This policy explains what personal data Sightrz collects, why, where it is stored, and what you can do about it. It covers this website and the Sightrz platform.
Two roles are worth separating up front. For visitors to this website and for the people who administer a Sightrz workspace, we are the controller — we decide what is collected and why. For the marketing data a customer connects to Sightrz, we are a processor acting on that customer's instructions; the customer is the controller. The data processing addendum governs that second relationship.
1. Who we are
Sightrz operates a marketing intelligence platform that unifies advertising, attribution and social data for business customers. For privacy questions, contact privacy@sightrz.com.
2. What we collect
We collect three distinct categories, and we keep them separate.
- Website data — pages visited, referrer, approximate country, browser and device type. Collected in aggregate through Cloudflare Web Analytics, which uses no cookies and does not fingerprint visitors.
- Data you give us — your name, work email, company, website, ad spend band, the channels you run and any message, when you submit the demo form or join the waitlist.
- Account data — the name, email and locale of each user in a workspace, workspace and organisation settings, role assignments, and an append-only audit log of security-relevant actions.
- Customer marketing data — campaign, ad set, ad, creative and performance records retrieved from the advertising platforms a customer connects. This is processed on the customer's behalf, not for our own purposes.
- Connector credentials — OAuth tokens or API keys for the platforms a customer connects, stored only in encrypted form (see section 8).
3. Why we use it, and on what basis
Website and form data is used to respond to enquiries, to understand which pages bring in serious interest, and to keep the site available and free of abuse. The basis is our legitimate interest in operating and improving the business, and — for a demo request — taking steps at your request before entering a contract.
Account data is used to provide the service under our contract with the customer: authenticating users, applying roles, and keeping an audit trail.
Customer marketing data is processed solely to provide the service to that customer, under their documented instructions.
4. Cookies
We set as few as we can, and none for advertising.
- A session cookie for signed-in users of the platform. Strictly necessary; there is no way to stay signed in without one.
- No advertising, retargeting or cross-site tracking cookies. Our analytics is cookieless by design, which is also why this site does not confront you with a consent banner.
5. Who we share it with
We do not sell personal data and we do not share it for advertising. We use a small number of service providers, each with a specific role:
- Cloudflare — hosting, content delivery, DDoS protection and cookieless analytics.
- Neon — the managed Postgres database storing account and customer data. Frankfurt, Germany.
- Anthropic — the model provider behind Sightrz AI. Only pre-computed metrics and the text required to narrate them are sent; inputs are not used to train models.
- Resend — transactional email: notifications, scheduled reports and confirmations.
- Stripe — payment processing and invoicing. Card details go to Stripe directly and never reach our systems.
- Sentry — application error reporting, with personal data scrubbed from event payloads.
6. Where your data is stored, and transfers
Customer data and account data are stored in the European Union, in Frankfurt, Germany. Our compute runs on Cloudflare's network and is placed near the database rather than near the visitor, so processing of stored data also happens in the EU.
If you are in Saudi Arabia or the United Arab Emirates, this means your data crosses a border. Both the Saudi Personal Data Protection Law and the UAE Personal Data Protection Law permit transfer to jurisdictions that provide an adequate level of protection, and the European Union is the most established such destination. The transfer basis is recorded in our data processing addendum, and we will provide it on request.
We state this plainly because the alternative is worse: some vendors imply in-region storage they do not have. We do not store customer data in the Gulf today. In-region storage is available as an Enterprise arrangement, and when a workspace is provisioned in-region we say so in writing and in the contract.
7. How long we keep it
- Demo requests and waitlist entries — 24 months from the last contact, then deleted.
- Account data — for the life of the workspace, then 30 days after closure to allow recovery and export.
- Customer marketing data — per the plan's retention window: 13 months on Starter, 25 months on Growth and Agency, and as contracted on Enterprise.
- Audit logs — 24 months. These are append-only and cannot be edited or deleted by anyone, including us, before that.
- Aggregate, non-identifying benchmark statistics may be retained indefinitely. These cannot be resolved back to a workspace, a person or an advertiser.
8. Security
The controls that matter most here are the ones that keep one customer's data away from another's, and platform credentials out of reach.
- Every tenant-scoped query runs inside a transaction with the organisation set transaction-locally, so a pooled database connection cannot carry one tenant's scope into another tenant's request.
- Row-level security is enabled on every organisation-scoped table, as a second, independent layer.
- An automated test seeds two organisations and asserts zero cross-visibility. It runs on every deploy and blocks release on failure.
- Connector credentials are encrypted with AES-256-GCM under a per-organisation key, which is itself wrapped by a key held in a separate secrets store. Plaintext credentials are never written to the database, never logged, and never returned by any API.
- All traffic is TLS-encrypted. Passwords, where used, are hashed with a memory-hard function.
- Audit logs are append-only at the database privilege level: insert and select are granted; update and delete are granted to nobody.
9. Your rights
Depending on where you are, you have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where consent is the basis.
Write to privacy@sightrz.com and we will respond within 30 days. If you are a user of a customer's workspace rather than our direct customer, we will refer your request to that customer, who is the controller of that data, and assist them in answering it.
You also have the right to complain to your supervisory authority — the Saudi Data & AI Authority in Saudi Arabia, the UAE Data Office in the United Arab Emirates, or your national data protection authority in the EU or UK.
10. Automated decisions
Sightrz AI produces observations and recommendations. It does not make decisions with a legal or similarly significant effect on any individual, and it never changes a campaign, a budget or an account by itself. Every recommendation requires a person to act on it.
11. Children
Sightrz is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@sightrz.com and we will delete it.
12. Changes to this policy
If we change this policy materially we will update the date at the top and, for changes affecting customers, email the workspace owner at least 30 days before the change takes effect.
Questions about this document: privacy@sightrz.com