Skip to content
SiteList

Legal

Privacy Policy

Last updated: 30 July 2026

This policy explains what SiteList (“we”) collects when you use sitelist.co, why, who processes it on our behalf, how long we keep it, and the rights you have. Plain summary first: we collect what the product needs and nothing more, we run no advertising trackers, and we never sell personal data.

1 · Who is responsible

SiteList operates sitelist.co and is the data controller for the processing described here. Contact: privacy@sitelist.co.

2 · What we collect

  • Account data — email, password hash, or your Google identity when you sign in with it (name, email, avatar as Google shares them).
  • Profile data — display name, role, region, and what you choose to add.
  • Reviews and verification materials — your review content and ratings; your declared relationship to the vendor; proof you upload (receipts or screenshots), which is stored privately; a work-email domain if you provide one; and the verification decision trail.
  • Marketplace data — applications, acknowledgements (including the incentive you accepted), seat and credential-reveal events. Vendor credentials are sealed-box encrypted; the web application cannot decrypt them.
  • Business/owner data — claimed listings, offers, responses; if you connect Google Search Console, an encrypted refresh token that only our worker can decrypt, and the search metrics Google returns.
  • Technical data — server logs (IP, user agent) for security and abuse prevention (for example on review submission and credential reveals), and a first-party analytics beacon whose identifiers are privacy-hashed. We run no third-party advertising or cross-site tracking.
  • Reviewed site data — publicly available content of the websites we review. This concerns businesses; where it incidentally contains personal data (e.g., a founder’s name on a public page), we process it under legitimate interest in publishing reviews of publicly offered products.

3 · Why we use it (and the legal bases)

  • To run the service — accounts, listings, reviews, marketplace, widget (performance of a contract).
  • To verify reviews — checking proof of use, detecting duplicates and fraud, recording the audit trail (legitimate interest in review integrity, and legal obligation where consumer law requires verification transparency).
  • To meet disclosure law — publishing incentive and relationship disclosures with reviews (legal obligation / legitimate interest).
  • To secure and improve the service — logs, rate limits, aggregated analytics (legitimate interest).
  • To communicate — transactional email such as reveal links, application decisions, and review status (performance of a contract).

Automated processing note: uploaded proof is first analyzed by software, including AI models, which can only verify, defer to a human, or (for clear fabrication signals) reject verification of a review; uncertain cases go to human review, and you can contest any outcome via privacy@sitelist.co. SiteList Review Scores are automated analyses of businesses’ public websites, not decisions about individuals.

4 · Who processes or receives data

We share personal data only with:

  • Processors that host and run the service — Supabase (database, auth, storage), Vercel (web hosting), our EU-hosted worker server, Resend (email), Stripe (payments, if you buy a paid plan), and our AI inference provider (which receives proof-of-use images and reviewed public content for analysis, without your account identity).
  • Identity providers you choose — Google, under its own policy, when you use it to sign in or connect Search Console.
  • The public — your published reviews (with your display name and disclosure labels), owner responses, and claimed-listing attributions are public and appear in the directory, the widget, and syndication.
  • Authorities or successors — where law requires, to defend legal claims, or as part of a business transfer.

We never sell personal data and we run no third-party advertising.

5 · Verification materials

Uploads live in a private bucket, are never public, and are visible only to automated verification and to platform administrators reviewing your case. Redact anything you do not want seen — we ask our systems to extract the minimum (vendor, plan, date) and to redact identifiers, and the upload is retained only as provenance for the review’s verification status.

6 · Cookies and local storage

  • Essential cookies — authentication/session (Supabase). No consent banner is required for these.
  • Local storage — your theme choice and recent searches, stored in your browser only.
  • Analytics — first-party beacon with hashed identifiers; no cross-site tracking, no ad cookies. Analytics runs only with your consent, asked on your first visit; change or withdraw it any time via “Cookie settings” in the footer — withdrawing is as easy as accepting.

7 · Retention

  • Account and profile data: for the life of the account, then deleted or de-identified.
  • Published reviews and their disclosure/verification records: for the life of the review; the verification audit trail is retained as long as the review’s status may need proving.
  • Credential-reveal tickets: minutes — ciphertext is destroyed at consumption or expiry.
  • Security logs and IP records: up to 12 months.
  • Private review inputs: normally 7 days after a review is published; a compact normalized bundle may be kept for up to 30 days. Active previews and retryable reviews are kept until they finish. Published review results and promoted gallery images remain for the life of the listing.

8 · Security

Transport encryption everywhere; row-level security on the database; vendor credentials sealed-box encrypted so the web tier can never decrypt them; one-time encrypted reveal tickets; append-only audit trails for verification and vault events; least-privilege service roles. No system is perfectly secure — report concerns to privacy@sitelist.co.

9 · Your rights

Depending on where you live (GDPR/UK GDPR, CCPA/CPRA, and similar), you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, to opt out of “sale/share” (we do neither), and to complain to your supervisory authority. Exercise them from your account settings or by emailing privacy@sitelist.co; we respond within the legally required time. Deleting your account removes personal data, subject to the review license in the Terms and records we must keep (e.g., disclosure and verification provenance for published reviews, fraud prevention, legal claims).

10 · International transfers

Our processors run in the United States and the European Union. Where data leaves your jurisdiction we rely on the processors’ safeguards (EU Standard Contractual Clauses and, for US providers, the EU-US Data Privacy Framework where certified).

11 · Children

The service is not directed to children under 16, and we do not knowingly collect their data.

12 · If we reviewed your website

We analyze publicly available web content under legitimate interest in publishing product reviews. As a site owner you can claim your listing, respond to reviews, use the factual correction process, and contact privacy@sitelist.co about personal data appearing in a listing. See How reviews work for the methodology and moderation rules.

13 · Changes and contact

We will update this page when practices change and adjust the date above; material changes get in-product notice. Questions and requests: privacy@sitelist.co.