SiteSmith

Drop off your website

SITESMITH · LEGAL

Privacy Policy

Last updated: September 1, 2026

1. Who is responsible for your data

The controller of personal data described here is Rosseta Systems sp. z o.o., ul. Zwycięstwa 2, 42-700 Lubliniec, Poland, registered in the Polish National Court Register (KRS) under number 0000482365, NIP (tax ID) 5761576472 ("we", "us"), which operates the SiteSmith service.

For anything in this policy, including any request below, write to [email protected]. A person reads that address; there is no ticket system to fight.

2. What we collect, and why

If you ask us for a preview

When you submit the form on this site we store the email address, website address, business name and description you type, plus the IP address the request came from, the country our host reports, and which campaign referred you. We use it to build and send your preview, and to keep an audit trail of who asked us for what. Legal basis: steps taken at your request before entering a contract (GDPR Art. 6(1)(b)), and our legitimate interest in preventing abuse of the form (Art. 6(1)(f)).

If we wrote to you first

We contact business owners about their existing business websites, using business contact details published on those websites. We store the website address, the published contact address, and whether you replied or asked us to stop. Every message carries a one-click unsubscribe, and an unsubscribe is permanent — we keep the address on a suppression list precisely so we never write again. Legal basis: our legitimate interest in offering a relevant business service (Art. 6(1)(f)). You may object at any time, and unsubscribing is that objection.

If you buy

Payment is taken by Stripe. We never see or store your card number — it goes directly to Stripe. We store your email address, what you bought, and the Stripe session reference, so we can deliver the site, prove the purchase, and issue receipts. Legal basis: performance of our contract with you (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)).

If you sign in to the customer panel

Sign-in is handled by Auth0 (Okta). You either receive a one-time code by email or use Sign in with Google; in both cases we receive your email address and, from Google, your name. We create a session record so the panel knows which websites are yours. We ask Google for nothing beyond your email address and basic profile — no contacts, no Drive, no Gmail. Legal basis: performance of our contract with you (Art. 6(1)(b)).

If you buy a domain or mailboxes

Domains are registered through OVHcloud with you as the registrant. That means your name and contact details are sent to the domain registry and may appear in public WHOIS/RDDS records — this is a requirement of the domain system, not our choice. Mailbox contents on business email plans are yours; we do not read them. Legal basis: performance of our contract with you (Art. 6(1)(b)).

If you use a contact form on a website we built

Forms on the sites we build submit through our gateway, which forwards the message to the business that owns the site and applies bot protection (Cloudflare Turnstile). For those messages the business owning that website is the controller and we act as its processor. Ask that business about its own privacy notice.

3. Who else processes it

We keep the list short on purpose. Each of these does one job:

WhoWhat forWhere
CloudflareHosting, storage, bot protection, DNSEU/US
StripePaymentsEU/US
Auth0 (Okta)Panel sign-inUS
GoogleSign in with Google, if you choose itEU/US
Postmark, SmartleadSending our emailUS
OVHcloudDomains and business mailboxesEU
MetaMeasuring our own advertising on this siteEU/US

Transfers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell personal data, and we do not share it for anyone else's advertising.

4. Advertising and measurement on this site

This site carries the Meta pixel so we can measure whether our own ads work. It records that a visit or an enquiry happened and which campaign it came from. It fires only for visitors arriving from our Meta campaigns — if you came from an email or typed the address, it does not report you as a lead. Websites we build for customers ship with analytics switched off; the owner decides whether to turn it on.

5. How long we keep it

6. Your rights

Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to someone else in a portable format. You may also complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.

To exercise any of these, email [email protected]. We answer within 30 days. You do not need to give a reason, and asking costs nothing.

7. Cookies

We use cookies that are necessary for the service to function: a sign-in session cookie for the customer panel, and short-lived cookies that protect the sign-in and the forms against abuse. The Meta pixel described in section 4 also sets cookies. We do not use cookies to build advertising profiles of you across other websites.

8. Automated decisions

We use automated tooling to build websites, and a person reviews every site before it reaches you. We do not make decisions about you with legal or similarly significant effects by automated means alone.

9. Children

SiteSmith is a service for businesses and is not directed at children.

10. Changes

If we change this policy we update the date at the top. Where a change materially affects customers, we tell them by email rather than expecting them to re-read this page.