Privacy policy
Effective .
Last updated 26 July 2026.
This policy covers two different groups of people, and it is worth being explicit about both: the customers who hold a SiteAssay account, and the businesses whose public information our customers research using it.
Data we hold about customers
When you create an account we store your name, email address, hashed password, and the workspace you belong to. If you subscribe, our payment processor (Paddle, acting as merchant of record) handles your payment details; we never see or store a card number. We keep a record of what your workspace has spent usage against, because that is your billing record.
We use privacy-preserving, cookieless analytics on this marketing site and product analytics inside the application to understand which features are used. Neither is sold or shared with advertisers.
Data we hold about researched businesses
SiteAssay collects information about businesses from public sources: map and directory listings, search results, and the businesses' own websites and public DNS, TLS and domain registry records. That typically includes a trading name, address, phone number, website, published business email addresses, public social profiles, and the technical measurements of the website itself.
We do not buy contact lists from data brokers, and we do not collect from any source that requires an account to access. We do not knowingly collect special-category personal data, and the product is not designed to profile individuals. It profiles websites.
Where this processing concerns personal data, the lawful basis is legitimate interest in B2B commercial communication, balanced by the controls below.
Outreach and your right to be left alone
Every message sent through SiteAssay carries a working unsubscribe link and a one-click
List-Unsubscribeheader, so a single click in your mail client stops it.Unsubscribes, spam complaints and hard bounces are added to a permanent suppression list. Suppression is enforced when a message is drafted, not only when it is sent, so a suppressed address cannot re-enter a follow-up sequence.
Every message identifies the sending agency and carries a postal address.
Sending is never automatic. A person at the sending agency reads and approves each message.
Retention
Prospect records, audits, scores and reports are kept for as long as the customer's workspace holds them, and are deleted when the customer deletes them or closes the account. Suppression records are the deliberate exception: they are kept indefinitely, because forgetting that somebody opted out is how they get contacted again.
Your rights
If you are a business that has been researched or contacted through SiteAssay, you can ask us for a copy of what is held about you, ask for it to be corrected, or ask for it to be erased and suppressed. Write to hello@siteassay.com and we will act on it, and pass the request to the customer whose workspace holds the record. Customers with UK or EU data-protection rights can also complain to their local supervisory authority.
Sub-processors
We use third parties for hosting, object storage, email delivery, error monitoring, analytics, payment processing, and, when a customer enables it, an AI provider used to draft outreach copy. Audit measurements and prospect records are not used to train anyone's models.
Contact
SiteAssay. hello@siteassay.com