LEGAL

PRIVACY POLICY

LAST UPDATED: 30 JUNE 2026

01

INTRODUCTION

Welcome to Sightful.

This Privacy Policy explains how we collect, use, protect and share information when you visit https://www.sightful.info or use our broken link detection service (the "Service").

We use your data solely to provide and improve the Service. By using the Service, you agree to the collection and use of information as described in this policy. Unless otherwise defined here, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.

02

DEFINITIONS

SERVICE
The Sightful website and broken link detection platform at https://www.sightful.info.
PERSONAL DATA
Data about a living individual who can be identified from that data (or from that data combined with other information in our possession or likely to come into our possession).
USAGE DATA
Data collected automatically, either generated by your use of the Service or from the Service infrastructure itself (for example, the number of API calls made in a calendar month).
DATA CONTROLLER
The natural or legal person who determines the purposes and means of processing Personal Data. For this Privacy Policy, Sightful is the Data Controller of your data.
DATA PROCESSORS (SERVICE PROVIDERS)
Third parties who process data on behalf of the Data Controller. We use several Service Providers to operate and deliver the Service.
DATA SUBJECT
Any living individual who is the subject of Personal Data.
USER
The individual using our Service — the Data Subject.
03

INFORMATION WE COLLECT

Account information. When you register, we collect your email address. Your password is stored exclusively as a secure hash by our authentication provider (Supabase) and is never accessible to us in any form.

Scan URLs. When you submit a URL for scanning — via the web interface or the API — that URL is processed to detect broken links. URLs submitted through scheduled scans are stored to enable recurring checks and to detect changes between scans.

API usage data. For API key holders, we record the number of calls made in the current calendar month, the date of the last call, and your subscription tier. We store only a SHA-256 hash of your API key — the key itself is shown to you once at creation and is never stored by us.

Subscription and billing data. We record your subscription tier and status. Payment card details are handled entirely by Stripe and never pass through or are stored on our servers.

Contact form submissions. If you contact us via the contact form, we receive your email address and the content of your message.

Usage data. Our servers automatically log standard technical data including your IP address, browser type and version, pages visited, and the date and time of requests. This data is used for security monitoring and service operation.

We do not use advertising cookies, third-party tracking scripts, or behavioural analytics tools.

04

HOW WE USE YOUR DATA

We use the data we collect for the following purposes:

  • To create and manage your account.
  • To perform broken link scans on URLs you submit.
  • To process your subscription payments and manage billing.
  • To send transactional account notifications, including password reset emails, API quota warnings, and subscription-related notices.
  • To deliver scheduled scan alert emails if you have enabled that feature.
  • To respond to support requests submitted via the contact form.
  • To monitor service health, detect abuse, and address security issues.
  • To improve and develop the Service.
  • To comply with legal obligations.

We do not send marketing or promotional emails. We do not sell, rent, or share your Personal Data with third parties for advertising purposes.

05

RETENTION OF DATA

We retain your Personal Data only for as long as is necessary for the purposes described in this Privacy Policy, or as required by law.

Account data (your email address and authentication record) is retained while your account is active. If you request deletion of your account, we will delete your Personal Data within a reasonable period, subject to any legal retention obligations.

API key records (hashed key, usage counters) are retained while the key is active and deleted when you revoke it.

Server log data is retained for a short operational period for security and debugging purposes and is then deleted.

06

SECURITY OF DATA

We take reasonable technical and organisational measures to protect your Personal Data, including:

  • All connections to the Service are encrypted via HTTPS.
  • Passwords are never stored — only a secure hash managed by Supabase.
  • API keys are never stored in plaintext — only a SHA-256 hash is persisted; the full key is shown to you exactly once at creation.
  • Payment card details are handled exclusively by Stripe (PCI-DSS compliant) and never transmitted to or stored on our infrastructure.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.

07

TRANSFER OF DATA

Your information, including Personal Data, may be transferred to and maintained on computers located outside of your country or other governmental jurisdiction where data protection laws may differ.

Our primary infrastructure is hosted in the United States (Heroku/Salesforce). Our authentication and database provider (Supabase) and email delivery provider (Resend) also operate infrastructure in the United States. Our JavaScript rendering provider (ScrapingBee) operates infrastructure in the European Union.

By using the Service and submitting your information, you consent to this transfer. We take steps reasonably necessary to ensure your data is treated securely and in accordance with this Privacy Policy.

08

DISCLOSURE OF DATA

We do not sell or rent your Personal Data. We may disclose your information only in the following limited circumstances:

  • Legal obligations. We may disclose your data where required to do so by law or in response to valid requests by public authorities (such as a court order or government agency).
  • Service Providers. We share data with third-party service providers (listed in Section 9) solely to operate and deliver the Service. These providers are contractually obligated not to use your data for any other purpose.
  • Business transfers. In the event of a merger, acquisition, or sale of assets, your Personal Data may be transferred. We will provide notice before your data becomes subject to a different privacy policy.
  • With your consent. We may share your information for any other purpose with your explicit consent.
09

THIRD-PARTY SERVICE PROVIDERS

We use the following third-party providers to operate the Service. Each has access to your data only to perform their specific function and is obligated not to disclose or use it for any other purpose.

  • Supabase — authentication and database hosting. Stores your email address, authentication records, API key hashes, and usage data. Privacy Policy: supabase.com/privacy
  • Stripe — payment processing and subscription management. Handles all payment card data; we receive only subscription status. Privacy Policy: stripe.com/privacy
  • Resend — transactional email delivery (password resets, scan alerts, account notifications). Privacy Policy: resend.com/legal/privacy-policy
  • Heroku (Salesforce) — application hosting and infrastructure. Privacy Policy: salesforce.com/company/privacy
  • ScrapingBee — JavaScript rendering for Professional tier scans. Receives only the URL you submit for scanning; no Personal Data is passed. Privacy Policy: scrapingbee.com/privacy-policy
10

PAYMENTS

Paid subscriptions are processed by Stripe, Inc. We do not store or have access to your payment card number, expiry date, or CVV at any point. That information is entered directly into Stripe's secure checkout and governed by their Privacy Policy.

Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council. Their Privacy Policy can be viewed at stripe.com/privacy.

11

YOUR GDPR RIGHTS (EU / EEA)

If you are a resident of the European Union or European Economic Area, you have data protection rights under the General Data Protection Regulation (GDPR). We aim to take reasonable steps to allow you to exercise these rights by contacting us.

You have the right to:

  • Access — request a copy of the Personal Data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your Personal Data (the "right to be forgotten"), subject to legal obligations.
  • Restriction — request that we limit processing of your data in certain circumstances.
  • Data portability — request your data in a structured, machine-readable format.
  • Object — object to our processing of your Personal Data where we rely on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw that consent at any time.

We may ask you to verify your identity before responding to such requests. Please note that some data is necessary to provide the Service and deletion may result in loss of access.

You also have the right to lodge a complaint with your local Data Protection Authority in the EEA.

12

CALOPPA (CALIFORNIA)

In accordance with the California Online Privacy Protection Act (CalOPPA):

  • Users may visit our site anonymously.
  • A link to this Privacy Policy containing the word "Privacy" is accessible from our home page.
  • You will be notified of any material changes to this Privacy Policy on this page and, where appropriate, via email.
  • You can update your personal information by contacting us.

Do Not Track. We honour Do Not Track signals. We do not plant tracking cookies or use advertising when a Do Not Track signal is detected in your browser.

13

CCPA (CALIFORNIA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights regarding your personal information.

Right to know. You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the purposes for which it is used, and any third parties with whom it is shared.

Right to delete. You may request deletion of the personal information we hold about you. Note that some data may be required to provide the Service.

Right to opt out of sale. We do not sell or rent your personal information to any third party for any purpose. You are the sole owner of your Personal Data.

We will not discriminate against you for exercising any of the above rights. To make a request, please contact us. The CCPA took effect on 1 January 2020.

14

CHILDREN'S PRIVACY

Our Service is not directed to anyone under the age of 18. We do not knowingly collect Personal Data from children. If you are a parent or guardian and become aware that your child has provided us with Personal Data, please contact us and we will take steps to remove that information.

15

LINKS TO OTHER SITES

Our Service may contain links to third-party websites that are not operated by us. If you click a third-party link, you will be directed to that site. We strongly advise you to review the privacy policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party site or service.

16

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date at the top.

Where appropriate — for example, if we begin collecting new categories of data or sharing data with new third parties — we will also notify you via email or a prominent notice on the Service before the change takes effect.

We encourage you to review this page periodically. Changes are effective when posted.

17

CONTACT US

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or want to request access to, correction of, or deletion of your Personal Data, please contact us via the contact page.