1. Summary
Fasite is a website-as-a-service for trades and home-services businesses. We help small business owners launch a site, collect leads from that site, and manage paying customers. This policy explains what we collect, why, who we share it with, and the rights you have over your data.
- If you are a Fasite customer (a business that signed up for our service), we collect your account info, billing details (through Stripe), and the business intake you provide so we can build and run your site.
- If you submitted a contact form on a Fasite-built site (e.g. you asked a landscaper for a quote), we collect your contact info and request on behalf of that business so they can reply to you. We act as a processor for them; the business itself is the controller of that data.
- We do not sell or share personal information for cross-context behavioral advertising.
- We use Google Analytics 4 on our marketing site to understand aggregate traffic and usage. We do not run session recording or advertising trackers, and analytics data is not used to identify individual visitors.
- We do not use customer business data or end-user lead data to train AI models. Our AI generation pipeline only sees the business intake you provide for the purpose of building your site.
2. Scope and Our Role
This policy covers personal information processed through:
- Our marketing site at
fasite.org, the customer dashboard atfasite.org/dashboard, and the admin console (operated internally by Fasite). - Customer-facing websites we host on customer subdomains (
*.fasite.org) and custom domains pointed at our infrastructure.
For account, billing, and business-owner data, Fasite is the data controller. For data submitted through a contact form on a customer's Fasite-built site (a "lead"), Fasite is the processor acting on behalf of the customer business. Each customer business is the controller of the leads collected through their site.
3. Information We Collect
3a. Information you provide directly (Fasite customers)
- Account identifiers: name, email, password (hashed; we never see the plaintext), profile photo (optional).
- Business intake: business name, phone, email, street address, service area, years in business, services offered, certifications, tagline, target audience, brand voice preferences, niche, and color palette. We use this to generate and host your site.
- Billing information: payment method, billing email, subscription status. Card numbers are handled by Stripe directly; Fasite never stores them. We retain a Stripe customer ID and subscription metadata locally.
- Support communications: any email, chat, or form messages you send us.
3b. Information collected from end users (visitors to a customer's site)
When someone contacts a Fasite-hosted business through a web form, a phone call, a text message, or an online booking, we collect what the visitor provides on behalf of the business that owns the site:
- Contact name, email, phone
- Property or job-site address (free-form text)
- Service type requested
- Free-form message
- Call recordings and transcripts: on the AI Front Office plan, inbound and some outbound phone calls are recorded and transcribed by our AI receptionist. We collect the audio recording, the text transcript, an AI-generated summary, and call metadata such as the caller's phone number, the time and duration of the call, and the business the call was placed to.
- Text message (SMS) content and metadata: the content of text messages sent to and from the business's dedicated number, the participating phone numbers, timestamps, and delivery status.
- Booking and appointment data: the requested service, appointment date and time, and any details the visitor provides when booking.
- Lead and contact history (CRM): the combined record of a contact's web-form submissions, calls, and texts, kept together so the business can follow up.
- Submission metadata: timestamp, the source page, the business ID it was submitted to
We do not retain visitor IP address or user-agent in our lead database. Our hosting providers (Vercel, Render) keep short-term request logs that may include this information for fraud prevention and infrastructure security.
3c. Information collected automatically
- Authentication cookies: Supabase session cookies (
sb-<ref>-auth-token, set as HTTP-only). These are strictly necessary for sign-in. - Server logs: Vercel and Render keep request metadata for operational and security purposes. Retention is governed by their respective policies.
- Analytics cookies: our marketing site loads Google Analytics 4, which sets cookies to measure page views, traffic sources, and aggregate usage patterns. Your IP address and usage data are shared with Google LLC for this purpose. We do not load advertising or session-recording trackers, and our customer dashboards do not load analytics cookies. See Section 6 for how to opt out.
3d. Information from third parties
We do not currently receive personal information about you from third parties. We may add integrations with third-party services in the future. If we do, we will update this policy before processing personal information from those sources.
4. How We Use Information
For each purpose below, we identify the GDPR lawful basis.
- Provide the Service (build, host, and bill your site; deliver leads to you). Lawful basis: contract (GDPR Art. 6(1)(b)).
- Generate site content via AI. We pass your business intake to large language model providers (currently OpenAI) and image generation providers (currently fal.ai) for the purpose of producing your site. We do not pass lead data, customer messages, or visitor information to these providers. Lawful basis: contract.
- Email notifications for new leads. When a lead is submitted, we email the business owner via Resend. The email contains the lead's contact information and message. Lawful basis: contract (for the customer); legitimate interest of the business (for the end user, which the customer business is responsible for).
- AI receptionist, texting, and booking (on the AI Front Office plan). To answer calls, record and transcribe them, send and receive text messages, and take bookings, we pass the relevant call audio, text content, and phone numbers to our voice and messaging providers (currently Telnyx for voice and SMS connectivity, and Retell for the AI voice agent). We use this to operate the feature for the business and to store the resulting lead. Lawful basis: contract (for the customer); legitimate interest of the business (for the end user, which the customer business is responsible for).
- Account security and fraud prevention (rate limits, spam filtering on lead forms, audit logs of admin actions). Lawful basis: legitimate interest (GDPR Art. 6(1)(f)).
- Billing and tax compliance. We retain subscription records as required by accounting law. Lawful basis: legal obligation (GDPR Art. 6(1)(c)).
- Service improvement. We may use aggregate, de-identified metrics (number of leads received, sites published, generation latency) to improve the platform. We do not use identifiable customer or end-user data to train AI models. Lawful basis: legitimate interest.
- Support and communication. Lawful basis: legitimate interest.
5. How We Share Information
We share personal information with the following categories of third parties for the purposes described. We do not sell personal information.
- Hosting and infrastructure: Vercel (customer site hosting, admin and customer dashboards), Render (API backend), Supabase (authentication and PostgreSQL database, US East), Upstash (Redis for job queues), Cloudflare R2 (image and asset storage).
- Website analytics: Google LLC (Google Analytics 4) receives IP address, device and browser information, and page-level usage data from visitors to our marketing site, used to measure aggregate traffic and usage. This does not run on customer dashboards or customer-built sites.
- Payments: Stripe handles card processing and subscription billing. Stripe receives your name, email, billing address, and card data directly. We do not currently use Stripe Tax to calculate or collect sales tax on your behalf. Their privacy policy governs payment data.
- Email delivery: Resend delivers transactional email (lead notifications, password resets, billing receipts, support-ticket updates).
- AI generation: OpenAI (LLM inference for site copy and SEO content) and fal.ai (image generation). They receive only the business intake you provide. They do not receive lead data, visitor data, or payment information.
- Voice and messaging (AI Front Office plan): Telnyx provides phone numbers and carries voice calls and SMS, and Retell powers the AI voice agent that answers and transcribes calls. They receive the call audio, transcripts, text message content, and the participating phone numbers needed to deliver these features. They do not receive your payment information.
- Legal and safety: we may disclose information if required by law, subpoena, court order, or to prevent fraud or abuse.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred subject to the same protections described here.
6. Cookies and Tracking Technologies
Fasite uses two categories of cookies:
- Strictly necessary cookies: Supabase session cookies used for sign-in and authentication (see Section 3c). These cannot be disabled without breaking sign-in.
- Analytics cookies: Google Analytics 4 cookies on our marketing site, used to measure aggregate page views and traffic sources. These are not used for advertising or cross-context behavioral tracking.
You can opt out of Google Analytics by adjusting your browser's cookie settings, using a browser extension such as the Google Analytics Opt-out Browser Add-on, or enabling Global Privacy Control, which we honor for analytics cookies on our marketing site. We do not use advertising or social-media tracking cookies, so there is nothing to opt out of on that front.
If we add advertising or marketing cookies in the future, we will update this policy and present a cookie consent prompt to visitors in jurisdictions that require one (e.g. EU ePrivacy).
7. Data Retention
- Account and profile data: retained while your account is active. Deleted within 30 days after final account termination, subject to legal-hold exceptions.
- Business intake and generated site content: retained while your subscription is active. Soft-deleted on cancellation and fully purged by our weekly cleanup job once retention expiry is reached.
- Leads (visitor submissions): retained until the customer business deletes them or terminates their account, then purged with the business.
- Call recordings, transcripts, and text messages: the recording, transcript, AI summary, and SMS history for a lead are retained as long as needed to provide the service to the customer business and to meet our legal obligations, and are deleted when the customer business deletes the lead or terminates their account, then purged with the business. Our voice and messaging providers (Telnyx, Retell) may retain copies for their own short-term operational and compliance purposes under their respective policies.
- Billing records: retained as long as required by tax and accounting law (typically 7 years in the US).
- Audit logs: retained indefinitely for security and compliance purposes; access is limited to operations personnel.
- Server access logs: retained by Vercel and Render per their policies (typically 30 to 90 days).
8. Security
We use industry-standard safeguards including TLS encryption in transit, encrypted-at-rest databases through Supabase, scoped service-role credentials, row-level security policies on customer-data tables, and password hashing via Supabase Auth.
Access to personal information, including lead contact information, is restricted to authorized personnel on a need-to-know basis and is recorded in administrative access logs.
No system is perfectly secure; we will notify affected users without undue delay (and within statutory windows where applicable) in the event of a personal-data breach.
9. International Data Transfers
Fasite is based in the United States. Our infrastructure runs primarily in US data centers (Supabase US East, Vercel and Render US regions). If you access Fasite from outside the US, your data will be transferred to and processed in the US. Where required for EU/UK/Swiss data, we rely on Standard Contractual Clauses with our subprocessors and intend to certify under the EU and US Data Privacy Framework. Contact us at privacy@fasite.org for the current list of subprocessor transfer mechanisms.
10. Your Privacy Rights
10a. Everyone
Regardless of location, you can email privacy@fasite.org to request a copy of the personal information we hold about you, to correct inaccurate information, or to request deletion. We will verify your identity before acting on requests that involve personal data.
10b. European Economic Area, UK, and Switzerland (GDPR / UK GDPR)
You have the right to:
- Access your personal data
- Rectify inaccurate or incomplete data
- Erase your data (the "right to be forgotten")
- Restrict processing
- Object to processing based on legitimate interest
- Data portability (receive your data in a portable format)
- Withdraw consent at any time, where consent was the basis
- Lodge a complaint with your national data protection authority
Fasite does not currently appoint an EU representative because we do not specifically target the EU market. We will appoint one if we cross the GDPR Article 27 threshold or expand to EU-focused operations.
10c. California (CCPA / CPRA)
California residents have the right to know what personal information we collect, the right to delete it, the right to correct it, the right to opt out of sale or sharing (we do not sell or share, so this right is honored by default), the right to limit use of sensitive personal information, the right to non-discrimination for exercising these rights, and the right to data portability.
Categories of personal information collected in the past 12 months: identifiers (name, email, phone, address), commercial information (subscription details), internet activity information (authentication session, request metadata), geolocation (business address only), and professional information (business attributes you provide). We do not collect biometric, health, or precise geolocation data.
To exercise California rights, email privacy@fasite.org with the subject "California Privacy Request".
10d. Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Hampshire, New Jersey, Tennessee, and Maryland have similar rights under their respective state privacy laws. Send requests to the same email with your state and the action you want taken.
11. Do Not Sell or Share My Personal Information
Fasite does not sell personal information and does not share it for cross-context behavioral advertising. No opt-out is necessary. We do not require a "Do Not Sell or Share My Personal Information" link because there is nothing to opt out of. If this changes, we will update this policy and provide the link before any such sharing begins.
12. Children's Privacy
Fasite is intended for business owners and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, email privacy@fasite.org and we will delete it.
13. Third-Party Links
Fasite-built sites and our marketing pages may link to third-party websites. We are not responsible for the privacy practices of those sites; check their respective policies.
14. Automated Decision-Making
Fasite uses AI models (LLMs and image generators) to create website content based on the business intake you provide. This is not used to make decisions about you with legal or similarly significant effects (it does not determine eligibility for services, pricing, credit, or employment). You can request that we manually review or override any AI-generated content on your site by contacting support.
15. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. For material changes, we will provide reasonable advance notice by email to active customers and a banner on the marketing site. Continued use after the effective date of an update constitutes acceptance.
16. Contact Us
- Privacy questions, data requests, or complaints: privacy@fasite.org
- Legal notices, DMCA, or contract questions: legal@fasite.org
- General account or product help: support@fasite.org
See our Terms of Service for the contract terms governing use of Fasite.