Legal
Privacy Policy
How SiteReady collects, uses, and shares personal information when you use sitereadywebsites.com, create an account, or publish a website with us. This policy is written for customers and visitors in Europe, the United States, Asia-Pacific, and elsewhere.
Last updated 25 August 2026
1. Who we are
SiteReady (“we”, “us”, “our”) operates sitereadywebsites.com and the related editor, hosting, and support services (the “Service”). For personal information we collect about our own customers and visitors to sitereadywebsites.com, SiteReady is the data controller (or equivalent under local law).
Contact: siteready.operation.team@gmail.com
2. Who this covers
This policy applies to:
- People who visit sitereadywebsites.com or contact us.
- People who create an account, subscribe, or use the website editor.
- People whose information appears in a SiteReady-hosted website because a customer added it (for example staff names in a team section).
It does not replace the privacy notice a customer should publish on their own live website. If you visit a café, salon, or trade site we host, that business is usually the controller of data you send them. See Your published website.
3. Information we collect
Account and profile. Name, email address, authentication identifiers, and sign-in activity. We use Clerk to create and manage accounts.
Business and site content. Business name, phone, address, hours, services, prices, photos, copy, domains, and other content you enter in the editor so we can host and publish your site.
Billing. Plan, billing cycle, subscription status, and payment outcome. Card details are collected and stored by Stripe, not on SiteReady servers. Checkout is billed in USD.
Enquiries. Name, email, optional business name, topic, and message when you use the contact form or email us.
Usage and device. Pages viewed in the editor and on sitereadywebsites.com, approximate location from IP address, browser type, and diagnostics needed to keep the Service running.
Site analytics (on your live site). Aggregated visitor counts, page views, approximate session length, and QR scans, so you can see how your published site is used. We do not use this to sell advertising profiles.
4. How we use it
- Provide the editor, hosting, domains, QR codes, analytics, and support.
- Create and secure your account, and prevent abuse.
- Process subscriptions, invoices, and the Stripe customer portal.
- Reply to contact form messages and custom-website requests.
- Improve reliability, templates, and the editor.
- Meet legal, tax, and accounting duties.
We do not sell your personal information. We do not use it for cross-context behavioural advertising.
5. Legal bases (EEA, UK, Switzerland)
Where the GDPR, UK GDPR, or Swiss FADP applies, we rely on:
- Contract: to create your account, host your site, and provide the plan you buy.
- Legitimate interests: to secure the Service, understand product use, and reply to enquiries that are not yet a contract.
- Legal obligation: tax, accounting, and responding to lawful requests.
- Consent: where we ask for it (for example optional cookies, if we introduce them). You can withdraw consent at any time.
7. International transfers
SiteReady serves customers in Europe, the United States, Asia, and other regions. Your information may be processed in countries other than the one you live in, including where our subprocessors operate.
For transfers out of the EEA, UK, or Switzerland, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and similar tools, plus supplementary measures where needed. You can ask us for more detail at siteready.operation.team@gmail.com.
8. How long we keep it
We keep account, site, and billing records for as long as you have an account and for a reasonable period afterwards (typically up to 24 months, or longer if tax or dispute rules require it). Contact messages are kept long enough to handle the request. Analytics aggregates are kept in summarised form. When we no longer need information, we delete or irreversibly anonymise it.
9. Security
We use industry-standard measures: encrypted connections, access controls, and processors who commit to appropriate security. No internet service is perfectly secure. Please use a strong password and keep your login details private.
10. Rights in Europe (EEA, UK, Switzerland)
Subject to the GDPR / UK GDPR / FADP, you may:
- Access a copy of your personal data and ask for it to be corrected.
- Ask us to delete it, restrict processing, or object to certain uses.
- Receive data you provided in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local supervisory authority.
To use these rights, email siteready.operation.team@gmail.com. We may need to verify it is you. We will respond within the time the law allows (usually one month).
If we appoint an EU or UK representative, we will list their details here and in any required public register.
11. Rights in the United States
Residents of California and of other states with privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others as they come into force) may have rights to know, access, correct, delete, and opt out of certain processing of personal information.
We do not sell personal information and we do not “share” it for cross-context behavioural advertising as those terms are used in the CCPA/CPRA. We also do not use sensitive personal information to infer characteristics about you for advertising.
To make a request, email siteready.operation.team@gmail.com with the subject “Privacy request”. You may use an authorised agent where the law allows. We will not discriminate against you for exercising these rights. If we deny a request, you may appeal by replying to our decision email.
12. Rights in Asia-Pacific and elsewhere
Depending on where you live, local law may give you similar rights of access, correction, deletion, and complaint. Examples include:
- Singapore (PDPA): access and correction; withdraw consent for optional uses.
- Japan (APPI): disclosure, correction, and cessation of use in stated cases.
- South Korea (PIPA): access, correction, deletion, and suspension of processing.
- India (DPDP Act): access, correction, erasure, and grievance redress through the contact below.
- Australia (Privacy Act / APPs) and New Zealand (Privacy Act): access and correction.
- Mainland China (PIPL), Thailand, Malaysia, Indonesia, Philippines, Vietnam, Hong Kong, and Taiwan: local access, correction, and deletion rights may apply, including rules on cross-border transfers. Contact us if you need a local-language response or a transfer explanation.
Email siteready.operation.team@gmail.com and tell us where you live so we can apply the right process. If a local law requires a designated person (for example a grievance officer or data protection officer), that role is fulfilled through this contact until we name someone else on this page.
14. Your published website
When you publish a SiteReady site, you decide what to collect from your visitors (enquiry forms, phone numbers, booking requests). For that data you are the controller. SiteReady hosts and processes it on your instructions so the pages work.
You are responsible for telling your visitors how you use their information, for collecting any consent your local law requires, and for honouring their requests. We will help with technical deletion or export where we hold a copy.
15. Children
The Service is for businesses and is not directed at children under 16 (or the higher age in your country). We do not knowingly collect personal information from children. If you believe we have, email us and we will delete it.
16. Changes
We may update this policy when the Service or the law changes. The “Last updated” date at the top will change. If a change is material, we will notify account holders by email or a notice in the dashboard where reasonably possible.
17. Contact
Privacy questions and requests: siteready.operation.team@gmail.com
Related: Terms of Service · Contact