SITEDIA · UK
Privacy notice
Effective: 7 October 2026
This notice explains how sitedia uses your personal data, as required by the UK GDPR and the Data Protection Act 2018.
Summary
| Controller | sitedia · [email protected] |
|---|---|
| Purposes | Providing the Service and your account, managing passes and refunds, answering your messages, improving the Service and protecting it from abuse |
| Lawful bases | Contract; legitimate interests (security and improvement); legal obligation (accounting records); consent (surveys) |
| Recipients | Service providers (Google, Resend, Cloudflare) and Polar, which sells the pass. Some data is transferred outside the UK |
| Your rights | Access, rectification, erasure, restriction, objection and portability; complaint to us and to the Information Commission (ICO) |
1. What we collect and why
| When | Data | Purpose | Lawful basis |
|---|---|---|---|
| Google sign-in | Google account ID, email, name, profile image | Identifying you and signing you in | Contract |
| Email sign-up | Email, verification code (hashed), password (hashed) | Verification and account security | Contract |
| Sessions | Session ID, browser information, access records | Keeping you signed in, preventing abuse | Contract; legitimate interests (security) |
| Using the Service | Addresses, postcodes, coordinates, radius and settings you enter; records of the features you use | Generating results, improving the Service, applying the refund policy | Contract; legitimate interests (improvement) |
| Buying a pass | What Polar sends us: order number, pass, amount, VAT, currency, payment and refund status and dates, and the email, name and billing address on the order | Adding and managing your pass, refunds, accounting | Contract; legal obligation |
| Surveys | Your answers | Improving the Service | Consent (surveys are optional) |
| Messages to us | Message, contact details, attachments | Replying to you | Contract; legitimate interests |
Passwords are never stored in plain text. sitedia never receives your card number or security code. The data needed for an account and a pass is required to provide them; without it you cannot sign in or buy a pass. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
The Service is not directed at children under 13, who may not create an account. You must be 18 or over to buy a pass.
2. How long we keep it
We keep account data until you delete your account or ask us to delete it, and then erase it without undue delay. Email verification codes expire after 10 minutes and sessions after 30 days. Purchase records that the law requires us to keep (for tax and accounting) are kept for the period the law sets.
3. Service providers
| Provider | Purpose |
|---|---|
| Google LLC | Google sign-in |
| Resend | Sending verification and password reset emails |
| Cloudflare, Inc. | Content delivery and security |
When your browser loads maps or data directly from another provider (for example Esri's aerial imagery or OpenStreetMap-based basemaps), that provider receives your connection data.
4. Payments: Polar
Passes are sold by Polar Software, Inc. ([email protected]) as the merchant of record. Polar handles payment data under its own policy: the Polar privacy policy.
| Item | Detail |
|---|---|
| Sent by sitedia when you open checkout | Your account ID and email, the pass you chose, your IP address (used to show the currency, payment methods and tax for your location) and the checkout language |
| Entered by you at checkout | Payment details (received only by Polar and its payment processors), billing address, name and email |
| Sent back to sitedia by Polar | The order details listed under “Buying a pass” in section 1 |
| Purpose | Payment processing, VAT, receipts, order management and fraud prevention |
| Countries | United States and others |
Nothing is sent to Polar unless you open a checkout. Free features remain available either way.
5. International transfers
sitedia is run from the Republic of Korea, and account data is stored there. UK law recognises the Republic of Korea as providing an adequate level of protection for personal data (the Data Protection (Adequacy) (Republic of Korea) Regulations 2022). The providers in sections 3 and 4 process data in the United States and other countries, with the safeguards each describes in its own privacy policy.
6. Cookies
| Cookie | Purpose | Lifetime |
|---|---|---|
sd_session | Keeps you signed in (strictly necessary) | 30 days |
The UK edition (pages under sitedia.app/uk) does not set any statistics, advertising or tracking cookies. We count visits and purchases on our own server without a cookie, so we cannot tell whether two visits came from the same person. If you block sd_session, you will not stay signed in.
7. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict its use, to receive it in a portable form, and to object to processing based on legitimate interests. Where you gave consent (surveys), you can withdraw it at any time; this does not affect what happened before. Email [email protected]. We will check your identity and reply within one month. If we cannot do what you ask for a legal reason, we will tell you why.
8. Complaints
If you are unhappy with how we use your personal data, you can complain to us by email at [email protected]. We will acknowledge your complaint within 30 days, look into it without undue delay and tell you the outcome.
You also have the right to complain to the UK data protection regulator, the Information Commission (formerly the Information Commissioner's Office, ICO): ico.org.uk/make-a-complaint, helpline 0303 123 1113.
9. Contact
For anything about your personal data: [email protected].
10. Changes
If we change this notice, we will announce it in the Service at least 7 days before the change takes effect.