Privacy Policy
How SitegenOS collects, uses, and protects your data.
Last updated: August 22, 2026
SitegenOS is operated by ApeTec Ltd (UK), the data controller for your account data. Contact: hello@sitegenos.com.
What we collect
- Account data: email address, password (hashed), display name, role (Builder or Owner), notification preferences.
- Billing data: processed by Stripe — we never see your card number. We store your Stripe customer ID and subscription state. Invoices are held by Stripe and available through the billing portal.
- Generation data: business details you paste, uploaded logos and media, generated site content, and your edit history.
- Site activity: we do not track individual visitors on published sites and set no analytics or advertising cookies anywhere. The only site-level counting we do is of form submissions, so they can be shown in the dashboard.
- Form submissions on generated sites: the details a visitor submits, plus a one-way hashed IP address and hashed browser identifier used for rate limiting and abuse prevention. These hashes cannot be reversed to identify a visitor.
- A client's email address, given to us by a Builder: when a Builder publishes a site for a client, they give us that client's email address so SitegenOS can send them the link to activate hosting. We hold it before the client has any account with us, and often before they have heard from us at all. It comes from the Builder, not from the client. We use it for three things and nothing else: sending the link to activate hosting, sending one email when the free week ends, and delivering the enquiries the client's own site receives during that week. It is never used for marketing and is never sold. Our lawful basis is legitimate interests — delivering the website a Builder made for that business, and passing on that site's enquiries. The Builder is responsible for having the client's permission to give us the address. To have it removed, email hello@sitegenos.com.
- Operational data: rate-limit counters (hashed IPs), abuse-event records, error monitoring via Sentry (which may capture a session replay of the moments around an error), and email-delivery records (recipient address, subject line, and the Postmark message ID — not the body of the message). Our authentication provider (Supabase) records session IP addresses as part of operating sign-in.
Why we process it
Contract performance (running your account, generating and hosting sites, billing), legitimate interest (security, rate limiting, abuse prevention, error monitoring, and delivering a Builder's finished website — and that site's enquiries — to the client it was made for), and legal obligation (tax and accounting records).
Who we share it with
We share specific data with these service providers, and no one else except as required by law. We do not sell your data.
| Provider | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, storage | Account + site data, session IPs |
| Stripe | Payments and tax | Billing identity, transactions |
| Anthropic | AI generation and editing (Claude models) | Generation prompts, business details |
| Apify | Business Finder listing retrieval | Search queries, and the returned business listings (names, addresses, phone numbers) |
| Pexels | Stock imagery sourcing | Search terms |
| Postmark | Transactional email | Recipient address, message content |
| Cloudflare (Turnstile) | Bot protection | Challenge tokens, hashed IP |
| Upstash | Rate limiting | Hashed identifiers |
| Vercel | Hosting and domains | Request data |
| Sentry | Error monitoring | Error context, on-error session replay |
How long we keep it
- Account data: until you delete your account. Deletion is immediate and permanent.
- Form submissions on generated sites: 12 months, then deleted automatically.
- Abuse-event records: deleted after 1 year.
- Email-delivery records: 6 months, then deleted automatically.
- Payment-event records from Stripe: the record is kept for the payment audit trail, and the raw event body — which can carry a name, an email address, or a billing address — is stripped after 90 days.
- Billing records: kept as required by UK tax law, with personal identifiers severed on account deletion beyond the Stripe customer ID.
Your rights
You have the rights UK GDPR and applicable privacy laws give you over your data — access, rectification, deletion, portability, objection, and restriction. For Builder accounts, deletion is self-service in your account settings and takes effect immediately: it erases your personal data, cancels any active subscription without refund, and preserves sites that belong to a paying site owner or are in a client's live trial. For site-owner accounts, request deletion by emailing hello@sitegenos.com from your account address — we action it within 30 days, and it cancels your hosting subscription without refund (your website goes offline). For anything else, email hello@sitegenos.com and we will handle your request as the law requires. You can complain to the UK Information Commissioner's Office (ico.org.uk).
Transfers
Where personal data is transferred outside the UK/EEA, we rely on our providers' Standard Contractual Clauses or equivalent safeguards.
Children
SitegenOS is for users aged 18 and over. It is not directed at children and we do not knowingly collect data from anyone under 18.
Changes
We may update this policy. The date above shows the current version.
Contact
hello@sitegenos.com · ApeTec Ltd, registered in England and Wales, company number 17065917.