Privacy
Privacy Policy
Last updated: September 6, 2026
Siteline is operated by PAICE.work (sometimes referred to in this Privacy Policy as the Company, we, or us). This policy explains what data Siteline collects, why, and what happens to it. We keep this short and honest because we value your trust. As always, please let us know if you have questions. Our contact information is included at the bottom of this Privacy Policy (sometimes referred to as the Policy).
We use the data we collect to provide and improve our services. By using Siteline, you agree to the collection and use of information in accordance with this Policy.
Scanning a website
We process the URL you submit, including its path and query parameters, to fetch public pages and evaluate their accessibility to agents. We collect scan scores, findings, response metadata, and limited evidence excerpts from those pages. Do not submit private links, passwords, access tokens, or other confidential information in a URL.
The web scanner also sends the target URL to Cloudflare's Agent Readiness service for its separate readiness panel. That service receives the target URL, including its path and query, and returns its own findings.
Saved scan results are public to anyone who has the report link or retrieves the result through our API. They can contain the submitted URL and evidence excerpts. Share only reports you intend others to see.
Email, feedback, and purchases
- Report and contact requests: we process your email, the relevant scan result, and any name, message, qualification details, or notification preference you provide. Supabase stores these records. Resend processes recipient addresses and message content for delivery. When configured, an operational webhook also receives the submission to support follow-up.
- Optional feedback: survey ratings, selected reasons, and comments you choose to submit are sent to PostHog. Please leave confidential information out of survey comments.
- Paid services: Stripe hosts checkout for our paid services and processes payment, customer contact, and requested service details. Siteline does not receive full card numbers. Stripe and PAICE.work retain payment and service records for administration.
Analytics and operational records
PostHog collects page categories, selected product interactions, scan scores, and optional survey feedback. We configure it with in-memory identifiers, without persistent browser storage, person profiles, automatic interaction capture, or session recordings. We do not send report-request email addresses or submitted scan URLs as analytics identifiers or event properties. Intentional survey comments are an exception: they contain the text you choose to send.
Vercel Web Analytics and Speed Insights measure page usage and loading performance. Our browser analytics filters remove URL query strings and fragments and replace report identifiers with a generic route. Browser requests to hosting, analytics, and asset providers still expose connection metadata, such as your IP address and browser details, to those providers.
We use IP addresses for abuse prevention. Rate-limit records can be stored in Supabase across server sessions. Application and hosting logs may also contain IP addresses, requested URLs, request identifiers, errors, and scan details. If Sentry error monitoring is enabled, diagnostic errors and request context are sent to Sentry. Its default personal-information collection and performance tracing are disabled, but application-supplied error context can still contain URLs.
Retention and access
- Saved scan results: results become unavailable from the result service after 30 days. Database maintenance scripts remove expired results; physical deletion depends on scheduled cleanup and provider backups. This expiration does not delete copies already shared, downloaded, emailed, or included in a contact record.
- Rate-limit records: rate limits use recent request timestamps. Database cleanup scripts target rows older than two hours; records can remain longer until cleanup runs successfully.
- Email and service records: contact records, attached scan snapshots, and email queue payloads have no automatic deletion period in the application. Contact us to request deletion.
- Provider records: hosting logs, error reports, analytics, payment records, and provider backups follow the applicable provider and account retention settings. The scan-result expiration period does not apply to these records.
Database access is restricted to the service backend using row-level security. Public scan reports are intentionally accessible through the result service. We use the information above to provide requested services, follow up on opted-in requests, improve the product, and prevent abuse. We do not sell personal data.
Your rights
You can request deletion of your email and associated data at any time by emailing privacy@paice.work or using the contact form. Please identify the email address or report involved so we can locate the relevant records.
If you are in the EU, UK, or California, you have additional rights under the General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), or the California Consumer Privacy Act (CCPA), respectively. These include the right to access, correct, or delete your personal data, and the right to object to processing. Contact us at the address above to exercise these rights.
Third-party services
- Vercel: hosting, function logs, Web Analytics, and Speed Insights (privacy policy).
- Supabase: database hosting (privacy policy).
- Resend: email delivery (privacy policy).
- Stripe: hosted payment processing (privacy policy).
- PostHog: product analytics and submitted feedback (privacy policy).
- Cloudflare: the Agent Readiness assessment and CDN-hosted assets (privacy policy).
- Sentry: error monitoring when configured (privacy policy).
- Google Fonts: hosted fonts on pages that use them (privacy policy).
A configured operational webhook is an additional recipient for contact and report submissions. Contact us for details about the current follow-up integration and provider retention settings.
Disclosure of your Personal Data
If the Company is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court of competent jurisdiction or a government agency).
Other legal requirements
We may disclose your Personal Data in the good-faith belief that such action is necessary to do any of the following:
- Comply with a legal obligation
- Protect and defend the rights of the Company
- Protect the personal safety of users of the Service or the public
- Protect against legal liability
Changes to this Privacy Policy
We may update our Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this Privacy Policy. We do not notify by email for policy changes unless they affect how we handle data you have already provided.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page, unless otherwise noted.
Contact
If you have any questions about this Privacy Policy, you can contact us:
- By visiting this page on our website: https://paice.work/contact
- By sending us an email: hello@paice.work
- Questions about this policy: privacy@paice.work or the contact form