Privacy policy
What personal data SiteNext collects, why, who it is shared with and how you stay in control of it.
Last updated: 8 October 2026
1. Who is responsible for your data
SiteNext is operated by Sagar Luniya, Entrepreneur individuel (EI) (SIREN 844 903 443), 4 place de Bretagne, 35000 Rennes, France. For any question about this policy or about your data, write to hello@sitenext.io.
We handle personal data in two different roles:
- As data controller for the visitors of this website, the people on the waitlist, the holders of a SiteNext account and our customers’ billing contacts.
- As data processor for everything a customer organization puts into its workspace: its projects, its team, site diaries, photos, hours worked. The organization that invited you decides what is recorded there and why; requests about that data are best addressed to it first, and we help it answer.
2. The data we collect and why
When you join the waitlist
Your name, company, email address and phone number, used only to contact you about early access to SiteNext. We rely on your request to be contacted. We keep this data until you have been invited or ask to be removed, and no longer than three years after our last exchange.
When you create an account
Your name, email address, phone number, password (stored as a hash, never in clear), profile picture and security settings such as two-factor authentication. We need them to provide the service you signed up for. They are kept for as long as the account exists and deleted when it is closed, apart from what the law requires us to keep.
What your organization records in its workspace
Projects, tasks, site diary entries, photos, documents, RFIs, messages, voice notes and their transcripts, and attendance records. Attendance records hold the times of clock-in and clock-out and, when the organization has switched these options on, the position of the phone at those two moments and a photo. No position is read between a clock-in and a clock-out. Positions and attendance photos are deleted automatically after the retention period the organization has set (90 days by default).
When you subscribe
The name and address of your company, your billing contact and your invoices. Payments are handled by Stripe: card numbers never reach our servers. Invoices are kept for ten years, as French accounting law requires.
When you use the site and the application
Technical data needed to run and secure the service: IP address, browser type, date and time of requests, and a log of sensitive actions in your workspace. We use it to keep the service working, prevent abuse and investigate incidents, which is our legitimate interest.
Audience measurement
The public pages of sitenext.io use Umami, an analytics tool we host ourselves. It sets no cookie, builds no profile and stores no personal data: it only counts page views in aggregate. The signed-in application is not tracked.
3. Who receives your data
Your data is not sold and is not used for advertising. It is shared only with the providers we need to run SiteNext, each for a precise task:
- OVH SAS — hosting of the application and its database, in Germany (European Union).
- Stripe — payments and invoicing.
- OpenAI — two optional features: turning a photographed paper form into a diary template, and transcribing voice notes. Only the file concerned is sent.
- Tawk.to — the support chat inside the application, which receives your name, email address, organization and role when you are signed in.
- Our email delivery provider — the emails the service sends you: account verification, invitations, reminders, password reset.
- Google or Microsoft — only if you choose to connect your calendar.
- OpenStreetMap, Open-Meteo and Brandfetch — maps, weather and company logos. They receive site addresses, coordinates or company names, not information about people.
We may also disclose data when the law or a court order requires it.
4. Transfers outside the European Union
The application and its database are hosted in the European Union. Stripe, OpenAI and Tawk.to may process data in the United States; those transfers are covered by the European Commission’s standard contractual clauses or by the provider’s certification under the EU–US Data Privacy Framework.
5. Cookies
SiteNext only uses the cookies it needs to work: one that keeps you signed in, one that carries a pending invitation, and one that remembers your display preferences. There are no advertising or tracking cookies, which is why this site shows no cookie banner. Stripe’s payment page and the support chat may set their own cookies when you use them.
6. Security
Connections are encrypted (HTTPS), passwords are hashed, two-factor authentication is available, access inside a workspace follows the role and the projects of each person, and the database is backed up. No system is beyond risk: if a breach were to affect your data, we would inform you and the supervisory authority as the law requires.
7. Your rights
Under the General Data Protection Regulation you may access your data, have it corrected or erased, restrict or object to its processing, receive it in a portable format, withdraw a consent you gave, and set instructions for what happens to it after your death. Write to hello@sitenext.io: we answer within one month.
If you believe your rights are not respected, you may lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with the authority of your country.
8. Children
SiteNext is a professional tool. It is not intended for children and we do not knowingly collect their data.
9. Changes to this policy
When this policy changes, the date at the top of the page changes with it, and we tell account holders by email when the change is significant. See also the terms of service and the legal notice.