Privacy Policy
Last updated: July 22, 2026
1. Overview
SiteHalo (“SiteHalo,” “we,” “us”) provides automated website monitoring: SEO, accessibility, performance, SSL, uptime, security, cookie, form, tracking-pixel, and legal-compliance scans, daily AI-assisted reports, and an optional client-side JavaScript snippet that measures real visitor performance and errors on sites you monitor.
This policy explains what we collect, why, and how it's handled. It applies to two different groups of people, covered separately below because their relationship to us is different:
- Customers — people who create a SiteHalo account to monitor websites they own or manage.
- Site visitors — people who visit a website that one of our customers has chosen to monitor, on which the customer has installed our optional monitoring snippet.
2. Information We Collect
Account & organization data
Name, email address, and password (stored as a salted hash, never in plain text) when you register. If you sign in with Google or GitHub, we receive your name, email, and profile image from that provider instead. We also store the organization/agency name you create, its members and their roles, and optional white-label branding (logo, color, display name) you configure.
Sites, scans & reports
The URLs you add for monitoring, the results of each scan (scores and issues across SEO, accessibility, performance, SSL, uptime, security, cookies, forms, tracking, and legal dimensions), and the AI-generated or template-generated reports built from those results.
Monitoring snippet data (if you install it)
The optional sitehalo.js snippet, when installed on a monitored site, collects only the following from that site's visitors:
- Core Web Vitals (LCP, CLS, INP) and page load timing.
- JavaScript error messages, stack traces, and the page URL they occurred on — used to help you debug your site.
- Form submission metadata: the form's action URL, HTTP method, and field count/outcome. We never capture what a visitor typed into a field.
- The names of cookies present on the page (e.g. to flag undisclosed trackers) — never cookie values.
The snippet does not fingerprint devices, does not set its own cookies, does not track visitors across different websites, and does not collect names, emails, or other direct identifiers. See Section 8 if you're a visitor to a site that uses our snippet.
Billing data
Payments are processed by Stripe. We store your Stripe customer and subscription IDs, plan, status, and billing period — never your full card number, which Stripe handles directly.
Communications
Transactional emails (report delivery, password resets, billing notices) are sent via Resend using the address you provide.
Activity & security logs
We keep an audit log of account-level actions (e.g. site added, scan triggered, report sent) for security, troubleshooting, and accountability within your organization. Standard server request logs (IP address, user agent, timestamps) are retained briefly by our hosting infrastructure for abuse prevention and reliability.
3. How We Use Information
- To run scans, generate health scores, and produce reports for your sites.
- To generate AI-assisted report narratives — scan summaries and issue data (not raw visitor personal data) are sent to OpenAI for this purpose; see Section 4.
- To operate your account: authentication, billing, and email delivery.
- To maintain security, prevent abuse, and enforce our Terms of Service.
- To improve the product and understand feature usage in aggregate.
- To comply with legal obligations.
We do not sell personal data, and we do not use it for third-party advertising.
4. AI-Assisted Reports
When an OpenAI API key is configured, report narratives are generated by sending your site name, URL, and structured scan results (scores and issue descriptions) to OpenAI's API. If no key is configured, reports are generated from a fixed template instead. In neither case do we send snippet-collected visitor data, account passwords, or billing details to OpenAI.
6. Data Retention
Scan results and snippet-collected metrics are retained according to your plan, then automatically purged:
- Starter — 30 days
- Pro — 90 days
- Agency — 180 days
- Enterprise — 365 days
Account and organization data is retained for as long as your account is active. If you delete your account, we delete your account data and remaining monitoring data within a reasonable period, except where we're required to keep billing records for tax or legal purposes.
7. If You're a Visitor to a Monitored Site
SiteHalo is a tool that our customers — website owners and agencies — use to monitor their own sites. If a site you're visiting has installed our monitoring snippet, we act as a data processor on that site owner's behalf, collecting only the limited technical data described in Section 2 to help them keep their site healthy.
We don't have a direct relationship with site visitors and can't look up individual visitors by name or contact them. The site owner is responsible for disclosing their use of monitoring tools (including SiteHalo) in their own privacy policy and for obtaining any consent required under applicable law. If you have concerns about a specific site, please contact that site's owner directly.
8. Your Rights & Choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to or restrict certain processing. Account holders can update most account data directly in dashboard settings, or delete their account entirely. To exercise any of these rights, email us at the address in Section 14 and we'll respond within a reasonable timeframe.
10. Security
We use industry-standard measures to protect data — encrypted connections (HTTPS) in transit, hashed passwords, and access controls scoped to your organization. No system is perfectly secure, and we can't guarantee absolute security, but we work to protect your data and will notify affected users as required by law in the event of a breach.
11. Children's Privacy
SiteHalo is a business tool not directed at children, and we don't knowingly collect personal data from anyone under 16.
12. International Data Transfers
Our infrastructure providers may process and store data in the United States and other countries. Where required, we rely on appropriate safeguards for these transfers.
13. Changes to This Policy
We may update this policy as SiteHalo evolves. Material changes will be reflected by updating the “Last updated” date above, and for significant changes we will make reasonable efforts to notify account holders by email.
14. Contact Us
Questions about this policy or your data? Email support@sitehalo.io.
See also our Terms of Service.
