Privacy Policy

Last updated: 8 May 2026

1. Introduction

SiteKeeper™ ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal data when you use our website at sitekeeper.co.uk or our compliance management application.

Please read this policy carefully. By using SiteKeeper you confirm that you have read and understood how we handle your personal data.

2. Who We Are

SiteKeeper is a compliance management platform for caravan and mobile home site operators in the United Kingdom. SiteKeeper is operated as an independent service. For any data-related enquiries, please contact us at [email protected].

For the purposes of UK data protection law, SiteKeeper is the data controller in respect of your personal data.

3. Data We Collect

We collect and process the following categories of personal data:

Account & Identity Data

Your name and email address, collected when you register for or sign in to SiteKeeper. This is provided directly by you or via your chosen authentication provider (Auth0).

Site Management Data

Information you enter while using the application, including site details, plot records, resident names and contact details, inspection records, fire drill logs and evacuation plans. This data relates to your site operations and is provided entirely by you.

Contact Form Data

Your name, email address and message content when you submit an enquiry via our contact form on the website or within the application.

Payment & Billing Data

Billing information required to process your subscription payments, including your card details. Payment information is handled directly by Stripe — we do not store your full card number, expiry date, or CVV on our systems.

Technical Data

Your IP address, browser type, device type and pages visited. This data is collected automatically by our hosting and security infrastructure when you access SiteKeeper.

4. How We Use Your Data

We use your personal data for the following purposes:

  • To create and manage your SiteKeeper account
  • To provide the compliance management features of the application
  • To respond to enquiries submitted via our contact form
  • To process subscription payments and manage billing
  • To send you transactional emails related to your account or subscription
  • To maintain the security, performance and integrity of our service
  • To comply with legal and regulatory obligations

We do not use your personal data for automated decision-making or profiling, and we do not sell your data to third parties.

5. Legal Basis for Processing

Under UK GDPR, we rely on the following legal bases to process your personal data:

  • Performance of a contract — to provide the SiteKeeper service you have signed up to use
  • Legitimate interests — to maintain security, prevent fraud, and improve our service, where these interests are not overridden by your rights
  • Legal obligation — where we are required to process data to comply with applicable law

6. Third-Party Services

We use a small number of trusted third-party services to operate SiteKeeper. Each acts as a data processor on our behalf and is subject to appropriate data protection obligations:

Auth0 (Okta)

Handles user authentication and sign-in. Auth0 processes your email address and authentication tokens. Auth0 is GDPR-compliant and operates under Standard Contractual Clauses for international transfers.

Microsoft Azure

Hosts the SiteKeeper application and stores your data. Microsoft is GDPR-compliant and provides appropriate safeguards for data processed within its cloud infrastructure.

Cloudflare

Provides content delivery and security for SiteKeeper. Cloudflare may process technical data such as IP addresses. Cloudflare is GDPR-compliant.

Stripe

Processes subscription payments on our behalf. Stripe handles your payment card details directly and securely — we do not store your full card number, expiry date, or CVV on our systems. Stripe is certified to PCI-DSS Level 1 and is GDPR-compliant.

Resend

Delivers transactional emails, including responses to contact form submissions. Resend processes the name, email address, subject and enquiry content included in your submission. Resend is GDPR-compliant.

We do not share your personal data with any other third parties unless required to do so by law.

7. International Data Transfers

Some of the third-party services we use are based outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place — including Standard Contractual Clauses or adequacy decisions — to maintain a level of data protection equivalent to UK standards.

8. Data Retention

We retain your personal data for as long as your account remains active or as necessary to provide the service. If you close your account or request deletion, we will remove your personal data within a reasonable timeframe, except where we are required to retain it by law or for legitimate business purposes such as resolving disputes.

Contact form enquiries are retained for as long as necessary to respond to and resolve your enquiry.

9. Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure. These include encrypted data transmission (HTTPS), access controls, and use of secure cloud infrastructure.

While we take reasonable steps to protect your data, no method of transmission over the internet is entirely secure. In the unlikely event of a data breach that affects your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

10. Cookies

SiteKeeper uses a small number of essential cookies and browser storage to operate. These include authentication tokens required to keep you signed in. We do not use third-party advertising or tracking cookies.

Cloudflare's bot protection (Turnstile) may set cookies in connection with security checks on our contact forms. These are strictly functional and do not track you across other websites.

11. Your Rights

Under UK GDPR, you have the following rights in respect of your personal data:

  • Right of access — to request a copy of the personal data we hold about you
  • Right to rectification — to request correction of inaccurate or incomplete data
  • Right to erasure — to request deletion of your personal data in certain circumstances
  • Right to restrict processing — to request that we limit how we use your data
  • Right to data portability — to receive your data in a structured, machine-readable format
  • Right to object — to object to processing based on legitimate interests

To exercise any of these rights, please contact us at [email protected]. We will respond within one month of receiving your request.

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of SiteKeeper after any changes constitutes your acceptance of the updated policy.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your personal data, please contact us: