Privacy Policy
Last updated: May 2026
1. Who We Are
SiteSnap ("we", "our", "us") operates the SiteSnap mobile application and website. We are the data controller for personal data processed through our services.
For data protection enquiries, contact us at privacy@sitesnappro.co.uk
2. What Data We Collect
When you use SiteSnap we may collect:
- Account information — email address and password (stored securely via Supabase Auth)
- Profile information — company name, logo, and contact details you provide
- Site and project data — names, addresses, and details of construction sites and projects you create
- Photos — images you capture or upload, including GPS coordinates and timestamps extracted from EXIF data
- Client data — names, email addresses, and phone numbers of clients you add
- Usage data — how you interact with the app (page views, feature usage, error logs)
- Payment data — billing information processed by Stripe or Apple — we never store full card details
- Device information — device type, operating system version, and app version
3. How We Use Your Data
We use your data to:
- Provide and maintain the SiteSnap service
- Organise and store your site photographs and project records
- Generate PDF reports for your projects
- Process subscription payments
- Send you important service notifications (not marketing without consent)
- Improve the app based on anonymised usage patterns
- Comply with our legal obligations
4. Legal Basis for Processing (GDPR)
We process your data on the following legal bases:
- Contract performance — to provide the services you have subscribed to
- Legitimate interests — to improve our service and ensure security
- Legal obligation — to comply with applicable law
- Consent — for any optional processing such as marketing emails
5. Data Sharing
We share your data with trusted third-party service providers only where necessary to deliver the SiteSnap service:
- Supabase — database and authentication hosting
- Stripe — payment processing for web subscriptions
- Apple — in-app purchase billing on iOS
- RevenueCat — subscription management and analytics
We do not sell your personal data to third parties. We do not use your photos or project data for any purpose other than providing SiteSnap services to you.
6. Data Storage and Security
Your data is stored securely using industry-standard encryption in transit and at rest. Photos and documents are stored in Supabase's secure object storage. Authentication credentials are hashed and never stored in plain text.
While we take commercially reasonable measures to protect your data, no method of transmission over the internet or electronic storage is 100% secure.
7. Data Retention
- Active accounts — data retained for as long as your account is active
- After deletion — all personal data removed within 30 days of account deletion
- Payment records — retained for up to 7 years for legal and tax compliance
8. Your Rights (GDPR)
Under UK and EU data protection law, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data ("right to be forgotten")
- Portability — receive your data in a machine-readable format — use the Export feature in Account Settings
- Restriction — limit how we process your data
- Objection — object to processing based on legitimate interests
To exercise these rights, contact us at privacy@sitesnappro.co.uk or use the data export and account deletion features within the app.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
The SiteSnap website uses only essential cookies for:
- Keeping you signed in (session authentication cookies)
- Security (CSRF protection)
We do not use advertising, tracking, or analytics cookies. You can decline non-essential cookies via the cookie notice on first visit without affecting core functionality.
10. Children's Privacy
SiteSnap is not intended for anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of SiteSnap after changes take effect constitutes your acceptance of the updated policy.
12. Contact Us
For privacy-related enquiries: