Privacy Policy
Last updated: 15 July 2026
1. Who we are
SiteSpyAI (“SiteSpy”, “we”, “us” or “our”) is a business-to-business software-as-a-service operated from Ireland. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Irish Data Protection Act 2018, SiteSpy is the data controller of personal data submitted by our customers’ authorised users and the data processor of personal data our customers process through the service.
Questions or requests can be sent to privacy@sitespyai.com.
2. Scope
This policy applies to the SiteSpyAI web application, marketing website and related APIs. SiteSpy is a B2B tool used by professional users in the course of their employment. We do not knowingly market to or collect data from children.
3. Personal data we process
- Account data — name, work email, hashed password or federated identity, workspace and role.
- Billing data — company name, billing address, VAT number, plan, invoice history. Card details are captured directly by Stripe and never touch our servers.
- Usage data — scan history, search queries, filters, exports, feature interactions, IP address, user agent, approximate location derived from IP.
- Support data — messages you send us and any attachments.
- Scan output — publicly available business information (name, address, imagery from Google Street View, derived facility metrics). This is business data about commercial premises and, in the EEA, typically does not identify a living individual; where it incidentally does, GDPR applies.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide and maintain the service | Contract — Art. 6(1)(b) |
| Bill customers and prevent payment fraud | Contract & legal obligation — Art. 6(1)(b), (c) |
| Secure the service, detect abuse, keep audit logs | Legitimate interests — Art. 6(1)(f) |
| Improve the product and analytics | Legitimate interests — Art. 6(1)(f) |
| Send transactional emails (receipts, security) | Contract — Art. 6(1)(b) |
| Send product marketing to business contacts | Legitimate interests / consent where required |
| Comply with tax and accounting law | Legal obligation — Art. 6(1)(c) |
5. How we use Google Maps data
SiteSpy uses the Google Maps Platform APIs (Places, Geocoding and Street View Static) to locate commercial premises and retrieve street-level imagery, which our spatial AI then analyses. Your use of Google-sourced content is additionally governed by the Google Privacy Policy. We do not send your account credentials to Google; only search queries and coordinates necessary to fulfil your scan.
6. Sub-processors
We rely on a small number of vetted sub-processors. Each is bound by a data-processing agreement compliant with GDPR Art. 28 and, where applicable, the EU Standard Contractual Clauses.
- Supabase — managed Postgres, authentication and file storage. EU region hosting.
- Stripe Payments Europe, Ltd. — payment processing and subscription billing (Ireland).
- Google Ireland Ltd. — Maps Platform APIs (Places, Geocoding, Street View).
- Cloudflare, Inc. — content delivery, DDoS protection and edge compute.
7. International transfers
Personal data is stored in the European Union by default. Where a sub-processor transfers data outside the EEA (for example Stripe or Cloudflare processing in the United States), we rely on the EU Commission’s Standard Contractual Clauses and, where available, the EU–US Data Privacy Framework, together with supplementary technical measures such as encryption in transit and at rest.
8. Retention
- Account data — for the life of the account and 30 days after deletion.
- Billing records — 7 years, as required by Irish tax law.
- Scan history — for the life of the account, unless deleted earlier by the user.
- Application logs — up to 90 days.
- Support correspondence — up to 24 months.
9. Your rights
Subject to GDPR you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. Send requests to privacy@sitespyai.com. We will respond within one month. You may lodge a complaint with the Irish Data Protection Commission (dataprotection.ie), which is our lead supervisory authority.
10. Security
We use TLS in transit, encryption at rest, row-level authorisation in our database, principle-of-least-privilege access controls, audit logging, and regular dependency scanning. No system is perfectly secure; if you believe you have discovered a vulnerability, please email security@sitespyai.com.
11. Cookies
We use strictly necessary cookies for authentication and CSRF protection, and first-party analytics cookies to measure product usage in aggregate. We do not use third-party advertising cookies.
12. Changes to this policy
We will post material changes on this page and, where appropriate, notify account administrators by email at least 14 days before they take effect.