1. Who we are
SinceCode LTD is the data controller for personal data we hold about you as a SinceCode account holder. We are a company registered in England & Wales.
SinceCode is established in the United Kingdom and primarily offers its services to customers in the United Kingdom. Our service, pricing and marketing are not directed at residents of the European Economic Area. If you are accessing this service from outside the UK, you do so on your own initiative.
For data-protection enquiries, email privacy@sincecode.com. For general support, email support@sincecode.com.
If you use SinceCode to build a website for someone else, you are the controller for the personal data submitted by your visitors, and SinceCode acts as a processor on your behalf under our Data Processing Agreement.
2. What personal data we collect
2.1 Account
- Identity: name, email address, date of birth (used to verify you are 16+), optional company name.
- Credentials: bcrypt hash of your password (never the password itself). Google sign-in stores no password.
- Billing: we do not store card details. Payments are handled by Stripe; we store the Stripe customer/subscription identifier.
- Operational data: sites, pages, media, usage counters.
2.2 Security & audit
- Login events, admin re-auth events, originating IP and user-agent. Retained as needed to investigate misuse or satisfy a legal obligation.
- Cloudflare Turnstile bot challenge on sign-up (we receive a pass/fail token only).
2.3 Visitor analytics on your customer site
Our visitor analytics are cookieless. We do not store visitor IP addresses, user-agent strings or visitor identifiers. We hold a short-lived hash for 30 minutes for refresh dedup; it expires automatically. Per pageview we keep: URL path, referrer domain, country code, device family, timestamp.
3. How we use personal data
- Provide the Service — Art. 6(1)(b) contract.
- Take payment — Art. 6(1)(b) contract.
- Keep the Service secure — Art. 6(1)(f) legitimate interests.
- Comply with the law — Art. 6(1)(c) legal obligation.
- Service emails — Art. 6(1)(b) contract.
- Marketing emails (only if you opted in) — Art. 6(1)(a) consent. Withdraw any time.
4. Sub-processors
We share personal data only with the sub-processors listed at /sub-processors, each bound by a written contract. Current sub-processors: Stripe Payments Europe Ltd, Cloudflare Inc., 1&1 IONOS Ltd, Brevo SA, Hostinger International Ltd.
5. International transfers
Personal data is primarily stored in the UK and EEA. Where a sub-processor operates outside the UK/EEA, we rely on UK adequacy decisions and on standard contractual clauses included in the sub-processor's contract, per Article 46 of UK GDPR.
6. Retention
- Account data — for as long as your account is active.
- After deletion — anonymised immediately, permanently deleted after 30 days.
- Free-plan form submissions — 7 days.
- Free-plan pageviews — 7 days; Premium — 90 days.
- Billing & tax records — 6 years (HMRC).
- Security & audit logs — up to 12 months.
7. Your rights
You have the right to be informed (this notice), to access (Account → Export), to rectify, to erase (Account → Delete account), to restrict, to port, to object, and to withdraw consent. We respond within one calendar month. ICO complaints: ico.org.uk, 0303 123 1113.
8. Cookies
We use only strictly-necessary cookies (PECR Reg. 6(4) exempt). No analytics, no advertising, no tracking. The sign-in session token, CSRF token, admin impersonation cookie and Auth.js OAuth flow cookies are the full set. See the public CI guard in our repo.
9. Children
You must be 16 to create a SinceCode account. We verify this at sign-up by collecting a date of birth and blocking under-16s before the account is created.
Because the Service is not intended for under-16s, we have not designed it against the ICO's Age Appropriate Design Code ("Children's Code") — the age gate is the front-line control. If we become aware that an under-16 has created an account, we will close it and erase the personal data, except where retention is required by law (e.g. fraud or safeguarding records).
If you publish a SinceCode-built site that is likely to be accessed by children, you (the site owner) are the controller for any personal data your visitors submit and the Children's Code applies to you, not to us. The DPA sets out the controller/processor split.
10. Changes
Material changes are announced via email and require your re-acceptance before continued use.