Privacy Policy
Last updated: 8 May 2026
1. Introduction
SiteKeeper™ ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal data when you use our website at sitekeeper.co.uk or our compliance management application.
Please read this policy carefully. By using SiteKeeper you confirm that you have read and understood how we handle your personal data.
2. Who We Are
SiteKeeper is a compliance management platform for caravan and mobile home site operators in the United Kingdom. SiteKeeper is operated as an independent service. For any data-related enquiries, please contact us at [email protected].
For the purposes of UK data protection law, SiteKeeper is the data controller in respect of your personal data.
3. Data We Collect
We collect and process the following categories of personal data:
Account & Identity Data
Your name and email address, collected when you register for or sign in to SiteKeeper. This is provided directly by you or via your chosen authentication provider (Auth0).
Site Management Data
Information you enter while using the application, including site details, plot records, resident names and contact details, inspection records, fire drill logs and evacuation plans. This data relates to your site operations and is provided entirely by you.
Contact Form Data
Your name, email address and message content when you submit an enquiry via our contact form on the website or within the application.
Payment & Billing Data
Billing information required to process your subscription payments, including your card details. Payment information is handled directly by Stripe — we do not store your full card number, expiry date, or CVV on our systems.
Technical Data
Your IP address, browser type, device type and pages visited. This data is collected automatically by our hosting and security infrastructure when you access SiteKeeper.
4. How We Use Your Data
We use your personal data for the following purposes:
- To create and manage your SiteKeeper account
- To provide the compliance management features of the application
- To respond to enquiries submitted via our contact form
- To process subscription payments and manage billing
- To send you transactional emails related to your account or subscription
- To maintain the security, performance and integrity of our service
- To comply with legal and regulatory obligations
We do not use your personal data for automated decision-making or profiling, and we do not sell your data to third parties.
5. Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases to process your personal data:
- Performance of a contract — to provide the SiteKeeper service you have signed up to use
- Legitimate interests — to maintain security, prevent fraud, and improve our service, where these interests are not overridden by your rights
- Legal obligation — where we are required to process data to comply with applicable law
6. Third-Party Services
We use a small number of trusted third-party services to operate SiteKeeper. Each acts as a data processor on our behalf and is subject to appropriate data protection obligations:
Auth0 (Okta)
Handles user authentication and sign-in. Auth0 processes your email address and authentication tokens. Auth0 is GDPR-compliant and operates under Standard Contractual Clauses for international transfers.
Microsoft Azure
Hosts the SiteKeeper application and stores your data. Microsoft is GDPR-compliant and provides appropriate safeguards for data processed within its cloud infrastructure.
Cloudflare
Provides content delivery and security for SiteKeeper. Cloudflare may process technical data such as IP addresses. Cloudflare is GDPR-compliant.
Stripe
Processes subscription payments on our behalf. Stripe handles your payment card details directly and securely — we do not store your full card number, expiry date, or CVV on our systems. Stripe is certified to PCI-DSS Level 1 and is GDPR-compliant.
Resend
Delivers transactional emails, including responses to contact form submissions. Resend processes the name, email address, subject and enquiry content included in your submission. Resend is GDPR-compliant.
We do not share your personal data with any other third parties unless required to do so by law.
7. International Data Transfers
Some of the third-party services we use are based outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place — including Standard Contractual Clauses or adequacy decisions — to maintain a level of data protection equivalent to UK standards.
8. Data Retention
We retain your personal data for as long as your account remains active or as necessary to provide the service. If you close your account or request deletion, we will remove your personal data within a reasonable timeframe, except where we are required to retain it by law or for legitimate business purposes such as resolving disputes.
Contact form enquiries are retained for as long as necessary to respond to and resolve your enquiry.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure. These include encrypted data transmission (HTTPS), access controls, and use of secure cloud infrastructure.
While we take reasonable steps to protect your data, no method of transmission over the internet is entirely secure. In the unlikely event of a data breach that affects your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.
10. Cookies
SiteKeeper uses a small number of essential cookies and browser storage to operate. These include authentication tokens required to keep you signed in. We do not use third-party advertising or tracking cookies.
Cloudflare's bot protection (Turnstile) may set cookies in connection with security checks on our contact forms. These are strictly functional and do not track you across other websites.
11. Your Rights
Under UK GDPR, you have the following rights in respect of your personal data:
- Right of access — to request a copy of the personal data we hold about you
- Right to rectification — to request correction of inaccurate or incomplete data
- Right to erasure — to request deletion of your personal data in certain circumstances
- Right to restrict processing — to request that we limit how we use your data
- Right to data portability — to receive your data in a structured, machine-readable format
- Right to object — to object to processing based on legitimate interests
To exercise any of these rights, please contact us at [email protected]. We will respond within one month of receiving your request.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of SiteKeeper after any changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions or concerns about this Privacy Policy or how we handle your personal data, please contact us: