Privacy Policy
Last updated: 27 September 2026
Sitebrief is operated by KUDAI CO PTY LTD (ACN 681 442 697, ABN 86 681 442 697, "we", "us", "our"). We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why, and what you can do about it.
1. What we collect
When you use Sitebrief we may collect:
- Business details you give us through the questionnaire — business name,
trade, services, hours, service area, and similar.
- A business type you type yourself — if none of the listed business
types fits and you type your own, that text is sent to Google's Gemini AI service to match it to one of our website templates. Only that text is sent: never your name, contact details or other answers.
- Contact details — name, email address, phone number.
- Content you upload — photos and other material for your site.
- Domain registration details — if you buy a domain through Sitebrief,
the registrant's name, postal address, phone number and email address. The rules for registering a domain require these to be given to the registrar and to the registry that runs that domain ending, because the domain is registered in your name. We ask for them to be kept out of the public WHOIS directory.
- Account credentials — an email and password, or a Google sign-in, for
your site's portal.
- Payment information — handled entirely by Stripe. We receive
confirmation that a payment succeeded or failed, never your full card number.
- Technical information — a salted, one-way hash of your IP address (we
store the hash, not the address), used to rate-limit submissions and reduce abuse of the public form. Our web server also keeps an access log of requests to sitebrief.au: your IP address, the page requested and when. We keep it for 30 days, to investigate security problems, and then delete it. It does not include the websites we host for businesses, so their visitors are not recorded in it.
- Usage data — how you use Sitebrief's own site: the pages you visit and
the elements you click, collected with PostHog, a product-analytics service. Your IP address is sent to PostHog to derive an approximate location (such as your city) and is discarded rather than stored.
- Advertising source — if you arrive by clicking one of our ads or a
tagged link, the campaign tags in that link (such as which ad it was), the click identifier the ad platform adds to it, and the site that referred you. We keep these with your brief.
2. Why we collect it
We use this information to:
- generate and operate your website;
- bill your subscription and handle payment issues;
- provide support when you contact us;
- protect the public parts of Sitebrief from abuse and fraud;
- understand and improve Sitebrief — how it is used and what to fix;
- measure whether our own advertising works;
- meet our legal and accounting obligations.
We do not sell your personal information. We do not use it to show you advertising for anyone else, and we do not build advertising profiles of you. The one advertising use is measuring our own ads, described in section 6.
3. Who we share it with
We use a small number of service providers to run Sitebrief, and share only what each one needs to do its job:
- Stripe — payment processing and billing.
- Cloudflare — DNS, receiving email sent to sitebrief.au, and, if you
buy a domain through us, registering it in your name (Cloudflare Registrar). Cloudflare passes your registrant details on to the registry for that domain ending.
- Google — Google sign-in, if you choose to use it, and the Gemini AI
service, which matches a business type you typed yourself to one of our templates.
- DigitalOcean — the servers and file storage Sitebrief runs on, in
Sydney.
- Resend — sending transactional email on our behalf.
- PostHog — product analytics (how visitors use our site).
- Meta (Facebook and Instagram) — measuring our own ads, only if you
arrived from one of them (see section 6).
Some of these providers process information outside Australia: Stripe, Cloudflare, Google, Resend and Meta mainly in the United States (Cloudflare also across its worldwide network), PostHog in the European Union, and the registry for your domain ending wherever it operates (for .com and .net, the United States). DigitalOcean stores Sitebrief's data in Sydney. Where information goes overseas, we rely on their own compliance obligations (each of the above is a well-known provider with its own privacy and security commitments) and, where required, on the safeguards the Australian Privacy Principles allow for overseas disclosure.
We do not otherwise share your personal information with third parties, except where required by law.
4. Security
We take reasonable steps to protect the personal information we hold, including storing passwords hashed rather than in readable form, and using encrypted connections (HTTPS) throughout. No system is completely secure, and we cannot guarantee absolute security.
5. How long we keep it
We keep your information for as long as you need it to use Sitebrief, and we delete it when it is no longer needed:
- Unsaved sites: A site that is not saved to a confirmed email address is
deleted after 8 days (the free week plus one day).
- Cancelled subscriptions: If your subscription ends, we delete the site's
data 12 months after the subscription ended.
- Deleting your account: You can delete your account from your settings.
We wait 7 days before deleting your account and sites, during which time your sites are offline but you can change your mind.
- Deleting a site: You can delete a site from your settings and keep your
account. We wait 7 days before deleting the site. It is offline during this time, but you can change your mind.
When your account or site is deleted, we remove your data, with a few exceptions required for legal, tax, or technical reasons:
- Tax and billing records: We keep payment and invoice records to meet our
legal and tax obligations, for as long as tax law requires. Invoices already issued keep the details they were issued with; your card details, and the name and email on your Stripe customer profile, are removed.
- Backups and logs: Your data may remain in our encrypted backups for up to
30 days. Our web server's access log is kept for 30 days. Records of emails we have already sent are kept for a short period and then deleted.
- Analytics and advertising: We delete your site analytics through
PostHog's API. If you arrived from a Meta ad, the hashed conversion data we already sent to Meta (described in section 6) cannot be recalled by us.
- Domains: If you bought a domain through us, we keep a minimal record of
it until it expires or is transferred.
6. Cookies and analytics
Sitebrief uses cookies for two things. First, for the service to function — for example, keeping you signed in to your site's portal. Second, for product analytics: we use PostHog to measure how people use our own site, so we can see what is working and what to improve. PostHog sets cookies to tell visitors apart and to link the pages one visitor sees in a single session.
Through PostHog we learn which pages are visited and which elements are clicked (a button, for example), and we use your IP address to work out an approximate location such as your city. That data is processed in the European Union, and your IP address is discarded rather than stored. We do not use session replay, and we do not record the text you type into the site.
If you arrive from one of our Facebook or Instagram ads, our server tells Meta that you arrived, and if you then start building a site (by choosing your business type), send us a brief, confirm your email address or start a subscription, it reports that the ad led to that result, so we can tell which ads are worth running and Meta can show them to similar businesses. What we send is: the event, the click identifier Meta added to the ad link, your browser's user-agent and IP address, a random identifier our analytics gives your browser (which lets Meta connect your steps from arriving to subscribing, but is not a name or contact detail), and your email address and phone number if you gave them — with the analytics identifier, email and phone number hashed (converted to a one-way code) before they leave our server, never in readable form. Nothing is sent to Meta about visitors who did not come from a Meta ad, and no Meta code or cookie runs on our site. Meta handles this data under its own terms and privacy policy, and may process it outside Australia.
We do not use third-party advertising cookies, and we do not sell your information.
7. Accessing or correcting your information
You can ask us for a copy of the personal information we hold about you, or ask us to correct it, at any time by contacting us at the details below. We will respond within a reasonable time and will not charge you for making the request. Much of your own business information is also editable directly from your site's portal. You can also initiate the deletion of your account and its data at any time from your account settings (Settings > Account), subject to the retention periods described in section 5.
8. Complaints
If you have a concern about how we have handled your personal information, contact us first at the address below so we can try to resolve it. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "last updated" date.
10. Contact us
support@sitebrief.au