Privacy policy
Privacy Policy
Last updated: 8 August 2026
The Site Book (“we”, “us”, “our”) is a construction compliance software service operated by REDCLAN VENTURES LTD (Company No. 17142372), registered in England and Wales, trading as The Site Book. This policy explains how we collect, use, and protect personal data when you use The Site Book.
If you use our iOS or Android app, the Mobile App Privacy Addendum explains mobile permissions, optional push notifications, app analytics, diagnostics and on-device storage.
We are subject to the UK GDPR (as retained in UK law under the Data Protection Act 2018) and, where applicable, the EU GDPR.
1. Who is the Data Controller?
For your account and billing data, REDCLAN VENTURES LTD is the Data Controller. For project records — including worker sign-offs, incident logs, and CDM documents — you (the principal contractor or CDM duty holder) are the Data Controller. We act as your Data Processor for those records.
2. What personal data we collect
Account data
- Email address, company name, and contact phone number — required to create and operate your account
- Company logo — optional, used on generated documents
- Billing information — processed by Stripe (we do not store card numbers)
Sales enquiries and Business walkthrough requests
- Name, work email address, company, role, number of active jobs, team size, and the main thing you want to sort
- Optional: phone number, when you need it, and a message with more context
- IP address, used to rate-limit the public form and prevent abuse
- Where you consent, limited acquisition and advertising attribution described in Section 5
Worker and project data
- Names, roles, email addresses, and phone numbers of workers you add to the system
- Worker certifications and expiry dates (e.g. CSCS cards)
- Digital sign-off records: worker name, date and time, IP address, device type
- Incident and near-miss logs, including descriptions of injuries and people involved
- Permits to work: names of persons issuing and receiving each permit
- Site diary entries, including visitor names and optional photographs
- Subcontractor company names and contact details
Technical and analytics data
- Authentication tokens managed by Clerk
- AI processing logs (inputs and outputs) retained for 90 days
- Audit logs for security and dispute resolution, retained for 2 years
- Analytics data collected via Google Analytics (GA4), PostHog, and Microsoft Clarity — see Section 5
- Purpose-specific Analytics and Advertising choices, their disclosure version and change times, retained to remember and enforce what you chose — see Section 5
- Where you allow Advertising, first-party acquisition attribution, such as campaign and referral parameters, landing page, referrer, a pseudonymous visitor identifier and, where present in the arrival URL, a Google or Microsoft advertising click identifier — see Section 5
- Where you consent, a separate Google Ads conversion-matching record containing a click identifier and SHA-256 email hash — see Section 5
- After a confirmed Google Ads matching withdrawal, a separate suppression record containing only domain-separated, keyed email digests — see Sections 5 and 8
- After account deletion, a privacy-minimised anti-resurrection record containing the opaque account user ID and a domain-separated, keyed HMAC-SHA-256 email digest. It contains no raw email address.
3. Legal basis for processing
| Data | Legal Basis |
|---|---|
| Account data | Contract performance (Art. 6(1)(b)) |
| Sales enquiries and Business walkthrough requests | Consent (Art. 6(1)(a)) — to respond to your request, contact you and arrange the walkthrough |
| Public enquiry IP address | Legitimate interest (Art. 6(1)(f)) — abuse prevention and service security |
| Worker names, roles, and CDM records | Legal obligation — CDM 2015 (Art. 6(1)(c)) |
| Worker sign-off records, certifications | Legal obligation — CDM 2015, RIDDOR 2013 (Art. 6(1)(c)) |
| Incident and injury descriptions | Legal obligation + employment law (Art. 6(1)(c), Art. 9(2)(b)) |
| IP addresses in sign-offs | Legitimate interest — document authenticity (Art. 6(1)(f)) |
| Optional Analytics | Consent (Art. 6(1)(a)) — a separate, renewable choice managed through Cookie preferences |
| Advertising tags and first-party acquisition attribution | Consent (Art. 6(1)(a)) — a separate, renewable Advertising choice; not inferred from Analytics consent |
| Analytics and Advertising consent-choice evidence | Legal obligation and legitimate interests (Art. 6(1)(c) and (f)) — recording and enforcing what was chosen, when, and under which disclosure version |
| Google Ads / Google Data Manager conversion matching (click IDs and hashed email) | Consent (Art. 6(1)(a)) — matching or upload is enabled only when ad-user-data consent is granted |
| Microsoft Advertising UET conversion measurement | Consent (Art. 6(1)(a)) — browser UET measurement is enabled only after the separate Advertising choice is allowed |
| Google Ads address-withdrawal suppression record | Legitimate interests (Art. 6(1)(f)) — keeping a confirmed withdrawal effective across lead or account deletion without retaining the raw email address |
| Billing data | Contract performance (Art. 6(1)(b)) |
| Minimum paid transaction and accounting record | Legal obligation (Art. 6(1)(c)) — company, accounting and tax record-keeping |
| Audit and security logs | Legitimate interest — fraud prevention (Art. 6(1)(f)) |
| Account-deletion anti-resurrection record | Legitimate interests (Art. 6(1)(f)) — preventing delayed or replayed billing events from recreating an erased account, and supporting billing, fraud and legal audit |
4. How we use your data
- To generate and store CDM-compliant construction documents (RAMS, CPP, Site Inductions, Emergency Plans)
- To provide worker sign-off links and record digital attendance at safety briefings
- To track certification expiry and send alerts if you enable notifications
- To produce audit-ready compliance packs for HSE inspectors or principal contractors
- To maintain audit trails of document generation and access
- To process payments and manage subscriptions
- To respond to sales enquiries and arrange a requested Business walkthrough
- To measure and improve the service using analytics
We do not sell personal data. Where you consent, we use limited first-party acquisition attribution to understand which of our own campaigns and referrals produce enquiries and customers. That first-party processing does not itself authorise an upload to Google. Where you consent, we also use limited advertising conversion data for Google Ads matching and campaign measurement. We do not use your construction documents, worker records, incident data, or project safety information for advertising or build advertising profiles from that content.
5. Cookies and analytics
We use cookies and similar technologies to operate the service and understand how it is used. When you first visit the site, we show a cookie consent banner. You can allow or decline Analytics, Advertising and Personalised advertising separately, accept all, or reject all. Personalised advertising is a distinct choice from Advertising: it controls whether Google can build a remarketing audience from your visit, not campaign measurement. Each choice is current for up to 180 days and can be changed at any time. For a full list of cookies we use, see our Cookie Policy.
Essential cookies
Required for the site to function — authentication sessions and security tokens. We also use first-party preference cookies only to remember and enforce the Analytics, Advertising and Personalised advertising choices you make.
Analytics cookies
We use Google Analytics (GA4), PostHog, and Microsoft Clarity to understand how people use the site — which pages are visited, where users drop off, how features are used, and where the interface needs improvement. Microsoft Clarity provides heatmaps and session recordings on the live site only after you allow Analytics. If you decline Analytics, we do not configure or send events to Google Analytics, Google Analytics cookies are not set, Microsoft Clarity is not loaded, and PostHog analytics are disabled. If you separately allow Advertising, the shared Google tag may still load for Google Ads while analytics_storage remains denied.
First-party acquisition attribution
After you allow Advertising, an arrival URL containing campaign, referral or advertising click parameters may be stored with the first and latest source, landing page, referrer and a pseudonymous visitor identifier in first-party local storage and in our service. This carries the source through a lead, signup or checkout journey, measures our own marketing and helps prevent duplicate referral credit. If you have not allowed Advertising, we do not write that acquisition data to browser storage or our attribution capture service, and our lead and checkout endpoints ignore client-supplied attribution. This is separate from Google Data Manager matching, which also requires ad-user-data consent.
Advertising cookies
If you arrive via a Google Ads campaign, the Google Ads tag (AW-18049615348) can measure whether the visit leads to a signup or paid subscription. If you arrive via Microsoft Advertising, Microsoft UET can measure a Business walkthrough request, signup, checkout and paid-subscription events. Where configured, Meta Pixel can measure page views for advertising and retargeting. These providers are controlled only by the separate Advertising choice, not by Analytics consent. Their libraries are not loaded until Advertising is allowed.
If you separately grant ad-user-data consent, we may create a privacy-minimised conversion-matching record containing the relevant Google click identifier and a SHA-256 hash of your normalised email address, together with the conversion stage, time, transaction identifier and value. This consented record may be sent to Google Ads through Google Data Manager to match an ad interaction with a valid lead, qualified lead, or paid customer and to improve campaign measurement. We do not place the raw email address in this record. For a submission where ad-user-data consent is not granted, the Google matching record contains neither a click identifier nor an email hash and cannot be uploaded.
Declining Analytics stops optional browser and consented server-side product analytics. Declining Advertising prevents your browser from granting advertising consent on later submissions and removes advertising identifiers from that browser. For a signed-in billing owner, we also keep each current purpose-specific choice, its disclosure version and change time on the product account. Declining Advertising makes unsent matching records linked to that user permanently unmatchable and creates a server-side Google Ads suppression barrier for the verified address. Allowing Advertising later can re-enable browser advertising tags, but it does not clear that barrier or authorise new Google Data Manager matching for the address. A separate, verified Google Ads regrant request would be required. A signed-out one-off setup-service checkout has no account at that point, so any consented completion measurement uses only the choice captured for that checkout. For an existing Site Control enquiry or Business walkthrough request, use the separate one-time confirmation process in our Cookie Policy. Confirmation revokes the stored ad-user-data consent for every matching request linked to the verified email address and permanently removes the matching keys from unsent records. It cannot recall data already submitted to Google.
To keep a confirmed Google Ads withdrawal effective if a related enquiry, lead or account is later deleted, we retain a separate suppression record containing only one or more domain-separated, keyed HMAC-SHA-256 digests of the normalised email address. It does not contain the raw email address, advertising click identifiers, campaign parameters or the content of your enquiry. We keep the suppression record, and the cryptographic key history needed to recognise it, for as long as needed to prevent Google Ads matching from being silently restored. Allowing Advertising again does not remove it. A later Google Ads regrant would require a separate, verified request; contact [email protected] if you want us to review that choice.
This one-time process is specific to Google Ads matching. It does not by itself withdraw your request for us to contact you, erase first-party campaign or UTM attribution, or change Microsoft Advertising identifiers. Those uses remain subject to their own consent choices and your data-protection rights.
Browser Microsoft UET measurement and any server-side Microsoft Business-outcome upload are different purposes. Allowing Advertising permits UET in the browser; it does not authorise a server-side Microsoft offline conversion upload. That separate feature is disabled and would require its own specific choice and disclosure before use.
6. AI processing
When you upload a Pre-Construction Phase Plan (PCPP) or similar document, the text content is sent to our AI infrastructure provider to extract project information. The AI models run under a Data Processing Agreement. Uploaded text may include names and project details mentioned in the document. We minimise the amount of text sent and do not send documents containing sensitive personal health data to AI models.
AI processing logs are retained for 90 days then automatically deleted.
7. Third-party processors
We use the following service providers and sub-processors. The table describes their purpose and the safeguards that apply or are made available for the service:
| Processor | Purpose | Safeguards |
|---|---|---|
| DigitalOcean App Platform | Application hosting and compute | EU SCCs |
| DigitalOcean Managed PostgreSQL | PostgreSQL database hosting | EU SCCs |
| Clerk | User authentication and session management | EU SCCs |
| Stripe | Payment processing and subscription management | PCI DSS Level 1, EU SCCs |
| DigitalOcean Spaces | File storage for generated PDFs and uploaded photos | EU SCCs |
| Google Analytics | Website analytics and conversion measurement | Consent Mode v2, EU SCCs |
| Google Ads / Google Data Manager | Consented advertising conversion matching and campaign measurement | Consent Mode v2, EU SCCs |
| PostHog | Product analytics and session replay | US cloud hosting (Virginia); Data Privacy Framework, including the UK Extension; SCCs and UK Addendum |
| Expo | Mobile app updates and optional push-notification delivery | Data Processing Agreement and international-transfer safeguards |
| Microsoft Clarity | Website analytics, heatmaps, and session recordings | Consent API v2, EU SCCs |
| Microsoft Advertising | Consented browser UET campaign and conversion measurement | UET consent mode, EU SCCs |
| Meta Pixel | Advertising measurement and retargeting, where configured | Consent-gated; Meta's published privacy and international-transfer terms |
| Resend | Transactional email delivery | EU SCCs |
| Gotenberg | PDF generation from HTML templates | Self-hosted (London region) |
Our PostHog project uses PostHog's US cloud in Virginia. PostHog's published DPA says that data may be processed in the US and elsewhere outside the protected area. It identifies the EU-US Data Privacy Framework, including the UK Extension, together with Standard Contractual Clauses and the UK Addendum as international-transfer mechanisms.
8. Data retention
| Data type | Retention period |
|---|---|
| CDM documents (RAMS, CPP, Site Induction) | 6 years after project completion |
| Worker sign-off records (including IP addresses) | Duration of the project plus 6 years |
| RIDDOR incident logs | 6 years (minimum 3 years under RIDDOR 2013) |
| Permits to work | 6 years after permit expiry |
| Worker certifications | 6 years after worker leaves the project |
| AI processing logs | 90 days |
| Audit/security logs | 2 years |
| User account data | Duration of subscription + 30 days after cancellation |
| Non-paid Business sales enquiries and opportunities | 12 months after the last activity, or earlier when a valid erasure request is actioned |
| Paid Business opportunity contact and sales-workflow details | Removed or anonymised 12 months after the last activity. This includes the linked sales enquiry, contact and qualification details, appointment information, campaign and advertising attribution (including whether an ad click was present), and operator free text. |
| Minimum paid Business transaction record | Up to 7 years from the transaction. The retained record is limited to the payment date, amount, currency, product and status, with the minimum Stripe reference and, where still needed, an internal account reference for company, accounting and tax records. It does not extend the retention of campaign or advertising attribution, advertising identifiers, appointment details or operator free text. |
| Analytics data | 14 months (Google Analytics default) |
| Analytics and Advertising consent preferences | Browser choices expire after 180 days and must be renewed. Current account or lead evidence follows the same maximum age and is replaced or withdrawn when you change the choice. An old all-in-one acceptance is not migrated into a new grant. |
| First-party acquisition attribution | Raw capture events: 90 days. Attribution copied into an enquiry or Business opportunity is removed no later than 12 months after its last activity, including where a minimum paid transaction record remains. Attribution copied into an account follows that account's retention lifecycle, or is removed earlier when a valid erasure request is actioned. |
| Google Ads conversion matching records (click IDs and hashed email) | 90 days, or earlier when a valid withdrawal or erasure request is actioned |
| Google Ads address-withdrawal suppression record | For as long as needed to keep a confirmed withdrawal effective. Allowing Advertising again does not remove it; any later Google Ads regrant requires a separate, verified request. The record contains keyed email digests, not the raw email address. |
| Microsoft Advertising browser identifiers | 1 day to 13 months, depending on the UET identifier |
| Account-deletion anti-resurrection record | Up to 7 years after account deletion |
9. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data (subject to legal retention obligations — CDM and RIDDOR records may be exempt for the periods above)
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — decline Analytics, Advertising, or both through Cookie preferences. An Advertising decline stops new browser advertising and new browser-granted matching and, when signed in as billing owner, updates the account choice and suppresses unsent matching records; use the one-time process in our Cookie Policy for an existing Site Control lead or Business walkthrough request, turn off notification emails, or contact us for another consent request
To exercise any right, contact [email protected]. We will respond within 30 days.
If you are a worker whose name appears in a sign-off record, contact the site manager or principal contractor — they are the Data Controller for that record, not The Site Book.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
10. Deleting your account
You can delete your account at any time from Settings → Delete Account. The deletion process removes your user record, records owned solely through that user and any linked Site Control lead record. Where an account or a compliance record is shared with other users, account-scoped business and compliance records may remain available to those users or be retained for the legal periods in Section 8; your user link is removed or anonymised. Contact us if you need confirmation of the scope for a shared account. A minimum paid Business transaction record may remain for up to 7 years from the transaction, but its campaign or advertising attribution, appointment details, operator free text and other sales-workflow data are not retained for that longer period. This action cannot be undone. To prevent a delayed or replayed paid Stripe event from recreating the erased user, we retain one separate privacy-minimised tombstone containing the opaque user ID and a domain-separated, keyed HMAC-SHA-256 digest of the normalised email address. It stores no raw email and expires after a maximum of 7 years. It is used only for account anti-resurrection and billing, fraud or legal audit.
11. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access is controlled by Clerk authentication with session tokens. We conduct periodic security reviews and maintain access logs. If we become aware of a data breach that poses risk to individuals, we will notify the ICO within 72 hours and affected users without undue delay. For full details, see our Security & Data Protection page.
12. International transfers
Some of our sub-processors are based outside the UK and EU. Where data is transferred internationally, we rely on EU Standard Contractual Clauses (SCCs) or equivalent safeguards as set out in the table above. We do not transfer data to countries without adequate protection unless appropriate safeguards are in place.
13. Changes to this policy
We may update this policy. We will notify users of material changes by email or in-app notice. Continued use after notification constitutes acceptance.
14. Contact
Data Protection enquiries: [email protected]
General support: [email protected]
REDCLAN VENTURES LTD (Company No. 17142372) • Registered in England and Wales • Trading as The Site Book