Siteflare

Privacy Policy

Effective date: July 19, 2026
Last updated: August 18, 2026

This Privacy Policy explains how Siteflare (“Siteflare,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our website builder platform, related websites, APIs, and services (collectively, the “Service”).

By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.

1. Who we are

Siteflare is an AI-assisted, multi-tenant website builder. You can create and edit websites (each a “Site”), publish content, and optionally subscribe to paid plans. Paid transactions may be processed by our Merchant of Record, Polar (polar.sh) (“Polar”). Infrastructure is primarily provided by Cloudflare (including Workers, D1, R2, and related services).

Privacy requests: privacy@siteflare.org
General support: support@siteflare.org

2. Information we collect

2.1 Account and identity information

2.2 Site and content information

2.3 Usage, technical, and security data

2.4 Billing and subscription information

If you purchase a paid plan, billing is handled by Polar as Merchant of Record. Polar may collect payment method details, billing name and address, tax identifiers, and transaction history under Polar’s own privacy policy. We receive limited billing status data necessary to provision your plan (for example plan tier, subscription status, and Polar customer or subscription identifiers)—not full card numbers.

2.5 Information we do not intentionally collect

We do not require government ID numbers or special-category sensitive data to use Siteflare. Please do not upload unlawful content or data you are not authorized to process. If you publish personal data of others on your Site, you are responsible for having a lawful basis to do so.

3. How we use information

We use information to:

4. AI features

When you use AI features, prompts and relevant Site content (for example empty template fields, niche hints, or page summaries) may be sent to AI providers we configure (including infrastructure AI services operated by Cloudflare or other model providers). Outputs are used to update your Site content or metadata only as the product allows.

5. Cookies and similar technologies

We use cookies and similar technologies for:

We do not use third-party advertising cookies on the core Service. If we add analytics cookies later, we will update this Policy and, where required, obtain consent.

Bot protection on published Sites

Published Sites that show a contact form load Cloudflare Turnstile, a bot check. When the form page loads and when a message is submitted, the visitor’s IP address is transmitted to Cloudflare so it can verify the request is not automated. This is strictly necessary to keep forms usable and is not advertising or profiling. Turnstile is designed not to track visitors across sites.

6. How we share information

We share information only as needed:

We do not sell your personal information and we do not share personal information for cross-context behavioral advertising.

Public Sites: Content you publish on a Site is accessible according to how that Site is configured (for example public URLs or custom domains). Do not publish personal data you do not want public.

7. Multi-tenant and team access

Sites are scoped to tenants (workspaces). Members you invite or add may access content and settings for that tenant according to their role. You are responsible for managing membership and for activity under your accounts. If you use an organization email domain, administrators of that organization may obtain access through roles you assign.

8. International transfers

We and our processors may process data in multiple regions, including where Cloudflare and Polar operate. Where required, we rely on appropriate transfer mechanisms (such as standard contractual clauses) provided by our processors.

9. Data retention

10. Security

We implement technical and organizational measures appropriate to the Service, including encrypted transport (HTTPS), hashed passwords, access controls, and infrastructure isolation provided by our cloud providers. No method of transmission or storage is 100% secure; you use the Service at your own residual risk. Notify us promptly at privacy@siteflare.org if you suspect unauthorized access to your account.

11. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to withdraw consent where processing is consent-based.

If you are in the EEA/UK, you may also lodge a complaint with your local supervisory authority. If you are a California resident, you may have rights under the CCPA/CPRA (including rights to know, delete, and correct); we do not sell or share personal information as defined by those laws.

12. Children’s privacy

The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

13. Controllers for Site visitors

If you publish a Site on Siteflare, you are typically the controller of personal data collected from your Site’s visitors (for example contact forms you configure). You must provide your own privacy notices and obtain any required consents. Siteflare processes such data only as a host/processor to provide the Service, except where we process platform-level security and operational logs as an independent controller.

14. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated by email or in-product notice. Continued use after the effective date constitutes acceptance of the updated Policy.

15. Contact

Privacy questions or requests: privacy@siteflare.org
General inquiries: support@siteflare.org