onpage.site

Privacy Policy

Version 2026-08-24

We collect your email address, the images you upload, and a minimal amount of technical data. We never sell personal data, we never see your card number, and our visitor counter deliberately stores nothing that can identify a person.

This agreement is written in English. Translations are provided for convenience only; if they conflict, the English version governs.

01Who controls your data

onpage.site is the data controller for the personal data described here. Contact privacy@onpage.site for any privacy matter, including requests to exercise your rights.

For payments, Paddle.com Market Ltd acts as Merchant of Record and is an independent controller of the payment data it collects. Its own privacy notice applies to that processing.

02What we collect, and why

Email address. Required to create and edit a page, to send sign-in codes, and to send service notices. Legal basis: performance of our contract with you.

Images and page text you upload. Stored so we can publish them. Legal basis: performance of our contract.

IP address and user agent, captured at sign-in, at page creation, and when you accept the terms. Kept as evidence of consent and to detect abuse. Legal basis: legitimate interest in securing the Service, and legal obligation.

Billing records: subscription status, plan, currency, period dates and Paddle identifiers. We do not receive or store card numbers. Legal basis: contract and legal obligation (tax records).

AI briefs, if you buy the AI add-on: the business details and copy you type into the brief form, plus the images generated from it. Legal basis: performance of our contract.

Aggregate visitor counts for your page. See the analytics section below.

Support correspondence, kept so we can answer follow-ups.

03How our visitor analytics works

We do not use tracking cookies, fingerprinting, cross-site identifiers, or advertising pixels of our own.

To tell a repeat visit from a new one, we compute a one-way SHA-256 hash of the visitor's IP address, user agent, the page identifier, the current date and a secret salt. Only that hash is stored, and every hash is deleted within 48 hours. After that, only aggregate daily counts remain.

Because the salt rotates and the raw inputs are never stored, these hashes cannot be reversed to identify a person, and we cannot use them to follow anyone across pages or across days.

04Analytics that page owners add themselves

A page owner may attach their own Google Analytics 4 or Meta Pixel identifier to their page. If they do, those third parties will set cookies and collect data from visitors to that page.

For that processing the page owner is the controller, not us. It is the page owner's responsibility to obtain any consent their jurisdiction requires and to publish their own privacy notice. We provide the field; we do not operate the tracker.

If you are a page owner and you enable this, you agree to comply with the ePrivacy Directive, the GDPR, and any other consent rules applicable to your visitors, and to indemnify us for claims arising from your failure to do so.

05Cookies

On onpage.site itself we set two cookies, both strictly necessary and neither used for advertising: a signed session cookie so you stay logged in to the editor, and a language cookie remembering your interface language.

The session cookie is host-only, which means it is never sent to any *.onpage.site customer page.

Published customer pages set no cookies from us at all, unless the owner has added their own analytics as described above.

06Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We use a small number of processors, each contractually bound to protect it:

Vercel Inc. (United States) - application hosting and CDN delivery.

Supabase Inc. (database and object storage, in the region we configure) - stores your account record, page data and images.

Resend (United States) - transactional email delivery for sign-in codes and service notices.

Paddle.com Market Ltd (United Kingdom) - payment processing, invoicing and tax remittance, as Merchant of Record.

Google LLC or OpenAI, L.L.C. (United States) - AI image generation, only if you purchase the AI add-on, and receiving only the brief text you submit.

We may also disclose data where legally compelled, to enforce our Terms, or to protect the rights, property or safety of our users or the public. We will tell you about such a request unless we are legally prohibited from doing so.

07International transfers

Our providers are primarily located in the United States. Where personal data leaves the European Economic Area, the United Kingdom or the Republic of Korea, the transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses, with the UK Addendum where applicable.

You may request a copy of the relevant transfer safeguards from privacy@onpage.site.

08How long we keep it

Account and page data: while your page exists, then 30 days after deletion, after which it is permanently removed.

Unpaid drafts: deleted 30 days after creation if never published.

Sign-in codes: valid 10 minutes, deleted within 24 hours.

Visitor hashes: 48 hours. Aggregate daily counts: retained while the page exists.

Consent records and audit logs: 2 years, as evidence of what was agreed and what actions were taken.

Billing and tax records: as required by tax law in the relevant jurisdiction, typically 5 to 10 years, held largely by Paddle.

Backups: overwritten on a rolling basis, normally within 30 days.

09Your rights

Subject to local law you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, and portability in a machine-readable format, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time.

If you are in California you additionally have the right to know what is collected, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising these rights.

If you are in the Republic of Korea you hold the corresponding rights under the Personal Information Protection Act.

Write to privacy@onpage.site. We verify requests through the email address on the account and respond within 30 days. There is no charge unless a request is manifestly unfounded or excessive.

You may also complain to your local supervisory authority. We would rather hear from you first so we can fix the problem.

10Security

Data is encrypted in transit with TLS and at rest by our storage providers. Access to production data is restricted, and every administrative action taken against a customer page is written to an audit log.

Our database enforces row-level security with a deny-by-default posture, so the public API key shipped to browsers grants no read access to any table.

Uploaded files are re-encoded and validated before storage, and vector formats such as SVG are rejected outright.

No system is perfectly secure. If a breach affects your personal data and presents a risk to you, we will notify you and the relevant authority without undue delay and, where required, within 72 hours of becoming aware of it.

11Children

The Service is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, write to privacy@onpage.site and we will delete it.

12Changes

We post updates here with a new date, and notify you by email of material changes at least 30 days before they take effect.

Privacy Policy · onpage.site