Privacy Policy

Last updated: April 15, 2026

1. Introduction

Welcome to Sitelas ("we," "our," or "us"). We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered website builder platform.

By using Sitelas, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address for account creation and authentication via one-time password (OTP).
  • Website Content: Any content you add to your website, including text, images, and other materials you choose to publish.
  • Subdomain Selection: Your chosen subdomain (e.g., yourname.sitelas.com).
  • Payment Information (Sitelas subscription): When you subscribe to Sitelas, Stripe processes your payment. We do not store your full card details on our servers — Stripe tokenizes and holds them.
  • Contact Form Submissions: Messages submitted through your website's contact form by visitors.
  • Support Communications: Any messages you send to our support team.

2.2 Information Collected Automatically

  • Analytics Data: We collect anonymized analytics on website visits, including page views, unique visitors, referral sources, and browsing paths.
  • Device Information: Browser type, operating system, and device type for optimization purposes.
  • Log Data: Server logs including IP addresses, access times, and pages visited for security and troubleshooting.
  • Cookies: We use essential cookies for authentication and session management. We may use analytics cookies to improve our service.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide Our Service: To create, host, and display your website.
  • Authentication: To verify your identity and secure your account using OTP-based email verification.
  • Process Payments: To handle subscription billing through our payment processor, Stripe.
  • Send Notifications: To send you important emails including trial reminders, expiration notices, contact form submissions, and service updates.
  • Analytics: To provide you with visitor analytics for your website and to improve our platform.
  • Customer Support: To respond to your inquiries and provide assistance.
  • Security: To protect against fraud, abuse, and unauthorized access.
  • Legal Compliance: To comply with applicable laws and regulations.

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:

  • Service Providers (subprocessors): We use the following third-party services to operate the platform. Each acts as a subprocessor of your data for the specific purpose listed:
    • Supabase: Database and authentication services. Stores account data, site content, bookings, orders, and contact records.
    • Stripe: Sitelas subscription billing only. Processes payment methods for your Sitelas plan. Sitelas does not touch end-customer payments — those flow through the site owner's own Stripe account via the site owner's own Payment Links.
    • Resend: Email delivery for transactional emails from Sitelas (form submission notifications, site lifecycle notices, billing warnings).
    • Twilio: SMS booking reminders (Starter and Business tiers). Phone numbers you collect from Buyers are passed to Twilio for the specific notification; Twilio does not retain them beyond delivery.
    • Google Cloud (Gemini): AI generation and chat. Prompts and generated content are sent to Google and subject to Google's enterprise data terms.
    • Vercel: Hosting, edge delivery, and analytics infrastructure.
  • Storefront Buyer Data: If a visitor purchases a product on one of your sites, Stripe collects their payment and (for physical orders) shipping information at checkout. Sitelas receives only the order metadata (items, total, shipping address for your fulfillment, buyer email for receipt) and stores it in your site's order inbox. We act as a processor on your behalf for this data; you are the controller as the site owner.
  • Public Website Content: Content you publish on your website is publicly accessible. This includes any text, images, and other content you choose to display.
  • Legal Requirements: We may disclose information if required by law, court order, or government request.
  • Protection of Rights: We may disclose information to protect our rights, property, or safety, or that of our users.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • All data transmission is encrypted using SSL/HTTPS.
  • Database encryption at rest and in transit.
  • Row-level security (RLS) for multi-tenant data isolation.
  • Secure OTP-based authentication (no passwords stored).
  • Regular security audits and updates.

While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide our services:

  • Active Accounts: Data is retained while your subscription is active.
  • Cancelled Accounts: After subscription cancellation, your website is unpublished. Account data may be retained for a reasonable period for legal and business purposes.
  • Trial Expiration: If you do not subscribe after your trial, your website is unpublished, but data may be retained for a period to allow reactivation.
  • Deletion Requests: You may request deletion of your account and data by contacting us.

7. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request access to your personal data.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your personal data.
  • Portability: Request a copy of your data in a portable format.
  • Objection: Object to certain processing of your data.
  • Withdraw Consent: Withdraw consent where processing is based on consent.

To exercise these rights, please contact us at contact@sitelas.com.

8. Cookies

We use cookies and similar technologies for:

  • Essential Cookies: Required for authentication, session management, and core functionality.
  • Analytics Cookies: To understand how visitors use our platform and improve our service.

You can control cookies through your browser settings, but disabling essential cookies may affect your ability to use our service.

9. Third-Party Links

Your website may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

10. Children's Privacy

Our service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. International Data Transfers

Our services are hosted in the United States. If you access our service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our service after any changes constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Code Axiom

5900 Balcones Drive Ste 5193
Austin, TX 78731
USA

Email: contact@sitelas.com