Effective date: August 23, 2026
Privacy Policy
This Policy explains how Siteplane handles personal data when you use our website, product and support channels.
1. Controller and contact
Lukas van Uden operates Siteplane and is the controller for the processing described in this Policy. For privacy questions or requests, email hello@siteplane.io.
2. Data we process
- Account and profile data: name, email address, authentication status, role and onboarding choices.
- Workspace and website data: site URLs, project configuration, structured content, assets, memberships, invitations, drafts, changes and audit history.
- Technical and security data: IP address, device and browser information, timestamps, request identifiers, logs and security events.
- Communications: messages and information you send through support, waitlist or email channels.
- Enabled feature data: analytics, booking, payment and connected-service data when you choose to use those features.
3. Why we process data
- To create accounts, provide requested features and support users under Article 6(1)(b) GDPR.
- To secure, maintain and improve Siteplane, prevent abuse and understand service reliability under our legitimate interests in Article 6(1)(f) GDPR.
- To comply with tax, accounting and other legal duties under Article 6(1)(c) GDPR.
- For optional processing based on consent under Article 6(1)(a) GDPR, where consent is requested.
4. Customer website data
When a Siteplane customer uses the service to process personal data about their own clients or website visitors, that customer generally determines the purpose and means of processing and acts as controller. Siteplane then processes that data on the customer's behalf, subject to the applicable agreement and instructions. Requests about that data should normally be directed to the relevant customer first.
5. Service providers and recipients
We share data only where needed to operate Siteplane, follow your instructions or meet legal duties. Providers may include Supabase for authentication, databases and storage; Vercel for hosting; Resend for email; GitHub for connected source-control workflows; and Stripe for enabled payment features. We may also disclose data to professional advisers or public authorities where legally required. Each optional provider receives data only when its feature is used.
6. International transfers
Some providers may process data outside the European Economic Area. Where required, we rely on an adequacy decision, standard contractual clauses or another lawful transfer mechanism and apply appropriate safeguards.
7. Retention
We keep account, workspace and website data while the service is active and as needed to provide requested features. After deletion or termination, we remove or anonymize data according to operational backup cycles, configured feature-retention periods and legal requirements. Security records are kept only as long as reasonably necessary to investigate abuse and protect the service. Billing and transaction records may be retained for statutory periods.
8. Cookies and browser storage
The Siteplane product uses cookies and similar browser storage where necessary for authentication, security, session continuity and user preferences. We do not currently use non-essential advertising cookies in the Siteplane app. Customer websites may have their own storage and consent choices, which are controlled by the relevant website owner.
9. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction or portability of your personal data, and may object to processing based on legitimate interests. You can withdraw consent at any time without affecting earlier lawful processing. You also have the right to complain to a competent data-protection supervisory authority. Send requests to hello@siteplane.io.
10. Security
We use technical and organizational measures designed to protect personal data, including scoped access controls, encryption in transit, audit records and restricted service credentials. No internet service can guarantee absolute security, so please contact us promptly if you suspect misuse of your account.
11. Changes to this Policy
We may update this Policy when Siteplane, our providers or legal requirements change. We will provide reasonable notice of material changes, and the effective date above identifies the current version.