Sitebase
Legal

Privacy policy

This policy explains what personal data Sitebase collects, why, how long it is kept, and the rights you have over it. Last updated June 12, 2026.

Who we are

Sitebase is operated by [PLACEHOLDER: legal entity name], [PLACEHOLDER: registered address], [PLACEHOLDER: company/VAT registration]. You can reach us at hello@sitebase.dev for any privacy question or request.

Two roles: controller and processor

Sitebase handles personal data in two distinct roles:

  • As a controller for the people who visit sitebase.dev and the customers who hold a Sitebase account. Sections 1–6 below cover this.
  • As a processor for the data our customers collect through Sitebase features embedded on their own websites (form submissions, subscribers, testimonials, analytics, consent logs). Our customers are the controllers of that data; we process it only on their instructions under our Data Processing Addendum. Section 7 covers this.

1. Data we collect about account holders

  • Account data: your email address, display name, and optional avatar URL. Accounts are created when you complete checkout or accept a collaborator invite.
  • Authentication data: hashed sign-in (magic link) tokens and hashed session tokens. We never store passwords because there are none.
  • Team data: workspace membership, role, invited collaborators' email addresses, and per-website access scopes.
  • Billing data: payment and tax handling is performed by Polar (our merchant of record). We store your Polar customer and subscription identifiers, plan, and billing status — never your card details.
  • Activity (audit) logs: administrative actions in the dashboard (for example "invited a collaborator", "changed plan") with the acting user's id, kept for security and accountability.
  • Notification preferences and in-app notifications about activity on your websites.
  • Support correspondence if you email us.

2. Why we process it (legal bases)

  • Performance of a contract (GDPR Art. 6(1)(b)): providing the service, authentication, billing, team collaboration, and transactional email such as sign-in links and invites.
  • Legitimate interests (Art. 6(1)(f)): securing the service, preventing fraud and abuse (rate limiting, spam protection), and keeping audit logs.
  • Legal obligations (Art. 6(1)(c)): tax and accounting records, handled primarily by Polar as merchant of record.

We do not run advertising, we do not sell personal data, and we do not send marketing email without consent.

3. Cookies

Sitebase sets a single, strictly necessary cookie: sitebase_session, which keeps you signed in to the dashboard for up to 30 days. It is HTTP-only and is not used for tracking. We use no advertising, analytics, or third-party cookies, which is why sitebase.dev shows no cookie banner.

4. How long we keep data

  • Account data: until you delete your account.
  • Sessions: expire after 30 days; expired sessions are purged automatically.
  • Sign-in links: valid for minutes and purged automatically after expiry.
  • Audit logs: per your plan's retention window, with a fixed cleanup for deleted accounts.
  • In-app notifications: 30 days.
  • Billing webhook records: 90 days for the raw payloads; the resulting subscription state is kept for the life of the account.

5. Who receives data (subprocessors and services)

We use a small set of infrastructure providers, listed with their roles on the subprocessors page: Cloudflare (hosting, storage, spam protection), Resend (transactional email), and Polar (billing). Additionally, if you have not set a custom avatar, your dashboard avatar is loaded from Gravatar (Automattic) using a hash of your email address; you can avoid this by setting any custom avatar URL in your profile.

Some providers are located in the United States. Where personal data is transferred outside the EEA/UK, transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses as implemented in each provider's data processing agreement.

6. Your rights

If you are in the EEA, UK, or a jurisdiction with similar laws, you have the right to:

  • access the personal data we hold about you (use Export my data on your profile page);
  • correct it (your name and avatar are editable in the dashboard; email us for the rest);
  • erase it (use Delete account on your profile page, or email us);
  • receive it in a portable format (the export is machine-readable JSON);
  • restrict or object to processing based on legitimate interests;
  • lodge a complaint with your local supervisory authority.

If you are a California resident (CCPA/CPRA) or a resident of another US state with a privacy law: you have the right to know what personal information we collect (this policy), to delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information as defined by those laws, and we do not use sensitive personal information beyond what is necessary to provide the service. We will never discriminate against you for exercising your rights. Submit requests via the in-dashboard tools or hello@sitebase.dev; we verify requests by confirming control of the account email.

7. Data we process for our customers

When you interact with a Sitebase-powered feature on a customer's website (for example joining a waiting list, sending a contact message, or leaving a testimonial), the data you submit belongs to that website's owner — they are the controller and their privacy policy applies. Sitebase stores it on their behalf in an isolated, per-customer database. To exercise your rights over that data, contact the website owner; we support them with built-in export and erasure tools and will assist as their processor.

Specifics worth knowing about how we minimize this data:

  • Analytics is cookieless: the tracking script sets no cookies and uses no localStorage or fingerprinting. Visitors are counted using a salted hash of IP address, user agent, and site, with the salt rotated daily and deleted after two days — after which the hash cannot be linked back to anyone. Raw IP addresses are never stored with analytics data.
  • Raw analytics detail (individual pageviews and sessions) is deleted after 6 months; only aggregate daily counts are kept longer.
  • Form submissions store a keyed hash of the submitting IP address for spam protection, not the raw address.
  • Consent logs collected by the cookie banner feature are anonymous: they record the choice and time, not who made it.

8. Security

All traffic is encrypted in transit (TLS) and all stored data is encrypted at rest by our hosting provider. Each customer workspace lives in its own isolated database. Authentication tokens are stored only as hashes. Access within a workspace is role-gated, and administrative actions are audit-logged.

9. Children

Sitebase is a business tool and is not directed at children under 16. We do not knowingly collect their data.

10. Changes

We will post any changes to this policy here and update the date at the top. For material changes we will notify account holders by email.

Contact

Privacy questions, rights requests, complaints: hello@sitebase.dev.