Contents
- 1. Overview and Scope
- 2. What We Collect
- 3. How We Use It
- 4. What We Don't Collect
- 5. Legal Bases for Processing
- 6. Who We Share It With
- 7. Data Retention
- 8. Your Rights Under CCPA/CPRA
- 9. Deletion and Correction Requests in Practice
- 10. Do Not Track / Global Privacy Control
- 11. Children's Privacy
- 12. Cookies and Tracking
- 13. Data Security
- 14. Data Breach Notification
- 15. Changes to This Policy
- 16. Contact
Effective date: July 19, 2026
Last updated: July 19, 2026
This Privacy Policy explains how Site Vetted (a sole proprietorship operating in California) ("Site Vetted," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use our website and services (together, the "Service"). We're a small team of engineers and researchers building a US-focused website compliance product, and we've tried to write this policy in plain language.
1. Overview and Scope
Site Vetted is a US-only product, built for US small businesses. This policy is written for a US audience and describes our practices under US law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), which applies to California residents. We do not currently offer the Service outside the United States, and this policy does not address non-US privacy frameworks.
This policy applies to the Site Vetted website, our waitlist, our free scan queue, our paid audit tiers, our book chapter and book preorder checkout flows, and our blog. It applies whenever you interact with any part of the Service, whether or not you end up making a purchase. If you simply browse our blog or read a Case File post without submitting any information, this policy still describes how we would handle any information you choose to give us.
We built Site Vetted around a simple idea: collect only what we need, tell you clearly what we're doing with it, and give you real control over it. This policy is our attempt to explain that in plain language rather than dense legal text.
2. What We Collect
We collect the minimum information needed to deliver the Service:
- Email address — required for the waitlist, scan queue, purchases, and preorders
- Name — if you provide it (for example, on the waitlist or at checkout)
- Website URL — the URL you submit for scanning when you request a free scan or paid audit
- Payment information — handled directly by Stripe, our payment processor; we don't store your card numbers
- Basic server logs — IP address, browser type, and timestamp, retained for 90 days
We don't ask for, and don't want, any information beyond what's needed to deliver your product or report. We don't ask for your date of birth, home address (unless you're shipping a physical book preorder), Social Security number, or any other sensitive identifier as part of our normal signup, scan, or checkout flows.
3. How We Use It
We use the information we collect to:
- Deliver the product or report you requested — for example, emailing your scan results, audit report, or book chapter
- Send transactional emails — order confirmations, report delivery notices, and receipts
- Send marketing emails — such as book launch updates and product news; every marketing email includes an unsubscribe link, and you can opt out at any time
- Improve the product — using aggregated, non-personal data to understand how people use the Service; we don't use this to identify you individually
4. What We Don't Collect
To be clear about the boundaries of what we gather: we don't collect biometric data, precise geolocation, government ID numbers, or health information. We don't buy supplemental data about you from third-party data brokers to build a profile. Our data footprint is intentionally small — a byproduct of being a small team of engineers and researchers who would rather build a good product than manage a sprawling data warehouse.
5. Legal Bases for Processing
Because Site Vetted operates under US law, we don't rely on the "lawful basis" framework used in some other countries. Instead, we collect and use your information:
- With your consent — for example, when you join our waitlist or opt in to marketing emails
- To fulfill our contract with you — for example, processing your payment and delivering the audit report or book chapter you purchased
- To comply with legal obligations — such as tax recordkeeping requirements
We don't use any framework beyond these three categories. If a future feature would require a different basis for processing your information, we'll update this policy and, where appropriate, ask for your consent before proceeding.
6. Who We Share It With
We share your information only with the following categories of parties, and only as needed to run the Service:
- Stripe — for payment processing. Stripe handles your payment details directly; we never see your full card number.
- Our email service provider — to send transactional and marketing emails on our behalf.
- Our hosting provider — currently a Perplexity Computer sandbox environment; we're migrating to Supabase and/or Vercel managed storage as we scale.
- Legal compliance — if required to respond to valid legal process, such as a subpoena or court order, from a US government authority.
We never sell your personal information, and we never rent it to third parties. We also don't share your information with advertising networks, data brokers, or analytics companies that build cross-site profiles. The list above represents the complete set of categories of third parties who receive your information, and we'll update this policy if that ever changes.
7. Data Retention
We keep your information only as long as we need it:
- Contact information (email, name) — 24 months from your last interaction with us, or until you request deletion, whichever comes first
- Scan submissions (website URLs and related audit data) — 12 months, kept for audit-trail purposes, then deleted
- Payment records — 7 years, to comply with IRS tax recordkeeping requirements
- Server logs — 90 days
8. Your Rights Under CCPA/CPRA
If you're a California resident, you have the following rights under the CCPA/CPRA:
- Right to know what personal information we've collected about you and how we've used it
- Right to delete your personal information, subject to certain legal exceptions
- Right to correct inaccurate personal information we hold about you
- Right to opt out of "sale" or "sharing" — we don't sell your data or share it for cross-context behavioral advertising, but you're welcome to submit an opt-out request anyway
- Right to non-discrimination — we won't deny you service, charge you a different price, or provide a different level of service because you exercised any of these rights
How to exercise your rights: Email us at privacy@sitevetted.com. We'll respond within 45 days. We may need to verify your identity before fulfilling certain requests.
Authorized agents: You may designate an authorized agent to submit a request on your behalf. We'll ask for proof of the agent's authorization and may still require you to verify your own identity directly with us.
9. Deletion and Correction Requests in Practice
When you ask us to delete your information, we'll remove your contact details, scan submissions, and any associated records from our active systems, subject to the retention exceptions in Section 6 (for example, we're required to keep payment records for 7 years for tax purposes even after a deletion request). When you ask us to correct information, we'll update the record and confirm the change back to you by email. Because we're a small team, most requests are handled by a real person reading your email — not an automated system — so please give us the full 45-day window to respond, even though we often respond faster.
10. Do Not Track / Global Privacy Control
Some browsers and extensions send a "Do Not Track" or "Global Privacy Control" (GPC) signal. We honor GPC signals as a valid opt-out-of-sale/sharing preference for California residents, even though we don't currently sell or share personal information for cross-context advertising.
11. Children's Privacy
The Service is not intended for anyone under 18. We don't knowingly collect personal information from minors. If we learn that we've collected information from someone under 18, we'll delete it promptly. If you believe a minor has provided us information, contact us at privacy@sitevetted.com.
12. Cookies and Tracking
Our use of cookies is minimal. We use:
- Session cookies — to keep basic site functionality working during your visit
- Basic analytics — to understand aggregate traffic patterns (for example, how many people visit a given page)
We do not use third-party advertising trackers, and we don't run retargeting or cross-site ad campaigns on this site.
13. Data Security
We take reasonable measures to protect your information, including:
- HTTPS/TLS 1.2 or higher encryption for data in transit
- Reliance on Stripe, a PCI-DSS Level 1 certified payment processor, for all payment handling
- Password hashing (if and when account login is introduced)
- SHA-256 receipts that cryptographically anchor audit findings, so reports can't be silently altered after delivery
No system is 100% secure, and we can't guarantee absolute security, but we work to keep your information protected using industry-standard practices.
14. Data Breach Notification
If a data breach affecting your personal information occurs, we'll notify affected users without unreasonable delay. If a breach affects more than 500 California residents, we'll also notify the California Attorney General within 30 days, as required under California law.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we'll post the updated "Last updated" date at the top of this page. If we make a material change — one that affects how we use your previously collected information — we'll notify you by email in addition to updating this page.