Skip to content

Privacy policy

This privacy policy explains what personal data we process when you visit this website, use the SiteRemark service, or give feedback on a website through SiteRemark – why we do so, how long we keep the data, and what rights you have. This English version is provided for convenience; if the two versions differ, the German version prevails.

1. Privacy at a glance

2. Controller

The controller under the EU General Data Protection Regulation (GDPR) is:

Whale Marketing
Owner: Uwe Hermann
c/o MDC Management#5698
Welserstraße 3
87463 Dietmannsried
Germany

Email: [email protected]

Phone: +49 15679 290767

We have not appointed a data protection officer, as we are not legally required to. If you have questions about data protection, please email us at the address above.

3. General information

Legal bases

We process personal data only when a legal basis allows it. We name it for each processing activity; here’s an overview:

How long we keep data

We keep personal data only as long as we need it for the purpose in question. Where a fixed period applies, we state it in the relevant section. If you withdraw your consent or ask us to delete your data, we delete it unless another legal reason requires us to keep it – for example, statutory retention periods under tax and commercial law. In that case, we restrict the data from any other use and delete it once the period ends.

Recipients

We share data only when it’s necessary for the purpose or required by law. The main recipients are our hosting provider (section 4) and, only with your consent, Google (section 8). Data that you choose to send to other services goes to the providers you select (section 12). We have concluded agreements under Art. 28 GDPR with service providers that process data on our behalf. Authorities receive data only where we are legally obligated to provide it.

Transfers to third countries

Data may be processed outside the EU and the European Economic Area in two cases: with Google Analytics, if you have consented (section 8), and with integrations that customers turn on themselves, such as Slack or Zapier (section 12). For the United States, the European Commission has adopted an adequacy decision covering companies certified under the EU-U.S. Data Privacy Framework. Where it doesn’t apply, transfers are based on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).

Withdrawing your consent

You can withdraw your consent at any time with effect for the future (Art. 7(3) GDPR). This doesn’t affect the lawfulness of processing before the withdrawal. For cookies, just click “Cookie settings” at the bottom of any public page; otherwise, a short email to [email protected] is enough.

Right to object under Art. 21 GDPR

Where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation; this also applies to profiling based on that provision. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves to establish, exercise, or defend legal claims (Art. 21(1) GDPR).

Where we process data for direct marketing, you may object at any time without giving reasons, and we will no longer use the data for that purpose (Art. 21(2) and (3) GDPR). We currently don’t engage in direct marketing.

To object, just email us at [email protected].

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state where you live or work or where the alleged infringement took place. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach

Access, rectification, erasure, and other rights

You have the right at any time to

An email to [email protected] is all it takes. In the dashboard, you can change much of your information yourself, export your data, and delete your account.

SSL/TLS encryption

This website, the dashboard, and the widget transmit data only in encrypted form using TLS – you can tell by “https://” and the padlock icon in your browser’s address bar. This keeps third parties from reading the data you send us.

Objection to promotional emails

We hereby object to the use of the contact details published in our legal notice for sending advertising and information materials we haven’t expressly requested. We don’t send you promotional emails without your consent; the service emails described in section 11 are not advertising.

4. Hosting and server log files

This website, the dashboard, the widget, and the database are hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. The servers are located in Germany. Hostinger processes data only on our behalf and according to our instructions, under a data processing agreement pursuant to Art. 28 GDPR. We also send the service’s emails through Hostinger’s mail server.

Whenever you open a page, the dashboard, or the widget on a customer’s website, your browser sends information that the server records in log files:

We need this data to deliver our services, run them securely, fend off attacks, and track down errors. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure and stable service. Hostinger keeps the log files only for a short period and then deletes them. We don’t combine them with other data.

5. Cookies and local storage

Cookies are small text files that your browser stores on your device. Your browser’s local storage (local storage and session storage) works in a similar way. We use both sparingly – almost exclusively for things without which a feature you want to use wouldn’t work. Such entries don’t require consent under Section 25(2) no. 2 TDDDG. Only for Google Analytics do we ask you first (Section 25(1) TDDDG). You can view and delete all entries in your browser at any time.

On siteremark.com – website, dashboard, and client area

Name and typePurposeRetentionLegal basis
PHPSESSID
cookie
Keeps you logged in to the dashboard or the client area; contains only a random identifier.until you log out or close your browserSection 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
sfb_bleiben
cookie
Only if you choose “Stay logged in”: keeps you logged in on this device. Contains a single-use token, never your password.30 daysSection 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR
sfb_sprache
cookie
Remembers the language you chose.365 daysSection 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR
sfb_seite
cookie
Only while the website is a password-protected preview: remembers that you entered the password.30 daysSection 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR
sr_einwilligung
cookie
Stores your choice in the cookie banner (section 6).365 daysSection 25(2) no. 2 TDDDG; Art. 6(1)(c) in conjunction with Art. 7(1) GDPR
sfb-ansicht
local storage
In the dashboard: the list view you chose.until you clear your browser storageSection 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR
sr-hallo:…
local storage
In the dashboard: whether the note in the contact window has already appeared today, so it shows up only once a day.until the next day, then replacedSection 25(2) no. 2 TDDDG; Art. 6(1)(f) GDPR
_ga
cookie
Only with your consent: Google Analytics uses it to distinguish visitors (section 8).2 yearsArt. 6(1)(a) GDPR; Section 25(1) TDDDG
_ga_873B9RWB8L
cookie
Only with your consent: Google Analytics uses it to keep track of the session.2 yearsArt. 6(1)(a) GDPR; Section 25(1) TDDDG

In the widget – on our customers’ websites

The widget stores a few entries in the browser of people who give or view feedback. They’re stored under the domain of the customer’s website, not siteremark.com; stands for the website’s key. The widget itself doesn’t set any cookies. The agency that embedded the widget is the controller for this processing; we act on its behalf (section 10).

Name and typePurposeRetentionLegal basis
sfb:name:…
local storage
The name you use for your notes, so you don’t have to enter it every time.until you clear your browser storageSection 25(2) no. 2 TDDDG; for the agency as controller, usually Art. 6(1)(b) or (f) GDPR
sfb:autor:…
local storage
Only if your name is protected by a PIN: proof that you entered the PIN.valid for 30 days
sfb:review:…
local storage
The guest key from your invitation link, so the widget appears again on your next visit.until you clear your browser storage
sfb:admin:…
local storage
For the agency’s team only: the login in the widget.valid for 12 hours, deleted when you log out
sfb:seen:…
local storage
Which replies you’ve already seen, so new ones can be highlighted.until you clear your browser storage
sfb:gross:…, sfb:konto:…
local storage
Whether the widget is shown enlarged, and whether the suggestion to create a client account has already appeared.until you clear your browser storage
sfb-gemeldet-…
session storage
Makes sure the widget reports only once per browser session that it has been loaded. The report contains only the website’s key.until you close the tab

6. Consent management

Our cookie banner is our own solution, not a third-party service. On your first visit to our public pages, we ask whether you agree to Google Analytics. Until you agree, the page loads nothing from Google. We store your choice – consent or refusal – in the sr_einwilligung cookie on your device, so we don’t have to ask again on every page and can demonstrate that you consented. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR; storing the cookie is permitted under Section 25(2) no. 2 TDDDG. We don’t store your choice on our server.

You can change or withdraw your choice at any time using the “Cookie settings” link at the bottom of every public page. If you withdraw consent, we delete the Google Analytics cookies on your device, as far as your browser allows.

7. Contacting us

By email or phone

When you write to us or call us, we process the information you provide – usually your name, contact details, and your request – to respond to you. The legal basis is Art. 6(1)(b) GDPR if your request relates to a contract with us or steps prior to entering into one, and otherwise Art. 6(1)(f) GDPR; our legitimate interest is responding to inquiries. We delete the data once your request has been resolved, unless statutory retention obligations apply.

Question bubble on the website

You can send us a question through the question bubble (“Questions? Write to us.”). We process your name, email address, and question, along with the time and your browser’s identifier (user agent). The message goes to our support inbox, a database on our hosting provider’s server, and we also receive an email notification. We reply by email. We don’t send a confirmation to the address you enter – that way, no one can use the bubble to send emails to other people. To prevent abuse, we limit how many questions can come from one IP address (section 14).

Contact window in the dashboard

When you’re logged in, you can reach us through the contact window. We store your message along with its subject, the type of request, the page you wrote it on, your browser’s identifier, and your account. You receive a copy by email, and we receive a notification. You’ll find our replies in the dashboard and in your inbox.

For both channels: the legal basis is Art. 6(1)(b) GDPR where your contract or steps prior to entering into one are concerned, and otherwise Art. 6(1)(f) GDPR. We delete messages 365 days after we receive them, and messages sent from the dashboard no later than when your account is deleted.

8. Google Analytics 4

With your consent, we use Google Analytics 4 (measurement ID G-873B9RWB8L), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics runs only on our public pages – not in the dashboard, the client area, or the widget – and loads only after you’ve agreed in the cookie banner. The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Google Analytics recognizes your browser by a random identifier in the _ga and _ga_873B9RWB8L cookies and processes pseudonymous usage data: the pages you view, the time and duration of your visit, interactions such as scrolling or clicking links, the page you came from, information about your device, browser, operating system, screen, and language, and your approximate location. Google derives the location from your IP address; according to Google, Google Analytics 4 doesn’t store IP addresses. On our behalf, Google uses this data to compile reports on how the website is used. We don’t learn who you are, and we don’t combine the data with other data about you.

We’ve turned off Google signals and ad personalization, and the page explicitly tells Google not to store data for advertising purposes. Google deletes event data linked to individual visitors after 2 months; aggregated reports are retained.

Google processes the data as our processor; for this purpose, we have accepted Google’s data processing terms. Data may be transferred to Google LLC in the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework, for which the European Commission adopted an adequacy decision on July 10, 2023 (Art. 45 GDPR). In addition, Google has concluded the European Commission’s standard contractual clauses.

You can withdraw your consent at any time with effect for the future using “Cookie settings” at the bottom of any public page. Independently of that, the Google Analytics opt-out browser add-on stops your browser from sending data to Google Analytics. For more information, see Google’s privacy policy.

9. Registration, account, and team

Requesting access and approval

When you request access, we process your email address, name, company, a referral code if you came through a referral link, and the time you accepted our terms and conditions. We send you a confirmation link that’s valid for 24 hours; we delete unconfirmed requests after that. Your account is created only once you confirm. We then review the request manually and activate the account – this keeps people from using the service under a false name or for abuse. We’ll let you know by email once you’re approved. The legal basis is Art. 6(1)(b) GDPR, and for the review, also Art. 6(1)(f) GDPR.

As proof that the contract was concluded, we store with your account when you accepted the terms and conditions and which version you accepted (Art. 6(1)(b) and (f) GDPR).

Your account

For your account, we process your first and last name, email address, company, password (stored only as a hash, never in plain text), a profile picture if you add one, your language and dashboard settings, your product name and logo if you use white labeling, the websites and projects you create, and technical data such as the time of your last login and failed login attempts (to protect against password guessing). If you change your email address, we store the new address until you confirm it. For password resets, we store only the hash of a time-limited link.

If you choose “Stay logged in,” we store an entry for each device with a name derived from your browser (for example, “Chrome on Windows”), the time it was last used, and its expiration date. You’ll find the list in your profile, where you can log out on all devices. We delete expired entries.

The legal basis is Art. 6(1)(b) GDPR. Without this data, we can’t provide you with an account. We keep it for as long as your account exists.

Team and invitations

When you invite members to your team, we process their email address and role and send them an invitation link that’s valid for 7 days. We store only the link’s hash. If they accept, they set up their account as described above. In the dashboard, team members can see who took on, was assigned, or resolved a note, and the statistics evaluate this for the team. The legal basis is Art. 6(1)(b) GDPR (your contract with us) and Art. 6(1)(f) GDPR. It’s your responsibility as an employer or client to make sure you’re allowed to invite members and evaluate their work in the dashboard.

Client accounts in the client area

If an agency allows it for a project, its clients can create a client account to follow all notes on a project. For this, we process the email address, name, password (stored only as a hash), confirmation of the address (double opt-in), the time of the last login, failed login attempts, and which projects the account can see and under which name. We delete unconfirmed accounts after 7 days. A client account can bring together projects from several agencies, so we are the controller for the login data (Art. 6(1)(b) GDPR), while the respective agency is the controller for the project content (section 10). You can delete your client account yourself in the client area at any time; your notes then remain in the agency’s project.

Data export and account deletion

In the dashboard, you can export all of your team’s data and delete your account. When you do, we delete your team along with all its members, websites, notes, screenshots, recordings, files, and support messages. Only the following are kept longer: the email log until its period ends (180 days, section 11), the record of the data processing agreement (section 16), billing records subject to statutory retention periods (section 17), and backups until they’re deleted in rotation (section 14).

10. Feedback through the widget

Agencies embed the SiteRemark widget in websites so that their clients and team can leave notes there. We process this data solely on behalf of the respective agency – as a processor under Art. 28 GDPR, based on the data processing agreement the agency accepts in the dashboard. The agency is the controller. If you give feedback through the widget, please contact the agency with questions or to exercise your rights; if such a request reaches us, we’ll forward it.

Depending on what you do in the widget, we process:

When the widget loads, the usual connection data is processed on our server (section 4). If the widget on a website is visible to everyone, every visitor’s browser loads it from our server; if it’s limited to guest links, visitors fetch only a small loader script from us – or not even that with the privacy-friendly embed option – and only people with a guest link or team members load the widget itself. In addition, once per browser session, the widget records when it was last loaded on the website – without any personal information. What the widget stores in your browser is listed in section 5.

The data is kept as long as the agency maintains the project. Deleted notes stay in the trash for 30 days and are then permanently deleted, including screenshots, recordings, and files. If the agency deletes the website or its account, we delete all associated data.

11. Service emails

SiteRemark sends emails that are part of the service: confirmation links, the approval of your access, invitations to a team or a client account, password resets, notifications about new notes and replies (bundled after a quiet period), deadline reminders, notices about new feedback rounds, completed items, and sign-offs, as well as copies of support messages. We send them through our hosting provider’s mail server. They contain no advertising, and we don’t track opens or clicks – there are no tracking pixels and no redirected links.

To answer questions about delivery, we log the recipient, subject, type, time, whether the handover to the mail server succeeded, and the related team or project for each email – but not its content. We delete the log after 180 days. The legal basis for sending is Art. 6(1)(b) GDPR, and for the log, Art. 6(1)(f) GDPR. Notifications to an agency’s clients, at addresses the agency provides, are sent on the agency’s behalf (section 10).

12. Integrations with other services

In the dashboard, customers can connect SiteRemark to other services: Slack, Microsoft Teams, Discord, Trello, Zapier, Make, n8n, or a webhook URL of their own. As long as no one turns on an integration, nothing is sent to these services. Once it’s on, we send the website name, the name of the person who left the note, the text, the page, the status, and a link to the dashboard to the selected service whenever something happens, such as a new note, a reply, a status change, an approval, or a new round. With Trello, we create cards and receive a notification from Trello when a card is moved.

For each integration, we store the destination URL, a key for signing messages, and, for Trello, the access credentials you authorize. We keep delivered messages in the delivery log for 14 days so that errors can be traced. We transmit the data on the instructions of the customer, who as controller selects the service (Art. 28 GDPR; for the customer’s own account data, Art. 6(1)(b) GDPR). The selected service’s privacy policy applies to data it receives. Several of these providers are based in the United States; transfers then rely on certification under the EU-U.S. Data Privacy Framework or on standard contractual clauses that the agency, as controller, agrees with the provider.

13. Browser extension

For agency teams, SiteRemark is also available as a browser extension that lets them add notes to pages that don’t have the widget embedded. The extension isn’t distributed through a store. It acts only when you click its icon in a tab: it then adds the widget to that tab (“activeTab” and “scripting” permissions). It doesn’t access your history, other tabs, or pages you don’t activate yourself, and it communicates only with siteremark.com. After you log in with your credentials, it stores a time-limited token in the extension’s storage – never your password. Notes you add with the extension are processed like feedback through the widget (section 10). The legal basis is Art. 6(1)(b) GDPR.

14. Security, backups, and error reports

Protection against abuse

To protect the login, forms, the question bubble, and the widget from automated attacks, we count requests per IP address (for IPv6, per network block) within short time windows. We don’t store the address in plain text for this, only as a hash together with the counter’s name and the time window. The windows last from a few minutes to a day at most, and we regularly delete expired counters. After several incorrect passwords, we lock an account for a short time. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting our users and the service.

Backups

Every night, we back up the database. The backups are stored on our hosting provider’s server in Germany, in a directory that can’t be accessed from outside. We keep the 7 most recent backups and delete any older ones. Data you delete therefore usually disappears from our backups after 7 days as well. The legal basis is Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR; we want to prevent data loss.

Error reports

If an error occurs in the service, we receive an email with the error message, the affected place in the code, the requested address, and the call stack – at most one per type of error per hour. These rarely contain personal data, for example if it’s part of the requested address. The server’s error log also records such messages. We use both only to fix errors and delete the emails once they’re no longer needed for that. The legal basis is Art. 6(1)(f) GDPR.

15. Referral program

Every team receives a personal referral code that it can share as a link or for typing in. If someone requests access using this code, we store the code with the request and assign the new team to the referring team. We don’t use cookies or any other tracking for this. The referring team can see in its dashboard the names of the teams it referred, when they signed up, and whether they have become paying customers; when a referred team pays, the referring team’s access is extended. The legal basis is Art. 6(1)(b) GDPR and, for showing this information to the referring team, Art. 6(1)(f) GDPR – both sides have an interest in the credit being traceable. We keep the assignment as long as both accounts exist.

16. Data processing agreement

When you accept the data processing agreement in the dashboard, we record, as proof, who accepted which version and when: your name, email address, and company at the time of acceptance, the team, the full text of that version of the agreement, your IP address, and your browser identifier. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 28(9) and Art. 5(2) GDPR, as well as Art. 6(1)(f) GDPR. We keep this record even after the agreement ends and after an account is deleted, for as long as claims under the agreement can be asserted, and delete it afterward.

17. Invoices and statutory retention

We currently bill by invoice and bank transfer and don’t use a payment service provider. For billing, we process your name, company, address, VAT identification number if applicable, email address, the plan you booked, invoice amounts, and payments received (Art. 6(1)(b) GDPR). German commercial and tax law requires us to keep invoices and accounting records (Section 257 HGB, Section 147 AO) for six, eight, or ten years, depending on the document. The legal basis for this is Art. 6(1)(c) GDPR. For bookkeeping and tax filings, these records may be passed on to a tax advisor bound by professional secrecy. If we add a payment service provider, we’ll update this policy before we start using it.

18. No automated decisions, no sale of data

We don’t use automated decision-making, including profiling, within the meaning of Art. 22 GDPR; a person decides whether to approve access. We don’t sell personal data, don’t share it for advertising purposes, and don’t use our customers’ feedback data for our own purposes.

19. Changes

If our services or the legal situation change, we’ll update this privacy policy. The version published here applies.

Last updated: September 2026