Privacy Policy & Data Retention
Effective date: July 28, 2026
Last updated: September 19, 2026
This Privacy Policy explains how Ascent Web Solutions ("SyteCheck", "we", "us") collects, uses, shares, and retains personal data when you use SyteCheck (the "Service"). It supplements our Terms of Service.
1. Who is responsible
Ascent Web Solutions is the controller of the personal data described here. For privacy questions or to exercise your rights, contact [email protected].
2. Data we collect
a. Account data (you provide).
- Email address.
- A securely hashed password (we never store your password in plaintext; it is stored as a bcrypt hash). If you sign in with Google, we store your Google account identifier and email instead of a password.
- Account preferences (for example, your default scan settings, interface language, light/dark theme, and whether you want scan-completion emails).
- How you heard about SyteCheck, if you choose to tell us when you first sign in. This question is optional.
- How you arrived when you signed up: the website that referred you (its domain only,
not the full address), any campaign tags in the link you followed (such as
utm_source), and the first page you visited. Your browser holds this only for that browsing session, and we store it with your account only if you create one.
b. Scan data (you generate by using the Service).
- The target URLs you submit and any labels you add.
- The analysis results for each scan, including per-category findings, scores, an executive summary, and the raw analyzer output retained for report generation.
- Screenshots of the scanned pages, captured at mobile, tablet, and desktop viewport sizes.
- Optional webhook URLs you configure to receive scan results.
Because a scan inspects a third-party web page, the results and screenshots may incidentally contain personal data that appears on that page (for example, names, email addresses, or photos in the site's content). See §6 for how we treat this.
c. API usage data.
- If you create API keys, we store a hash of each key (never the raw secret), a non-secret key prefix so you can recognize it, and usage counters (number of requests and scans, and last-used time).
d. Billing data (if you buy a paid plan or a one-off scan).
- Paid plans are sold through a payment provider acting as merchant of record (§4). We never receive or store your card number, and we do not process your payment. From the provider we receive only what we need to run your account: the plan you bought, its status and renewal date, the country the provider determined for tax purposes, and a provider-side customer and subscription identifier.
- The provider itself collects your payment details and billing address directly from you, under its own privacy policy.
e. Technical and log data (collected automatically).
- When you access the Service, our servers and error-monitoring tooling may log technical information such as your IP address, user-agent, and the requested path — for example, when an unauthorized attempt is made to reach a restricted endpoint. This information is used for security, abuse prevention, and debugging. It lives in operational logs and our error-tracking provider; it is not stored as part of your account or scan records in our primary database.
- We do not use third-party advertising cookies. Authentication uses tokens necessary to keep you signed in.
3. How we use your data
We use personal data to:
- Provide the Service — run scans, render and store reports and screenshots, and show you your history.
- Authenticate you and secure your account and API keys.
- Send transactional messages you have enabled or that are necessary to operate the account (for example, password-reset emails and, if enabled, scan-completion notifications).
- Apply the entitlements of the plan you purchased, and send billing-related messages about your subscription.
- Enforce rate limits, quotas, and our Acceptable Use Policy, and to detect, prevent, and investigate abuse, fraud, and security incidents.
- Maintain, debug, and improve the Service.
- Understand, in aggregate, how people find the Service, so we know which channels work.
- Comply with legal obligations.
Legal bases (GDPR). Where GDPR applies, we rely on: performance of a contract (to provide the Service you request); our legitimate interests (security, abuse prevention, and improving the Service); your consent (where we ask for it, such as optional notifications — which you can withdraw); and compliance with legal obligations.
4. When we share data — sub-processors
We do not sell your personal data. We share it only with service providers ("sub-processors") that process it on our behalf to run the Service, under contractual confidentiality and data-protection obligations. Current sub-processors:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Anthropic (Claude API) | AI visual/aesthetic analysis, AI-visibility analysis, executive-summary generation, and on-demand report translation | Screenshots of scanned pages and extracted page text/findings are transmitted for analysis; results are returned to us. |
| Render | Application hosting (API, worker, database, key-value store) | All stored account and scan data resides on this infrastructure. |
| Cloudflare (R2 object storage; Pages) | Screenshot storage; frontend delivery | Scan screenshots; requests to the web app. |
| Email delivery provider (e.g. Postmark / Resend / SMTP, as configured) | Sending transactional email | Your email address and the message content. |
| Sentry (if enabled) | Error monitoring | Technical/log data, which may include IP address and user-agent. |
| Google (if you use Google Sign-In) | Authentication | Your Google identifier and email, exchanged during login. |
Our payment provider is not a sub-processor. Paid plans are sold through a payment provider acting as merchant of record — it is the seller of the transaction, not a processor acting on our behalf, and it is an independent controller of the payment data you give it. It decides how to handle that data for its own legal purposes, including collecting and remitting tax, preventing fraud, and complying with financial regulation, under its own privacy policy rather than this one. The provider is identified at checkout; we share your email address with it so it can associate the purchase with your account, and it shares back the limited subscription data described in §2(d).
We may also disclose data if required by law, to enforce our Terms, or to protect the rights, safety, and security of SyteCheck, our users, or the public. If we undergo a merger, acquisition, or asset sale, data may be transferred subject to this policy.
International transfers. Our providers may process data outside your country, including in the United States. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses for such transfers.
5. Data retention
We keep personal data only as long as needed for the purposes above, then delete it on the following schedule. These windows are enforced automatically by a scheduled purge job, not merely stated as policy:
- Scan records, results, and screenshots are retained for a period that depends on your plan — 30 days on the free plan and up to 12 months on a paid plan — from the date the scan was created, after which they are permanently deleted, both the database rows and the stored screenshot files. The current retention period for each plan is stated in the Terms of Service §6. If your plan changes to one with a shorter window, the longer window continues to apply for a further 14 days, so a cancellation never deletes your history overnight; we show you that date on your billing page and in the email confirming the plan has ended.
- Scans you delete are hidden immediately (a "soft delete," so they disappear from your account right away, and no feature of the Service will restore them). The record itself remains in our database until it is permanently purged 30 days after you delete it, including its screenshots. During that window our administrative staff can still reach it directly — for instance to recover a scan you deleted by mistake, or where a security or abuse investigation requires it (§9). After the purge it is gone and cannot be recovered by anyone.
- Account data is retained while your account is open. When you delete your account (§7), it is erased immediately.
- API keys persist until you revoke them or delete your account; revocation is immediate.
- Billing records. The subscription data we hold (§2(d)) is deleted with your account. The transaction records themselves are held by our payment provider as merchant of record, which retains them for as long as tax and accounting law requires — typically several years — independently of your account with us. Deleting your SyteCheck account does not erase the provider's records of a purchase, because it is legally required to keep them.
- Operational logs and error-monitoring data are retained on a shorter rolling basis by the respective systems and are used only for security and debugging.
We may retain limited information longer where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
6. Screenshots and content of third-party sites
A scan captures screenshots and extracts content from the target website so we can analyze it, and it transmits screenshots and page text to our AI sub-processor (Anthropic) for analysis. This material may include personal data that the third-party site itself publishes.
- Screenshots are stored privately. They are never served from a public URL; the app displays them only to you (and our support/administrative staff acting on your account) through short-lived, signed links that expire automatically.
- This content is retained and purged on the same schedule as the scan it belongs to (§5), and it is deleted when you delete the scan or your account.
- You are responsible for having authorization to scan a target (see the Terms, §3). If you believe a scan captured personal data about you that a SyteCheck user was not authorized to collect, contact [email protected].
7. Deleting scans and erasing your account
- Delete a scan: you can delete any individual scan from your history. It is hidden immediately and permanently purged (with its screenshots) within 30 days.
- Erase your account ("right to be forgotten"): you can permanently delete your entire account from your account settings. This is immediate and irreversible: your user record, all of your scans, their results and screenshots, your API keys, and your authentication tokens are deleted, and the associated screenshot files are removed from object storage. Any active sessions and API keys stop working at once. Where records of administrative actions must be retained for accountability, any reference to you in those internal audit records is cleared. Two things this cannot reach: if you have an active paid subscription, cancel it before erasing your account, and the transaction records held by our payment provider are retained by it under its own legal obligations (§5).
If you cannot access your account, email [email protected] and we will process your request.
8. Your rights
Depending on where you live, you may have rights over your personal data. We honor these rights for all users where we can.
If you are in the EEA, UK, or a similar regime (GDPR): you have the right to access, correct, delete, restrict, or object to processing of your data, to data portability, and to withdraw consent. You may also lodge a complaint with your local data-protection authority.
If you are a California resident (CCPA/CPRA): you have the right to know what personal information we collect and how we use and share it, to access and delete it, and to correct it. We do not sell or "share" personal information for cross-context behavioral advertising, and we do not discriminate against you for exercising your rights.
To exercise any right, use the in-app account and scan controls (§7) or contact [email protected]. We will verify your request against your account and respond within the timeframe required by applicable law.
9. Security
We use industry-standard measures to protect your data, including encrypted transport (HTTPS), hashed passwords and tokens, private storage for screenshots with signed time-limited access, least-privilege access controls, and restricted, audited administrative access. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to incidents.
Your scans are yours. Accounts are strictly separated: no other customer can see your scans, reports, or screenshots, and every request for a scan is checked against the account that created it. Our administrative staff can access an account's records only where necessary — to answer a support request you have made, to investigate abuse or a security issue, or to diagnose a failed scan — and every such access is recorded in an internal audit log that is reviewed regularly. Nobody, ourselves included, can recover your password or an API key you have generated: only irreversible hashes of these are stored.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact [email protected] and we will delete it.
11. Contact and representatives
- Privacy questions and rights requests: [email protected]
- Controller: Ascent Web Solutions — https://ascentwebs.com
- EU/UK representative (if appointed): N/A
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted here with a new effective date and, where appropriate, communicated to you. Please review it periodically.