Draft. Fill in the highlighted details in lib/legal.ts and have the text reviewed. Until then these pages aren't indexed or linked.
Legal
Privacy Policy
How SiteBackend handles personal data, both yours as a customer and that of the people who fill in your forms.
Effective 28 September 2026
In short
- No analytics, no ads, no tracking cookies. Our cookies keep you signed in and keep a support chat going.
- We store form submissions for the website owner who created the form, and deliver them only where the owner chooses.
- Sender IP addresses are stored as hashes, and notification secrets are encrypted.
- We never sell personal data. It stays until you delete it, and deleting it removes uploaded files too.
Who we are
SiteBackend is run by [company legal name], [registered address] ("we", "us"). This policy explains how we handle personal data when you visit our website, create an account, or send a message through a form that uses SiteBackend.
We play two different roles, depending on whose data it is:
- Controller for our customers' account data and for visitors to our website.
- Processor for form submissions. The website owner who created the form decides what it collects and what happens to it. We store and deliver it on their behalf under our Data Processing Agreement.
What we collect
When you create and use an account
- Your name, email address and password. Passwords are stored only as a secure hash.
- Sign-in sessions, with the IP address and browser (user agent) they started from, so you can review and end them.
- Your workspaces, sites and forms, team memberships and invitations, including the email addresses you invite.
- Notification settings, such as email recipients, chat channels and webhook URLs. Tokens and secrets for these are stored encrypted.
- Usage counts, such as submissions received this month, so we can apply your plan's limits.
- If you upgrade: your plan, billing period, renewal date and the payment provider's customer and subscription IDs. Payments are handled by Dodo Payments as merchant of record: they collect your card or other payment details and your billing address, and we never see or store your full card number.
When someone submits a form that uses SiteBackend
- The fields the form sends, exactly as sent, and any files attached.
- Technical details: a hashed version of the sender's IP address (we never store the raw IP), their country as reported by our network provider, their browser (user agent) and the page they submitted from (referrer).
- A spam score and the reason for it, when our spam checks flag a submission.
- If the form owner turns on contacts: a contact record for each email address, with the name if given, when they were first and last seen, how many times they've submitted, and any notes or tags the owner's team adds.
When someone leaves a testimonial through a SiteBackend widget
- What they write, their name, and, if the site owner asks for them, a star rating, their role and company, and a photo.
- That they agreed to have it shown publicly, and a hashed version of their IP address (used only to limit repeated submissions).
- The site owner decides whether to publish it. Only approved testimonials are shown on the owner's website, and only the name, role, company, photo, rating and text.
When you visit our website
We don't use analytics, advertising or tracking tools. Our servers process your IP address and browser details to deliver pages and protect the service, and our hosting infrastructure may keep them briefly in standard server logs.
Our website and dashboard have a live chat from Crisp. If you write to us there, Crisp stores your messages, and any name or email address you give, so we can reply.
Why we use it
- To provide the service you signed up for (performance of a contract): running your account, receiving and storing submissions, sending notifications and applying plan limits.
- To keep SiteBackend secure and working (legitimate interests): spam and abuse prevention, rate limiting and fixing errors.
- To send account emails (performance of a contract): email verification, password resets, invitations and usage alerts. We don't send marketing email.
- To meet legal obligations, for example responding to lawful requests from authorities.
Cookies and local storage
We use only what the service needs to work:
- A sign-in session cookie, set when you log in, so the dashboard knows it's you. It's strictly necessary, so it doesn't need consent.
- Your dashboard theme choice (light, dark or system), kept in your browser's local storage. It never leaves your device.
- A chat cookie from Crisp, so a support conversation you started carries on across pages and visits. It isn't used for advertising or tracking.
Forms on other websites may use a captcha from Cloudflare Turnstile, hCaptcha or Google reCAPTCHA if the site owner turns one on. Those services run on the owner's site under their own policies.
Who we share it with
We don't sell personal data or share it for advertising. It goes only to:
- Our subprocessors, who host, store, email, take payments and run our support chat for us under contract. They're listed on the Subprocessors page.
- Destinations the form owner chooses. Submissions are sent wherever the owner sets up notifications: email, Slack, Discord, Microsoft Teams, Telegram, WhatsApp, Google Sheets or their own webhook. Those services handle the data under their own terms.
- Captcha providers, when the form owner turns one on. The captcha token and the sender's IP address are sent to that provider to verify the submission.
- Authorities, when the law requires it, or to protect people and the service from harm.
How long we keep it
- Submissions, files and contacts are kept until the form owner deletes them, or deletes the form, site or workspace they belong to. Deleting them removes the stored files too. Submissions marked as spam are kept until deleted in the same way.
- Notification delivery records, which hold a copy of the message sent, are deleted along with their submission or notification channel.
- Testimonials and their photos are kept until the site owner deletes them, or deletes the site or workspace they belong to.
- Account data is kept while your account is open. You can delete your account yourself in Account settings: it's removed right away, together with the workspaces only you were in, except anything the law requires us to keep.
- Backups may hold deleted data for a short time until they're replaced.
How we protect it
- All traffic to SiteBackend is encrypted in transit with HTTPS.
- Notification secrets and tokens are encrypted at rest (AES-256-GCM), and sender IP addresses are stored only as keyed hashes.
- Uploaded files are private: only signed-in members of the workspace can download them.
- Each workspace's data is visible only to its members, who have owner, admin or member roles.
Where your data is stored
Our servers and database run in [hosting region]. Some subprocessors may process data in other countries. Where data leaves the UK or the European Economic Area, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses.
Your rights
Depending on where you live (for example under the GDPR, UK GDPR or California law), you can ask to access, correct, delete or export your personal data, and to restrict or object to how we use it. You can also complain to your local data protection authority.
Your data & rights explains what you can do yourself in the dashboard and how to ask us for the rest. If you sent a message through someone's form, contact that website's owner first: they control that data, and we'll help them respond.
Children
SiteBackend is a tool for businesses and developers. It isn't meant for children under 16, and we don't knowingly collect their data.
Changes to this policy
When we make a significant change, we'll tell account holders by email or in the dashboard before it takes effect, and update the date at the top of this page.
Contact
Questions or requests about privacy: [privacy email]. Post: [company legal name], [registered address].