Privacy policy
What personal data websitev0 collects, why, and what you can do about it. Written plainly; it satisfies our notice duties under the GDPR (Articles 13–14), the CCPA/CPRA, and the UK GDPR. prototype published
On this page
- Who we are & who this covers
- What we collect
- How we use it — and our legal basis
- Controller vs processor
- Sub-processors
- Sharing & disclosure
- International transfers
- How long we keep it
- Your rights
- California & US state privacy rights
- Do Not Track & cross-site tracking
- Security
- Children’s data
- Changes to this policy
This explains what personal data websitev0 collects, why, and what you can do about it. It sits alongside our terms of service and cookie policy — read together, they cover the whole relationship.
Who we are & who this covers
websitev0 ("we," "us") is the firm that turns a business’s Google Maps link into a deployed marketing website. We are the data controller for the accounts and billing data of the operators who use our portal, and a data processor for the visitor data collected by the customer sites we host on our operators’ behalf (see "Controller vs processor").
This policy covers three groups: the operators who log into our portal, the small-business owners we build sites for, and the end visitors who land on those published sites. Questions or requests go to privacy@websitev0.com.
websitev0 is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. That entity is the data controller for the account, billing, and marketing-site data described here.
What we collect
We keep collection tight — we take what the product needs to resolve a place, generate a site, publish it, and bill for it. Nothing more.
Account & contact data
- Operator account — name, work email, and a magic-link sign-in identifier (we use passwordless, magic-link auth, so there is no password to store), plus role.
- Business contact — the name, phone, and email of the owner we’re building the site for, so we can share the preview.
Customer content — the site spec
- Place data — the pasted Google Maps URL, the resolved place_id, and cached coordinates.
- Business details — name, category, hours, description, photos, and public reviews pulled from Google Places to seed the site spec.
- Your edits — every tweak an operator makes to the spec: theme, sections, copy, add-on settings, custom domain.
Product, billing & technical data
- Usage — which specs were generated, previewed, and published, and add-on metering counts (calls answered, bookings, quotes).
- Billing — plan, invoices, and a payment token held by our processor. We never store full card numbers.
- Device & log — IP, browser, and portal event logs, kept for security and debugging.
- Cookies — a small first-party set on our portal and marketing site only; see the cookie policy.
How we use it — and our legal basis
Every use maps to a lawful basis under the GDPR. We don’t sell personal data, and we don’t use it to train third-party advertising models.
| Purpose | Data used | Legal basis |
|---|---|---|
| Resolve a place & generate a site | Maps URL, place data, business details | Contract / legitimate interest |
| Run the operator account | Account & contact data | Contract |
| Publish, host & meter add-ons | Site spec, usage, add-on counts | Contract |
| Bill for published sites | Billing data, usage | Contract / legal obligation |
| Secure the service & debug | Device & log data | Legitimate interest |
| Product notices & support | Contact data | Legitimate interest / consent |
We don’t use your personal data to make automated decisions that produce legal or similarly significant effects about you. Generating a site is automated, but it acts on business information, not on judgements about a person.
Controller vs processor
Because websitev0 runs two planes, our role changes with the data — this is the most important distinction in the policy.
- We are the controller for operator accounts, our own billing, and our marketing site. We decide why and how that data is handled.
- We are a processor for the personal data a published customer site collects from its visitors — a booking, a call transcript, a quote request. The business owner is the controller of that data; we only process it to run the site and its add-ons under our terms.
Sub-processors
We use a short list of vetted vendors to run the service. Each is bound by a data-processing agreement and only receives what its job requires. We update this list within 30 days of any change.
| Sub-processor | What it does | Region |
|---|---|---|
| Cloudflare | Edge hosting & CDN for published sites | Global |
| Google Places | Place resolution & business details | Global |
| Stripe | Payments & on-site checkout | US, EU |
| Twilio | Voice add-on & SMS delivery | US, EU |
| Resend | Transactional & marketing email | US |
| Amazon Web Services | Application database & storage | EU (Frankfurt) |
A live, named list is kept at websitev0.com/legal/subprocessors. Published sites with add-ons enabled tell their visitors which of these apply.
Sharing & disclosure
We share personal data only with the sub-processors above, and otherwise only when we must: to comply with the law or a valid legal request; to protect the rights, safety, or property of websitev0, our operators, or the public; or as part of a merger or acquisition, in which case we’ll notify you first. We do not sell or rent personal data, and we do not "share" it for cross-context behavioural advertising as defined by the CPRA.
International transfers
Our vendors operate in the US and EU. When personal data moves out of the UK/EEA, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, plus supplementary technical measures such as encryption in transit and at rest. You can request a copy of the transfer mechanism that applies to you.
How long we keep it
We hold data only as long as its purpose needs, then delete or anonymise it.
| Category | Retention |
|---|---|
| Prototype spec (pre-signature demo) | 90 days, then purged |
| Published site spec & content | Life of the site + 30 days |
| Visitor / add-on data (calls, bookings, quotes) | 24 months, or your setting |
| Billing & invoices | 7 years (tax law) |
| Security & event logs | 12 months |
Your rights
Depending on where you live, you can ask us to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything inaccurate.
- Delete — erase your data, subject to legal retention.
- Port — export your leads, analytics, and spec to CSV or JSON any time; nothing is locked in.
- Object or restrict — opt out of processing based on legitimate interest, and unsubscribe from marketing in one click.
Email privacy@websitev0.com and we’ll respond within 30 days (see the California section below for CCPA timing). We honour Global Privacy Control (GPC) signals as opt-out requests. You can also complain to a regulator: in California, the California Privacy Protection Agency or the state Attorney General; in the UK/EEA, your local supervisory authority (for example, the ICO).
California & US state privacy rights
If you live in California, the CCPA (as amended by the CPRA) gives you specific rights and asks us to spell a few things out. This is the California-specific version of what the rest of this policy already covers.
What we collect, by category
In the last 12 months we’ve collected: identifiers (name, work email, magic-link sign-in identifier, IP); customer records (the business owner’s name, phone, email); commercial information (plan, invoices, add-on usage counts); internet activity (portal logs, and first-party page counts only if you allow analytics); coarse geolocation (the approximate coordinates of the business you resolve from a Maps link — not your device location); and, where a site turns on the Voice add-on, audio and transcripts of calls. We don’t collect government IDs, biometrics, or precise device location.
Where it comes from, and who sees it
We collect it from you (what you enter in the portal), from the business owner you’re building for, from Google Places (business details and public reviews), and automatically from your device (log and cookie data). The only third parties we disclose it to are the sub-processors listed above, each under contract as our service provider.
Sale & sharing
We do not sell or share your personal information — and we haven’t in the last 12 months. We don’t “share” it for cross-context behavioural advertising as the CPRA defines that. Because we don’t, we’re not required to post a “Do Not Sell or Share My Personal Information” link, and we don’t.
Sensitive information
The only sensitive category we might touch is the contents of a call handled by the Voice add-on. We process that solely to run the service the business owner switched on — never to infer anything about a person — which is a use the CPRA does not treat as triggering the “right to limit.”
Your rights, and how to use them
You can ask us to tell you what we hold, delete it, or correct it, and you have the right not to be treated differently for asking. The “opt out of sale/sharing” and “limit sensitive data” rights have nothing to act on here, but you’re welcome to ask and we’ll confirm.
Email privacy@websitev0.com. Because we operate online and deal with you directly, that inbox is our request channel. We verify a request against the account email we already hold, respond within 45 days (we may extend once by another 45 and will say so), and won’t charge unless a request is manifestly unfounded or excessive. You can name an authorized agent to act for you — we’ll ask for your written, signed permission and may still verify your identity. If you’re in another US state with a privacy law (for example Virginia, Colorado, Connecticut, or Texas), you have similar rights plus a right to appeal a decision; email the same address.
Do Not Track & cross-site tracking
Some browsers send a “Do Not Track” (DNT) signal. There’s still no agreed standard for what a site should do with it, so — like most sites — we don’t respond to DNT differently. You don’t need it here: we don’t track you across other companies’ websites, we set no advertising cookies, and our analytics and marketing cookies stay off until you opt in. We don’t let third parties collect personal information about your activity across other sites through ours. We do honour the Global Privacy Control (GPC) signal, and treat it as an opt-out of every non-essential cookie.
Security
We encrypt data in transit (TLS) and at rest, isolate each customer site’s data in its own tenant, scope access to the operators who need it, and log administrative actions. No system is perfectly secure, but if a breach ever affects your personal data we’ll notify you and the relevant authority without undue delay, as the law requires.
Children’s data
websitev0 is a business tool, not intended for children — under 13 in the US (COPPA) or under 16 in the EEA/UK. We don’t knowingly collect children’s personal data. If you believe a child has provided data through us, tell us and we’ll delete it.
Changes to this policy
We review this policy at least once a year and whenever our data practices change. Material changes get an in-portal notice and an email to operators before they take effect. The version and date at the top always reflect the current text; superseded versions are archived and available on request.