Legal
Privacy Policy
Last updated: August 31, 2026
This policy explains what information Sitesui collects when you use Sitesui(the “Service”) or our website, how we use it, and the choices you have.
Information we collect
- Account information — name, email, and role, provided when your organization invites you.
- Customer content — inspections, condition ratings, notes, photos, reports, and work orders your team creates.
- Resident reports — issues submitted through a workspace's Pinpoint report page, including the location, description, urgency, up to five optional photos, and the reporter's name and email if they chose to provide them. Reports are visible only to that workspace.
- Contact requests — details you send through our demo or contact forms.
- Usage & technical data — basic logs and analytics needed to run and secure the Service.
How we use information
- to provide, maintain, and improve the Service;
- to generate reports, route work orders, and triage resident reports;
- to respond to your requests and provide support;
- to keep the Service secure and prevent abuse; and
- to comply with legal obligations.
We do not sell your personal information, and we do not use your Customer Content to advertise to you.
How data is stored and secured
Data is stored in a managed Postgres database with row-level security, and photos are kept in private storage served through signed, expiring links. Traffic is encrypted in transit, and data is encrypted at rest by our infrastructure provider. Access within your organization is controlled by role.
Cookies
We use strictly necessary cookies to keep you signed in and to keep the Service secure. We keep analytics minimal and privacy-preserving.
Sharing and sub-processors
We share data only with service providers who help us run the Service, under confidentiality obligations, and when required by law. Today those providers are: Vercel (hosting, edge network and privacy-preserving site analytics), Supabase (database, authentication and private file storage), Stripe (payments — we never see or store card numbers), Resend (transactional email, when enabled), andOpenStreetMap / Photon (address suggestions — only the address text you type is sent, never your account details). We do not sell personal information and we do not use your inspection data to train models. Reports you choose to share by link are accessible to anyone with that link until it expires or you revoke it, so share it carefully.
Location
When someone reports an issue through a workspace’s resident report link, they can optionally tap “Pin my location” to attach the coordinates of the problem. This is never collected automatically — the browser asks first, the report works without it, and the pin can be removed before sending. We store the coordinates and their accuracy so the property manager can find the issue and match it to the right property. We do not track location in the background or build location histories.
Your rights
You can access, correct, export, and delete your data yourself. Workspace owners can export inspections and the audit log as CSV, download any report as PDF or ZIP, and permanently delete the whole workspace from Settings → Danger zone (files, records, member logins and any subscription go with it). Team members can delete their own login from the same page. Because organizations control their own workspaces, some requests may be directed to your administrator. Contact us and we'll help.
Retention
We keep Customer Content for as long as your account is active. When you delete a workspace it is removed immediately from our production database and file storage; encrypted backups roll off within 30 days.
Contact
Questions or requests? Email hello@sitesui.com.
Questions about this policy? Email hello@sitesui.com and we'll get you a clear answer.