Skip to main content
Platform Review
PricingSign in
← Sitefire assessment

Sitefire procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Sitefire
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown“ Under the GDPR, you have the following rights:”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ To exercise any of these rights, please contact us at privacy@sitefire.ai We will respond to your request within 30 days and may ask for additional information to verify your identity.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Your personal data is primarily processed within the European Economic Area (EEA). When data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow“ Minimalist Processing: Sitefire only stores login credentials (username/pw). DPA: Our standard Data Processing Addendum (including EU Standard Contractual Clauses for US transfers) is incorporated by reference and applies automatically to the extent Sitefire processes personal data on the Customer’s behalf.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ _gcl_au Google Connects an advertising click to a later conversion, such as a booked demo Cookie 90 days sf_gclid , sf_utm_source Sitefire Keeps the advertising click identifier and campaign source from the page you arrived on, so a later booking can be attributed to it Local storage Until you clear it ”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ c15t Sitefire Stores your consent choice and the version of this policy you agreed to Cookie and local storage 12 months sf_geo Sitefire Holds the country and region our hosting provider derives from your IP address, so we can apply the correct consent rules Cookie Session sidebar_state Sitefire Remembers whether the documentation sidebar is open Cookie 7 days ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We use Resend to send transactional emails such as account verification, password resets, and team invitations. Resend processes your email address to deliver these messages.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We use Supabase for data storage and backend services. Supabase is hosted in Frankfurt, Germany.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We use Stripe to process payments and manage subscriptions. Stripe handles your payment information (card details, billing address) as an independent data controller for payment processing, and as a data processor for other account-related data such as your email address and subscription status.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Our website is hosted on Vercel, which may collect standard server logs including IP addresses and request information.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ With your explicit consent, we use PostHog to record user sessions to improve our website functionality and user experience. These recordings may include:”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ PostHog processes measurement data on servers in the European Union. See the PostHog privacy policy . Google loads through Google Tag Manager and receives measurement and marketing data. Google processes this data in the United States under the EU-US Data Privacy Framework and standard contractual clauses. See the Google privacy policy . No Google technology loads before you consent to the matching category.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We use Cloudflare Turnstile on authentication forms to protect against automated abuse. Turnstile runs in invisible mode: it shows no challenge and needs no action from you. To tell human visitors from bots, Cloudflare processes your IP address, TLS fingerprint, User-Agent header, and the sitekey with its origin. Cloudflare acts as our processor for that check, and as an independent controller when it uses the same signals to improve its bot detection. Cloudflare states that it cannot identify individuals from these signals.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We use PostHog EU Cloud for analytics and session recordings to improve our website functionality.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We use the following third-party services to process and store your data:”Captured 2026-09-25Open source →Finding permalink →
Tier differencesAll applicable tiersunknown“ The Service: “Sitefire” by pulse Energy GmbH is an AI Visibility and Analytics Platform (“Platform”). The specific scope of features, usage limits, and service tiers are defined by the plan selected by the Customer during the checkout process or as displayed in the Customer’s account dashboard. Product Evolution: Sitefire reserves the right to modify, update, or pivot features of the platform to improve the service, provided the core functionality remains substantially similar.”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.