PRIVACY / TRUST

GDPR & CCPA PRIVACY CONTROLS

Useful data should still be handled responsibly.

PagePith is built to support customers’ GDPR and California privacy obligations with consent controls, contractual protections, transparent vendors, and limited retention.

01

Consent-first analytics

Optional PostHog analytics stays off until a visitor accepts it, and the choice can be changed at any time.

02

A customer DPA

Our DPA covers controller–processor duties, California service-provider terms, security measures, and EU transfer clauses.

03

Subprocessor transparency

We publish provider names, purposes, data categories, processing locations, and a 30-day change-notice process.

04

Bounded retention

Successful scrape results are cached for seven days by default, and monitoring history is generally pruned after 30 days.

05

Data rights support

People can request access, correction, deletion, restriction, objection, or portability through a documented privacy channel.

06

Security by design

Public-URL validation, scoped credentials, encrypted webhook secrets, rate limits, logging, and monitoring protect the service.

SHARED RESPONSIBILITY

Compliance includes how you use the data.

PagePith provides processing controls; customers remain responsible for choosing lawful URLs, establishing a legal basis, providing notices, and respecting third-party rights. Sensitive or regulated personal data is not supported without a separate written agreement.

Talk to us about privacy