Legal
What personal data PageReflect collects, why, who we share it with, how long we keep it, and the rights you can exercise over it.
needs input: ENTITY_NAME, needs input: ENTITY_FORM ("we", "us"), operates PageReflect at pagereflect.com. This policy explains how we handle personal data. Our registered address is needs input: ENTITY_ADDRESS.
This policy covers two different relationships. For your account, billing, and use of the product, we are the controller and this policy is our notice to you. For the content we collect from sites at your direction, and for leads captured through your reports, we are a processor acting on your instructions and the Data Processing Addendum governs.
We do not intentionally collect special category data, government identifiers, or financial account numbers. Do not submit them through the contact form or a lead capture field.
Where the GDPR or UK GDPR applies, we rely on the following bases.
Our primary database and file storage run in the United States. Some of our providers process data in other countries. We do not currently offer a self-serve EU data residency option.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or on an adequacy decision where one applies. Contact privacy@pagereflect.com for a copy of the relevant transfer mechanism.
Product records of state, including your account, organizations, sites, runs, and reports, are kept until you delete them or close your account, because they are what the product is for. Operational and log tables are swept daily against fixed windows.
You can delete your account from Settings, Profile. Deletion is immediate and irreversible. Organizations you solely own are deleted with the account, which cascades to their sites, runs, and reports. If you own an organization that still has other members, you must transfer ownership or remove those members first, so their data is not destroyed without warning.
After deletion, residual copies can persist in encrypted backups for up to 30 days before rotating out, and in log tables until their retention window expires. We also retain what we must for tax, accounting, and legal-claim purposes.
Depending on where you live, you may have some or all of the following rights. Exercise them by emailing privacy@pagereflect.com from your account address, or by using the in-product controls where they exist.
We verify a request by matching it to the email on the account, and may ask for more information if the request is broad or the identity is unclear. We respond within 30 days for GDPR requests and within 45 days for US state law requests, and will tell you if we need an extension.
An authorized agent may submit a request on your behalf with written proof of authorization. There is no fee unless a request is manifestly unfounded or excessive.
If you are a visitor whose personal data was collected through a lead form on a customer's report, or whose personal data appeared on a site one of our customers audited, we are a processor and the customer is the controller. Send your request to that customer. Contact privacy@pagereflect.com if you cannot identify them and we will route it.
Every tenant table carries an organization identifier and is protected by database row-level security. API keys are stored as Argon2id hashes and shown once. Integration secrets are encrypted at rest. Transport is HTTPS-only with HSTS, and responses carry a nonce-based Content Security Policy. Stripe webhooks are signature-verified before any side effect. Details are at /security.
No system is perfectly secure. Report a suspected vulnerability or incident to security@pagereflect.com. We triage the same business day and will notify affected customers and regulators where the law requires, without undue delay.
The Service is for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact privacy@pagereflect.com and we will delete it.
We may update this policy. The version and effective date at the top identify the current text. For material changes we will give notice by email or in-product before the change takes effect, and we record which version you accepted.
Privacy questions and rights requests: privacy@pagereflect.com. Security reports: security@pagereflect.com. Postal mail: needs input: ENTITY_ADDRESS.
If you are in the European Economic Area or the United Kingdom and believe we have mishandled your personal data, you may complain to your local supervisory authority. We would rather hear from you first and fix it.
Questions about this document? Email privacy@pagereflect.com.