Privacy Policy
Last updated 29 September 2026
Sitefar helps you manage your WordPress sites. This policy explains what personal data we handle when you visit sitefar.com or use the Sitefar app, and what we do with it.
1. Who we are
The controller of your personal data is Where Design SRL (34856386), Iuliu Maniu 246, cam. 412, Romania ("Sitefar", "we"). You can reach us about anything in this policy at contact@sitefar.com.
This policy covers this website (sitefar.com) and the Sitefar app. Your rights are explained in more detail on our GDPR page, and cookies on our cookie policy.
2. What we collect, why, and on what basis
| What | Data | Why | Legal basis (GDPR) |
|---|---|---|---|
| Visiting the website | IP address, browser, page requested and time, in our server's technical logs. | Serving the site, keeping it secure, fixing faults. | Legitimate interests (Art. 6(1)(f)) |
| Analytics (website and app) | Pages viewed, referring site, device and browser type, approximate location derived from your IP address, and an anonymous identifier stored in a cookie. In the app, also which features you use (for example opening a demo site, running an update or connecting a site) and, when you are signed in, your internal account ID, so visits can be linked to your account. Never your email address, your sites' addresses or any WordPress details. | Understanding how the website and the app are used so we can improve them. | Consent (Art. 6(1)(a)). Off unless you accept; you can withdraw at any time. |
| Your account | Email address, password (stored only as a salted hash), two-step verification and passkey data if you turn them on. | Creating and securing your account, and signing you in. | Contract (Art. 6(1)(b)) |
| Sessions and security | The IP address and browser details of your sign-ins and active sessions, and request counts per IP address. | Keeping accounts safe and limiting abuse, such as repeated sign-in attempts. | Legitimate interests (Art. 6(1)(f)) |
| Your WordPress sites | Each site's address and name, the WordPress username and application password you provide (stored encrypted), WordPress and PHP versions, installed plugins and themes with their versions, backup status, the site icon, and, if you use Site Kit, aggregated traffic and search figures. | Showing your sites, finding updates and applying the changes you ask for. | Contract (Art. 6(1)(b)) |
| Activity history | A record of what was changed on your sites (for example an update or rollback), when, and whether it succeeded. | Showing you what happened and letting you undo changes. | Contract (Art. 6(1)(b)) |
| Connected AI apps | Which assistant you authorised, the permissions and sites you allowed, and the actions it took. | Letting assistants you approve work on your behalf, within limits you set. | Contract (Art. 6(1)(b)) |
| Emails we send | Your email address and the message: address confirmation, password reset and security notices. | Delivering messages you need to use and secure your account. | Contract (Art. 6(1)(b)) |
| Getting in touch | What you send us, such as your email address and message. | Replying to you and keeping a record of the conversation. | Legitimate interests (Art. 6(1)(f)) or contract |
We never receive or store your WordPress admin password, only the application password you create for Sitefar, which you can revoke in WordPress at any time. We do not sell personal data, and we do not use it for advertising or profiling.
3. Who receives your data
We use a small number of service providers (processors) who handle data only on our instructions:
- Hostinger, which hosts the Sitefar servers. The server is located in EU.
- Resend, which delivers the emails described above.
- PostHog, which provides analytics, only if you accept analytics cookies. Data is stored in the European Union (PostHog Cloud EU).
- Have I Been Pwned, used to check whether a password appears in known breaches. Only the first five characters of a hash of the password are sent, never the password or your email address, so the service cannot tell whose password it is.
We may also disclose data where the law requires it, or to protect our rights, or in a business transfer, in which case this policy continues to apply.
4. Transfers outside the EEA
Some providers, such as Resend and PostHog, may process data outside the European Economic Area. Where they do, we rely on an adequacy decision, including the EU–US Data Privacy Framework, or on the European Commission's Standard Contractual Clauses, together with additional safeguards where needed. You can ask us for a copy of the safeguards.
5. How long we keep it
- Account and site data: until you delete your account or disconnect the site. Deleting your account, which you confirm by email, removes your sites, stored credentials and activity.
- Sessions: sign-ins expire after seven days, and you can end them earlier by signing out.
- Server logs: only as long as needed for security and troubleshooting.
- Analytics cookies: the identifier lasts up to one year and is removed if you withdraw consent.
- Messages to us: as long as needed to deal with your request, and afterwards only where we have a legal reason to keep them.
6. How we protect it
WordPress application passwords are encrypted before they are stored and are never sent back to your browser. Account passwords are hashed and checked against known breaches. You can add two-step verification and passkeys. Connections use HTTPS, sign-in attempts are rate limited, and AI assistants only get the permissions and sites you choose. No system is perfectly secure, so if you find a problem please tell us at contact@sitefar.com.
7. Your rights
You can ask to see, correct, delete, restrict or receive a copy of your data, object to how we use it, and withdraw consent, and you may complain to a data protection authority. Details, and how to do these, are on our GDPR page.
8. Children
Sitefar is a tool for people who run websites and is not directed at anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
9. Changes
We will update this policy when what we do changes. The date at the top shows the latest version, and for significant changes we will tell account holders by email.