1. Who we are
SinceCode LTD is the data controller for personal data we hold about you as a SinceCode account holder. We are a company registered in England & Wales.
SinceCode is established in the United Kingdom and primarily offers its services to customers in the United Kingdom. Our service, pricing and marketing are not directed at residents of the European Economic Area. If you are accessing this service from outside the UK, you do so on your own initiative.
For data-protection enquiries, email privacy@sincecode.com. For general support, email support@sincecode.com.
If you use SinceCode to build a website for someone else, you are the controller for the personal data submitted by your visitors, and SinceCode acts as a processor on your behalf under our Data Processing Agreement.
2. What personal data we collect
2.1 Account
- Identity: name, email address, date of birth (used to verify you are 16+), optional company name.
- Credentials: bcrypt hash of your password (never the password itself). Google sign-in stores no password.
- Billing: we do not store card details. Payments are handled by Stripe; we store the Stripe customer/subscription identifier.
- Operational data: sites, pages, media, usage counters.
2.2 Security & audit
- Login events, admin re-auth events, originating IP and user-agent. Retained as needed to investigate misuse or satisfy a legal obligation.
- Cloudflare Turnstile bot challenge on sign-up (we receive a pass/fail token only).
2.3 Visitor analytics on your customer site
Our visitor analytics are cookieless. We do not store visitor IP addresses, user-agent strings or visitor identifiers. We hold a short-lived hash for 30 minutes for refresh dedup; it expires automatically. Per pageview we keep: URL path, referrer domain, country code, device family, timestamp.
3. How we use personal data
- Provide the Service — Art. 6(1)(b) contract.
- Take payment — Art. 6(1)(b) contract.
- Keep the Service secure — Art. 6(1)(f) legitimate interests.
- Comply with the law — Art. 6(1)(c) legal obligation.
- Service emails — Art. 6(1)(b) contract.
- Marketing emails (only if you opted in) — Art. 6(1)(a) consent. Withdraw any time.
4. Sub-processors
We share personal data only with the sub-processors listed at /sub-processors, each bound by a written contract. Current sub-processors: Stripe Payments Europe Ltd, Cloudflare Inc., 1&1 IONOS Ltd, Brevo SA, Hostinger International Ltd.
5. International transfers
Personal data is primarily stored in the UK and EEA. Where a sub-processor operates outside the UK/EEA, we rely on UK adequacy decisions and on standard contractual clauses included in the sub-processor's contract, per Article 46 of UK GDPR.
6. Retention
- Account data — for as long as your account is active.
- After deletion — anonymised immediately, permanently deleted after 30 days.
- Form submissions (leads) — kept for 30 days on the Free plan and 12 months on a paid plan. Site owners can choose a shorter window for their own site, and delete any submission at any time.
- Visitor analytics — individual pageview records are deleted after 90 days on every plan. Daily totals (no individual records) are kept for the site’s plan window: 7 days on Free, 90 / 180 / 365 days on the paid plans.
- Payment records — we do not hold your card details or your invoices. Stripe, our payment processor, holds those as a data controller in its own right and keeps them for the six years UK tax law requires — so deleting your SinceCode account does not erase them, and we cannot delete them on your behalf. What we hold is your plan and its status, which goes with your account.
- Inactive free sites — if you do not sign in for a year, the sites on your account that are not on a paid plan are deleted. We email you 30 days beforehand and again 7 days beforehand, and nothing is deleted unless that warning was sent. Signing in resets the clock. Sites on a paid plan are never removed this way, and your account itself stays open.
- Security & audit logs — up to 12 months.
7. Your rights
You have the right to be informed (this notice), to access (Account → Export), to rectify, to erase (Account → Delete account), to restrict, to port, to object, and to withdraw consent. We respond within one calendar month. ICO complaints: ico.org.uk, 0303 123 1113.
8. Cookies
We use only strictly-necessary cookies (PECR Reg. 6(4) exempt). No analytics, no advertising, no tracking — not in your dashboard, and not on any site built with SinceCode.
When you use SinceCode: the sign-in session token, the CSRF token, the sign-in callback URL, the OAuth flow cookies used when you sign in with Google (state, nonce and PKCE verifier), the marketing preference you chose on the signup form, and — if you start building before you sign in — an id for that draft. One more is set only while a SinceCode administrator is signed in as you: the impersonation token, which exists so that access is always visible and revocable.
When you visit a site built with SinceCode: nothing is set unless you do something that needs it. Entering a gallery password, marking a photo as a favourite, replying to an invitation, and uploading to a photo wall each set a first-party id so the site remembers you for that one purpose. A visitor who only reads a page is given no cookies at all.
That is the complete list, and it is enforced rather than asserted: a cookie name that appears anywhere in our code without being on it fails our build.
9. Children
You must be 16 to create a SinceCode account. We verify this at sign-up by collecting a date of birth and blocking under-16s before the account is created.
Because the Service is not intended for under-16s, we have not designed it against the ICO's Age Appropriate Design Code ("Children's Code") — the age gate is the front-line control. If we become aware that an under-16 has created an account, we will close it and erase the personal data, except where retention is required by law (e.g. fraud or safeguarding records).
If you publish a SinceCode-built site that is likely to be accessed by children, you (the site owner) are the controller for any personal data your visitors submit and the Children's Code applies to you, not to us. The DPA sets out the controller/processor split.
10. Changes
Material changes are announced via email and require your re-acceptance before continued use.