Legal Document

Privacy Policy

This policy explains how SiteSorted collects, uses, and protects your personal data — including data received from Facebook when you connect your account.

Last updated: 17 May 2026

1

Introduction — Who We Are

SiteSorted (“we”, “us”, or “our”) is a software-as-a-service (SaaS) platform based in Ireland that automates Facebook ad creation and scheduling for small businesses. We use artificial intelligence to generate ad copy and imagery, and the Facebook Marketing API to post ads to your connected Facebook Page on your behalf.

As data controller, we are responsible for deciding how and why your personal data is processed. We operate under the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. This policy applies to all users of the SiteSorted platform at sitesorted.org.

Questions about this policy? Contact us at sitesortedapp@gmail.com.

2

Information We Collect

We collect the following categories of information when you use SiteSorted:

Account Information

When you sign up, we collect your name and email address through Clerk, our authentication provider. Clerk manages your login credentials and identity securely on our behalf.

Business Information

To generate ads tailored to your business, you provide us with:

  • Business name, industry, and description
  • Target audience profile and customer age range
  • Business address, phone number, website URL, and opening hours
  • Facebook Page URL and current promotions or offers
  • Location (county or city in Ireland)
  • Photos uploaded for use in ads

Payment Information

Subscription payments are processed securely by Stripe. We do not store your card number, CVC, or full billing details on our servers. We receive only non-sensitive metadata from Stripe such as your subscription plan, status, and billing period dates.

Facebook Data

When you connect your Facebook account to SiteSorted, we receive and store the following data from the Facebook Marketing API:

  • Facebook Page access tokens (used to post ads on your behalf)
  • Facebook Page ID and Page name
  • Facebook Ad Account ID (used to create and manage ad campaigns)
  • Token expiry dates

This data is collected only when you explicitly choose to connect your Facebook account and is used solely to create and manage ads on your behalf. See Section 4 for full details on how we handle Facebook data.

Usage Data

We automatically collect limited technical and usage data including:

  • Ad performance metrics returned by the Facebook Marketing API (impressions, clicks, CTR, spend)
  • Timestamps of ad generation, scheduling, and posting activity
  • Browser and device type, IP address, and pages visited within the platform
  • Error and diagnostic logs for platform stability
3

How We Use Your Information

We process your personal data for the following purposes and legal bases:

PurposeLegal Basis (GDPR)
Providing the SiteSorted serviceContract performance
Generating AI-powered ad copy via the Claude API (Anthropic)Contract performance
Generating ad imagery via Replicate (AI image generation)Contract performance
Posting ads to your Facebook Page via the Marketing APIContract performance
Processing subscription payments via StripeContract performance
Sending service emails (monthly reports, failure alerts) via ResendContract performance
Preventing fraud and ensuring platform securityLegitimate interests
Improving our service through aggregated analyticsLegitimate interests
Complying with legal obligations (e.g. tax records)Legal obligation
4

Facebook / Meta Data — Detailed Policy

This section is specifically relevant to our use of the Facebook Marketing API and is required for Meta Platform compliance.

What Facebook Data We Collect

When you connect your Facebook account via OAuth, SiteSorted receives:

  • Page Access Tokens — short and long-lived tokens that authorise us to manage ads on your Facebook Page
  • Facebook Page ID — identifies which Page your ads are posted to
  • Facebook Ad Account ID — the ad account used to create and fund campaigns
  • Page name — displayed in your SiteSorted dashboard for identification

How We Use Facebook Data

Facebook data is used solely and exclusively for the following purposes:

  • Creating ad campaigns, ad sets, and ads via the Facebook Marketing API on your behalf
  • Retrieving ad performance metrics (impressions, clicks, spend, CTR) from the Facebook Insights API
  • Displaying your connected Page name in your dashboard

We do not use Facebook data for any other purpose. We do not analyse, sell, license, or share Facebook data with any third parties other than what is strictly required to operate the Marketing API on your behalf.

Data Sharing

Facebook data is not shared with any third parties. It is stored securely in our database (Supabase, EU region) and accessed only by the automated systems that post ads on your behalf.

User Control — Disconnecting Facebook

You can disconnect your Facebook account from SiteSorted at any time from the dashboard Settings panel. When you disconnect:

  • All stored Facebook Page access tokens are immediately deleted from our database
  • Your Facebook Page ID and Ad Account ID are immediately cleared
  • No further API calls will be made to Facebook on your behalf
  • Existing ad records (headlines, body text, images) are retained in your account but are no longer connected to Facebook

Data Retention

Facebook access tokens and related credentials are stored only for as long as your Facebook account is connected to SiteSorted. They are permanently deleted when you disconnect your Facebook account or delete your SiteSorted account.

Token Security

Facebook access tokens are stored encrypted in our database. They are never exposed in client-side code, logged in plain text, or transmitted outside of server-side API calls to the Facebook Marketing API.

Permissions We Request

When you connect Facebook, SiteSorted requests the following permissions:

  • ads_management — to create and manage ad campaigns
  • ads_read — to retrieve ad performance data
  • pages_manage_ads — to manage ads on your Facebook Page
  • pages_read_engagement — to read basic Page engagement data
  • pages_show_list — to list Pages you manage so you can select the correct one

We request only the minimum permissions necessary to perform ad management on your behalf.

5

Data Storage and Security

Where Your Data Is Stored

Your data is stored in Supabase, a managed PostgreSQL database hosted on AWS infrastructure in the EU (Ireland region). As an Irish company processing Irish customers' data, we maintain EU data residency by default.

Security Measures

We implement the following security measures to protect your data:

  • Encryption in transit via TLS 1.2+ for all data transfers
  • Encryption at rest for all database storage
  • Row-level security policies enforcing that users can only access their own data
  • Service role keys never exposed to client-side code
  • Regular security reviews and dependency updates

GDPR Compliance

We are a company based in Ireland and are fully subject to the GDPR and the Irish Data Protection Act 2018. We maintain a lawful basis for all data processing activities as described in Section 3.

Data Retention

  • Account and business data: retained for the duration of your subscription plus 2 years after cancellation (to comply with Irish accounting obligations)
  • Ad content and performance data: retained for the duration of your subscription plus 1 year
  • Facebook tokens and credentials: deleted immediately upon disconnection or account deletion
  • Payment records: 7 years (Irish tax law requirement)
  • Server logs: up to 90 days

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Irish Data Protection Commission within 72 hours and affected individuals without undue delay, as required by GDPR Article 33.

6

Third-Party Services

We share your data only with the following trusted third-party processors to operate the SiteSorted platform. Each is engaged under appropriate data processing agreements:

ClerkUser authentication and identity management
StripeSubscription billing and payment processing
SupabaseDatabase and storage hosting (EU region)
Anthropic (Claude API)AI-powered ad copy generation
ReplicateAI image generation for ad creative
Meta / Facebook Marketing APIAd creation and performance tracking on your connected Facebook Page
ResendTransactional email delivery (reports and alerts)
VercelApplication hosting and global edge network

We do not sell your personal data to any third party. We do not share your data with advertisers, data brokers, or any other parties not listed above.

7

International Data Transfers

Some third-party processors listed above (including Anthropic, Clerk, Replicate, Resend, and Vercel) are based in the United States. Where we transfer personal data outside the European Economic Area (EEA), we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
  • The EU-U.S. Data Privacy Framework where applicable

We ensure that all international transfers meet the adequacy requirements of GDPR Chapter V.

8

Your Rights Under GDPR

As an Irish company, we fully respect your rights under the GDPR. You can exercise any of these rights by contacting sitesortedapp@gmail.com.

You have the following rights regarding your personal data:

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Request correction of any inaccurate or incomplete data.

Right to Erasure

Request deletion of your account and associated data. Note that some data must be retained for legal reasons (e.g. tax records).

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format (e.g. JSON).

Right to Object

Object to processing based on legitimate interests.

Right to Withdraw Consent

Where processing is based on consent, withdraw it at any time without affecting prior processing.

We will respond to all requests within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Data Protection Commission (Ireland).

9

Cookies

SiteSorted uses only essential cookies required for the platform to function:

  • Authentication cookies — set by Clerk to maintain your login session. These are strictly necessary and cannot be disabled.
  • Security cookies — used to protect against cross-site request forgery (CSRF).

We do not use advertising cookies, tracking pixels, or third-party analytics cookies (such as Google Analytics). We do not profile you for advertising purposes.

10

Children

SiteSorted is designed for businesses and is intended only for users aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with data, please contact us immediately and we will delete it.

11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Display a notice in your dashboard
  • Send an email notification to your registered address
  • Update the “Last updated” date at the top of this page

Continued use of SiteSorted after the effective date of any updated policy constitutes acceptance of that policy. If you disagree with any changes, you may cancel your subscription and request deletion of your data.

12

Contact Us

If you have any questions about this Privacy Policy, how we handle your data, or wish to exercise your data rights, please contact us:

SiteSorted Privacy Contact

sitesortedapp@gmail.com

We aim to respond to all privacy enquiries within 5 business days and all formal data subject requests within 30 days.