Privacy

Sitefinite is not a live service yet. It is an internal preview. No production payments can be taken, transactional email is disabled, and custom-domain activation is disabled. The operating entity has not been formed, so this page describes what the software actually does today rather than a contract with a company.

What we store

We store what is needed to build the website and operate the customer-controlled tools you choose:

  • Your business name, trade, town, services and contact details.
  • Your email address, if you sign in.
  • Any logo or photographs you upload.
  • If you adopt a Logo Studio concept, its selected vector and PNG artwork, style, colours and your recorded approval and trademark-responsibility acknowledgement. A description entered only to preview concepts is not stored unless it becomes part of another record you deliberately save.
  • Private drafts, immutable published versions, domain requests and enquiry records.
  • Daily website page-request counts reduced to one of five source categories: direct, search, social, referral or internal. Enquiry totals are compared with those aggregate counts in Business HQ.
  • Business HQ contacts, pipeline records, tasks, bookings or jobs, commercial-document records, campaign drafts and assistant proposals entered or approved by the account owner.
  • Local Opportunity Radar search terms and minimal public signals: the original source URL, a short title or excerpt, source, location label, timestamps, deterministic fit reasons, and the account owner's review decision.
  • For Sitefinite's own prospecting, public business facts, exact source and terms-evidence URLs, retrieval time, website-fit classification, jurisdiction/channel eligibility, suppression state and funnel events. A public contact endpoint is encrypted at rest and its suppression key is stored as a keyed hash.
  • If you use the optional shop: your products, prices, availability, inventory history, delivery settings, orders, fulfilment updates, refund evidence, access entitlements and subscription state.
  • For a shop customer: the name, email, delivery address when needed, their selected product configuration or booking slot, and the order history needed by the merchant to fulfil and support the purchase.
  • Payment-provider event identifiers, checkout references, connected-account identifiers and subscription references. Card and bank details stay on the hosted payment page and are never stored by Sitefinite.

We do not buy personal profiles or hidden contact data. When you ask the Local Opportunity Radar to check a supported source, it uses the source's public, connected or specifically approved interface and links you to the original. It does not enter private groups, circumvent logins, or copy full posts into Sitefinite.

Enquiries from your customers

If someone fills in the contact form on your website, we hold their name, the phone number or email they gave, and their message — so that we can pass it to you and you can reply.

Merchant shops and customer orders

A business that enables a shop is the seller responsible for its products, services, prices, tax position, delivery, cancellations and refunds. Its own connected Stripe account receives direct customer charges. Sitefinite provides the catalogue, cart, order and operational software and does not pool shop revenue in Sitefinite's subscription-billing account.

The cart uses a random first-party cookie so the same browser can retrieve that cart and, after payment, its order status. Only a one-way hash of the token is stored. Server-side prices, stock and capacity control checkout; payment status changes only after a signed provider event. Digital and membership access records are linked to the paid order. A merchant's PDF or ZIP download is stored privately, content-detected, hash-verified and accepted only after a local malware scan; scan metadata and the file remain in the merchant's managed artifacts and protected backups after a download is retired, until the site-deletion and backup-retention processes remove them. No shop order data is used for advertising or model training.

Private prospect demonstrations

We may create a private, expiring and clearly unofficial website concept for a business using public business details from an evidenced source. Discovery does not authorise outreach, and a public address is not treated as consent in every market. The acquisition register separately records source permission, applicable business/entity type, market, channel, legal or consent basis, evidence date, recheck date and suppression state. A draft cannot pass its gate if any of those controls is absent or expired.

The target business is the reviewer of its website content. It can correct the public facts, remove anything, accept or reject drafted wording and decide whether to adopt the concept. The preview is not published as its official site merely because it exists. Opt-outs and do-not-contact requests are retained as keyed hashes so that deletion of a sales record does not accidentally permit later contact.

Customer Hub

If a business enables a Customer Hub, it may issue an expiring, revocable private link to a named contact. The invitation and session are stored only as hashes. A contact sees only records linked to that contact, can download those commercial records, decide a sent quote, and submit a change or repeat-work request. The request enters the business owner's queue; it does not confirm a booking, price or automated action. Link and session metadata are not used for advertising or model training.

That information belongs to you and them, not to us. We hold it on your behalf. We do not market to the people who contact you, we do not add them to anything, and we do not share them with anyone. If you ask us to delete an enquiry, or all of them, we do.

We take the least that makes a reply possible: a name, one way to contact them, and what they wrote. There is no tracking on the form. A configured transactional-email provider may deliver the message to the site owner; until that is enabled the message remains saved in the owner's dashboard and the thank-you page says exactly that.

What we do not do

  • Private first-party measurement only. No Google Analytics, advertising pixels, visitor profiles, fingerprinting or unique-person tracking. We count eligible page requests by day and reduce the incoming referrer to a broad source category before storage. We do not store the visitor's IP address, user agent, full referrer, path history or an analytics cookie, and we honour Do Not Track and Global Privacy Control.
  • No advertising. Your details are never sold, shared or used to target anything at you.
  • No third-party requests on generated websites. They load nothing from any other company's servers — no fonts, no scripts, no images. This is enforced automatically: a generated site that references an outside origin fails our build and is never shown to anyone.

Local Opportunity Radar

The Radar is an account-owner review tool, not an automatic outreach system. Results are scored from the services, locations and exclusion terms that the owner supplies. A result is never treated as consent to contact, and Sitefinite does not message, follow, join, reply to or impersonate anyone. The owner chooses whether to open, dismiss or save each result, and that decision is recorded in the account audit trail.

Unreviewed public signals expire after no more than thirty days (fourteen days for short-lived neighbourhood results). Saved pipeline records remain until the owner removes the site or account, subject to any legal record-holding duty. If the original content is deleted, it should be treated as unavailable; the source remains authoritative.

Local business assistant

If the owner enables a local model, the model receives aggregate operating counts and the business's vertical—not customer names, contact details, enquiry messages, notes, credentials or documents. Its output is an inert task or campaign proposal. It cannot send, publish, charge, file or delete, and the owner must approve and separately execute a safe internal draft.

Logo Studio

Logo Studio builds ten controlled vector concepts inside your signed-in workspace. It does not search trademark registers, decide whether a mark is legally available or silently publish a selection. You choose the concept, confirm that it represents the business and accept responsibility for appropriate trademark and professional clearance before the selected artwork is saved to the site.

Cookies

An anonymous intake cookie keeps your six-step form answers together. If you sign in, a separate session cookie lets the site know it is you. A shop uses an additional anonymous cart cookie to retrieve that browser's cart, order status and subscription-management entry point. It may remain for up to 400 days so a returning customer can manage a recurring purchase without a weaker email-only lookup. All are first-party, essential and never used for tracking.

Sign-in links and session tokens are stored only as one-way hashes, so a copy of our database could not be used to sign in as you.

How long we keep it

Preview links expire thirty days after they are created, and the preview is deleted with them. When no paid site or other preview needs the business record, that orphan record and its uploaded media are deleted too. A paid site is never deleted merely because its old preview expires. Intake records expire after fourteen days, sessions after thirty days, and sign-in links after fifteen minutes; sign-in links work once. Enquiries are kept for twelve months by default so the site owner can follow them up, then deleted automatically. Customer Hub sessions expire after seven days, invitations expire after the duration chosen by the owner (no more than 180 days), and revocation invalidates every related session. Acquisition drafts expire with their seven-day offer and protected prospect records remain subject to suppression and applicable direct-marketing/privacy retention duties. When a merchant site is deleted, customer names, emails, addresses, line items and operational order history are removed. For paid or otherwise financially material orders, a separate minimised record retains only amounts, currency, dates, payment-provider name and hashed references for seven years by default; the configured period is constrained to five to ten years. The operating entity must confirm the correct market-specific period before launch.

Your site is yours

You own your website and everything on it. If you ask us to delete your details we will, and if you leave we hand over a complete copy of the site and unlock the domain within seven days, at no charge. We do not hold anyone's website hostage.

Asking us anything

Write to hello@sitefinite.com to see what we hold about you, correct it, or have it deleted.

Last updated 28 August 2026.