Privacy Policy
How we process your personal data
Last updated: 15. Juli 2026
1. Controller
Controller within the meaning of the General Data Protection Regulation (GDPR):
SitebazeTim-Alexander Schulz
Brunnenweg 18a
21643 Beckdorf
Germany
Email: support@sitebaze.com
2. Overview of processing activities
Below we inform you about the processing of your personal data when using our platform Sitebaze. We process the following categories of personal data:
- Master data - name, email address, organisation membership
- Contact data - email address
- Authentication and security data - two-factor configuration, passkey credentials (public key only), sign-in and security logs
- Usage data - access times, pages viewed, features used
- Payment data - billing information (processed by Stripe)
- Content data - URLs, keywords and website data you enter, AI-generated content
Processing takes place to provide our SaaS platform, to perform the contract, to improve our service and to comply with legal obligations.
Language note: The Sitebaze application is currently provided in German only - this includes the user interface, system emails, invoices, AI-generated content and customer support. This privacy policy is available in English so that you can understand how your data is processed. You are welcome to contact us in English at support@sitebaze.com regarding your data protection rights.
3. Legal bases
We process your personal data on the basis of the following legal bases under the GDPR:
- Art. 6(1)(b) GDPR (performance of a contract) - processing to perform the usage agreement, e.g. account creation, provision of the SaaS features, payment processing.
- Art. 6(1)(f) GDPR (legitimate interests) - processing to ensure operation, fix errors, protect against misuse and improve our service.
- Art. 6(1)(a) GDPR (consent) - where you have consented to specific processing, e.g. connecting Google Search Console or your social media channels. For connecting TikTok we additionally obtain your express consent to the third-country transfer under Art. 49(1)(a) GDPR.
- Art. 6(1)(c) GDPR (legal obligation) - where we are legally required to process data, e.g. retention obligations under tax law.
4. Data collected in detail
Master data
When you register we collect your name and email address. This data is required to create and administer your user account.
Contact data
We use your email address for transactional notifications (e.g. email verification, password reset, monitoring alerts).
Usage data
When you use our platform, technical data is collected automatically, including IP address, access times, browser type and pages viewed. This data serves the security and stability of our service.
Payment data
Payment information (e.g. card numbers) is processed exclusively by our payment service provider Stripe. We do not store complete payment data on our systems.
Content data
To provide our SEO features we process the URLs, keywords and website data you enter. AI-generated content is stored in your account until you delete it or cancel your account.
5. Hosting and provision
Our platform is hosted in Germany with Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). Application, database and file storage are located exclusively in German data centres (location Falkenstein/Nuremberg, EU). No transfer to third countries takes place as part of the hosting.
When you access our platform, access logs are created automatically containing your IP address, the time of access, the URL requested and the HTTP status code. These logs serve security, abuse detection and error correction and are kept for a limited period only, regularly for up to 30 days.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable provision). A data processing agreement under Art. 28 GDPR is in place with Hetzner Online GmbH.
5a. Content delivery and protection (Cloudflare)
To deliver our website sitebaze.com and as an upstream protection proxy (including DDoS defence, TLS termination, caching) we use Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; for the EEA: Cloudflare Germany GmbH, with Cloudflare, Inc. certified under the EU-US Data Privacy Framework). In doing so, Cloudflare processes technically necessary connection data (in particular IP address, date and time, requested resource, browser and device information) in order to deliver requests and repel attacks.
The application itself, the database and file storage remain unchanged on servers in Germany (Hetzner); Cloudflare acts as a transit and protection layer. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, performant provision). A data processing agreement including EU standard contractual clauses is in place with Cloudflare; Cloudflare is certified under the EU-US Data Privacy Framework. Connection logs are kept for a short period only.
5b. Statistics and audience measurement (with consent only)
On your first visit to sitebaze.com we ask via a cookie banner whether we may evaluate the use of the website statistically. Without your active consent, no statistics tool is loaded. We store your choice with a version and timestamp locally in your browser (localStorage, entry „sitebaze_consent“) - this is technically necessary in order to respect your decision. You can change or withdraw your choice at any time via the „Cookie settings“ link in the footer.
Where consent has been given, we use Cloudflare Web Analytics (Cloudflare, Inc., certified under the EU-US Data Privacy Framework) - cookie-free audience measurement: it works without cookies, without cross-site tracking and without profiling; aggregated metrics such as page views, country of origin and browser type are recorded.
The legal basis is your consent (Art. 6(1)(a) GDPR, section 25(1) TDDDG - the German act implementing the ePrivacy rules). You may withdraw it at any time with effect for the future (footer → „Cookie settings“).
6. Bot protection at registration (Friendly Captcha)
To protect against automated mass registrations and misuse we use Friendly Captcha at registration (Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee, Germany).
Friendly Captcha works without puzzles and without cookies. Instead of tracking you, your browser solves a cryptographic task in the background (proof of work). Only technically necessary data is processed (including IP address and an anonymous application identifier); there is no cross-site tracking and no profiling.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing spam and automated misuse). Processing takes place in the EU (Germany).
8. Database and authentication
Database and file storage
Your data is stored in a PostgreSQL database and in object storage (for uploaded files). Both are operated by Hetzner Online GmbH in Germany (see section 5); encrypted backups also remain in Germany. No transfer to third countries takes place here. Particularly sensitive data (e.g. access tokens for connected services) is additionally stored encrypted at application level (AES-256-GCM).
Better Auth (authentication)
For authentication we use the open source library Better Auth, which runs server-side on our own infrastructure. Passwords are stored using industry-standard hashing procedures and are not visible to us in plain text. Sessions are managed via secure, encrypted cookies.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Two-factor authentication (authenticator app and passkeys/WebAuthn)
To protect your account we offer optional two-factor authentication (2FA). You can choose between an authenticator app (TOTP) and a passkey (WebAuthn/FIDO2), e.g. Face ID, Touch ID or a hardware security key.
For passkeys we store only the public key, a credential identifier and minimal technical metadata (device type, synchronisation status, supported transports, an authenticator model identifier („AAGUID“) and the creation date). Your biometric data (fingerprint, face) remains solely on your device - it is never transmitted to us or stored by us. The public key alone does not permit access to your account.
For the authenticator app (TOTP) we store the associated secret encrypted, and your backup codes only as a non-reversible hash. After a successful 2FA check we set a secure cookie bound to the respective session (__user_2fa_verified) so that you do not have to confirm again at every step within a session.
You can manage and remove stored passkeys and the authenticator app at any time in the security settings of your account. If you delete your account, all 2FA data and passkey credentials are deleted along with it (Art. 17 GDPR). Only the data required for the security purpose is processed (data minimisation, Art. 5(1)(c) GDPR).
The legal basis is Art. 6(1)(b) GDPR (performance of a contract - providing a secure account) and Art. 6(1)(f) GDPR (legitimate interest in protection against unauthorised access). If your organisation requires 2FA for team access, Art. 6(1)(f) GDPR (security of organisational data) applies in addition.
9. Email delivery
To send transactional emails we use the service Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; parent company Sendinblue SAS, France/EU). The following emails are sent on an event-driven basis only:
- email verification at registration
- password reset
- monitoring alerts (e.g. website outages)
- billing notifications
The legal basis is Art. 6(1)(b) GDPR (performance of a contract). A data processing agreement under Art. 28 GDPR is in place with the provider; processing takes place within the EU. These emails are currently sent in German.
Newsletter
On our website you can subscribe to our newsletter with news about Sitebaze and tips on online visibility. Only your email address is processed. Sign-up follows the double opt-in procedure: you first receive a confirmation email; only after you click the confirmation link are you added to the recipient list. The time of sign-up and confirmation are logged for evidence purposes.
Delivery is likewise handled via Brevo (processing in the EU, data processing agreement under Art. 28 GDPR). The legal basis is your consent under Art. 6(1)(a) GDPR. You can unsubscribe at any time via the unsubscribe link in every email and thereby withdraw your consent with effect for the future (Art. 7(3) GDPR); your address is then removed from the list. Transactional emails (see above) are sent independently of this on an event-driven basis only.
10. Support tickets and support communication (Crisp)
To handle support tickets and support messages in your dashboard we use the service Crisp.
Provider
Crisp IM SAS, 2 Boulevard de Launay, 44100 Nantes, France (EU).
Type of integration
In the current product version no general Crisp live chat widget is loaded client-side on all pages. Support requests are transmitted server-side from the Sitebaze dashboard to Crisp as soon as you create a ticket or reply to an existing one.
Data processed
When a support ticket is created or handled, the following data is processed in particular:
- name and email address of your Sitebaze account
- subject, ticket content and follow-up messages
- timestamps and ticket metadata
- content you voluntarily provide to us as part of your support request
Purpose
Receiving, handling and documenting support requests, and technical assistance for existing customers. Support is currently provided in German.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in efficient customer support).
Crisp processes the data on servers within the EU. Further information can be found in Crisp’s privacy terms.
11. Payment processing
Payments are processed via Stripe Inc. According to Stripe, the transfer mechanisms provided by the company are in place for appropriate data transfers to the USA, in particular certification under the EU-U.S. Data Privacy Framework (DPF) and further contractual documentation.
When booking a paid plan you are redirected to Stripe’s secure payment page. Card numbers and bank details are processed and stored exclusively by Stripe. At no point do we have access to your complete payment data.
From Stripe we receive only a confirmation of the payment status, the last four digits of your card and the billing address.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract). For further information on Stripe’s role under data protection law and its contractual mechanisms we refer to Stripe’s privacy and contract documentation.
12. SEO data processing
For SEO analyses (e.g. keyword tracking, site audit, backlink data) we use an external SEO data provider. Only domain, keyword and technical website data is transmitted to that provider (e.g. the domain to be analysed, keywords, HTTP status codes, load times).
No personal data of you or your website visitors is transmitted in the process. There is therefore no recipient relationship with regard to personal data. The legal basis for providing the SEO features is Art. 6(1)(b) GDPR (performance of a contract).
13. Core Web Vitals analysis (Google CrUX API)
Purpose
Measuring the loading speed and user experience of the analysed customer websites as part of the site audit feature. The Core Web Vitals (LCP, INP, CLS, TTFB) are based on real Chrome user data from the past 28 days.
Service and provider
Google Chrome User Experience Report API (CrUX)
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Data transmitted
Only the domain (origin URL) of the analysed website is sent server-side to the CrUX API. No IP addresses, cookies or personal data of users or website visitors are transmitted.
Data received
Aggregated, anonymised performance metrics (Core Web Vitals: LCP, INP, CLS, TTFB) based on Chrome user data from the past 28 days. The CrUX data is fully anonymised and does not allow any conclusions about individual website visitors.
Third-country transfer
According to Google, certifications under the EU-U.S. Data Privacy Framework (DPF) and further contractual safeguards are in place for appropriate data transfers to the USA. Google’s current privacy and transfer information is authoritative.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract - part of the site audit feature).
14. AI-assisted features
For AI-assisted features (e.g. content optimisation, meta title suggestions, legal text generator) we use the API of Anthropic (Claude). According to Anthropic, the transfer mechanisms provided by the company are in place for appropriate data transfers to the USA, in particular certification under the EU-U.S. Data Privacy Framework (DPF).
When AI features are used, the following data is transmitted to Anthropic:
- the texts and instructions you enter
- context information about your website (URLs, existing content)
According to Anthropic, transmitted data is not used to train general AI models. Processing takes place solely to generate the requested results. For further information on deletion periods and data protection measures, please refer to Anthropic’s current documentation.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Where required for this use, we rely on the data protection and contractual mechanisms provided by the supplier. Content generated by these features is currently produced in German.
15. External analytics integrations (Google Search Console, GA4, Matomo)
Google Search Console (OAuth 2.0)
Sitebaze offers the optional possibility of connecting your Google Search Console account to our platform. This integration serves to display your search performance data (clicks, impressions, average positions, click-through rate) directly within our platform. The connection is voluntary and not required for basic use of Sitebaze.
Technical procedure (OAuth 2.0)
Authorisation takes place via the industry-standard OAuth 2.0 protocol with the security extension PKCE (Proof Key for Code Exchange, RFC 7636). In this procedure you are redirected to Google’s sign-in page, where you explicitly approve access to your Search Console data. At no point does Sitebaze learn your Google password. Authentication takes place exclusively on Google’s servers.
Requested scope of access
We request read access only to your Search Console data (webmasters.readonly). Sitebaze cannot make changes to your Google account or your Search Console settings. In addition, your email address (email) is retrieved in order to display the connection in the platform.
Data retrieved
Where a connection exists, the following data is retrieved from the Google Search Console API:
- search queries (keywords) and associated clicks/impressions
- average positions in Google search results
- click-through rate (CTR) per query and page
- breakdown by device type (desktop, mobile, tablet) and country
- list of properties verified in Search Console (domains/URLs)
No personal data of your website visitors is processed. The retrieved data relates exclusively to the aggregated search performance of your website.
Storage and encryption
The access token and refresh token issued by Google are stored AES-256-GCM encrypted in our database. Encryption takes place server-side with a secret key held exclusively on our servers. Without that key the stored tokens are worthless.
Search performance data is stored per project in our database and is accessible only to the respective user or organisation.
Withdrawal and deletion
You can revoke the connection to Google Search Console at any time:
- In Sitebaze: via the „Disconnect“ button in the analytics settings. All stored tokens and retrieved Search Console data are irrevocably deleted.
- In your Google account: via myaccount.google.com/permissions. This invalidates the issued token on Google’s side.
If you delete your Sitebaze account, all Google tokens and Search Console data are deleted automatically and completely.
Limited use of Google user data
Sitebaze’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use this data solely to display and provide the features described here within Sitebaze. We do not transfer or sell this data to third parties, do not use it for advertising and do not use it to train AI models. Staff have no read access to this data, except with your express consent, for security reasons, or where legally required.
Data transfer to Google
When using the Search Console integration, API requests are sent to servers of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). According to Google, certifications under the EU-U.S. Data Privacy Framework (DPF) and further data protection and contractual mechanisms are in place for appropriate data transfers to the USA. Google’s privacy terms apply.
The legal basis for this optional account connection is Art. 6(1)(b) GDPR, insofar as you initiate the integration yourself and use it for the product you have booked.
Google Analytics 4 (OAuth 2.0)
Optionally, you can also connect a Google Analytics 4 property to Sitebaze. For this we use a secured OAuth 2.0 procedure with PKCE. Only read access rights are requested (https://www.googleapis.com/auth/analytics.readonly) along with the email address of your Google account in order to assign the connection.
Aggregated reporting data of the selected property is retrieved and stored, such as visitor numbers, page views, device, browser and referrer data. The OAuth tokens are stored encrypted. For this connection too, the legal basis is Art. 6(1)(b) GDPR.
Matomo (cloud or self-hosted)
Sitebaze optionally supports connecting a Matomo instance. Depending on your configuration, this may be a self-operated Matomo installation or Matomo Cloud. For the connection we store the instance URL you provide, the site ID and an encrypted API token.
Through the Matomo interface we retrieve aggregated reporting data such as visitors, page views, referrers, device and country statistics. The specific role under data protection law and any third-country transfers depend, in the case of Matomo, on the instance you choose. The legal basis for the technical processing within Sitebaze is likewise Art. 6(1)(b) GDPR.
You can disconnect connected Google or Matomo integrations at any time in the respective analytics settings. The tokens and connection data stored in Sitebaze for that integration are deleted in the process.
16. Google favicon service
To display project websites visually in our user interface (e.g. in the project switcher and on the dashboard) we load website icons (favicons) via Google’s public favicon service: www.google.com/s2/favicons
Prior blocking
The favicon service is disabled by default. Requests to Google servers are only made after you have consented to the category „Functional“ via our cookie banner (section 25(1) TDDDG). Without consent, a neutral placeholder (first letter of the domain) is displayed instead.
Data transmitted
When the icons are loaded, your browser establishes a direct connection to servers of Google LLC. The following data is transmitted to Google:
- your IP address
- the domain name for which the favicon is requested
- customary HTTP headers (user agent, referrer)
To the best of our knowledge, this retrieval is not linked to your Google account.
According to Google, certifications under the EU-U.S. Data Privacy Framework (DPF) are in place for appropriate data transfers to the USA. Google’s privacy terms apply.
The legal basis is Art. 6(1)(a) GDPR in conjunction with section 25(1) TDDDG (consent via the cookie banner, category „Functional“).
18. Your rights
As a data subject you have the following rights under the GDPR. To exercise your rights please contact support@sitebaze.com. You are welcome to write to us in English.
- Right of access (Art. 15 GDPR) - you can request information about the personal data we hold about you.
- Right to rectification (Art. 16 GDPR) - you can request that inaccurate data be corrected.
- Right to erasure (Art. 17 GDPR) - you can request that your data be deleted, provided no statutory retention obligations conflict with this.
- Right to restriction of processing (Art. 18 GDPR) - you can request that the processing of your data be restricted.
- Right to data portability (Art. 20 GDPR) - you can request the data you provided in a structured, commonly used and machine-readable format, where the statutory conditions are met.
- Right to object (Art. 21 GDPR) - you can object to the processing of your data where it is based on legitimate interests.
- Right to withdraw consent - you can withdraw consent at any time with effect for the future, e.g. via the „Cookie settings“ link.
- Right to lodge a complaint (Art. 77 GDPR) - you have the right to lodge a complaint with a data protection supervisory authority.
19. Data security
We use extensive technical and organisational measures to protect your data:
- Encrypted transmission - all data transmissions take place over TLS-encrypted connections (HTTPS).
- Encrypted storage - sensitive data such as OAuth tokens and API keys is stored encrypted in the database.
- Password hashing - passwords are stored using industry-standard hashing procedures and cannot be recovered.
- IP hashing - IP addresses in consent records are stored hashed with SHA-256 and cannot be traced back to the plain-text IP.
- Regular backups - automatic database backups protect your data against loss.
- Access control - access to production systems is kept to a minimum and protected by additional security mechanisms.
20. Retention periods
We store your personal data only for as long as is necessary for the respective purposes or as long as statutory retention obligations exist:
| Data category | Retention period |
|---|---|
| Account data | until account deletion + 30 days grace period |
| Server logs | regularly up to 30 days |
| Passkey credentials and 2FA configuration | until removed by you or until account deletion |
| Consent records | 3 years (limitation period), then deleted automatically |
| Consent cookie (sb_consent) | 365 days, re-consent after 12 months or on configuration change |
| Social media metrics (connected channels) | daily values up to 24 months, monthly aggregates long term; complete deletion when the connection is removed |
| SEO data and keywords | until deleted in the account, until account deletion or until deletion required under the contract |
| AI-generated content | until deleted by you or until account deletion |
| Payment data (records) | 10 years (retention obligation under tax law) |
| OAuth tokens (Google) | until the integration is disconnected, until withdrawal or until account deletion |
21. Changes and contact
We reserve the right to adapt this privacy policy where necessary, in order to reflect changes in the legal situation or changes to our service or data processing. The current version can always be found on this page.
In the event of material changes affecting your rights we will inform you by email.
For questions about data protection you can reach us at: support@sitebaze.com
This English version is provided to inform you in a language you understand, as required by Art. 12(1) GDPR. The German version is also available and is kept in step with this one.
7. Social media analysis (connecting your own channels)
If you use the optional social media analysis, you can connect your own social media channels in order to evaluate their reach and engagement metrics in the dashboard. The connection is made exclusively at your instigation via OAuth 2.0 and can be revoked at any time.
Important: Data is retrieved strictly read-only and server to server. No content is published, no data is transmitted back to the platforms, and no scripts or tracking pixels of the platforms are loaded in your browser. Only aggregated metrics of your own account are retrieved (e.g. follower count, views, interactions) - no personal data of your followers. We store access tokens and retrieved metrics encrypted in Germany (see section 5).
Providers and third-country transfers
The legal basis is your consent (Art. 6(1)(a) GDPR; for TikTok additionally Art. 49(1)(a) GDPR for the third-country transfer). When you disconnect, access is revoked at the platform and the stored histories are deleted (Art. 17 GDPR).