1. Who is responsible
For account, product, security, support and website data, the SiteAirbag supplier identified on your Paddle receipt acts as controller/business. For rescue requests and customer-site observations processed for a customer, that customer generally determines the purpose and acts as controller/business; SiteAirbag acts as processor/service provider under the DPA. Contact privacy@siteairbag.com for privacy requests or role questions.
2. Account and commercial data
We process name, email, authentication identifiers, workspace membership, plan and entitlement state, acceptance records, support communications and Paddle customer, subscription and transaction identifiers. Paddle independently processes checkout and payment information as merchant of record; SiteAirbag does not receive complete payment-card details.
- Purposes: create and secure accounts, provide the contract, administer billing, prevent abuse, support customers and comply with law.
- Legal bases where applicable: contract, legitimate interests in service security and administration, and legal obligations.
3. Customer-site runtime data
The runtime sends configured site/action identifiers, anonymous per-session identifiers, device class, runtime version, timestamps, summarized timing, normalized outcome/failure evidence, and rescue outcomes. It does not intentionally send keystrokes, original form fields or bodies, authorization values, page HTML, session replay, advertising identifiers, or full query strings. Setup may temporarily use a minimized pathname and expected fragment to complete an authorized connection.
During a controlled beta, SiteAirbag also stores the minimized detection category, confidence, evidence-domain names, rule version and production-or-shadow mode. A workspace owner may explicitly label an incident as correct or not an issue, or report a missed issue. These records do not add raw form fields, page URLs, error text or inferred revenue.
- Purpose: learn healthy behavior, assess configured actions, detect conservative failure evidence, operate rescue, secure the runtime, evaluate detection quality and test rule changes safely in shadow mode.
- SiteAirbag does not use customer runtime data for advertising or infer revenue.
4. Deliberate rescue requests
A visitor may choose a SiteAirbag backup form and deliberately submit name, email, phone and approved business-safe details such as company, service needed, preferred time, postcode, reference or a short message. The form warns visitors not to submit passwords, payment details, government IDs, health data or secrets. Controls screen prohibited patterns, but customers must not configure or request prohibited data.
- The owning workspace can view the request and its delivery state.
- Ordinary notification email contains contact and reference information but not arbitrary structured payload; additional details remain behind authentication.
- Legacy custom-field records that cannot be proven safe are quarantined from the ordinary inbox.
5. Website, support, research and analytics
The SiteAirbag website and app use necessary browser storage for theme, authentication and setup continuity. Optional product analytics is disabled until the applicable consent or lawful trigger is satisfied. The customer-site runtime does not load SiteAirbag marketing analytics. Support messages contain what you choose to provide; do not send secrets.
Account users may separately volunteer for product and pricing research. We record the participation choice and, if an interview occurs, controlled theme codes, audience, value-driver and pricing-response categories rather than a transcript or free-form notes. Withdrawing deletes linked interview codes. Funnel evidence is stored only as consented aggregate cohort cells with at least five participants; it contains no user or workspace identifier.
- See the Storage and Cookie Notice for the current key-by-key inventory.
- You can withdraw optional analytics consent without affecting necessary service storage, and withdraw research participation independently in Settings.
- Research participation is voluntary and is not used as a testimonial, entitlement, price assignment or automated decision.
6. Recipients and subprocessors
We disclose only what is necessary to subprocessors providing hosting/database/authentication, billing, transactional email, error monitoring and consented product analytics. The current list, purpose and location information appears on the Subprocessors page. We may also disclose data where required by law, to protect rights and security, or in a business transfer subject to appropriate safeguards.
7. International transfers
Providers may process data outside your country. Where required, SiteAirbag relies on contractual safeguards such as the European Commission Standard Contractual Clauses, the UK Addendum, adequacy decisions, or another lawful transfer mechanism, supplemented by technical and organizational measures.
8. Retention
Rescue-request personal content is scheduled for deletion or anonymization after 30 days unless a documented legal hold applies. Action-run history follows the purchased plan (30–365 days); inactive workspaces use a 30-day grace period. Minimized versioned detection decisions are retained for up to 180 days and explicit owner quality labels for up to 365 days. A withdrawn research choice and coded interview records are retained for no more than 365 days; linked interview codes are deleted immediately on withdrawal. Privacy-thresholded aggregate funnel cells may be retained for up to 730 days because they contain no user or workspace identifier. Short-lived credentials expire automatically and are removed after a short cleanup window; operational delivery and job records are normally retained for 30–90 days. Security/audit records are normally retained for up to 365 days. Account configuration is retained while the account is active and enters the controlled deletion workflow after a verified deletion request. Minimized lifecycle evidence may be retained for up to two years, and Paddle or legally required transaction records may be kept for up to seven years where tax, accounting, fraud or dispute law requires it.
- Backups age out under the provider backup cycle; deletion cannot remove an isolated backup instantly.
- Aggregated statistics that no longer identify a person or customer may be retained.
- Visitors can use the verified privacy-request form to access or delete the personal details attached to a SiteAirbag request reference.
9. Security
Controls include scoped origin-bound runtime authorization, short-lived credentials, Row Level Security, server-side ownership checks, signature-verified billing webhooks, data minimization, rate limits, audit records and monitored delivery queues. No control eliminates every risk. Report incidents to security@siteairbag.com.
10. Rights and requests
Depending on location and role, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, and complain to a regulator. SiteAirbag does not sell personal information or share it for cross-context behavioral advertising. Use the verified privacy-request form or email privacy@siteairbag.com. We verify authority before acting and target completion within 30 days unless applicable law requires a different period or permits an extension.
- Visitors should identify the customer website and request reference where available; the self-service flow sends a single-use link only to the email recorded on that request.
- Authorized agents must provide evidence of authority. Appeals or regulator complaints can be submitted through the same channel.
11. Children and sensitive data
SiteAirbag is a business service not directed to children and is not designed to collect sensitive personal information through rescue forms. Do not use SiteAirbag to solicit protected health, financial-account, precise location, biometric, government-identity, authentication or secret data.
12. Changes and contact
Material changes will be dated and, where appropriate, notified through the account or email. Questions and requests: privacy@siteairbag.com. Support: support@siteairbag.com. Security reports: security@siteairbag.com.
Related documents and contact
Terms · Privacy · DPA · Subprocessors · Acceptable use · Storage and cookies · Cancellation and refunds · Security
Support: support@siteairbag.com · Privacy: privacy@siteairbag.com · Security: security@siteairbag.com