Privacy Policy
Last updated:
This policy explains how Prime UI, Inc. ("we", "us", or "our") handles personal data in connection with SiteOS, including siteos.sh, app.siteos.sh, and the related services, APIs, and command-line tools.
Who is responsible for your data
SiteOS is operated by Prime UI, Inc., 1111b South Governors Ave STE 28388, Dover, DE, 19904, US. Contact us about privacy at help@primeui.com.
We act as a data controller when we decide how to use personal data for our own purposes, such as managing accounts, providing support, and protecting SiteOS.
When a customer processes data from their websites or applications through SiteOS, they normally determine the purpose of that processing. We process that data on their instructions to provide the configured service. This may include form submissions, indexed content, consent records, monitoring evidence, and tracking observations. For questions about a customer's website or its handling of your data, contact that website's operator first. We assist customers with requests concerning data processed on their behalf.
Information we handle
The information involved depends on the features you use and the data you or your organization provide:
- Account and organization information: email address, optional profile details, organization membership, invitations, permissions, and authentication or session records.
- Project information: names, website URLs, domains, environments, service settings, and configuration needed to connect your websites.
- Service content and results: monitoring tests and their logs, screenshots, or recordings; form submissions; indexed content and search requests; consent configurations and records; and observations produced by tracking diagnostics. These may contain personal data depending on the customer's setup and the source website.
- Integrations and credentials: connection details, authorization tokens, destinations, and delivery records needed for integrations you enable. Connected providers may also supply information under the permissions you grant.
- Operational records: service usage and credit balances, request timestamps, IP addresses, browser or device details, errors, and security or access logs generated while delivering and protecting SiteOS.
- Communications: messages and information you send when requesting support, access, or account assistance.
Information may come from you, authorized members of your organization, connected providers, or websites and systems you configure. Do not submit information you are not authorized to process. Avoid including sensitive data in tests, URLs, or logs unless you have established that the service and your configuration are appropriate for it.
Why we use information
We use personal data to authenticate accounts, manage organization access, run enabled services, deliver results and notifications, answer support requests, and administer usage limits. We also use operational information to investigate failures, prevent abuse, secure SiteOS, and meet legal obligations.
Where European or UK data protection law applies, our legal basis depends on the purpose:
- Contract: processing needed to provide the service you request under our agreement with you.
- Legitimate interests: operating a reliable business service, administering customer relationships, supporting users, and preventing abuse, where these interests are not overridden by your rights.
- Legal obligation: processing required by applicable law, including responding to valid legal requests and retaining required business records.
- Consent: processing for optional purposes where consent is required, including non-essential cookies and consent-based analytics.
An email address is necessary to create an account. Other information may be necessary for a feature you enable; without it, we may be unable to provide that feature. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects on you.
Analytics, cookies, and your choices
The application uses authentication and session cookies to keep you signed in and protect account access. These are necessary for the service you request. Blocking or removing them may sign you out or prevent account features from working.
We use Google Tag Manager, provided by Google, to load and manage website integrations. Loading Tag Manager involves a connection to Google's servers, which receive technical request information such as your IP address and browser details. See Google's Privacy Policy for information about Google's processing. Fonts are served by the website itself; loading them does not require your browser to contact Google Fonts.
Analytics, where enabled, helps us understand visits and interactions with SiteOS and improve the service. Depending on the tool and configuration, this may involve page URLs, interaction events, browser or device information, and pseudonymous identifiers. Necessary hosting and security logs may also be generated when you visit.
Where optional analytics or cookies require consent, the cookie banner provides a choice to accept, reject, or select categories. Optional processing that requires consent starts only after you opt in. When these tools are enabled, you can revisit the consent controls to change your choices or withdraw consent. Necessary storage remains available to deliver and protect the service you request.
We do not sell personal data, share it for cross-context behavioral advertising, or use advertising and remarketing trackers on the SiteOS website. Customers are responsible for the analytics, cookies, and notices on their own websites, including when they use SiteOS to manage consent or inspect tracking.
Who can receive information
Access is limited to what is needed for the relevant purpose. Recipients may include:
- Authorized people within your organization, according to the service's access controls.
- Our personnel and providers supporting hosting, storage, security, email delivery, and customer support.
- Providers and notification destinations your organization chooses to connect, as needed for the configured integration.
- Authorities or other parties where disclosure is legally required or necessary to protect rights or safety or investigate abuse.
- Parties involved in a merger, acquisition, or transfer of our business, subject to applicable protections and notice requirements.
Connected third-party services have their own privacy terms. Review the permissions and information you share with them.
International processing
Prime UI, Inc. is based in the United States. Depending on the infrastructure and providers used for a feature, information may be processed in the United States or other countries with different data protection laws.
Transfers subject to European or UK data protection requirements require an applicable transfer mechanism, such as an adequacy decision or approved contractual safeguards. Contact help@primeui.com for information about the locations and safeguards applicable to your use of SiteOS. This policy does not represent that SiteOS holds a particular transfer certification or that all data stays in one region.
Retention and security
We retain information for the purposes described here. The appropriate period depends on whether an account or project remains active, the service and retention settings involved, the need to investigate security incidents or resolve disputes, and legal recordkeeping duties.
Customer service data is retained according to the relevant service configuration and processing instructions. Account closure or a deletion request may not immediately remove information from backups or records we must retain for security or legal reasons. Retained information remains subject to applicable access restrictions and deletion processes.
We use access controls and other technical and organizational measures intended to protect personal data. No online service can guarantee complete security. Keep access links and credentials private, limit integration permissions, and contact us if you suspect unauthorized access.
Your choices and rights
Depending on your location and the law that applies, you may have rights to access or copy your personal data, correct it, request deletion, restrict processing, receive certain data in a portable format, or object to processing based on legitimate interests. You can withdraw consent without affecting processing that was lawful before withdrawal.
Send requests to help@primeui.com. We may need to verify your identity and authority. Rights can be subject to legal exceptions, and we will explain any applicable limitation. For data controlled by a SiteOS customer, we may direct your request to that customer or assist them with responding.
You may also complain to your local data protection authority. We will not discriminate against you for exercising applicable privacy rights.
Children
SiteOS is for adults acting in a business or professional capacity. It is not directed at children, and we do not knowingly collect children's personal data for our own account services. Contact us if you believe a child has provided us with personal data so we can investigate and take appropriate action.
Changes and contact
We may update this policy as SiteOS develops or our practices change. The date above identifies the latest version. We will provide additional notice of material changes where required and obtain consent when a change requires it.
For questions or requests, contact Prime UI, Inc. at help@primeui.com, or write to 1111b South Governors Ave STE 28388, Dover, DE, 19904, US.