SiteMind helps small businesses answer website questions and capture leads. This policy applies to our website, our owner dashboard, our widget, and our related services.
We currently offer a US-first pilot for ordinary business questions and lead capture. Our Data Processing Agreement explains the supported launch scope and restrictions on international data transfers. A US business or billing address alone does not mean that all of your visitors’ data falls outside European or UK privacy law. These limits do not take away any privacy rights that apply to you.
1. Who We Are
- SiteMind is a product of KA Digital Labs LLC, a North Carolina limited liability company doing business as SiteMind.
- When we say “we,” “us,” or “our,” we mean KA Digital Labs LLC.
- You can write to us at 4030 Wake Forest Road, Ste 349, Raleigh, NC 27609, USA, or email support@sitemind.bot.
2. Information We Collect
We collect information from two groups: SMB owners and website visitors.
Information from SMB owners
- Name, email address, phone number, and login details.
- Billing and subscription data handled through Stripe.
- Account settings, workspace details, and support requests.
- OAuth information from Google sign-in, if you use it.
Information from website visitors
- Name, email address, phone number, and questions they type.
- Landing page URL, referrer, and campaign data such as UTM tags and gclid.
- Consent choices such as email_opt_in, sms_opt_in, and consent_source.
- Lead and chat history, including messages and follow-up status.
The widget runs in Shadow DOM and sets no cookies. It does use your browser’s own storage to remember a few things, so it does not repeat itself: that you already acknowledged the AI notice (kept for 180 days), that you have seen the greeting nudge, your chosen language, a random per-tab session number that links your messages in one conversation together, whether you already sent your details, whether you dismissed the starter suggestions, and a short cache of the conversation and of the widget’s appearance. This stays in your browser. It is not a cookie, it is not sent to other sites, and we only collect what is needed to provide the service.
3. How We Use Information
- To run the service and answer questions.
- To capture leads and send them to the business owner.
- To send email or SMS follow-ups when the owner asks us to do that.
- To schedule or support integrations like Google Calendar.
- To process billing, account access, and support.
- To improve reliability, security, analytics, and fraud prevention.
4. How We Share Information
We share information with service providers that help us provide the service:
- Stripe for billing and payments.
- Google for OAuth sign-in and Calendar integration.
- OpenRouter (which routes to Mistral) for AI answer processing — this is the service that reads and answers your visitors' questions.
- Anthropic, reached through OpenRouter, for reading your website content and images during setup, for a safety check on live answers that confirms the answer is supported by your pages, and for drafting suggestions inside your dashboard. That safety check receives the visitor’s question and the draft answer.
- Resend for sending email, such as lead notifications and follow-ups.
- Twilio for SMS delivery, using your own Twilio account when you connect one.
- PostHog for product analytics. No PostHog code runs inside the chat widget; our server sends it counts of widget activity against your account, never against an individual visitor.
- Sentry for error monitoring.
- Cloudflare for content delivery, bot protection, and file storage.
- Railway for hosting our application and database.
We may also share information when required by law, to protect our rights, or to investigate abuse or security issues.
5. Cookies And Tracking
- When you log in to the owner dashboard, we set one secure, HttpOnly session cookie (named
__Host-sitemind_sessionon secure connections). We sign you out after 60 minutes with no activity, and the clock resets every time you use the dashboard. There is also a hard limit: even if you stay active, you are signed out after 12 hours, or after 30 days if you choose "remember me" or sign in with Google. - Our product analytics tool, PostHog, may set cookies and use local storage on our website and dashboard to measure usage. It does not run inside the chat widget.
- The chat widget on your site uses no cookies. It does store a small amount of data in the visitor’s own browser (localStorage and sessionStorage): the AI notice acknowledgement, the greeting nudge, language choice, a random per-tab session number, whether they already sent their details, whether they dismissed the starter suggestions, and a short cache of the conversation and the widget’s appearance. None of it is a tracking cookie and none of it follows the visitor to other websites.
6. Data Retention
- Chat conversation logs are retained for 180 days.
- Analytics and marketing event data are retained for 365 days.
- System notifications are retained for 90 days.
- Leads and account data are kept for the life of the account.
- The page content and facts we read from your website are kept while that site is connected to your account.
- When you remove a website, or your plan no longer covers it, that site stops answering right away and we hold its data for 90 days so you can bring it back. After 90 days we remove the site and everything we read from it from our live systems.
- Expired data is automatically purged on a regular schedule.
- When you delete your account, we keep the data for a 30-day recovery window in case you change your mind, then remove it from our live systems. You may ask us to delete it from our live systems sooner.
Encrypted disaster-recovery backups are separate from live systems. Backups are scheduled to expire 30 days after creation, with daily cleanup; deletion is not instant and may be delayed by a storage outage. A backup made during your account recovery window may therefore remain after that window ends. We restrict access to backups and do not use deleted data for normal service operations. Before a restored backup can return to service, we must reapply deletions; if we cannot verify that, the restored service stays unavailable.
We may keep records required by law, such as billing records. We also keep limited deletion records in our separate backup-recovery journal to prevent deleted data from returning through a restore. These contain account or record identifiers and deletion times, not messages or contact details. Records in this journal are scheduled for removal 60 days after the recorded deletion, with daily cleanup; storage outages may delay cleanup.
7. Your Rights
Depending on where you live, you may have rights over your personal data.
GDPR rights
- Access your data.
- Correct inaccurate data.
- Delete your data.
- Get a portable copy of your data.
- Restrict or object to some processing.
CCPA rights
- Know what personal information we collect and use.
- Delete personal information.
- Opt out of certain uses, where the law gives that right.
To exercise any of these rights, email support@sitemind.bot.
8. Children
- Our service is not directed to children under 13.
- We do not knowingly collect personal information from children under 13.
9. Changes To This Policy
- We may update this policy from time to time.
- If we make changes, we will update this page and change the last updated date above.
10. Contact Us
- If you have questions about this policy, email support@sitemind.bot.