Privacy Policy
Last updated: August 22, 2026
SiteLetter is operated by Donatas Petrauskas, acting as a sole proprietor under individuali veikla (individual activity) registered in Lithuania, registration number 1534445 ("SiteLetter").
This Privacy Policy explains how SiteLetter collects, uses, stores, and protects your personal data when you use SiteLetter's website monitoring services at siteletter.com (the "Service"). SiteLetter is committed to complying with the General Data Protection Regulation (GDPR) and applicable Lithuanian data protection laws.
1. SiteLetter's Role: Controller and Processor
SiteLetter plays two distinct data-protection roles depending on the data in question:
- Controller - for data SiteLetter collects about you as a SiteLetter user (your account, billing, login sessions, settings, usage logs). SiteLetter determines the purposes and means of processing this data and is directly accountable for it under the GDPR.
- Processor - for data you ask SiteLetter to collect on your behalf when you use SiteLetter to monitor websites, including sites belonging to your clients (for example, if you are an agency). When SiteLetter fetches pages, captures screenshots, or aggregates analytics from a website you configure, you (the SiteLetter account holder) are the controller of the resulting records, and SiteLetter is the processor acting on your documented instructions. You are responsible for ensuring you have a lawful basis to monitor those sites and, where required, a data processing agreement in place with their owners.
Agency customers monitoring client sites: a Data Processing Agreement (DPA) reflecting this processor relationship can be put in place. Email support@siteletter.com and SiteLetter will agree one with you. By using the Service to monitor sites you do not own, you confirm that you have the necessary rights and agreements to do so.
2. Data SiteLetter Collects
2.1 Account Data
When you create an account, SiteLetter collects:
- Name and email address
- Agency display name (the company name you enter at signup, shown on account and invitation emails; the branding that appears on reports is configured separately in Settings)
- Optional organization branding: logo URL (a pointer to an image you host on your own domain or a public CDN, not uploaded to SiteLetter's infrastructure), wordmark text, brand color, and branding preference
- Single-use email login tokens and session access tokens
- Account preferences and settings
- Marketing attribution: if you reached the site through a campaign link, the four campaign tags in that link (
utm_source,utm_medium,utm_campaign,utm_content) are sent with your signup and kept on your account, so SiteLetter can tell which campaign a signup came from. They are stored once and never updated, and signups that arrive without campaign tags have none of them. The Cookie Policy explains how they are held in your browser before signup and how to clear them.
2.2 Billing Data
When you subscribe to a paid plan, payment processing is handled entirely by Stripe. SiteLetter stores:
- Stripe customer ID and subscription ID
- Plan type and billing status
SiteLetter does not store your credit card number, CVC, or full payment details. These are handled exclusively by Stripe in accordance with PCI DSS standards.
2.3 Monitoring Data
When you add websites to monitor, SiteLetter collects and stores:
- Website URLs and hostnames you configure
- Lighthouse performance, accessibility, SEO, and best practices scores
- Screenshots of monitored pages
- The HTML source and extracted text content of monitored pages (used for the broken-asset check and change comparison)
- SSL certificate details and domain registration data
- Uptime check results and response times
- Sitemap data from your websites
2.4 Technical Data
When you use the Service, SiteLetter automatically collects:
- IP address (for security and bot prevention)
- Browser type and version (via standard HTTP headers)
- Backend error-trace metadata captured by Sentry (stack trace, request URL, headers, IP) when a server error occurs so SiteLetter can diagnose bugs
SiteLetter does not use advertising cookies or cross-site profiling. The only analytics SiteLetter uses are Cloudflare Web Analytics and Umami, both on the marketing site and neither inside the app. Both are cookieless and anonymous: neither sets a cookie and neither stores an IP address. See Section 5 for details. The anti-bot challenge on signup and on the free public tools (Cloudflare Turnstile) is used purely for fraud prevention. See Section 7 for details.
3. How SiteLetter Uses Your Data
SiteLetter uses your data for the following purposes:
- Providing the Service: Running website scans, generating reports, sending alerts and email notifications.
- Account management: Authentication, billing, team management, and customer support.
- AI-powered analysis: Screenshot images may be sent to the OpenAI API to classify visual changes as dynamic content, intentional updates, or broken pages. Only the screenshot images and the before/after text of the changed regions are sent, never your account or billing details. Because a screenshot can incidentally capture personal data shown on the monitored page (for example a name or photo), OpenAI processes these images as SiteLetter's data processor under a Data Processing Agreement. Under OpenAI's API data usage policy, data submitted through the API is not used to train its models.
- Service improvement: Diagnosing technical issues and improving reliability.
- Legal compliance: Meeting SiteLetter's legal obligations under applicable law.
4. Legal Basis for Processing
Under the GDPR, SiteLetter processes your data on the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)): Security, fraud prevention, service improvement, and understanding which marketing campaigns bring signups.
- Legal obligation (Art. 6(1)(c)): Compliance with tax, accounting, and other legal requirements.
- Consent (Art. 6(1)(a)): Where SiteLetter relies on your consent (e.g., optional marketing emails), you may withdraw it at any time.
5. Third-Party Services and Sub-processors
SiteLetter uses the following third-party services to operate. Your data may be processed by these providers in accordance with their own privacy policies. The full list, with the transfer mechanism in force for each and a dated log of additions and removals, is kept on the sub-processors page, which is also where changes to it are announced.
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Infrastructure, compute, storage, email delivery | All service data | EU (Stockholm, eu-north-1). Uptime probes also run in us-east-1 and ap-southeast-1 and return only an up/down result. |
| Amazon CloudFront (AWS) | Content delivery network for siteletter.com, the dashboard and the API. This is the only CDN in front of the Service. | IP address, request metadata, and the request and response in transit | Edge locations serving North America, Europe and Israel; origin in the EU. |
| MongoDB Atlas | Database | All account and monitoring data | EU (Frankfurt, AWS eu-central-1) |
| Stripe | Payment processing | Email, billing details, payment methods | US (PCI DSS compliant) |
| Cloudflare Turnstile | Anti-bot challenge on signup and on the free public tools | IP address, browser metadata, behavioral signals | Cloudflare's global network |
| Cloudflare Web Analytics | Anonymous traffic statistics on the marketing site | Page URL, referrer, country, browser, device type (no IP stored, no cookies, no fingerprinting) | Cloudflare's global network |
| Umami | Cookieless traffic statistics on the marketing site | Page URL, referrer, campaign tags, country, browser, device type (no IP stored, no cookies, no fingerprinting) | EU region |
| Cloudflare Email Routing | Inbound mail forwarding for the siteletter.com domain | Email sent to a siteletter.com address, including sender address, subject and message body, in transit | Cloudflare's global network |
| Sentry | Backend error tracking | Error stack traces, request URL/method/headers, IP address | US. The error data is stored in the United States, not only routed through it. |
| OpenAI (API) | AI visual change classification | Website screenshot images, plus the before/after text of the regions that changed | US (EU Standard Contractual Clauses) |
If you configure an optional webhook integration, alert notifications will be sent to the webhook URL you provide. Slack is the channel you can set up today. Microsoft Teams webhooks can no longer be added, but any alert rule created before May 2026 that already points at one still posts to it, so it is named here rather than left out. SiteLetter does not control how Slack or Microsoft Teams processes the data.
Domain expiry checks query public RDAP and WHOIS servers operated by registries and registrars. These queries carry the hostname being checked (not your personal data) and rely on open directory services, not a commercial sub-processor. SSL certificate checks read the certificate directly from the monitored site over TLS and involve no third party.
If you use SiteLetter on behalf of a third party (for example, an agency monitoring client websites), a Data Processing Agreement (DPA) under GDPR Article 28 can be put in place. Email support@siteletter.com and SiteLetter will agree one with you.
6. Data Storage and Retention
- Infrastructure location: All primary data is stored in the EU. Compute, screenshots, captured page content and email delivery run in AWS eu-north-1 (Stockholm, Sweden); the database is MongoDB Atlas on AWS eu-central-1 (Frankfurt, Germany). Uptime probes also run from AWS us-east-1 and ap-southeast-1 as cross-region verifiers, and they only return an up/down result for hostnames you already added. Account data is stored in the EU at rest. It leaves the EU only in the cases listed in Section 9. Screenshots leave it for one purpose only: visual change classification sends them to the OpenAI API in the US under EU Standard Contractual Clauses, as described in Sections 3 and 9. The probe functions write a request log in their own region (the checked hostname and path, up/down status, HTTP code, response time, and attempt count) that is deleted after 7 days.
- Monitoring data (subscribers): Lighthouse audits, screenshots, asset checks and reports are retained for 730 days (24 months), after which they are automatically deleted by a daily retention job. Raw uptime check rows roll off after 7 days; uptime incidents are kept alongside the rest of the history.
- Monitoring data (non-subscribers): For accounts without an active paid subscription, Lighthouse audits, screenshots, asset checks and reports are retained for 730 days. Raw uptime check rows roll off after 7 days; uptime incidents are kept alongside the rest of the history.
- Audit log: Security and team-activity audit entries expire automatically after 730 days via a database TTL index.
- Account data: Retained while your account is active. When you delete your account from Settings, your personal data is purged from SiteLetter's live database immediately, except for the email address recorded against security and team-activity audit entries, which expires with those entries after 730 days.
- Billing records: Your payment and invoice records are held by SiteLetter's payment processor Stripe, which retains them for at least 10 years in accordance with its own legal and tax-compliance obligations (including, for EU merchants, Lithuanian VAT Law Art. 88). When you delete your account SiteLetter removes your customer record from Stripe via API; Stripe keeps the historical invoices associated with your past transactions under its retention policies, with personal identifiers stripped on their side. If Lithuanian tax authorities request these records, SiteLetter produces them by exporting from Stripe. SiteLetter does not mirror invoice line-items in its own database - only the minimum operational state (Stripe customer and subscription IDs, subscription status, purchased slot count, and trial and grace-period dates) needed to run your account while it is active.
7. Cookies
Every cookie SiteLetter sets is strictly necessary. None of them are used for advertising or cross-site tracking. Neither of SiteLetter's analytics tools (Cloudflare Web Analytics and Umami) sets a cookie at all:
- Login cookie (JWT): keeps you logged in across siteletter.com and app.siteletter.com. Expires 30 days after you log in, or immediately when you log out.
- Cloudflare Turnstile: on signup and on the free public tools (for example the SSL checker), Turnstile may set short-lived cookies or read browser signals to verify that you are not a bot. This is a security measure for fraud prevention, and no personal profile is built.
SiteLetter also stores one thing in your browser that is not strictly necessary: the campaign tags from a marketing link, held in Session Storage until you sign up or close the tab, as described in Section 2.1. It is not a cookie, and it is stored without asking you first.
SiteLetter does not show a cookie consent banner: its cookies are strictly necessary (essential session management and fraud prevention) and its analytics is cookieless, so none of those need consent under ePrivacy Directive Article 5(3). If SiteLetter ever introduces optional cookies (for example, cookie-based analytics or advertising) a banner will be presented and they will not be set until you opt in. See the full Cookie Policy for what is stored, why, and how to clear it.
8. Your Rights Under GDPR
As an EU resident, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data SiteLetter holds about you.
- Right to rectification: Request correction of inaccurate data.
- Right to erasure: Request deletion of your personal data. You can delete your account directly from your account settings.
- Right to restrict processing: Request that SiteLetter limit how your data is used.
- Right to data portability: Request your data in a machine-readable format.
- Right to object: Object to data processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact SiteLetter at support@siteletter.com. SiteLetter will respond without undue delay and in any event within one month. Where a request is complex or you have made several, that period can be extended by up to two further months, and SiteLetter will tell you within the first month if that applies.
You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI) at vdai.lrv.lt.
9. International Data Transfers
SiteLetter's primary infrastructure is in the EU: compute, storage and email delivery in AWS eu-north-1 (Stockholm), and the database in AWS eu-central-1 (Frankfurt). Data leaves the EU in these cases, and only these:
- Visual change classification. Screenshots and the before/after text of the regions that changed go to the OpenAI API in the United States. OpenAI Ireland Ltd is the contracting entity, and the Data Processing Agreement signed on 17 June 2026 incorporates EU Standard Contractual Clauses.
- Payments. Stripe processes billing data in the United States.
- Error tracking. Sentry receives backend error data and stores it in the United States. It is not merely routed through the US.
- Uptime verification. Probe functions in AWS us-east-1 and ap-southeast-1 receive a hostname and a path and return an up/down result. Their request log stays in their own region and is deleted after 7 days.
- Content delivery. CloudFront edge locations serving North America, Europe and Israel handle requests in transit before they reach the EU origin.
- Bot protection, site analytics and inbound mail forwarding. Cloudflare Turnstile, Cloudflare Web Analytics and Cloudflare Email Routing run on Cloudflare's global network.
OpenAI is the one transfer above that is currently covered by a signed agreement with Standard Contractual Clauses. For AWS, MongoDB Atlas, Stripe, Sentry and Cloudflare, an agreement is being put in place and is not signed yet, so SiteLetter is not naming a safeguard it does not have. The status for each provider is on the sub-processors page and is updated there as agreements are signed.
10. Security
SiteLetter implements appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Passwordless authentication: SiteLetter never stores passwords. Sign-in uses single-use, expiring magic-link tokens.
- Access controls: each part of the system runs under its own scoped role rather than a shared set of credentials
- A pre-launch security review covering authorization, cloud permissions and data handling, with the findings tracked to closure
No system is 100% secure. If SiteLetter discovers a personal data breach SiteLetter will notify the Lithuanian State Data Protection Inspectorate (VDAI) within 72 hours as required by GDPR Article 33, and where the breach is likely to result in a high risk to your rights SiteLetter will notify you directly without undue delay as required by GDPR Article 34.
11. Children's Privacy
SiteLetter is not intended for use by anyone under 18 years of age. SiteLetter does not knowingly collect personal data from children. If you believe a child has provided SiteLetter with personal data, please get in touch and SiteLetter will delete it.
12. Changes to This Policy
SiteLetter may update this Privacy Policy from time to time. The current version is always the one published on this page, and the "Last updated" date at the top of the page changes whenever the text changes, including for material changes. Checking that date is the reliable way to see whether this policy has changed.
Your continued use of the Service after an update constitutes acceptance of the updated policy. If you do not agree with an update, stop using the Service and delete your account from your account settings.
13. Data Controller and Contact
The data controller responsible for your personal data is Donatas Petrauskas, operating as a sole proprietor under individuali veikla (individual activity) registered in Lithuania, registration number 1534445.
For questions about this Privacy Policy, to exercise any of your GDPR rights, or to report a data-protection concern, reach out at support@siteletter.com.