Legal
Privacy Policy
Your privacy matters. This policy explains what personal data Sitewatch collects, how we use it, how we protect it, and your rights under GDPR and other privacy regulations. We collect only what is necessary to deliver the monitoring service -- nothing more.
- GDPR compliant with full data subject rights
- Data encrypted in transit and at rest
- We never sell your data to third parties
01Key points
What you need to know
What data we collect
Account information (name, email), website URLs submitted for monitoring, monitoring results and logs, usage analytics, and payment information processed securely by Stripe.
How we use it
To provide the monitoring service, send alerts and notifications, process payments, improve product quality, and communicate important service updates.
Data storage & security
All data is stored on Google Cloud and Firebase infrastructure in the EU region (europe-west2). Data is encrypted both in transit (TLS) and at rest (AES-256).
Third-party services
We use Firebase (infrastructure), Stripe (payment processing), Bugsnag (error tracking), and Google Analytics (usage analytics). Each processes only the minimum data required.
Cookies
We use only essential cookies: authentication session cookies and service cookies required for the application to function. No advertising or third-party tracking cookies.
Your rights
You have the right to access, correct, and delete your personal data. You can request a data export, withdraw consent, or delete your account at any time.
02Transparency
Data we collect in detail
Account data
- Name and email address for authentication and communication
- Payment and billing information processed securely by Stripe -- we never store card details
- Account preferences, notification settings, and alert channel configuration
Monitoring data
- Website URLs you submit for monitoring
- HTTP response codes, headers, and page content fingerprints from monitoring checks
- Incident records including failure details, timelines, and resolution status
- Performance metrics and asset status codes for configured monitors
Page analysis data
- A structural summary of each public page we check: its title, its headings, the labels on its buttons, which types of form field are present, and the hostnames of the third-party scripts it loads
- That summary is sent to Anthropic (the Claude AI model) to rate how important the page is to your business. It is not used to train any model
- Never included: query strings, cookies, form contents, or personal data. We fetch public pages only and never sign in to your site
Usage & analytics data
- Feature usage patterns to improve the product experience
- Error and crash reports collected via Bugsnag for service reliability
- Aggregated analytics via Google Analytics (anonymized, no personal identifiers)
03GDPR compliance
Your rights under GDPR
Lawful basis for processing
We process your data under legitimate interest (delivering the monitoring service you signed up for) and contractual necessity. For analytics, we rely on consent where required.
Right to access
You can request a copy of all personal data we hold about you. We will respond to access requests within 30 days as required by GDPR.
Right to be forgotten
Request deletion of your account and all associated data at any time. Monitoring data is deleted within 72 hours of account closure. Contact hello@getsitewatch.com to make a request.
Data portability
You can export your monitoring data in standard formats. We support data portability rights so you are never locked in to our service.
Data retention
Monitoring data is retained based on your plan. Upon account deletion, all personal and monitoring data is permanently deleted within 72 hours from all storage systems.
Contact for privacy requests
For any privacy-related questions, data access requests, or deletion requests, contact us at hello@getsitewatch.com. We aim to respond within 48 hours.
Privacy-first monitoring
Monitor your websites without compromising privacy. Free plan available, no credit card required.
04FAQ
Privacy frequently asked questions
We collect your account information (name, email), the website URLs you configure for monitoring, monitoring results and logs, usage analytics, and payment information. Payment details are processed by Stripe -- we never store your card numbers. We collect only what is necessary to provide the service.
No. Your data is never sold, shared with advertisers, or used for any purpose other than delivering the Sitewatch service. We do not monetize your data in any way.
You can delete your account from your account settings or by contacting hello@getsitewatch.com. Upon deletion, all personal data and monitoring data is permanently removed from all storage systems within 72 hours. We will confirm deletion by email.
All data is stored on Google Cloud and Firebase infrastructure in the EU region (europe-west2, London). Data is encrypted in transit using TLS and at rest using AES-256 encryption. One processing step reaches outside that infrastructure: to rate how important a page is, Sitewatch sends a structural summary of that public page to Anthropic. See "Do you send my website content to an AI provider?" below.
Only a structural summary, and only for pages that are already public. To work out which of your pages matter most, Sitewatch sends Anthropic (the Claude AI model) the page title, its headings, the labels on its buttons, which types of form field exist, and the hostnames of the third-party scripts that load. It never sends query strings, cookies, form contents or personal data, and the summary is not used to train any model. The result is stored on your own site record and is never shared.
We use only essential cookies required for the service to function: authentication session cookies to keep you logged in, and service cookies for application state. We do not use advertising cookies, third-party tracking cookies, or any form of cross-site tracking.