Privacy Policy
Last updated 8 October 2026
This policy explains what personal data [Your full legal name], who operates SiteOps, collects when you use this website and the SiteOps app, why, and what you can do about it. We are the controller of this data.
What we collect
- Account details: your name, email address, password (stored only as a secure hash), two-factor authentication settings and the workspaces you belong to.
- Workspace data: the websites you add, their monitoring results, incidents, WordPress versions, plugins and themes reported by the read-only SiteOps agent, tracking tag IDs found on their homepages, and the business flows you configure. Any credentials you enter for a business flow are stored encrypted.
- Alert settings: email addresses and Slack webhooks you add to receive alerts.
- Usage and security data: IP address, browser, sign-in times and active sessions, used to keep your account secure.
- Billing details: handled by Paddle. We receive your plan, billing status, country and invoices, but never your full card details.
- Messages: what you send us when you email support.
Why we use it
- To provide SiteOps: run checks, show results and send the alerts you set up (performing our contract with you).
- To keep accounts and the service secure, and prevent abuse (our legitimate interest).
- To manage subscriptions, invoices and taxes (contract and legal obligation).
- To email you about your account, billing and important service changes. We send marketing email only if you agree to it, and you can unsubscribe at any time.
We do not sell personal data, and we do not use it for advertising.
Who we share it with
We share data only with service providers who help us run SiteOps, under contracts that protect it:
- Paddle, our reseller and merchant of record, for payments, tax and invoices.
- Resend, to deliver account and alert emails.
- Slack, only when you connect a Slack webhook for alerts.
- Our hosting and infrastructure providers, which store and run the service.
We may also disclose data when the law requires it.
International transfers
Our providers may process data in countries other than yours. Where required, transfers are protected by appropriate safeguards such as standard contractual clauses.
How long we keep it
We keep account and workspace data while your account is active. When you delete a workspace or your account, we delete its data within 30 days, except billing records we must keep for tax and accounting law.
Cookies
The SiteOps app uses only the cookies needed to keep you signed in and secure. This website does not use advertising or analytics cookies. Paddle’s checkout may set its own cookies to process a payment.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, or object to or restrict how we use it. Email [email protected] and we will respond within 30 days. You can also complain to your local data protection authority.
Security
We protect data with encryption in transit, hashed passwords, optional two-factor authentication, encrypted storage of business flow credentials and access limited to what each role needs.
Children
SiteOps is a business service and is not meant for anyone under 18.
Changes
We will post any change here and update the date above. If a change is significant, we will also tell you by email.
Contact
[Your full legal name]. Email [email protected].