Privacy Policy
Last updated: May 3, 2026
Introduction
This Privacy Policy explains how Sitefire (“we”, “our”, or “us”) collects, uses, and protects your information when you use our website and services. We are committed to protecting your privacy and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
By using our services, you agree to the collection and use of information in accordance with this policy.
Data controller
Sitefire is the data controller responsible for the processing of your personal data. For any questions about this privacy policy or our data practices, please contact us at:
Email: privacy@sitefire.ai
Information We Collect
Automatically Collected Information
- IP address and general location information
- Browser type and version
- Operating system
- Pages visited and time spent on pages
- Referring website
- Device information (screen resolution, device type)
Session Recordings (PostHog)
With your explicit consent, we use PostHog to record user sessions to improve our website functionality and user experience. These recordings may include:
- Mouse movements and clicks
- Page interactions and form inputs (sensitive data is automatically masked)
- Navigation patterns
- Error messages and performance issues
Information you provide
When you use our services, you may voluntarily provide:
- Email addresses for website analysis
- Feedback and support requests
- Any other information you choose to share
How we use your information
We use the collected information for the following purposes:
- Service provision: To provide and maintain our website and services
- Analytics: To understand how users interact with our website and improve user experience
- Performance monitoring: To identify and resolve technical issues
- Security: To protect against fraud and ensure the security of our services
- Communication: To respond to your inquiries and provide support
- Legal compliance: To comply with applicable laws and regulations
Data Processing and Storage
Data processors
We use the following third-party services to process and store your data:
Vercel (Hosting)
Our website is hosted on Vercel, which may collect standard server logs including IP addresses and request information.
Location: Global (with EU data centers)
Privacy Policy: vercel.com/legal/privacy-policy
Supabase (Database)
We use Supabase for data storage and backend services. Supabase is hosted in Frankfurt, Germany.
Location: Frankfurt, Germany (EU)
Privacy Policy: supabase.com/privacy
PostHog (Analytics & Session Recording)
We use PostHog EU Cloud for analytics and session recordings to improve our website functionality.
Location: EU Cloud (GDPR compliant)
Privacy Policy: posthog.com/privacy
Stripe (Payments)
We use Stripe to process payments and manage subscriptions. Stripe handles your payment information (card details, billing address) as an independent data controller for payment processing, and as a data processor for other account-related data such as your email address and subscription status.
Location: USA / Ireland (EU-US Data Privacy Framework)
Privacy Policy: stripe.com/privacy
Resend (Email)
We use Resend to send transactional emails such as account verification, password resets, and team invitations. Resend processes your email address to deliver these messages.
Location: USA (EU-US Data Privacy Framework)
Privacy Policy: resend.com/legal/privacy-policy
Cloudflare Turnstile (Bot Protection)
We use Cloudflare Turnstile on authentication forms to protect against automated abuse. Turnstile may process your IP address and browser characteristics to verify you are a real user.
Location: Global (GDPR compliant)
Privacy Policy: cloudflare.com/privacypolicy
Data retention
- Session recordings: Retained for up to 12 months
- Analytics data: Retained for up to 24 months
- Server logs: Retained for up to 30 days
- User-provided data: Retained until you request deletion
Your rights under GDPR
Under the GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Request your data in a structured format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw consent for data processing
Exercise your rights
To exercise any of these rights, please contact us at privacy@sitefire.ai
We will respond to your request within 30 days and may ask for additional information to verify your identity.
Cookie policy
Cookies are small text files that a website stores on your device. We also use local storage, which works the same way but holds the data until you clear it. This section covers both. German law (§ 25 TDDDG) treats them the same, so we ask for consent before we use any that are not strictly necessary.
Categories
We group these technologies into three categories. You choose each one separately in our consent banner.
- Strictly necessary. The site cannot work without these. They record your consent choice, decide which privacy rules apply to you, and keep the interface in the state you left it. These do not need your consent, but we still list them below.
- Measurement. These tell us how visitors find and use the site, so we can improve it. They include session replay, which records how you move through a page. All text you type is masked before it leaves your browser.
- Marketing. These connect an advertising click to what you do on the site, so we can measure which campaigns work.
What we store
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| Strictly necessary | ||||
c15t | Sitefire | Stores your consent choice and the version of this policy you agreed to | Cookie and local storage | 12 months |
sf_geo | Sitefire | Holds the country and region our hosting provider derives from your IP address, so we can apply the correct consent rules | Cookie | Session |
sidebar_state | Sitefire | Remembers whether the documentation sidebar is open | Cookie | 7 days |
| Measurement (only with your consent) | ||||
ph_*_posthog | PostHog (EU) | Recognizes your browser across visits to count usage and record sessions | Cookie and local storage | 12 months |
_ga, _ga_* | Recognizes your browser and measures sessions in Google Analytics | Cookie | 24 months | |
| Marketing (only with your consent) | ||||
_gcl_au | Connects an advertising click to a later conversion, such as a booked demo | Cookie | 90 days | |
sf_gclid, sf_utm_source | Sitefire | Keeps the advertising click identifier and campaign source from the page you arrived on, so a later booking can be attributed to it | Local storage | Until you clear it |
Third parties and international transfers
PostHog processes measurement data on servers in the European Union. See the PostHog privacy policy.
Google loads through Google Tag Manager and receives measurement and marketing data. Google processes this data in the United States under the EU-US Data Privacy Framework and standard contractual clauses. See the Google privacy policy. No Google technology loads before you consent to the matching category.
Legal basis
For measurement and marketing we rely on your consent, under Article 6(1)(a) GDPR and § 25(1) TDDDG. For strictly necessary storage we rely on § 25(2) TDDDG, which does not require consent, and on our legitimate interest in operating a secure website under Article 6(1)(f) GDPR.
How to withdraw your consent
Select Cookie Settings in the footer of any page. You can change or withdraw any category there at any time. Withdrawing is as easy as giving consent, and it takes effect immediately. Withdrawing does not affect what we processed before you withdrew.
You can also block or delete cookies in your browser settings. If you block strictly necessary cookies, parts of the site will stop working.
Data security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Secure hosting infrastructure
- Regular backups and disaster recovery procedures
International data transfers
Your personal data is primarily processed within the European Economic Area (EEA). When data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the European Commission
- Standard contractual clauses
- Binding corporate rules
- Other appropriate safeguards
Changes to this privacy policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last updated” date. We encourage you to review this Privacy Policy periodically.
Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us at privacy@sitefire.ai.