when you direct us to, to comply with law, or in connection with a business transfer. White-label dashboards you publish are accessible to anyone with the link you share.
6. Data retention
We retain information for as long as your account is active and as needed to provide the Service, then delete or anonymize it within [RETENTION PERIOD], except where longer retention is required by law.
7. Security
We use technical and organizational measures (encryption in transit, access controls, row-level data isolation between accounts). No method of transmission or storage is completely secure.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. To exercise these, contact [CONTACT EMAIL]. You may also have the right to lodge a complaint with a supervisory authority.
9. International transfers
Your data may be processed in countries other than yours. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses. [Confirm with counsel.]
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Cookies
We use strictly necessary cookies for authentication and session management. [Update if you add analytics/marketing cookies, and add a cookie banner if required in your jurisdiction.]
12. Changes
We may update this Policy; we will post the new effective date and, for material changes, notify you.
13. Contact
Privacy questions: [CONTACT EMAIL] · [LEGAL ENTITY NAME], [COMPANY ADDRESS].