SiteStock
Privacy Policy
1. Who is responsible for your data
The controller of personal data processed through the SiteStock application and website (the “Service”) is Archie Moore, 23 Grange Mansions, Kingston Road, Surrey, KT17 2AD. For any privacy question, or to exercise your rights, contact us at arcooreacc@gmail.com.
2. What we collect
- Account information
- Your email address, the display name you choose, the role you pick at sign-up, and - if you turn on two-factor authentication - a secret used to verify your authenticator codes. Your password is set and checked by our authentication provider and is stored only as a one-way hash; we never see it.
- Company and site information
- Company names and invite codes, and the sites you add - name, address, postcode, delivery and access notes, site contact name and phone number, project dates, and any budget you set.
- Order and activity information
- The material requests, orders, order items, approvals, cancellations, in-app messages, and the event history attached to them, including the name and account of the person who took each action, and timestamps.
- Delivery information
- Delivery postcodes and, where a driver chooses to share it, an approximate location from their device (used only to sort nearby pickups). Drivers may also upload photos as proof of delivery, which are stored privately and visible only to people who can already see that order.
- Notifications and preferences
- The in-app notifications generated for you and your notification settings.
- Feedback you send us
- If you use the in-app “Send feedback” box, we store the message you write, your account, which screen you were on, and the time. It goes only to us; it is not a public review.
- Technical information
- Standard server and security logs kept by our infrastructure providers, such as IP address and request times. If the app hits an unexpected error, your browser may send us a short diagnostic report - the error message, which page you were on, your browser and device type, and your account ID if you are signed in. It does not include what you typed. We also offer one optional, cookieless, privacy-preserving page-view counter that only runs if you allow it (see section 5); we do not use advertising or cross-site tracking of any kind.
3. Why we use it, and our legal basis
- To provide the Service - creating your account, showing your company its orders and sites, routing approvals, and coordinating deliveries. Legal basis: performance of a contract with you, or steps taken at your request before entering one.
- To keep the Service secure and working - authentication, two-factor checks, abuse prevention, debugging, and backups. Legal basis: our legitimate interests in running a safe, reliable service.
- To support you - responding when you contact us. Legal basis: legitimate interests, or performance of the contract.
- To understand how the Service is used - a cookieless page-view count, only if you allow it (see section 5). Legal basis: your consent, which you can withdraw at any time.
- To meet legal obligations - where we are required to keep or disclose information. Legal basis: legal obligation.
4. Who can see your data
- Other people in your company. The Service is a shared workspace. Owners, and the workers, buyers, and drivers your owner approves, can see company, site, order, and activity data according to the Service’s permission rules. Your display name and the actions you take are visible to them.
- Our service providers (see section 6), who process data only on our instructions.
- Authorities or advisers, where we are legally required to disclose, or need to establish or defend legal claims.
We do not sell your personal data, and we do not use it for advertising.
5. Cookies and local storage
The Service does not use tracking or advertising cookies. It stores a small amount of data in your browser that is strictly necessary to run the Service – a sign-in token and a note of which company and role you last used. The sign-in token is held in session storage, which your browser clears when you close the tab; it is never written to disk by us. This storage does not require consent, and blocking it will stop the Service working.
For basic page-view analytics we use Cloudflare Web Analytics, which is cookieless: it counts page views without setting cookies, without fingerprinting your device, and without tracking you across other sites. It does not store your IP address and does not identify individual visitors. Even so, it is optional: a short notice on your first visit asks you to choose “Allow analytics” or “Essential only”, and the analytics script only loads if you allow it. You can change that choice at any time from the “Cookie choices” link in the footer.
We also use Microsoft Clarity for session recordings and heatmaps – a record of how a visitor moved through a page (clicks, scrolling, taps), so we can find and fix confusing screens without guessing. It is gated by the exact same “Allow analytics” choice as Cloudflare Web Analytics above, is never switched on for anyone who chooses “Essential only”, and records the page you are looking at, not the contents of password fields or any field marked sensitive, which Clarity masks automatically before anything leaves your browser. See section 6 for what it receives.
6. Where your data is stored and processed
At a glance, this is every outside service the Service uses and what each one receives. None of them is used for advertising or to profile you, and none sets a tracking cookie.
| Service | What it receives | Why |
|---|---|---|
| Supabase | Everything you and your team enter (account, company, site, order, message and photo data), plus your IP address and request times in its security logs | The database, login, and file storage behind the app |
| Brevo | Your email address and the contents of the account emails we send you (sign-up confirmation, password reset, email change) | Delivers those emails on our behalf |
| GitHub Pages | Your IP address and which pages you request | Serves the website files |
| postcodes.io | A single postcode you type into a site or delivery field - nothing else | Converts it to approximate map coordinates |
| Cloudflare Turnstile | Your IP address and basic browser signals, on the sign-in and sign-up screens only (when the check is switched on) | Confirms you’re a person, not a bot |
| Have I Been Pwned | The first five characters of a one-way hash of a password you set - never the password, your email, or any account detail | Warns you if that password is in a known breach |
| Google, Microsoft or Apple | Only if you choose “Continue with” one of them: that provider confirms who you are and passes us your name and email address. If you sign in with an email and password instead, none of them is contacted | Optional social sign-in |
| Cloudflare Web Analytics | Only if you allow analytics: the page path and referring page. It does not store your IP address, sets no cookie, and does not identify you | Counts page views |
| Microsoft Clarity | Only if you allow analytics: a recording of clicks, scrolling and taps on the page, with password and other sensitive fields automatically masked before it leaves your browser | Session recordings and heatmaps, to find and fix confusing screens |
More detail on each:
- Supabase
- Database, authentication, file storage, and hosting for the application back end. Data is held in a Supabase region in the UK or Ireland; Ireland is in the EEA and covered by the UK’s adequacy decision.
- GitHub Pages
- Serves the static website files.
- Brevo (Sendinblue)
- Our email provider. When the Service needs to email you - to confirm your address at sign-up, to send a password-reset link, or to confirm an email change - your address and that message are handled by Brevo to deliver it. It is not used for marketing, and we do not add you to any mailing list.
- postcodes.io
- UK postcode lookup, run by a UK non-profit. When a postcode is entered for a site or a delivery, that postcode alone is sent to convert it to approximate coordinates; no account or personal data is sent.
- Cloudflare Turnstile
- A privacy-focused “are you human” check. If it is switched on, you will see it on the sign-in and sign-up screens; your browser contacts Cloudflare to run the check, which involves your IP address and basic browser signals. It does not use tracking cookies and is not used to advertise to you or profile you. No account data is sent to it.
- Have I Been Pwned (Pwned Passwords)
- When you set or change a password, your browser checks it against a public database of passwords exposed in known data breaches, and warns you if it appears. Only the first five characters of a one-way hash of the password are sent - never the password, your email, or any account detail - so the service cannot tell which password or account was checked. No cookie is set.
- Google, Microsoft, Apple (social sign-in)
- The sign-in screen may offer “Continue with Google / Microsoft / Apple”. If you use one, you are sent to that provider to confirm who you are, and it returns your name and email address to create or match your SiteStock account - nothing more, and only for the provider you pick. It also means that provider knows you use SiteStock. If you sign in with an email and password, none of these providers is involved at all.
- Cloudflare Web Analytics
- Optional cookieless page-view analytics (see section 5), loaded only if you choose “Allow analytics” in the cookie notice. When enabled, your browser sends one measurement request when a page loads; Cloudflare aggregates page path, referrer, and coarse browser/country information. It does not store your IP address, sets no cookie, and does not identify individual visitors. Cloudflare, Inc. is a US company; this data is covered by its standard data-processing terms.
- Microsoft Clarity
- Optional session recordings and heatmaps (see section 5), loaded only if you choose “Allow analytics” in the cookie notice - the exact same choice that gates Cloudflare Web Analytics above, not a separate one. It is configured in Strict Mode, which masks every piece of text on the page - names, addresses, postcodes, order details, everything - by default before it ever leaves your browser, and only the shape of what you clicked, scrolled to, or typed into is recorded, not the content. Microsoft is a US company; this data is covered by its standard data-processing terms. Free, with no separate charge to you.
Fonts, scripts and all other page assets, including the software library the app is built on, are served from the Service’s own domain. There is no Google Fonts, advertising, social-media, or cross-site tracking request of any kind.
Where a provider processes data outside the UK or EEA, we rely on an adequacy decision or on standard contractual clauses (or the provider’s equivalent safeguards) to protect it.
7. How long we keep it, and how to delete it
- Account data is kept while your account is open. You can delete your account at any time from your profile. When you do, we immediately and permanently delete your login and personal details - your email address, your hashed password, your sign-in sessions, your two-factor setup, your notifications and notification settings, any pending join or access requests, and the diagnostic error reports tied to your account - and remove you from every company team. This is removed from our providers’ backups as those backups rotate out (within 30 days). You cannot delete your account while you still own a company; transfer it to another owner, or delete the company, first.
- Company, site, and order data is kept while the company exists. An owner can permanently delete a site, or an empty company, from the app. So that a company’s records stay intact, your display name is kept against the orders, messages, and events you created or acted on, even after you delete your account or leave a company - it reads as, for example, “requested by [your name]” on that past order. This part is kept and deleted under the company’s control, not yours, and is covered by the note in section 9 about shared workspaces. To ask for your name to be removed from those records too, contact us (section 9).
- Read notifications older than 90 days are deleted automatically.
- Logs and backups are kept for a limited period by our providers and then rotated out.
We keep data beyond the periods above only where we are required to by law, or where we genuinely need it to establish, exercise, or defend a legal claim - and only for as long as that reason applies.
To ask us to delete personal data outside the in-app account deletion, email arcooreacc@gmail.com; we respond within one month.
8. How we protect it
Access to data is enforced at the database level by row-level security, so each request only returns what that account is entitled to see. Traffic is encrypted in transit. Passwords are hashed by our authentication provider, have a minimum length, and optional two-factor authentication is available. The site sends a strict Content-Security-Policy that blocks third-party and injected scripts, and your sign-in token is kept in session storage rather than long-lived local storage (see section 5). No system is perfectly secure, and while the Service is in development you should not store anything in it that you could not tolerate being lost or exposed.
9. Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- ask us to correct data that is wrong or incomplete;
- ask us to delete your data, or to restrict how we use it;
- object to processing based on our legitimate interests;
- ask for your data in a portable format;
- withdraw any consent you have given, without affecting past processing.
To exercise any of these, contact arcooreacc@gmail.com. Note that where data is part of your company’s shared workspace, some requests may need to go through that company’s owner, and we may not be able to delete data others in your company still rely on without ending your access.
If you are not happy with how we handle your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we would appreciate the chance to put things right first.
10. Children
The Service is for business use by adults. It is not directed at, marketed to, or intended for anyone under 18, and you must confirm you are 18 or over when you create an account (see section 2 of the Terms of Service).
We do not knowingly collect personal data from children, and we do not knowingly collect any personal data from a child under 13. We have no service, feature, or content aimed at children. If we learn that an account has been created by, or that we hold personal data about, someone under 18 - and especially someone under 13 - we will close the account and delete that personal data promptly.
If you are a parent or guardian and you believe a child has given us personal data, or has created an account, please contact us at arcooreacc@gmail.com and we will act on it without delay.
11. Changes to this policy
We may update this policy as the Service develops. The “last updated” date above shows when. For material changes we will give notice in the app or by email.
12. Contact
Privacy questions and rights requests: arcooreacc@gmail.com.