Legal
Privacy Policy
Last updated 20 April 2026
This policy explains what personal data SiteSnap.Build(the “Service”) collects, why we collect it, and your rights under UK GDPR and the Data Protection Act 2018. The Service is operated by Kingfield Services Ltd, a company registered in England and Wales with company number 16808865. Kingfield Services Ltd is the data controller for personal data processed via the Service.
1. What we collect
- Account data — your email address and an authentication credential (password hash or magic-link token) when you sign up.
- Profile data — your full name, company name, and logo image, only if you choose to provide them.
- Project content — project names, addresses, photos and notes you upload, and any notes left by clients on your share links.
- Billing data — your subscription status and the Stripe customer ID associated with your account. Card numbers and bank details are handled directly by Stripe; we never see or store them.
- Usage data — basic technical logs (IP address, user-agent, request paths) generated by our hosting and infrastructure providers for operational and security purposes.
2. How we use your data
We use your personal data to:
- provide the Service — store your photos and notes, render your dashboard, generate share links;
- operate billing — start your free trial, process subscription payments, send invoices;
- communicate — send transactional emails (welcome, client-note notifications, account changes) and reply to support requests;
- protect the Service — detect abuse, debug errors, and meet legal obligations.
3. Legal basis (UK GDPR Article 6)
- Contract (Art. 6(1)(b)) — providing the Service you subscribed to and processing your payments.
- Legitimate interests (Art. 6(1)(f)) — keeping the Service secure, debugging issues, and sending essential operational emails.
- Legal obligation (Art. 6(1)(c)) — retaining billing records as required by HMRC and responding to lawful requests from authorities.
- Consent (Art. 6(1)(a)) — for non-essential cookies and any future marketing emails. You can withdraw consent at any time.
4. Data retention
We retain your account and project content for as long as your account is active. If you cancel your subscription and stop using the Service, we delete account and project data within 30 days of closure, except where we are required to keep it longer (for example, billing records are kept for six years to comply with UK tax law). Backups are rotated within 30 days.
5. Sharing and third-party processors
We use a small number of trusted processors to deliver the Service. Each is bound by a data-processing agreement and processes data only on our instructions:
- Supabase Inc. — authentication and database hosting (data stored in the EU).
- Vercel Inc. — application hosting and edge delivery.
- Cloudinary Ltd — image storage and delivery.
- Stripe Payments Europe Ltd — subscription billing and payment processing. Stripe is the controller of your card data.
- Resend Inc. — transactional email delivery.
Some of these providers may transfer data outside the UK. Where they do, the transfer is covered by Standard Contractual Clauses or an adequacy decision recognised by the UK government.
6. Cookies
We use a small number of cookies and similar storage:
- Essential — Supabase session cookies that keep you signed in, and a local storage entry recording your cookie consent choice. These cannot be disabled without breaking the Service.
- Analytics — off by default. If we add analytics in future we will only enable it for users who opt in via our cookie banner.
You can change your cookie choices at any time by clearing site data in your browser.
7. Your rights under UK GDPR
You have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (the “right to be forgotten”);
- restrict or object to our processing in certain cases;
- portability — receive a copy of your data in a structured, machine-readable format;
- withdraw consent for any processing based on consent;
- complainto the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
To exercise any of these rights, email hello@sitesnap.build. We aim to respond within 30 days.
8. Security
We protect data with industry-standard measures: TLS for all traffic, encrypted storage, row-level security in our database, scoped service credentials, and strict access controls within Kingfield Services Ltd. No system is perfectly secure, but we work continuously to reduce risk.
9. Children
The Service is intended for adults running or working in trades. We do not knowingly collect data from anyone under 18. If you believe a child has provided personal data to us, please email us so we can delete it.
10. ICO registration
Kingfield Services Ltdis registered with the UK Information Commissioner's Office where required for our processing activities. Our ICO registration number will be added here once issued; in the meantime you can contact us at hello@sitesnap.build for any data-protection enquiry.
11. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be announced by email.
Data controller
Kingfield Services LtdTrading as SiteSnap.Build
20 Wenlock Road, London, England, N1 7GU
Company number 16808865 · Registered in England and Wales
Email: hello@sitesnap.build