This Privacy Policy explains how SiteBrew (“SiteBrew,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our website, planning workspaces, and related services (the “Service”).
1. Scope
This policy applies to visitors, account holders, invited collaborators, and people who contact us through the Service. It does not govern third-party websites or services that have their own privacy notices.
If you use SiteBrew through an organization, that organization may control the workspace and the content in it. Please direct questions about your organization’s use of your information to that organization as well as to us.
2. Information we collect
We collect the following categories of information:
- Account and profile information. Your name, email address, team or organization name, account credentials, profile details, verification status, and workspace role. Passwords are stored in hashed form, not as readable text.
- Workspace content. Site and team names, descriptions, sitemaps, page titles and URLs, page direction and copy, taxonomy, colors, comments, invitations, exports, and other material you or your collaborators add to a workspace.
- Collaboration and activity information. Team and site membership, roles, invitations, comment authorship, page updates, timestamps, and presence information used to show who is viewing or editing a workspace.
- Requests and communications. Information you submit in a quote request, including your name, company, contact details, and the relevant site, plus messages you send to us and transactional email delivery information.
- Device and usage information. IP address, browser and device details, request and security logs, session identifiers, approximate request time, referring page, and information used for rate limiting, troubleshooting, analytics, and abuse prevention.
- Analytics information. Google Analytics receives page views using a sanitized page path, along with general device, browser, approximate location, and interaction information generated by the Google tag. We do not send Google Analytics account IDs, email addresses, form contents, workspace content, URL query strings, invite tokens, or password-reset tokens.
- Information from service providers. Fraud and abuse assessment data from Google reCAPTCHA and delivery or service-status information from providers that support the Service.
We receive information directly from you, from other users who invite you or collaborate with you, automatically from your browser, and from the service providers described below.
3. How we use information
We use information to:
- create, verify, secure, and administer accounts and sessions;
- provide sitemaps, page planning, content editing, taxonomy, comments, team collaboration, exports, and related workspace features;
- send account verification, password reset, invitation, service, and other transactional messages;
- process and respond to quote requests, support requests, and other communications;
- protect the Service, prevent fraud and abuse, enforce limits, and investigate security incidents;
- measure page usage, maintain, troubleshoot, improve, and understand the performance of the Service; and
- comply with law, resolve disputes, and enforce our agreements.
Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in providing and securing the Service, consent where requested, and compliance with legal obligations.
6. Public demo
The public demo uses isolated sample data in your browser. Changes made in the demo reset when the page is refreshed and are not added to an account workspace. Standard network, security, and request information may still be processed when you load or use the demo. Do not enter personal, confidential, or production information into the demo.
7. Data retention
We retain account and workspace information for as long as needed to provide the Service, maintain the account or workspace, and fulfill the purposes described in this policy. We may retain certain records longer when reasonably necessary for security, backup and recovery, dispute resolution, legal compliance, or enforcement of our agreements.
Retention can also depend on workspace settings, the actions of workspace owners, and contractual requirements. When information is no longer needed, we take reasonable steps to delete or de-identify it.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls, hashed passwords, secure production cookies, encrypted network connections, request validation, and restricted database access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
You are responsible for using a strong, unique password, protecting your sign-in details, and limiting workspace access to appropriate collaborators.
9. International data transfers
SiteBrew and its service providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use recognized safeguards for international transfers.
10. Your choices and privacy rights
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; object to or restrict certain processing; withdraw consent; or appeal a decision about a privacy request. You may also have the right to complain to your local data-protection authority.
You can update some profile and workspace details in the Service. For other requests, contact us using the information below. We may need to verify your identity and authority before completing a request. If your information is controlled by a workspace owner or organization, we may direct your request to that organization.
Agreeing to the Terms of Service is an account agreement and is not represented as separate consent to advertising or personalized analytics. Depending on where you live, additional choices or rights may apply.
11. Children’s privacy
The Service is not directed to children and is not intended for anyone under 13. If the law where you live requires a higher minimum age to use an online service without parental consent, you must meet that age. If we learn that we collected a child’s personal information in violation of applicable law, we will take reasonable steps to delete it.
12. Changes to this policy
We may update this policy as the Service, our practices, or legal requirements change. We will post the revised policy here and update the effective date. If changes are material, we may provide additional notice through the Service or by email when appropriate.
13. Contact us
For questions about this policy or to make a privacy request, email privacy@sitebrew.app.