Privacy policy
Privacy Policy
Last updated: 13 July 2026
The Site Book (“we”, “us”, “our”) is a construction compliance software service operated by REDCLAN VENTURES LTD (Company No. 17142372), registered in England and Wales, trading as The Site Book. This policy explains how we collect, use, and protect personal data when you use The Site Book.
We are subject to the UK GDPR (as retained in UK law under the Data Protection Act 2018) and, where applicable, the EU GDPR.
1. Who is the Data Controller?
For your account and billing data, REDCLAN VENTURES LTD is the Data Controller. For project records — including worker sign-offs, incident logs, and CDM documents — you (the principal contractor or CDM duty holder) are the Data Controller. We act as your Data Processor for those records.
2. What personal data we collect
Account data
- Email address, company name, and contact phone number — required to create and operate your account
- Company logo — optional, used on generated documents
- Billing information — processed by Stripe (we do not store card numbers)
Worker and project data
- Names, roles, email addresses, and phone numbers of workers you add to the system
- Worker certifications and expiry dates (e.g. CSCS cards)
- Digital sign-off records: worker name, date and time, IP address, device type
- Incident and near-miss logs, including descriptions of injuries and people involved
- Permits to work: names of persons issuing and receiving each permit
- Site diary entries, including visitor names and optional photographs
- Subcontractor company names and contact details
Technical and analytics data
- Authentication tokens managed by Clerk
- AI processing logs (inputs and outputs) retained for 90 days
- Audit logs for security and dispute resolution, retained for 2 years
- Analytics data collected via Google Analytics (GA4), PostHog, and Microsoft Clarity — see Section 5
- Where you consent, first-party acquisition attribution, such as campaign and referral parameters, landing page, referrer, a pseudonymous visitor identifier and, where present in the arrival URL, a Google click identifier — see Section 5
- Where you consent, a separate Google Ads conversion-matching record containing a click identifier and SHA-256 email hash — see Section 5
- After account deletion, a privacy-minimised anti-resurrection record containing the opaque account user ID and a domain-separated, keyed HMAC-SHA-256 email digest. It contains no raw email address.
3. Legal basis for processing
| Data | Legal Basis |
|---|---|
| Account data | Contract performance (Art. 6(1)(b)) |
| Worker names, roles, and CDM records | Legal obligation — CDM 2015 (Art. 6(1)(c)) |
| Worker sign-off records, certifications | Legal obligation — CDM 2015, RIDDOR 2013 (Art. 6(1)(c)) |
| Incident and injury descriptions | Legal obligation + employment law (Art. 6(1)(c), Art. 9(2)(b)) |
| IP addresses in sign-offs | Legitimate interest — document authenticity (Art. 6(1)(f)) |
| Analytics and cookies | Consent (Art. 6(1)(a)) — managed via cookie banner |
| First-party acquisition attribution | Consent (Art. 6(1)(a)) — stored only after optional cookies are accepted |
| Google Ads / Google Data Manager conversion matching (click IDs and hashed email) | Consent (Art. 6(1)(a)) — matching or upload is enabled only when ad-user-data consent is granted |
| Billing data | Contract performance (Art. 6(1)(b)) |
| Audit and security logs | Legitimate interest — fraud prevention (Art. 6(1)(f)) |
| Account-deletion anti-resurrection record | Legitimate interests (Art. 6(1)(f)) — preventing delayed or replayed billing events from recreating an erased account, and supporting billing, fraud and legal audit |
4. How we use your data
- To generate and store CDM-compliant construction documents (RAMS, CPP, Site Inductions, Emergency Plans)
- To provide worker sign-off links and record digital attendance at safety briefings
- To track certification expiry and send alerts if you enable notifications
- To produce audit-ready compliance packs for HSE inspectors or principal contractors
- To maintain audit trails of document generation and access
- To process payments and manage subscriptions
- To measure and improve the service using analytics
We do not sell personal data. Where you consent, we use limited first-party acquisition attribution to understand which of our own campaigns and referrals produce enquiries and customers. That first-party processing does not itself authorise an upload to Google. Where you consent, we also use limited advertising conversion data for Google Ads matching and campaign measurement. We do not use your construction documents, worker records, incident data, or project safety information for advertising or build advertising profiles from that content.
5. Cookies and analytics
We use cookies and similar technologies to operate the service and understand how it is used. When you first visit the site, we show a cookie consent banner. You can accept or decline non-essential cookies at any time. For a full list of cookies we use, see our Cookie Policy.
Essential cookies
Required for the site to function — authentication session, security tokens, and consent preferences. These cannot be disabled.
Analytics cookies
We use Google Analytics (GA4), PostHog, and Microsoft Clarity to understand how people use the site — which pages are visited, where users drop off, how features are used, and where the interface needs improvement. Microsoft Clarity provides heatmaps and session recordings on the live site. If you decline cookies, Google Analytics and Microsoft Clarity operate in cookieless consent modes with no analytics cookies or persistent Clarity session identifiers. PostHog analytics are disabled.
First-party acquisition attribution
After you accept optional cookies, an arrival URL containing campaign, referral or Google click parameters may be stored with the first and latest source, landing page, referrer and a pseudonymous visitor identifier in first-party local storage and in our service. This carries the source through a lead, signup or checkout journey, measures our own marketing and helps prevent duplicate referral credit. If you have not accepted optional cookies, we do not write that acquisition data to browser storage or our attribution capture service, and our lead and checkout endpoints ignore client-supplied attribution. This is separate from Google Data Manager matching, which also requires ad-user-data consent.
Advertising cookies
If you arrive via a Google Ads campaign, the Google Ads tag (AW-18049615348) can measure whether the visit leads to a signup or paid subscription, subject to your cookie consent choice.
If you separately grant ad-user-data consent, we may create a privacy-minimised conversion-matching record containing the relevant Google click identifier and a SHA-256 hash of your normalised email address, together with the conversion stage, time, transaction identifier and value. This consented record may be sent to Google Ads through Google Data Manager to match an ad interaction with a valid lead, qualified lead, or paid customer and to improve campaign measurement. We do not place the raw email address in this record. For a submission where ad-user-data consent is not granted, the Google matching record contains neither a click identifier nor an email hash and cannot be uploaded.
Changing your cookie preference to declined prevents your browser from granting consent on later submissions. It does not automatically change consent stored against an existing lead, erase a matching record already created or recall data already sent to Google. To withdraw consent for existing Google Ads matching data, contact [email protected]; we will delete identifiable queued or retained matching records.
6. AI processing
When you upload a Pre-Construction Phase Plan (PCPP) or similar document, the text content is sent to our AI infrastructure provider to extract project information. The AI models run under a Data Processing Agreement. Uploaded text may include names and project details mentioned in the document. We minimise the amount of text sent and do not send documents containing sensitive personal health data to AI models.
AI processing logs are retained for 90 days then automatically deleted.
7. Third-party processors
We share data with the following sub-processors, all under Data Processing Agreements:
| Processor | Purpose | Safeguards |
|---|---|---|
| DigitalOcean App Platform | Application hosting and compute | EU SCCs |
| DigitalOcean Managed PostgreSQL | PostgreSQL database hosting | EU SCCs |
| Clerk | User authentication and session management | EU SCCs |
| Stripe | Payment processing and subscription management | PCI DSS Level 1, EU SCCs |
| DigitalOcean Spaces | File storage for generated PDFs and uploaded photos | EU SCCs |
| Google Analytics | Website analytics and conversion measurement | Consent Mode v2, EU SCCs |
| Google Ads / Google Data Manager | Consented advertising conversion matching and campaign measurement | Consent Mode v2, EU SCCs |
| PostHog | Product analytics and session replay | EU hosting (Frankfurt) |
| Microsoft Clarity | Website analytics, heatmaps, and session recordings | Consent API v2, EU SCCs |
| Resend | Transactional email delivery | EU SCCs |
| Gotenberg | PDF generation from HTML templates | Self-hosted (London region) |
All processors are contractually required to process data only on our instructions and to maintain appropriate security measures.
8. Data retention
| Data type | Retention period |
|---|---|
| CDM documents (RAMS, CPP, Site Induction) | 6 years after project completion |
| Worker sign-off records (including IP addresses) | Duration of the project plus 6 years |
| RIDDOR incident logs | 6 years (minimum 3 years under RIDDOR 2013) |
| Permits to work | 6 years after permit expiry |
| Worker certifications | 6 years after worker leaves the project |
| AI processing logs | 90 days |
| Audit/security logs | 2 years |
| User account data | Duration of subscription + 30 days after cancellation |
| Analytics data | 14 months (Google Analytics default) |
| First-party acquisition attribution | Raw capture events: 90 days. Attribution copied into an enquiry or account record follows the retention lifecycle of that record, or is removed earlier when a valid erasure request is actioned. |
| Google Ads conversion matching records (click IDs and hashed email) | 90 days, or earlier when a valid withdrawal or erasure request is actioned |
| Account-deletion anti-resurrection record | Up to 7 years after account deletion |
9. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data (subject to legal retention obligations — CDM and RIDDOR records may be exempt for the periods above)
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — decline cookies to stop future browser analytics and new browser-granted advertising matching, turn off notification emails, or contact us to withdraw consent stored with an existing lead or Google Ads matching record
To exercise any right, contact [email protected]. We will respond within 30 days.
If you are a worker whose name appears in a sign-off record, contact the site manager or principal contractor — they are the Data Controller for that record, not The Site Book.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
10. Deleting your account
You can delete your account at any time from Settings → Delete Account. The deletion process removes your user record, records owned solely through that user and any linked Site Control lead record. Where an account or a compliance record is shared with other users, account-scoped business and compliance records may remain available to those users or be retained for the legal periods in Section 8; your user link is removed or anonymised. Contact us if you need confirmation of the scope for a shared account. This action cannot be undone. To prevent a delayed or replayed paid Stripe event from recreating the erased user, we retain one separate privacy-minimised tombstone containing the opaque user ID and a domain-separated, keyed HMAC-SHA-256 digest of the normalised email address. It stores no raw email and expires after a maximum of 7 years. It is used only for account anti-resurrection and billing, fraud or legal audit.
11. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access is controlled by Clerk authentication with session tokens. We conduct periodic security reviews and maintain access logs. If we become aware of a data breach that poses risk to individuals, we will notify the ICO within 72 hours and affected users without undue delay. For full details, see our Security & Data Protection page.
12. International transfers
Some of our sub-processors are based outside the UK and EU. Where data is transferred internationally, we rely on EU Standard Contractual Clauses (SCCs) or equivalent safeguards as set out in the table above. We do not transfer data to countries without adequate protection unless appropriate safeguards are in place.
13. Changes to this policy
We may update this policy. We will notify users of material changes by email or in-app notice. Continued use after notification constitutes acceptance.
14. Contact
Data Protection enquiries: [email protected]
General support: [email protected]
REDCLAN VENTURES LTD (Company No. 17142372) • Registered in England and Wales • Trading as The Site Book