Privacy policy
Plain English about what SiteSums holds, why, for how long, and what you can do about it. Written for the people who use the platform — and for their clients, whose details end up in it.
Who we are
SiteSums is a business admin platform for UK trades, operated by Nikita-Jade Hancock. For your own account details we are the data controller. For the details of your clients that you store in SiteSums, you are the controller and we are your processor — the data processing terms set out how that works. We are registered with the Information Commissioner's Office under number ZC244828.
What we hold, and why
| What | For example | Why | How long |
|---|---|---|---|
| Your account and business details | Name, email, phone, address, VAT and registration numbers, logo, brand colours, website | To run your account and put your details on your documents | While your account is open; deleted with it |
| Your bank details | Bank name, sort code, account number, account name | Printed on invoices and payment schedules so clients can pay you | While your account is open; deleted with it. Encrypted at rest. |
| Your clients' details | Names, companies, addresses, emails, phone numbers, notes | You are the controller of this data; we process it on your instructions to produce and send your documents | Until you delete the client or close your account |
| Jobs, quotes, invoices, variations and payments | Line items, prices, costs, VAT, statuses, payment records | The core service — your paperwork and your margins | Until you delete them or close your account. Deleted documents are hidden, then removed with the account. |
| People you pay and what you pay them | Names, roles, pay rates, wage payments | Your wages record; nobody on this list has an account | While your account is open; deleted with it |
| Files you upload | Receipts, template masters (private); logos and project covers (public web addresses) | Attached to your records; logos and covers appear on client-facing pages | Until you remove them or close your account |
| Client actions on shared links | That a document was opened, accepted or a variation approved — with the approver's typed name, time and IP address | Evidence of agreement, kept for you | For as long as the document exists |
| Emails we send for you | Recipient address, subject, sent or failed | So you can see what was sent and chase failures | 90 days |
| Technical logs | Errors, with the account they affected | Keeping the service working | 90 days |
| Backups | Encrypted copies of the database | Recovery from failure | Rolling, up to 30 days after deletion |
Our lawful basis
- Contract — almost everything above is needed to provide the service you signed up for: producing documents, taking payments, keeping your records.
- Legitimate interests — technical logs and security measures that keep the service working and your data safe. We have weighed these against your interests and kept what we hold to the minimum.
- Legal obligation — where the law requires us to keep records, for example of payments processed.
- We do not rely on consent for any of the above, and we do not use your data for marketing unless you ask us to.
Your clients' details
When you add a client to SiteSums and send them a quote, you are the controller of their information. We store it on your instructions, show it only to you and to them (through the links you send), and delete it when you do. We never contact your clients ourselves, sell their details, or use them for anything except your documents. You are responsible for having a lawful basis to hold their details — for almost every trade, that is simply the contract or enquiry between you.
Who else sees data
We use a small number of specialist providers. None of them may use the data for their own purposes.
| Provider | Does | Where | Transfer safeguard |
|---|---|---|---|
| Supabase | Database, sign-in and file storage | London, UK (eu-west-2) | None — data at rest stays in the UK |
| Vercel Inc. | Application hosting | USA (global edge network) | UK Addendum to the EU Standard Contractual Clauses, via Vercel's DPA |
| Stripe | Card payments and subscriptions | USA / Ireland | UK Addendum via Stripe's DPA. Card numbers never reach SiteSums. |
| Resend | Sending email on your behalf | USA | UK Addendum via Resend's DPA |
| Shopify | Template shop orders (email and product only) | Canada / USA | UK Addendum via Shopify's DPA |
Your data at rest lives in the UK. Where a provider is outside the UK, the transfer is covered by the UK Addendum to the EU Standard Contractual Clauses in that provider's data processing agreement. We do not sell data, and we share it only as listed here or where the law requires.
Card payments
Card details go directly to Stripe and never touch SiteSums' servers. We hold a Stripe customer reference and your subscription status, nothing more. Your own bank details — which you enter so clients can pay you by transfer — are stored encrypted and appear only on the documents you produce.
Security
Every account is isolated at the database level: the rules that decide who may read a row are enforced by the database itself, not just by the application. Data is encrypted in transit and at rest. Receipts and template files are in private storage; logos and project cover images are public web addresses because they appear on pages your clients open. The security page has the detail.
Your rights
- Access and portability — Settings → Export gives you everything we hold about your account as a file, instantly.
- Erasure — Settings → Delete account removes your account and everything in it, including files. It is immediate and cannot be undone; backups age out within 30 days.
- Rectification — everything is editable in the app.
- Objection and restriction — email us and we will act within one month.
- You can complain to the ICO at ico.org.uk. We'd rather hear from you first: privacy@sitesums.co.uk.
Children
SiteSums is for businesses and is not intended for anyone under 18.
Changes
If we change this policy in a way that matters, we will tell you by email before it takes effect. The date at the top is the version you are reading.