Privacy Policy

How we process your personal data

Last updated: 15. Juli 2026

1. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

Sitebaze
Tim-Alexander Schulz
Brunnenweg 18a
21643 Beckdorf
Germany

Email: support@sitebaze.com

2. Overview of processing activities

Below we inform you about the processing of your personal data when using our platform Sitebaze. We process the following categories of personal data:

  • Master data - name, email address, organisation membership
  • Contact data - email address
  • Authentication and security data - two-factor configuration, passkey credentials (public key only), sign-in and security logs
  • Usage data - access times, pages viewed, features used
  • Payment data - billing information (processed by Stripe)
  • Content data - URLs, keywords and website data you enter, AI-generated content

Processing takes place to provide our SaaS platform, to perform the contract, to improve our service and to comply with legal obligations.

Language note: The Sitebaze application is currently provided in German only - this includes the user interface, system emails, invoices, AI-generated content and customer support. This privacy policy is available in English so that you can understand how your data is processed. You are welcome to contact us in English at support@sitebaze.com regarding your data protection rights.

3. Legal bases

We process your personal data on the basis of the following legal bases under the GDPR:

  • Art. 6(1)(b) GDPR (performance of a contract) - processing to perform the usage agreement, e.g. account creation, provision of the SaaS features, payment processing.
  • Art. 6(1)(f) GDPR (legitimate interests) - processing to ensure operation, fix errors, protect against misuse and improve our service.
  • Art. 6(1)(a) GDPR (consent) - where you have consented to specific processing, e.g. connecting Google Search Console or your social media channels. For connecting TikTok we additionally obtain your express consent to the third-country transfer under Art. 49(1)(a) GDPR.
  • Art. 6(1)(c) GDPR (legal obligation) - where we are legally required to process data, e.g. retention obligations under tax law.

4. Data collected in detail

Master data

When you register we collect your name and email address. This data is required to create and administer your user account.

Contact data

We use your email address for transactional notifications (e.g. email verification, password reset, monitoring alerts).

Usage data

When you use our platform, technical data is collected automatically, including IP address, access times, browser type and pages viewed. This data serves the security and stability of our service.

Payment data

Payment information (e.g. card numbers) is processed exclusively by our payment service provider Stripe. We do not store complete payment data on our systems.

Content data

To provide our SEO features we process the URLs, keywords and website data you enter. AI-generated content is stored in your account until you delete it or cancel your account.

5. Hosting and provision

Our platform is hosted in Germany with Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). Application, database and file storage are located exclusively in German data centres (location Falkenstein/Nuremberg, EU). No transfer to third countries takes place as part of the hosting.

When you access our platform, access logs are created automatically containing your IP address, the time of access, the URL requested and the HTTP status code. These logs serve security, abuse detection and error correction and are kept for a limited period only, regularly for up to 30 days.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable provision). A data processing agreement under Art. 28 GDPR is in place with Hetzner Online GmbH.

5a. Content delivery and protection (Cloudflare)

To deliver our website sitebaze.com and as an upstream protection proxy (including DDoS defence, TLS termination, caching) we use Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; for the EEA: Cloudflare Germany GmbH, with Cloudflare, Inc. certified under the EU-US Data Privacy Framework). In doing so, Cloudflare processes technically necessary connection data (in particular IP address, date and time, requested resource, browser and device information) in order to deliver requests and repel attacks.

The application itself, the database and file storage remain unchanged on servers in Germany (Hetzner); Cloudflare acts as a transit and protection layer. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, performant provision). A data processing agreement including EU standard contractual clauses is in place with Cloudflare; Cloudflare is certified under the EU-US Data Privacy Framework. Connection logs are kept for a short period only.

5b. Statistics and audience measurement (with consent only)

On your first visit to sitebaze.com we ask via a cookie banner whether we may evaluate the use of the website statistically. Without your active consent, no statistics tool is loaded. We store your choice with a version and timestamp locally in your browser (localStorage, entry „sitebaze_consent“) - this is technically necessary in order to respect your decision. You can change or withdraw your choice at any time via the „Cookie settings“ link in the footer.

Where consent has been given, we use Cloudflare Web Analytics (Cloudflare, Inc., certified under the EU-US Data Privacy Framework) - cookie-free audience measurement: it works without cookies, without cross-site tracking and without profiling; aggregated metrics such as page views, country of origin and browser type are recorded.

The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG - the German act implementing the ePrivacy rules). You may withdraw it at any time with effect for the future (footer → „Cookie settings“).

6. Bot protection at registration (Friendly Captcha)

To protect against automated mass registrations and misuse we use Friendly Captcha at registration (Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee, Germany).

Friendly Captcha works without puzzles and without cookies. Instead of tracking you, your browser solves a cryptographic task in the background (proof of work). Only technically necessary data is processed (including IP address and an anonymous application identifier); there is no cross-site tracking and no profiling.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing spam and automated misuse). Processing takes place in the EU (Germany).

7. Social media analysis (connecting your own channels)

If you use the optional social media analysis, you can connect your own social media channels in order to evaluate their reach and engagement metrics in the dashboard. The connection is made exclusively at your instigation via OAuth 2.0 and can be revoked at any time.

Important: Data is retrieved strictly read-only and server to server. No content is published, no data is transmitted back to the platforms, and no scripts or tracking pixels of the platforms are loaded in your browser. Only aggregated metrics of your own account are retrieved (e.g. follower count, views, interactions) - no personal data of your followers. We store access tokens and retrieved metrics encrypted in Germany (see section 5).

Providers and third-country transfers

  • YouTube / Google - Google Ireland Limited and Google LLC (USA). Google LLC is certified under the EU-U.S. Data Privacy Framework. For the YouTube connection Sitebaze uses the YouTube API Services; the YouTube Terms of Service and the Google Privacy Policy apply in addition. Besides disconnecting in Sitebaze, you can revoke access at any time directly in your Google security settings.
  • Instagram / Facebook (Meta) - Meta Platforms Ireland Ltd. and Meta Platforms, Inc. (USA). Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework.
  • TikTok - TikTok Technology Limited (Ireland) / ByteDance Ltd. With TikTok, data may be transferred to countries outside the EU, in particular China, for which there is no level of data protection equivalent to EU law. A TikTok connection is therefore only made after your separate, express consent (Art. 49(1)(a) GDPR), which we document and which you can withdraw at any time.

The legal basis is your consent (Art. 6(1)(a) GDPR; for TikTok additionally Art. 49(1)(a) GDPR for the third-country transfer). When you disconnect, access is revoked at the platform and the stored histories are deleted (Art. 17 GDPR).

8. Database and authentication

Database and file storage

Your data is stored in a PostgreSQL database and in object storage (for uploaded files). Both are operated by Hetzner Online GmbH in Germany (see section 5); encrypted backups also remain in Germany. No transfer to third countries takes place here. Particularly sensitive data (e.g. access tokens for connected services) is additionally stored encrypted at application level (AES-256-GCM).

Better Auth (authentication)

For authentication we use the open source library Better Auth, which runs server-side on our own infrastructure. Passwords are stored using industry-standard hashing procedures and are not visible to us in plain text. Sessions are managed via secure, encrypted cookies.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

Two-factor authentication (authenticator app and passkeys/WebAuthn)

To protect your account we offer optional two-factor authentication (2FA). You can choose between an authenticator app (TOTP) and a passkey (WebAuthn/FIDO2), e.g. Face ID, Touch ID or a hardware security key.

For passkeys we store only the public key, a credential identifier and minimal technical metadata (device type, synchronisation status, supported transports, an authenticator model identifier („AAGUID“) and the creation date). Your biometric data (fingerprint, face) remains solely on your device - it is never transmitted to us or stored by us. The public key alone does not permit access to your account.

For the authenticator app (TOTP) we store the associated secret encrypted, and your backup codes only as a non-reversible hash. After a successful 2FA check we set a secure cookie bound to the respective session (__user_2fa_verified) so that you do not have to confirm again at every step within a session.

You can manage and remove stored passkeys and the authenticator app at any time in the security settings of your account. If you delete your account, all 2FA data and passkey credentials are deleted along with it (Art. 17 GDPR). Only the data required for the security purpose is processed (data minimisation, Art. 5(1)(c) GDPR).

The legal basis is Art. 6(1)(b) GDPR (performance of a contract - providing a secure account) and Art. 6(1)(f) GDPR (legitimate interest in protection against unauthorised access). If your organisation requires 2FA for team access, Art. 6(1)(f) GDPR (security of organisational data) applies in addition.

9. Email delivery

To send transactional emails we use the service Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; parent company Sendinblue SAS, France/EU). The following emails are sent on an event-driven basis only:

  • email verification at registration
  • password reset
  • monitoring alerts (e.g. website outages)
  • billing notifications

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). A data processing agreement under Art. 28 GDPR is in place with the provider; processing takes place within the EU. These emails are currently sent in German.

Newsletter

On our website you can subscribe to our newsletter with news about Sitebaze and tips on online visibility. Only your email address is processed. Sign-up follows the double opt-in procedure: you first receive a confirmation email; only after you click the confirmation link are you added to the recipient list. The time of sign-up and confirmation are logged for evidence purposes.

Delivery is likewise handled via Brevo (processing in the EU, data processing agreement under Art. 28 GDPR). The legal basis is your consent under Art. 6(1)(a) GDPR. You can unsubscribe at any time via the unsubscribe link in every email and thereby withdraw your consent with effect for the future (Art. 7(3) GDPR); your address is then removed from the list. Transactional emails (see above) are sent independently of this on an event-driven basis only.

10. Support tickets and support communication (Crisp)

To handle support tickets and support messages in your dashboard we use the service Crisp.

Provider

Crisp IM SAS, 2 Boulevard de Launay, 44100 Nantes, France (EU).

Type of integration

In the current product version no general Crisp live chat widget is loaded client-side on all pages. Support requests are transmitted server-side from the Sitebaze dashboard to Crisp as soon as you create a ticket or reply to an existing one.

Data processed

When a support ticket is created or handled, the following data is processed in particular:

  • name and email address of your Sitebaze account
  • subject, ticket content and follow-up messages
  • timestamps and ticket metadata
  • content you voluntarily provide to us as part of your support request

Purpose

Receiving, handling and documenting support requests, and technical assistance for existing customers. Support is currently provided in German.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in efficient customer support).

Crisp processes the data on servers within the EU. Further information can be found in Crisp’s privacy terms.

11. Payment processing

Payments are processed via Stripe Inc. According to Stripe, the transfer mechanisms provided by the company are in place for appropriate data transfers to the USA, in particular certification under the EU-U.S. Data Privacy Framework (DPF) and further contractual documentation.

When booking a paid plan you are redirected to Stripe’s secure payment page. Card numbers and bank details are processed and stored exclusively by Stripe. At no point do we have access to your complete payment data.

From Stripe we receive only a confirmation of the payment status, the last four digits of your card and the billing address.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). For further information on Stripe’s role under data protection law and its contractual mechanisms we refer to Stripe’s privacy and contract documentation.

12. SEO data processing

For SEO analyses (e.g. keyword tracking, site audit, backlink data) we use an external SEO data provider. Only domain, keyword and technical website data is transmitted to that provider (e.g. the domain to be analysed, keywords, HTTP status codes, load times).

No personal data of you or your website visitors is transmitted in the process. There is therefore no recipient relationship with regard to personal data. The legal basis for providing the SEO features is Art. 6(1)(b) GDPR (performance of a contract).

13. Core Web Vitals analysis (Google CrUX API)

Purpose

Measuring the loading speed and user experience of the analysed customer websites as part of the site audit feature. The Core Web Vitals (LCP, INP, CLS, TTFB) are based on real Chrome user data from the past 28 days.

Service and provider

Google Chrome User Experience Report API (CrUX)
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Data transmitted

Only the domain (origin URL) of the analysed website is sent server-side to the CrUX API. No IP addresses, cookies or personal data of users or website visitors are transmitted.

Data received

Aggregated, anonymised performance metrics (Core Web Vitals: LCP, INP, CLS, TTFB) based on Chrome user data from the past 28 days. The CrUX data is fully anonymised and does not allow any conclusions about individual website visitors.

Third-country transfer

According to Google, certifications under the EU-U.S. Data Privacy Framework (DPF) and further contractual safeguards are in place for appropriate data transfers to the USA. Google’s current privacy and transfer information is authoritative.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract - part of the site audit feature).

14. AI-assisted features

For AI-assisted features (e.g. content optimisation, meta title suggestions, legal text generator) we use the API of Anthropic (Claude). According to Anthropic, the transfer mechanisms provided by the company are in place for appropriate data transfers to the USA, in particular certification under the EU-U.S. Data Privacy Framework (DPF).

When AI features are used, the following data is transmitted to Anthropic:

  • the texts and instructions you enter
  • context information about your website (URLs, existing content)

According to Anthropic, transmitted data is not used to train general AI models. Processing takes place solely to generate the requested results. For further information on deletion periods and data protection measures, please refer to Anthropic’s current documentation.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Where required for this use, we rely on the data protection and contractual mechanisms provided by the supplier. Content generated by these features is currently produced in German.

15. External analytics integrations (Google Search Console, GA4, Matomo)

Google Search Console (OAuth 2.0)

Sitebaze offers the optional possibility of connecting your Google Search Console account to our platform. This integration serves to display your search performance data (clicks, impressions, average positions, click-through rate) directly within our platform. The connection is voluntary and not required for basic use of Sitebaze.

Technical procedure (OAuth 2.0)

Authorisation takes place via the industry-standard OAuth 2.0 protocol with the security extension PKCE (Proof Key for Code Exchange, RFC 7636). In this procedure you are redirected to Google’s sign-in page, where you explicitly approve access to your Search Console data. At no point does Sitebaze learn your Google password. Authentication takes place exclusively on Google’s servers.

Requested scope of access

We request read access only to your Search Console data (webmasters.readonly). Sitebaze cannot make changes to your Google account or your Search Console settings. In addition, your email address (email) is retrieved in order to display the connection in the platform.

Data retrieved

Where a connection exists, the following data is retrieved from the Google Search Console API:

  • search queries (keywords) and associated clicks/impressions
  • average positions in Google search results
  • click-through rate (CTR) per query and page
  • breakdown by device type (desktop, mobile, tablet) and country
  • list of properties verified in Search Console (domains/URLs)

No personal data of your website visitors is processed. The retrieved data relates exclusively to the aggregated search performance of your website.

Storage and encryption

The access token and refresh token issued by Google are stored AES-256-GCM encrypted in our database. Encryption takes place server-side with a secret key held exclusively on our servers. Without that key the stored tokens are worthless.

Search performance data is stored per project in our database and is accessible only to the respective user or organisation.

Withdrawal and deletion

You can revoke the connection to Google Search Console at any time:

  • In Sitebaze: via the „Disconnect“ button in the analytics settings. All stored tokens and retrieved Search Console data are irrevocably deleted.
  • In your Google account: via myaccount.google.com/permissions. This invalidates the issued token on Google’s side.

If you delete your Sitebaze account, all Google tokens and Search Console data are deleted automatically and completely.

Limited use of Google user data

Sitebaze’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use this data solely to display and provide the features described here within Sitebaze. We do not transfer or sell this data to third parties, do not use it for advertising and do not use it to train AI models. Staff have no read access to this data, except with your express consent, for security reasons, or where legally required.

Data transfer to Google

When using the Search Console integration, API requests are sent to servers of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). According to Google, certifications under the EU-U.S. Data Privacy Framework (DPF) and further data protection and contractual mechanisms are in place for appropriate data transfers to the USA. Google’s privacy terms apply.

The legal basis for this optional account connection is Art. 6(1)(b) GDPR, insofar as you initiate the integration yourself and use it for the product you have booked.

Google Analytics 4 (OAuth 2.0)

Optionally, you can also connect a Google Analytics 4 property to Sitebaze. For this we use a secured OAuth 2.0 procedure with PKCE. Only read access rights are requested (https://www.googleapis.com/auth/analytics.readonly) along with the email address of your Google account in order to assign the connection.

Aggregated reporting data of the selected property is retrieved and stored, such as visitor numbers, page views, device, browser and referrer data. The OAuth tokens are stored encrypted. For this connection too, the legal basis is Art. 6(1)(b) GDPR.

Matomo (cloud or self-hosted)

Sitebaze optionally supports connecting a Matomo instance. Depending on your configuration, this may be a self-operated Matomo installation or Matomo Cloud. For the connection we store the instance URL you provide, the site ID and an encrypted API token.

Through the Matomo interface we retrieve aggregated reporting data such as visitors, page views, referrers, device and country statistics. The specific role under data protection law and any third-country transfers depend, in the case of Matomo, on the instance you choose. The legal basis for the technical processing within Sitebaze is likewise Art. 6(1)(b) GDPR.

You can disconnect connected Google or Matomo integrations at any time in the respective analytics settings. The tokens and connection data stored in Sitebaze for that integration are deleted in the process.

16. Google favicon service

To display project websites visually in our user interface (e.g. in the project switcher and on the dashboard) we load website icons (favicons) via Google’s public favicon service: www.google.com/s2/favicons

Prior blocking

The favicon service is disabled by default. Requests to Google servers are only made after you have consented to the category „Functional“ via our cookie banner (section 25(1) TDDDG). Without consent, a neutral placeholder (first letter of the domain) is displayed instead.

Data transmitted

When the icons are loaded, your browser establishes a direct connection to servers of Google LLC. The following data is transmitted to Google:

  • your IP address
  • the domain name for which the favicon is requested
  • customary HTTP headers (user agent, referrer)

To the best of our knowledge, this retrieval is not linked to your Google account.

According to Google, certifications under the EU-U.S. Data Privacy Framework (DPF) are in place for appropriate data transfers to the USA. Google’s privacy terms apply.

The legal basis is Art. 6(1)(a) GDPR in conjunction with section 25(1) TDDDG (consent via the cookie banner, category „Functional“).

17. Cookies, consent management and sessions

Cookie banner and consent management

Sitebaze uses its own consent management system (cookie banner) to obtain your consent for non-essential processing. On your first visit to our platform, a cookie banner is displayed through which you can grant or refuse consent granularly.

Without your active consent, no analytics, statistics or third-party services are loaded (prior blocking pursuant to section 25(1) TDDDG).

You can change or withdraw your cookie settings at any time via the „Cookie settings“ link in the sidebar (dashboard) or in the footer (marketing pages). Withdrawal is just as easy as giving consent in the first place (Art. 7(3) GDPR).

Consent categories

CategoryPre-selectedServices
EssentialYes (cannot be deselected)session cookies, OAuth security cookies, portal security cookies, consent cookie
FunctionalNoGoogle favicon service
StatisticsNono active statistics services at present
MarketingNono services at present

Evidence of consent

In accordance with Art. 7(1) GDPR we document your consent decision in an audit trail. The following data is stored:

  • time of consent
  • action chosen (accept all, reject all, individual selection, withdrawal)
  • categories chosen (functional, statistics, marketing)
  • version of the banner configuration at the time of consent
  • anonymous visitor ID (not personal)
  • SHA-256 hashed IP address (cannot be traced back to the plain-text IP)

This evidence data is retained for 3 years (limitation period for administrative fine proceedings) and is then deleted automatically (Art. 17 GDPR).

Cookies used

CookiePurposeCategoryDuration
sb_consentstoring your cookie settingsEssential365 days
better-auth.session_tokenauthentication and session managementEssential7 days
__user_2fa_verifiedevidence of a passed 2FA check (session-bound)Essential12 hours
__passkey_proofshort-lived one-time proof directly after passkey confirmationEssential2 minutes
__portal_sessionsession cookie for the client portalEssential7 days
__portal_csrfCSRF protection for portal formsEssential1 hour
gsc_oauth_state / gsc_code_verifiersecure OAuth start for Google Search ConsoleEssential5 minutes
ga4_oauth_state / ga4_code_verifiersecure OAuth start for Google Analytics 4Essential5 minutes

The bot protection used (Friendly Captcha) works without cookies.

The legal basis for essential cookies is Art. 6(1)(f) GDPR (legitimate interest in technical provision and security). For the consent evidence (audit trail) the legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (legal obligation to demonstrate consent).

18. Your rights

As a data subject you have the following rights under the GDPR. To exercise your rights please contact support@sitebaze.com. You are welcome to write to us in English.

  • Right of access (Art. 15 GDPR) - you can request information about the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR) - you can request that inaccurate data be corrected.
  • Right to erasure (Art. 17 GDPR) - you can request that your data be deleted, provided no statutory retention obligations conflict with this.
  • Right to restriction of processing (Art. 18 GDPR) - you can request that the processing of your data be restricted.
  • Right to data portability (Art. 20 GDPR) - you can request the data you provided in a structured, commonly used and machine-readable format, where the statutory conditions are met.
  • Right to object (Art. 21 GDPR) - you can object to the processing of your data where it is based on legitimate interests.
  • Right to withdraw consent - you can withdraw consent at any time with effect for the future, e.g. via the „Cookie settings“ link.
  • Right to lodge a complaint (Art. 77 GDPR) - you have the right to lodge a complaint with a data protection supervisory authority.

19. Data security

We use extensive technical and organisational measures to protect your data:

  • Encrypted transmission - all data transmissions take place over TLS-encrypted connections (HTTPS).
  • Encrypted storage - sensitive data such as OAuth tokens and API keys is stored encrypted in the database.
  • Password hashing - passwords are stored using industry-standard hashing procedures and cannot be recovered.
  • IP hashing - IP addresses in consent records are stored hashed with SHA-256 and cannot be traced back to the plain-text IP.
  • Regular backups - automatic database backups protect your data against loss.
  • Access control - access to production systems is kept to a minimum and protected by additional security mechanisms.

20. Retention periods

We store your personal data only for as long as is necessary for the respective purposes or as long as statutory retention obligations exist:

Data categoryRetention period
Account datauntil account deletion + 30 days grace period
Server logsregularly up to 30 days
Passkey credentials and 2FA configurationuntil removed by you or until account deletion
Consent records3 years (limitation period), then deleted automatically
Consent cookie (sb_consent)365 days, re-consent after 12 months or on configuration change
Social media metrics (connected channels)daily values up to 24 months, monthly aggregates long term; complete deletion when the connection is removed
SEO data and keywordsuntil deleted in the account, until account deletion or until deletion required under the contract
AI-generated contentuntil deleted by you or until account deletion
Payment data (records)10 years (retention obligation under tax law)
OAuth tokens (Google)until the integration is disconnected, until withdrawal or until account deletion

21. Changes and contact

We reserve the right to adapt this privacy policy where necessary, in order to reflect changes in the legal situation or changes to our service or data processing. The current version can always be found on this page.

In the event of material changes affecting your rights we will inform you by email.

For questions about data protection you can reach us at: support@sitebaze.com

This English version is provided to inform you in a language you understand, as required by Art. 12(1) GDPR. The German version is also available and is kept in step with this one.