Legal

Privacy Policy

Last updated:

This policy explains what Sitemark — the web app and the Chrome extension — collects, why, who can see it, how long we keep it, and what you can do about it. If anything is unclear, email info@sitemark.in.

The short version. We collect what is needed to run Sitemark and nothing more. We do not sell your data, show ads, or use tracking cookies. You can download a copy of your data or delete your account at any time from Profile → Privacy & data.

1. What we collect

  • Account data: your name, email address and profile picture. These come from Google when you sign in with Google, or from you when you sign in with an email link or edit your profile. You can upload your own picture.
  • Optional onboarding answers: what you do and how you heard about Sitemark. Both can be skipped.
  • Review content: the pins, notes, suggestions, comments, attachments and page notes you create, and the name and address of the websites you review.
  • Screenshots and page details: when you place a pin, the extension captures a screenshot of the visible page and records where on the page the pin was placed. It only does this on sites you have turned it on for, and only when you place a pin. We do not track your browsing history.
  • Browser details: with each pin, your operating system, browser and version, and window size, so the issue can be reproduced.
  • Activity: when you sign in and when you last used Sitemark, and the notifications created for you.
  • Terms acceptance: the date your account was created, which is when you accepted our Terms of Service by signing in.

2. How we use it

  • To sign you in and keep your session secure.
  • To show your feedback to the people you work with, and notify them of changes.
  • To email you sign-in links, invitations, and a notice when someone assigns you a Sitemark.
  • To send product news, only if you opt in. It is off by default and can be turned off in your profile at any time.

We do not sell your data, share it with advertisers, or use it for advertising.

3. Who can see what

  • Project memberssee the project's pins, comments, attachments and screenshots, and the names and pictures of the other members.
  • Owners and editorsalso see members' email addresses and pending invitations, because they manage who has access. Viewers do not.
  • Anyone with a public share linkcan read that project's report — its pins, notes, suggestions and screenshots, and members' names and pictures — but never email addresses or comment threads. Owners and editors control these links and can add a password or turn them off.

When you leave a project or delete your account, what you wrote in shared projects stays so the team keeps its history, but it is shown as “Former member” — your name and picture are removed from it.

4. Service providers

We use a small number of providers to run Sitemark. Each only processes data to provide their service to us:

  • Google — sign-in with Google, and hosting of the Sitemark API (Google Cloud).
  • Neon — the database that stores accounts and review content.
  • Google Cloud Storage — storage of screenshots, profile pictures and attachments.
  • Resend — delivery of sign-in, invitation and notification emails.
  • Our hosting providers for the Sitemark website.

5. How long we keep it

  • Your account and content: until you delete them, or your account.
  • Sign-in links: deleted a day after they expire or are used.
  • Unaccepted invitations: deleted 30 days after they expire.
  • Notifications: read ones after 90 days, all after 180 days.
  • Accounts unused for over a year may be scheduled for deletion. If so, we email you first and give you 30 days; signing in once keeps your account.

6. Your choices and rights

  • Download your dataas a JSON file from Profile → Privacy & data.
  • Correct it — edit your name, picture and answers in your profile.
  • Delete your accountfrom Profile → Privacy & data. Projects only you are in are deleted with it.
  • Stop product news— turn it off in Profile → Privacy & data.
  • For anything else, email info@sitemark.in.

7. Cookies

Sitemark uses one essential cookie: your sign-in session, which is HttpOnly so page scripts cannot read it. We do not use analytics, advertising or tracking cookies. The extension stores only your preferences, never your password or session.

8. Children

Sitemark is not meant for children under 13, and you must be at least 13 to sign in. If you believe a child has created an account, contact us and we will delete it.

9. Security

Data is encrypted in transit and at rest. Sessions are signed and short-lived tokens are used for realtime connections; share-link passwords are stored only as salted hashes. If a breach affects your data, we will tell you promptly, explain what happened, and what we are doing about it.

10. Changes

If we change this policy in a way that matters, we will update the date above and tell signed-in users before the change takes effect.

11. Contact

Questions or requests about your data: info@sitemark.in.