Privacy Policy
Last updated 6 August 2026. Effective 20 August 2026.
Overview
SiteGauge ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website monitoring and competitor intelligence platform (the "Service").
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service.
Information We Collect
Information you provide directly
• Account data - name, email address, and password (or single sign-on credentials) when you register. Authentication is handled by our provider, Clerk.
• Payment data - billing address and payment method details. Card numbers are processed directly by Stripe and never stored on our servers.
• Team data - names and email addresses of team members you invite.
• Alert destinations - contact details you add for alert delivery, such as a phone number for SMS alerts or a webhook address.
• Monitoring credentials and keys - any credentials you save to monitor authenticated pages, any signing secrets or bot tokens for outbound integrations, and any of your own third-party API keys you supply (bring-your-own-key). These are encrypted at rest and used only to perform the actions you configure; we do not use them for any other purpose.
• Communications - messages you send us via email or support channels.
Information collected automatically
• Usage data - pages visited, features used, actions taken within the dashboard, frequency and duration of use.
• Device and log data - IP address, browser type, operating system, referring URLs, and timestamps.
• Cookies and similar technologies - session cookies (required for authentication), preference cookies, and the analytics, session-replay, and advertising-measurement cookies described in the Cookies and Analytics section below.
Data collected on your behalf
When you add a URL to monitor, our crawlers fetch and store snapshots of those pages. This content belongs to the respective third-party websites. We store rendered HTML, screenshots, and extracted text solely to power the change-detection, AI summary, and alerting features of the Service. To generate AI change summaries, monitored-page content is processed by our AI provider, Anthropic, and under our agreement with Anthropic this content is not used to train Anthropic's models.
Authenticated monitoring. If you configure credentials (a cookie, header, or saved browser session) so we can monitor a page behind a login, we store those credentials encrypted at rest and transmit them only to the site you are monitoring, to fetch the page on your behalf. Provide only credentials you are authorised to use.
Rendering of protected pages. Some pages block ordinary automated requests. To capture them we may fetch them through a headless-browser (Browserless) or residential-proxy (Bright Data) provider; the monitored URL and any credentials you configured are shared with that provider only to complete the fetch.
How We Use Your Information
We use the information we collect to:
• Provide and operate the Service - crawl monitored URLs, detect changes, generate AI summaries, and deliver alerts.
• Process payments - manage subscriptions, issue invoices, and handle billing events.
• Send transactional communications - account verification, alert notifications, digest emails, and team invitations.
• Improve the Service - analyse usage patterns, debug issues, and develop new features.
• Ensure security - detect fraud, abuse, and unauthorised access.
• Comply with legal obligations - respond to lawful requests from public authorities.
We do not sell your personal data to third parties. We do not use your data to train AI models.
How We Share Your Information
We share your information only in these limited circumstances:
• Service providers - we engage trusted third parties to operate the Service: Clerk (authentication), Stripe (payments), Resend (email delivery), Twilio (SMS delivery, only where you enable SMS alerts), Cloudflare R2 (screenshot and snapshot storage), Neon (database), Anthropic (AI analysis of monitored-page content), Browserless (headless-browser rendering of monitored pages), Bright Data (residential proxy used only to fetch pages that block ordinary automated requests), Sentry (application error monitoring, which may process IP addresses and request metadata), Google (Google Analytics usage statistics and Google Ads conversion measurement, applied under the consent rules in the Cookies and Analytics section; and Google Sheets export only where you enable a Sheets integration), Microsoft (Microsoft Clarity session analytics, applied under the same consent rules), and Vercel and Railway (application hosting). Each provider processes data only as instructed and under appropriate data processing agreements.
• Alert channels you configure - where you connect an outbound integration (webhook, Slack, Microsoft Teams, Discord, Google Chat, or a Google Sheet), the change data you choose to send is delivered to that destination. Any signing secret or bot token you provide for these is encrypted at rest.
• Team members - if you invite someone to your workspace, they can see monitors, changes, and alerts within your organisation.
• Legal requirements - we may disclose information if required by law, court order, or to protect the rights, property, or safety of SiteGauge, our users, or the public.
• Business transfers - in the event of a merger, acquisition, or sale of assets, your data may be transferred. We will provide notice before any such transfer.
Data Retention
We retain your account data for as long as your account is active or as needed to provide the Service. You may delete your organisation and account at any time via Settings → Danger zone. Deletion takes effect immediately, and all associated data, including stored snapshots and screenshots, is permanently erased from our systems after a 30-day grace period.
Crawl snapshots and change history are retained according to your plan limits. Snapshots beyond your plan's retention window are automatically deleted. Aggregated, anonymised analytics data may be retained indefinitely.
Security
We implement industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest, access controls, and regular security reviews. SiteGauge API keys are stored as one-way hashes. Secrets that must be reused - monitoring credentials, outbound-integration signing secrets and bot tokens, and any bring-your-own third-party API keys - are encrypted at rest with authenticated encryption (AES-256-GCM) rather than stored in plaintext.
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we will notify you of any breach affecting your personal data as required by applicable law.
Your Rights
Depending on your jurisdiction, you may have the right to:
• Access - request a copy of the personal data we hold about you.
• Correction - request correction of inaccurate or incomplete data.
• Deletion - request deletion of your personal data ("right to be forgotten").
• Portability - request your data in a structured, machine-readable format.
• Objection - object to certain types of processing, including direct marketing.
• Restriction - request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, email us at privacy@sitegauge.com. We will respond within 30 days.
International Transfers
SiteGauge is operated from the United Kingdom. If you access the Service from outside the UK or EEA, your information may be transferred to and processed in countries with different data protection laws. Where we transfer data internationally, we rely on standard contractual clauses approved by relevant data protection authorities.
Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at privacy@sitegauge.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or by posting a notice in the dashboard at least 14 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact:
SiteGauge
privacy@sitegauge.com
For users in the UK/EEA, you also have the right to lodge a complaint with your local data protection authority.