Legal

Privacy Policy

What personal data PageReflect collects, why, who we share it with, how long we keep it, and the rights you can exercise over it.

Version
1.0
Effective
August 13, 2026

needs input: ENTITY_NAME, needs input: ENTITY_FORM ("we", "us"), operates PageReflect at pagereflect.com. This policy explains how we handle personal data. Our registered address is needs input: ENTITY_ADDRESS.

This policy covers two different relationships. For your account, billing, and use of the product, we are the controller and this policy is our notice to you. For the content we collect from sites at your direction, and for leads captured through your reports, we are a processor acting on your instructions and the Data Processing Addendum governs.

1.What we collect

We do not intentionally collect special category data, government identifiers, or financial account numbers. Do not submit them through the contact form or a lead capture field.

  • Account data: name, email address, hashed password or federated identity, organization name and membership role, and the timestamp and version of the legal terms you accepted.
  • Billing data: Stripe customer and subscription identifiers, plan, billing interval, invoice history, and billing contact email. We never receive or store full card numbers; Stripe handles card data directly.
  • Product usage: sites you add, runs you start, reports produced, schedules, quota consumption, API and MCP key metadata, tool invocation records, and activity logs of owner and admin mutations.
  • Technical data: IP address, user agent, request timestamps and paths, and error traces, collected in server logs for security, abuse prevention, and debugging.
  • Audited site content: for each run, the extracted text, page structure signals, metadata, screenshots, and lab measurements of the URLs you submit. If an audited page contains personal data, that data is captured incidentally and stored under your organization.
  • Lead submissions: where you enable lead capture on a shared report, the form fields you configured and the values a visitor enters. We process these on your behalf, not for our own purposes.
  • Support communications: the contents of emails and contact form submissions you send us.

2.Why we use it, and our legal bases

Where the GDPR or UK GDPR applies, we rely on the following bases.

  • To provide the Service, run audits, produce reports, and support you: performance of our contract with you.
  • To bill you and collect payment: performance of our contract, and compliance with tax and accounting law.
  • To secure the Service, enforce quotas, prevent abuse, investigate incidents, and defend legal claims: our legitimate interests in operating a safe service, balanced against your rights.
  • To send service and security notices, renewal reminders, and material changes to these policies: performance of our contract, and our legitimate interest in keeping you informed.
  • To send product marketing email: your consent, which you can withdraw at any time using the unsubscribe link in any marketing message.
  • To comply with legal obligations and lawful requests: compliance with a legal obligation.

3.What we do not do

  • We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA as amended by the CPRA. We have not done so in the preceding twelve months.
  • We do not use your audited site content or lead submissions to train our own models. Content sent to OpenAI is processed under its API terms, which do not use API inputs or outputs to train its models by default.
  • We do not run third-party advertising trackers on the product surfaces.

4.Who we share it with

We share personal data with the service providers listed at /legal/subprocessors, each of which is contractually limited to processing it for us. That list names the provider, its purpose, and the categories of data it receives, and we keep it current.

Audited URLs and extracted page content are transmitted to extraction, measurement, and analysis providers in order to produce a report. If you connect an optional integration such as Slack or an outbound webhook, we transmit the associated data to the destination you configured.

We may disclose data to comply with law, respond to a lawful request, enforce our Terms, investigate abuse, or protect the rights and safety of any person. Where a site operator complains about audit traffic, we may disclose the organization responsible.

If we are involved in a merger, acquisition, financing, or sale of assets, data may transfer as part of that transaction. We will give notice before your data becomes subject to a materially different policy.

5.International transfers

Our primary database and file storage run in the United States. Some of our providers process data in other countries. We do not currently offer a self-serve EU data residency option.

Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or on an adequacy decision where one applies. Contact privacy@pagereflect.com for a copy of the relevant transfer mechanism.

6.How long we keep it

Product records of state, including your account, organizations, sites, runs, and reports, are kept until you delete them or close your account, because they are what the product is for. Operational and log tables are swept daily against fixed windows.

  • Rate limit slots and CLI authorization codes: 1 day.
  • Run logs, Inngest run records, webhook events, MCP tool invocations, and export jobs: 90 days.
  • Pipeline events, notification deliveries, and email message records: 180 days.
  • Usage events and activity logs: 365 days.
  • Billing events: 730 days, to support tax and accounting obligations.

7.Deleting your account

You can delete your account from Settings, Profile. Deletion is immediate and irreversible. Organizations you solely own are deleted with the account, which cascades to their sites, runs, and reports. If you own an organization that still has other members, you must transfer ownership or remove those members first, so their data is not destroyed without warning.

After deletion, residual copies can persist in encrypted backups for up to 30 days before rotating out, and in log tables until their retention window expires. We also retain what we must for tax, accounting, and legal-claim purposes.

8.Your rights

Depending on where you live, you may have some or all of the following rights. Exercise them by emailing privacy@pagereflect.com from your account address, or by using the in-product controls where they exist.

  • Access a copy of the personal data we hold about you, and know the categories, sources, purposes, and recipients.
  • Correct inaccurate personal data.
  • Delete personal data, subject to the exceptions above.
  • Port your data in a portable format. Reports and leads can be exported from the product.
  • Object to or restrict processing based on legitimate interests.
  • Withdraw consent to marketing at any time, without affecting processing already carried out.
  • Opt out of sale or sharing. We do not sell or share, so there is nothing to opt out of, but you may still submit a request and we will confirm.
  • Be free from discrimination for exercising a privacy right.

9.How we handle requests

We verify a request by matching it to the email on the account, and may ask for more information if the request is broad or the identity is unclear. We respond within 30 days for GDPR requests and within 45 days for US state law requests, and will tell you if we need an extension.

An authorized agent may submit a request on your behalf with written proof of authorization. There is no fee unless a request is manifestly unfounded or excessive.

If you are a visitor whose personal data was collected through a lead form on a customer's report, or whose personal data appeared on a site one of our customers audited, we are a processor and the customer is the controller. Send your request to that customer. Contact privacy@pagereflect.com if you cannot identify them and we will route it.

10.Cookies

We use a small number of first-party cookies that are strictly necessary to operate the Service: an authentication session cookie, a cookie remembering your active organization, and short-lived state cookies protecting OAuth flows against cross-site request forgery.

We do not use advertising or cross-site tracking cookies. Because our cookies are strictly necessary, no consent banner is required under the ePrivacy Directive. If we add non-essential cookies, we will ask for consent first and update this section.

Blocking the session cookie will prevent you from signing in.

11.Security

Every tenant table carries an organization identifier and is protected by database row-level security. API keys are stored as Argon2id hashes and shown once. Integration secrets are encrypted at rest. Transport is HTTPS-only with HSTS, and responses carry a nonce-based Content Security Policy. Stripe webhooks are signature-verified before any side effect. Details are at /security.

No system is perfectly secure. Report a suspected vulnerability or incident to security@pagereflect.com. We triage the same business day and will notify affected customers and regulators where the law requires, without undue delay.

12.Children

The Service is for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact privacy@pagereflect.com and we will delete it.

13.Changes to this policy

We may update this policy. The version and effective date at the top identify the current text. For material changes we will give notice by email or in-product before the change takes effect, and we record which version you accepted.

14.Contact and complaints

Privacy questions and rights requests: privacy@pagereflect.com. Security reports: security@pagereflect.com. Postal mail: needs input: ENTITY_ADDRESS.

If you are in the European Economic Area or the United Kingdom and believe we have mishandled your personal data, you may complain to your local supervisory authority. We would rather hear from you first and fix it.

Privacy Policy, PageReflect