Legal
Privacy Policy
Version 1.5.0 · Effective 2026-09-23
This Privacy Policy describes how PostGrad, LLC (“sitelaunch”, “we”, “us” or “our”) collects, uses, shares and protects personal information when you use sitelaunch.io, the merchant console, and the storefronts published through it (together, the “Service”).
1. Who this policy covers, and in which role
Two different kinds of people use this Service, and our responsibilities to them are different.
If you run a business on the Service, you are our customer. We decide how your account information is handled, and this policy describes what we do with it.
If you bought from, booked with, or messaged a business whose website is built on the Service, you are that business’s customer, not ours. That business decides what is collected on its site and why. We hold that information on their behalf and act on their instructions. In data protection terms they are the controller and we are the processor. Section 10 explains what that means for you.
2. What we collect
From a business that holds an account:
- Account details: your name, email address, business name, business address, phone number, and a password that is stored only as a hash.
- What you put into your store: your products and prices, descriptions, images, opening hours, contact details, page copy, and the documents you publish.
- Subscription and billing records: your subscription status, the identifiers your payment provider gives us, and our record of what you were charged. We never receive or store your full card number.
- Evidence of your subscription purchase: when you start or pay for a subscription we record your network address, your browser’s user-agent string, and the exact wording of the terms you accepted with the time you accepted them. This is kept so that a payment can be defended if it is later disputed.
- Usage records: which pages and endpoints were requested, when, and what the response was.
- Error reports: when something fails, a report is sent to our error-reporting provider. Credentials and email addresses are removed from it before it leaves our systems.
- Support requests: what you write to us, any files you attach, the page you were on and the kind of browser you used.
- Connections you make: the access that lets the Service reach a payment, calendar or email account you connect, and any AI provider key you add. These are stored encrypted and used only for what you connected them to do.
- Referral records: who you referred and the credit you earned, if you join the referral program.
From a visitor to a storefront built on the Service, held for the business that runs it:
- What the business asks for in its own forms, which is typically a name, an email address, and the details of an order, booking or enquiry.
- Order and booking records, including what was bought and when.
- Ordinary technical information, such as the pages opened and the kind of browser used.
About network addresses, specifically. When you subscribe, and when you accept the policies for your own store, we keep your network address and browser details with the record of what you agreed to, so the agreement can be shown later if it is ever questioned. Otherwise we do not keep your network address: it is converted to a one-way fingerprint and used only to stop the same request being repeated abusively. We do not work out where you are from it, and we do not derive your location by any other means.
We do not knowingly collect biometric data, precise geolocation, or the special categories of data defined in Article 9 of the GDPR.
3. How we use it
- To provide, operate, maintain and improve the Service.
- To sign you in, keep your account secure, and prevent fraud and abuse.
- To take your subscription payment and send you billing messages.
- To send you transactional messages such as sign-in links, receipts, confirmations and service notices.
- To remind you to finish setting up your store. Every reminder carries a link that stops them.
- To answer your support requests.
- To keep a record of the agreements you accepted and when.
- To meet our legal obligations and respond to lawful requests.
- To understand how the Service is used in aggregate so we can make it better.
- To measure our own advertising on our marketing site, and to reach people who have visited it.
We do not build advertising profiles about what you do inside your account. The measurement described in Section 7 covers our marketing site, and you can switch it off there.
4. Automated features and the model provider
We use AI in a few places: to suggest words, pages and course outlines for your store, to answer visitors’ questions through the optional store assistant, to make photographs you buy, and to help our team look into support requests and improve the Service. The models come from Google (Gemini, through Google’s generative language service), Anthropic (Claude) and image models run through Replicate. We send each only what the task needs, and never your password or payment details. We do not train AI models of our own on your data.
If you add your own key for an AI provider, the features that use it send your store’s content to that provider under your own agreement with them. You can remove the key at any time.
If you choose to connect an outside assistant, such as Claude or ChatGPT, through the Service’s integration feature, your store’s data is sent to that provider under that provider’s own terms and privacy policy. That choice is yours, it is recorded in your console, and you can disconnect it at any time.
5. Who else processes it
We share personal information only with the providers that help us run the Service, and with each only what its part needs.
- Vercel: hosting for the marketing site, the console and every storefront.
- Supabase: the database, authentication, and file storage. Hosted in the United States.
- Square and Stripe: payment processing. Square handles the card for your subscription. The payment account you connect for your own customers, Square or Stripe, handles their payments and receives the details of each order.
- Resend: email, such as sign-in links, receipts, notifications and our messages to you.
- Composio: the connection to a calendar or email account you choose to connect, used only for what you connected it to do.
- Google: AI models that write suggestions and run the store assistant, and the fonts the site loads.
- Anthropic: AI models (Claude) that help our team look into support requests and improve the Service.
- Replicate: runs the image models that make photographs you buy.
- GoHighLevel: the customer relationship tool our team uses to keep track of accounts and help people finish setting up. It receives your name, business name, email address, phone number and how far you are through setup.
- Telegram: the messaging app our team uses to be told about new accounts and support requests, so they are answered quickly. Those alerts can include your contact details and what you wrote to us.
- Sentry: error reports, with credentials and email addresses removed before an event leaves our systems.
- feedlaunch: the optional social posting service on Growth > Social. Only if you set it up, we send it your store’s public details (its name, web address, phone number, public social media handles, colors, logo and products), your email address, and the customer reference our payment processor gave you, so it can make your posts and give you a login. It then handles your social posts under its own privacy policy.
- Collapporate: shows feedlaunch’s screens inside your console once you have set it up. It receives only coded references to you and your store, never your name, email address or store details.
- Meta: a measurement pixel on our public marketing pages and our signup page only, which tells Meta that a browser visited a page here, started a signup, went to pay, or subscribed, so we can see which advertising works. It is not on a merchant’s storefront, not in your console and not in our operator portal, and it does not run for a browser that has opted out or that sends a Global Privacy Control signal.
We do not sell personal information and we do not disclose it to third parties for their own marketing.
We do share one thing for advertising: the Meta pixel on our marketing site tells Meta that a browser visited a page here. Under California law that counts as sharing for cross-context behavioral advertising, so you can opt out, and Section 7 says how. Nothing you do inside your account, and nothing about your customers, is shared this way.
We may disclose information where the law requires it, in response to a subpoena, court order or other lawful process, or where we reasonably believe it is necessary to protect the rights, property or safety of our users, the public or us. If our business is merged, acquired or sold, information may be transferred as part of that transaction, and this policy will continue to apply until it is replaced.
6. When our team can see your account
To investigate a problem you have reported, an authorized member of our team may open your account and see it as you would see it.
Every such session requires a stated reason, and the record of who opened the account, when, and why is written before access is granted. We do this to support you, not to browse, and access to that capability is limited to named operators.
7. Cookies and advertising measurement
We use cookies that are strictly necessary to sign you in, keep your session, and protect against cross-site request forgery.
On our public marketing pages and our signup page, and only there, we also load a Meta pixel. It sets or reads identifiers so that Meta can tell us which of our advertising brought somebody here, and so that we can show our advertising to people who have visited. It is not loaded on a merchant’s storefront, where the only tracking is whatever that merchant has set for their own shop, and it is not loaded in our operator portal.
You can turn it off for this browser with the control at the end of this page, and we treat a Global Privacy Control signal as the same request, which we honor. Blocking cookies in your browser stops it too, though you will not be able to sign in without the necessary ones.
A browser "Do Not Track" header is a different thing. It has no agreed meaning, almost nothing on the web acts on it, and we do not treat it as an opt-out. Use the control on this page, or send Global Privacy Control, both of which we do act on.
8. How long we keep it
- Account information: while your account is open, and for thirty (30) days after it is closed so that it can be reopened.
- Billing and tax records: seven (7) years from the transaction, to meet tax record-keeping obligations.
- Evidence of agreement acceptance and of a subscription purchase: for as long as the payment can be disputed and for any applicable limitation period, in a record that is added to and not rewritten.
- Usage and request logs: ninety (90) days, unless a security investigation requires longer.
- Error reports: according to our error-reporting provider’s retention period, which is currently ninety (90) days.
- Store content and the records a business holds about its own customers: until the business deletes them, or thirty (30) days after the account is closed.
- Support requests and their attachments: while your account is open, and for thirty (30) days after it is closed.
- Backups: rotated on a thirty (30) day cycle.
When a retention period ends, information is deleted or irreversibly anonymized.
9. Your rights
Depending on where you live, you may have the right to:
- ask for a copy of the personal information we hold about you;
- ask us to correct information that is wrong or incomplete;
- ask us to delete it, subject to the retention obligations in Section 8;
- ask for a machine-readable export of it;
- object to or ask us to restrict certain processing;
- withdraw consent where processing is based on consent; and
- complain to your local supervisory authority.
To exercise any of these, email privacy@sitelaunch.io. We will verify who you are before we act. We will respond within thirty (30) days where the GDPR applies, and within forty-five (45) days where the CCPA or CPRA applies, and we will tell you if we need the extension the law allows. We will not treat you differently for exercising a privacy right.
10. If you bought from a store built on the Service
The business whose site you used decides what it collects and why. We hold that information for them.
Send your request to that business first. Their contact details are on their site and on your receipt, and they can act on it directly in their console.
If you cannot reach them, write to us at privacy@sitelaunch.io and we will pass your request on and help them act on it. We will not delete or hand over a business’s customer records on the say-so of someone else, because doing so would let anyone erase or obtain another person’s order history.
11. Legal bases, for the EEA, the UK and Switzerland
- Performance of a contract, Article 6(1)(b): to give you the Service you signed up for.
- Legal obligation, Article 6(1)(c): to keep tax and accounting records and to respond to lawful process.
- Legitimate interests, Article 6(1)(f): to keep the Service secure, prevent fraud and improve it, balanced against your rights. You may object at privacy@sitelaunch.io.
- Consent, Article 6(1)(a): where we ask for it. You may withdraw it at any time, which does not affect processing carried out before you did.
12. California privacy rights
If you live in California, you may ask what categories and specific pieces of personal information we have collected about you, where it came from, why we collected it, and who we shared it with. You may ask us to delete it or correct it, subject to the exceptions the statute allows.
We do not sell your personal information. We do share identifiers and internet activity with Meta through the pixel on our marketing site, which the statute treats as sharing for cross-context behavioral advertising. To opt out, use the control at the end of this page, or send a Global Privacy Control signal from your browser, which we honor. We will not deny you service, charge you a different price or give you a lower standard of service because you exercised a privacy right.
In the previous twelve (12) months we collected the categories described in Section 2, disclosed them to the providers listed in Section 5 for the purposes in Section 3, sold none of them, and shared identifiers and internet activity with Meta for the advertising measurement described in Section 7.
13. Where information is processed
Information is processed in the United States and may be processed in other countries whose data protection laws differ from those where you live. Where a transfer requires it, we rely on the Standard Contractual Clauses approved by the European Commission and equivalent safeguards.
We do not currently have an establishment in the European Union. If we begin processing the personal data of people in the EEA at a scale that requires it, we will appoint a representative under Article 27 and name them here.
14. Children
An account holder must be at least eighteen (18) years old. The Service is not directed at children, and we do not knowingly collect personal information from anyone under sixteen (16). If you believe a child under sixteen (16) has given us personal information, write to privacy@sitelaunch.io and we will delete it without undue delay.
15. Security
We encrypt traffic in transit and data at rest, store passwords and keys only as hashes, restrict access to the database with row-level security so that one business cannot read another’s data, limit administrative capability to named operators, and record administrative access.
Error reports have credentials, tokens and email addresses removed before they leave our systems.
No method of transmission or storage is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you as the law requires.
16. Changes to this policy
We may revise this policy. The current version number and effective date appear at the top of this page.
Changes that do not affect your rights take effect when they are posted. Material changes, such as a new category of information, a new purpose, or a new category of recipient, will be sent to you by email at least thirty (30) days before they take effect.
17. Contact
PostGrad, LLC, Orange County, Florida, United States.
Privacy questions and rights requests: privacy@sitelaunch.io. Other legal questions: legal@sitelaunch.io. Security reports: security@sitelaunch.io.
See also the Terms of Service.