Privacy Policy
Version 1.1 · Effective 2 October 2026
This policy explains what personal data SitesProof ("we", "us") collects when you use SitesProof (https://sitesproof.com) and its website, why we collect it, how long we keep it, and what rights you have.
Summary.
- We collect only what we need to run the product and bill you. We do not sell personal data, and we do not use it for advertising.
- Our website uses no tracking or advertising cookies. We measure visits with self-hosted, cookieless analytics.
- Data you put into the product belongs to your organisation. We process it on your organisation's instructions (we are its "processor"), under our Data Processing Addendum.
- Our servers are in Germany (EU). The few services we use are listed on our Subprocessors page.
- Email privacy@sitesproof.com to access, correct or delete your data.
Contents
- Who we are
- Our two roles: controller and processor
- What we collect and why
- Data in the product
- Cookies and analytics
- AI features
- Who we share data with
- Where your data is stored and international transfers
- How long we keep data
- How we protect data
- Your rights
- US state privacy notice
- Children
- Changes to this policy
- Contact and complaints
1. Who we are
SitesProof is provided by SitesProof, a sole proprietor registered in Ukraine, at Milutenka 23, Kyiv. For privacy questions email privacy@sitesproof.com.
Representatives. Because we are not established in the EU or the UK, we have appointed representatives you can also contact about data protection:
- EU representative: not appointed — the service is offered to businesses in the United States only
- UK representative: not appointed — the service is offered to businesses in the United States only
We are a one-person company, so we have not appointed a data protection officer; the founder is responsible for privacy.
2. Our two roles: controller and processor
- Controller. We decide how and why we use data about visitors to our website, people who use our free tools, people who sign up for an account, people we contact about our products, and people who contact us. This policy mainly covers that data.
- Processor. When your organisation uses SitesProof, it decides what data goes into the product (for example, content from a connected system, or details submitted by its own customers). For that data your organisation is the controller and we act on its instructions under our DPA. If you are one of those people (for example, a customer of a business that uses SitesProof), please contact that business first; we will help it respond. Section 4 describes this data.
3. What we collect and why
| Who | Data | Why | Legal basis (EU/UK) |
|---|---|---|---|
| Website visitors | Pages viewed, referrer, approximate country, browser and device type, derived from your request. Your IP address is used transiently and not stored by our analytics. | To understand which pages are useful and to keep the site secure (rate limits, abuse prevention). | Legitimate interests (running and improving a website; security) |
| Free-tool users | What you enter in the tool (see section 4 and the product section below), your email address if you ask us to email you the result, and technical data as for visitors. | To run the tool and send you the result you asked for. | Performance of your request (contract); legitimate interests (preventing abuse) |
| Account holders | Name, email address, organisation name, sign-in data (a Google account ID if you sign in with Google), team members you invite, settings, and records of your acceptance of our terms. | To create and secure your account, provide the service, and send service emails (for example email confirmation and password reset, alerts, reports, billing and security notices). | Contract; legitimate interests (security, keeping records) |
| Customers (billing) | Plan, subscription status, invoices and the country for tax. Creem collects your payment details; we never see or store full card numbers. | To manage your subscription. | Contract; legal obligation (tax and accounting records) |
| Product usage | Which features are used and when, error reports, and logs (IP address, time, request path). | To operate, fix, secure and improve the service. | Legitimate interests |
| People who contact us | Your messages to support (email or chat) and any information you include. | To answer you and improve support. | Legitimate interests; contract (if you are a customer) |
| People we contact about our products | Business contact details that are publicly available (for example a business name, website, business email address and city) that we gathered from public business listings and websites. | To tell businesses about a product that may be useful to them, by email, with an opt-out in every message. | Legitimate interests (B2B direct marketing). We don't send marketing email to individuals where the law requires prior consent. |
| Product news | Your email address, if you opt in (checkbox at sign-up or on a waitlist). | To send occasional product updates. You can unsubscribe at any time. | Consent |
We don't knowingly collect special-category data (such as health data) about you, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
If you don't provide data. We need your email address to create an account. Everything else is optional or comes from your use of the product.
4. Data in the product
SitesProof crawls the websites you tell it to crawl and stores what it observed. Almost all of that is information about a website, not about a person — but it comes from your clients' sites and it describes your relationship with your clients, so we treat the lot as your data and act as your processor under our Data Processing Addendum.
What you put in. Your clients' names and logos, the site addresses you add, your agency's own logo and colours, and the contact address you give for a client if you want reports emailed to them. We don't sell any of it, we don't use it to train AI models, and we never use a customer's name, logo or report as an example in marketing, a demo or a screenshot.
What a crawl stores. One artifact per scan, holding what the checks need and no more:
- the addresses crawled, the response status and headers of each page, and how many pages were looked at;
- an inventory of the scripts on each page — the script address, and a sha-256 hash of its contents where we read them. We store the hash rather than the script so that a later crawl can tell the contents changed;
- the names, domains and attributes of the cookies that were set, and whether each one was set before a consent banner was accepted. Cookie values are never stored;
- the third-party requests a page made, and whether they happened before consent;
- the accessibility findings reported by axe-core, including the CSS selector of each element involved;
- the plugin and theme names and version numbers that the site's own pages reveal, and the TLS certificate details of its main host;
- for each legal page we probed: whether it answered, its address, and the length of its visible text. We never store the text itself.
Full page bodies are never stored. An artifact may still contain fragments of a client's HTML in a selector or a URL, so we keep it in private storage, use it only to run and re-run the checks for you, and keep it for no longer than 90 days. Removing a site, or closing your workspace, removes its artifacts too.
Findings — the observations a report is made of — are kept while the site is in your portfolio, because the value of the product is the comparison with last month.
The free scanner. If you scan a URL at https://sitesproof.com/scan without an account, we store the address, the report, and the time, so that the shareable link keeps working and so we can enforce one scan per address per hour. That report page carries no evidence details and is not indexed by search engines, but anyone who has the link can read it. If you ask us to email you the report, we store the address you gave for that purpose.
5. Cookies and analytics
We don't use advertising, social-media or cross-site tracking cookies, and we don't use Google Analytics. That is why you don't see a cookie banner.
What we do use:
| Name / type | Where | Purpose | Duration |
|---|---|---|---|
Session cookie (for example better-auth.session_token) |
App, after you sign in | Keeps you signed in. Strictly necessary. | Until you sign out, or up to 30 days |
| Sign-in security cookies (state / CSRF) | Sign-in pages | Protects sign-in and "Sign in with Google" against forgery. Strictly necessary. | Minutes |
Cloudflare security cookies (for example __cf_bm, Turnstile) |
Website and app | Bot and abuse protection. Strictly necessary. | Up to 30 minutes |
| Creem checkout | On Creem's checkout only, when you choose to buy | Processes your payment and prevents fraud. Set by Creem as the seller, not by us. See Creem's privacy notice. | Set by Creem |
| Chat widget | Only after you click "Chat with us" | Keeps your support conversation open. See the Subprocessors page. | Up to 6 months |
Analytics. We use Ahrefs Web Analytics (Ahrefs Pte. Ltd.), a cookieless analytics tool. It does not set cookies and stores nothing on your device, and it builds no profile of you across sites. It records the page address, the referring page, your browser and device type, your screen size, and a country derived from your IP address; the IP address itself is not stored. We cannot identify you from this data and we don't combine it with other data. Unlike the tools we run on our own servers, Ahrefs is a third party, so it is listed on the Subprocessors page. If your browser sends Global Privacy Control or "Do Not Track", the analytics script is not loaded at all — it is never sent to your browser, rather than sent and asked to stay quiet. Pages whose address could itself identify you or carry a token — a shared report link, a password-reset link — load no analytics whatsoever.
If we ever add non-essential cookies (for example advertising conversion tracking), we will ask for your consent first and update this section.
6. AI features
The product section above says which features use AI and what they send — and a product that says it sends nothing, sends nothing. Where a feature does send content to an AI provider (named on the Subprocessors page) to generate results such as drafts or suggestions, we send only the content needed for the task. Under the provider's commercial terms, it does not use this content to train its models and keeps it only for a limited time for safety and abuse monitoring. We never use your content to train any AI model.
7. Who we share data with
We share personal data only:
- With service providers (subprocessors) who help us run the product, such as hosting, email delivery and AI. They may use the data only to provide their service to us. The full list, with locations, is on our Subprocessors page.
- With Creem, our reseller and Merchant of Record, which receives your order and payment details and processes them for its own account under its own privacy notice.
- With Google, if you choose "Sign in with Google" (Google tells us your name, email address and account ID; Google's privacy policy applies to your Google account).
- With systems you connect. When you connect a third-party system, data flows between it and SitesProof because you asked for it.
- When the law requires it, or to protect our rights, users or the public (for example in response to a valid court order). Where allowed, we will tell you first.
- If the business is transferred, for example if the product is moved into a company the founder sets up or is sold. We will tell you, and this policy will continue to protect your data.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
8. Where your data is stored and international transfers
Our application servers and database are hosted by Hetzner in Germany (EU). Encrypted backups are kept on our Hetzner server and in Cloudflare R2 storage restricted to the EU jurisdiction. Some subprocessors are in the United States (see the Subprocessors page); for those we rely on the EU–US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses (with the UK Addendum for UK data).
The founder works from Ukraine, which the EU and UK have not recognised as providing "adequate" protection. Access from Ukraine is remote, encrypted and limited to what is needed to run and support the service. Data is not copied to local devices except where needed to handle a support request, and then deleted.
9. How long we keep data
| Data | How long |
|---|---|
| Account data | While your account is open. Deleted within 30 days after you close it (60 more days in backups). |
| Customer data in the product | See the product section above. Deleted within 30 days after your account closes, or earlier when you delete it. |
| Billing records | As long as tax and accounting law requires (currently up to 7 years). Creem keeps its own records. |
| Support conversations | 3 years after the last message. |
| Server logs and error reports | 30 days. |
| Website analytics | Aggregated, without personal identifiers; kept indefinitely. |
| Records of outreach and opt-outs | Contact details of people we contacted: 24 months after the last contact. Opt-out list: kept permanently so we never contact you again (only the email address). |
| Records of your consents and acceptance of terms | For as long as your account exists plus 3 years, to prove what was agreed. |
10. How we protect data
Data is encrypted in transit (TLS) and at rest. Secrets such as API keys are additionally encrypted in our database. Access is limited to the founder, uses strong authentication, and is logged. See our Security page for details. If a personal-data breach affects you, we will notify you (and, as your processor, your organisation) without undue delay.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct it if it is wrong;
- delete it;
- restrict or object to our use of it, including objecting at any time to direct marketing;
- port it to another service in a machine-readable format;
- withdraw consent where we rely on consent (this doesn't affect what we did before); and
- complain to a data protection authority (see section 15).
To exercise these rights, email privacy@sitesproof.com from the address linked to your account, or use the account settings where available (export, delete account). We reply within 30 days. We may need to verify your identity. We don't charge for requests unless they are clearly unfounded or excessive.
If your request concerns data that an organisation put into SitesProof (section 2, "Processor"), we will forward it to that organisation and help it respond.
12. US state privacy notice
This section is for residents of US states with consumer privacy laws, including California.
- Categories of personal information we collect are described in section 3: identifiers (name, email, IP address), commercial information (subscription records), internet activity (product usage and analytics), and the content of your communications with us. Sources: you, your organisation, your device, Creem, Google sign-in and public business listings.
- We do not sell or share personal information (as those terms are defined in California law), and we have not done so in the past 12 months. We do not knowingly sell or share personal information of people under 16.
- We don't use sensitive personal information for purposes that would give you a right to limit it.
- Your rights: to know, access, correct and delete your personal information, and not to be discriminated against for exercising these rights. You can use an authorised agent. Contact privacy@sitesproof.com.
- Global Privacy Control and Do Not Track. We honour GPC and "Do Not Track" signals by disabling analytics for that browser. We don't track you across third-party websites.
13. Children
SitesProof is a business tool and is not intended for anyone under 18. We don't knowingly collect personal data from children. If you believe a child has given us personal data, email privacy@sitesproof.com and we will delete it.
14. Changes to this policy
We will update this policy when our practices change. The version and effective date are at the top. If a change materially affects how we use your personal data, we will email account owners at least 30 days before it takes effect (or ask for your consent where the law requires it).
15. Contact and complaints
SitesProof, Milutenka 23, Kyiv, Ukraine. Email: privacy@sitesproof.com.
If you are unhappy with how we handled your data, please contact us first. You can also complain to your local data protection authority, for example:
- in the EU, the supervisory authority of the country where you live or work (list);
- in the UK, the Information Commissioner's Office (ico.org.uk);
- in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.