Privacy

Privacy Policy

Last updated: May 28, 2026 · Effective immediately

Site Shield Canada (“SiteShield,” “we,” “us”) builds website audit reports that help agencies, schools, and businesses understand how AI search engines, accessibility tools, and search engines evaluate their websites. This policy explains what personal information we collect when you use the SiteShield website and product, how we use it, and the choices you have. We’ve written it in plain language. If something isn’t clear, email us — the contact details are at the bottom.

1. What we collect

Information you give us directly

When you request a free scan, submit a lead form, sign up for an account, or buy a plan, we collect the information you submit. Depending on the form, this can include:

Information we generate from your scans

When SiteShield scans a website you submit, we produce a report containing scores, findings, and recommendations across security, accessibility, performance, SEO, AI visibility, analytics, and trust signals. We store this report alongside your lead record so we can show you the results and so you can return to them later.

Payment information

If you purchase a paid plan, the actual payment is processed by Stripe. We never see or store your full card number, expiry date, or CVV. What we store is a Stripe session ID, a Stripe payment intent ID, the amount, the currency, the payment status, and the timestamp of payment. Stripe’s privacy practices are governed by Stripe’s privacy policy.

Information we collect automatically

Like most websites, our hosting and content-delivery infrastructure may log standard request data — IP address, user-agent, referrer, timestamp — for security, abuse prevention, and basic operational telemetry. We do not use these logs for advertising or build behavioral profiles from them.

2. How we use it

We use the information described above to:

We do not sell your personal information. We do not share your personal information with advertisers, and we don’t serve advertising in our products.

3. How we treat scan data

Public pages only. SiteShield scans pages that are publicly accessible on the open web. We do not log in to scan password-protected areas, member portals, or pages behind authentication. We do not collect customer data, student records, payment data, medical records, or any personal information stored on the websites we audit.

The data our scan engine inspects is information that any visitor (or any AI search engine) could see by visiting your public URLs — HTML markup, page metadata, structured data, response headers, and outputs from public testing endpoints such as Google’s PageSpeed Insights API. Our scan never extracts or transmits the contents of databases, member areas, or authenticated sessions.

For agencies who scan domains on behalf of clients: by submitting a domain, you confirm you have the authority to request a scan of that domain. You remain responsible for ensuring your scan request complies with any agreements you have with your client and with applicable law.

4. Third-party services we use

SiteShield uses the following third-party services to run the product. Each of these providers has its own privacy practices that govern the data they process on our behalf:

ProviderPurpose
StripeProcesses payments for paid plans. Stripe receives your name, email, billing address, and payment instrument directly — we do not handle the card data.
Google PageSpeed Insights APIProvides Lighthouse mobile and desktop performance and accessibility scores for the public URL you submit.
ScrapingBeeUsed as a fallback page-fetch service when a target website blocks direct requests. ScrapingBee only receives the public URL being scanned.
OpenAI, Anthropic, Google Gemini, PerplexityUsed to generate AI Visibility findings and executive-summary text. We send the public URL, brand name, and aggregated scan signals — we do not send your personal information from our lead form to these providers.
CloudflareProvides edge security and DDoS protection for our infrastructure. Cloudflare may process IP address and request metadata under their privacy policy.
WordPress hosting infrastructureThe SiteShield application runs on a WordPress hosting environment. Standard server logs apply.

We may add or replace providers as the product evolves. If we add a provider that materially changes how personal information is processed, we will update this policy and note the change in the “Last updated” date at the top.

5. Connecting your Google Analytics account

SiteShield offers an optional feature that lets you connect a Google Analytics 4 (GA4) property to your account so that your audit report can include real measurement data alongside our public-signal analysis. This connection is entirely optional — the rest of the product works without it, and we never require it.

Read-only, and only when you connect it. We request read-only access to your Google Analytics data. We never modify your analytics configuration, and we only access the specific GA4 property you choose to connect. You can disconnect at any time.

How the connection works

When you choose to connect Google Analytics, we use Google’s standard OAuth 2.0 process. You are taken to Google’s own sign-in and consent screen, where you sign in to your Google account and approve the access we request. We never see your Google password — authentication happens entirely on Google’s systems.

The access we request is limited to the read-only Google Analytics scope (analytics.readonly). After you approve, you select which GA4 property to connect, and we read aggregated reporting metrics — such as sessions, users, page views, conversions, and traffic sources — to display inside your own SiteShield report.

What we store

To keep your connection working without asking you to sign in repeatedly, Google issues us a long-lived “refresh token” for the property you connected. We store this token encrypted at rest in our database, along with the identifier and label of the GA4 property you selected, who connected it, and the connection status. We do not store your Google password, and we do not store Google account credentials beyond the encrypted token needed to read the property you authorized.

Connections are scoped to a single client or website within your account, so connecting one property does not grant access to any other.

How we use the data

We use the analytics data we read solely to generate and display the measurement portion of your SiteShield report to you (or, for agencies, to the client account the property belongs to). We do not use your Google Analytics data for advertising, we do not sell it, and we do not share it with third parties except the infrastructure providers listed in section 4 that operate the product on our behalf. SiteShield’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting and revoking access

You can disconnect a Google Analytics property from within SiteShield at any time, which deletes the stored token for that property. You can also revoke SiteShield’s access directly from your Google account’s security settings at myaccount.google.com/permissions. Revoking access there immediately prevents any further data access; disconnecting within SiteShield additionally removes the stored token on our side.

6. Cookies and tracking

SiteShield uses a minimal set of cookies and similar storage:

We do not use third-party advertising cookies. We do not load Google Analytics, Facebook Pixel, or comparable trackers on our marketing pages. If we change this, we will update this section first.

7. Sharing and disclosure

We do not sell your personal information to third parties.

We share your personal information only in these limited cases:

8. How long we keep it

We retain the personal information you submit for as long as your account or lead record is active and for as long thereafter as we have a legitimate operational, accounting, or legal reason to keep it. We do not currently have a fixed automatic-deletion schedule.

You can ask us to delete your personal information at any time using the contact details below. We will honor verified deletion requests unless we are required by law to retain certain records (for example, tax records for paid transactions).

9. Security

We protect your personal information using reasonable technical and organizational measures appropriate to the sensitivity of the data we hold. This includes encrypted transmission (HTTPS), access controls on administrative interfaces, and operating on infrastructure with edge security from Cloudflare. No system is perfectly secure. If we become aware of a security incident that affects your personal information, we will notify affected users in line with applicable law.

10. Your rights and choices

Depending on where you live, you may have specific rights regarding your personal information, including the right to:

To exercise any of these rights, contact us at the addresses in section 12. We will respond within the timeframe required by applicable law. We may ask you to verify your identity before acting on certain requests.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top. If a change is material — for example, a change in how we share personal information — we will provide additional notice, either by email or through a prominent notice on the SiteShield website. Continued use of the product after the effective date of an updated policy constitutes acceptance of the changes.

12. How to reach us

For privacy questions, deletion requests, or any other matter related to this policy, contact us:

The party responsible for processing your personal information under this policy is Site Shield Canada.