Skip to main content
Start your first project

Privacy policy

Privacy Policy

Last updated: 8 August 2026

Terms & Conditions →

The Site Book (“we”, “us”, “our”) is a construction compliance software service operated by REDCLAN VENTURES LTD (Company No. 17142372), registered in England and Wales, trading as The Site Book. This policy explains how we collect, use, and protect personal data when you use The Site Book.

If you use our iOS or Android app, the Mobile App Privacy Addendum explains mobile permissions, optional push notifications, app analytics, diagnostics and on-device storage.

We are subject to the UK GDPR (as retained in UK law under the Data Protection Act 2018) and, where applicable, the EU GDPR.

1. Who is the Data Controller?

For your account and billing data, REDCLAN VENTURES LTD is the Data Controller. For project records — including worker sign-offs, incident logs, and CDM documents — you (the principal contractor or CDM duty holder) are the Data Controller. We act as your Data Processor for those records.

2. What personal data we collect

Account data

  • Email address, company name, and contact phone number — required to create and operate your account
  • Company logo — optional, used on generated documents
  • Billing information — processed by Stripe (we do not store card numbers)

Sales enquiries and Business walkthrough requests

  • Name, work email address, company, role, number of active jobs, team size, and the main thing you want to sort
  • Optional: phone number, when you need it, and a message with more context
  • IP address, used to rate-limit the public form and prevent abuse
  • Where you consent, limited acquisition and advertising attribution described in Section 5

Worker and project data

  • Names, roles, email addresses, and phone numbers of workers you add to the system
  • Worker certifications and expiry dates (e.g. CSCS cards)
  • Digital sign-off records: worker name, date and time, IP address, device type
  • Incident and near-miss logs, including descriptions of injuries and people involved
  • Permits to work: names of persons issuing and receiving each permit
  • Site diary entries, including visitor names and optional photographs
  • Subcontractor company names and contact details

Technical and analytics data

  • Authentication tokens managed by Clerk
  • AI processing logs (inputs and outputs) retained for 90 days
  • Audit logs for security and dispute resolution, retained for 2 years
  • Analytics data collected via Google Analytics (GA4), PostHog, and Microsoft Clarity — see Section 5
  • Purpose-specific Analytics and Advertising choices, their disclosure version and change times, retained to remember and enforce what you chose — see Section 5
  • Where you allow Advertising, first-party acquisition attribution, such as campaign and referral parameters, landing page, referrer, a pseudonymous visitor identifier and, where present in the arrival URL, a Google or Microsoft advertising click identifier — see Section 5
  • Where you consent, a separate Google Ads conversion-matching record containing a click identifier and SHA-256 email hash — see Section 5
  • After a confirmed Google Ads matching withdrawal, a separate suppression record containing only domain-separated, keyed email digests — see Sections 5 and 8
  • After account deletion, a privacy-minimised anti-resurrection record containing the opaque account user ID and a domain-separated, keyed HMAC-SHA-256 email digest. It contains no raw email address.

3. Legal basis for processing

DataLegal Basis
Account dataContract performance (Art. 6(1)(b))
Sales enquiries and Business walkthrough requestsConsent (Art. 6(1)(a)) — to respond to your request, contact you and arrange the walkthrough
Public enquiry IP addressLegitimate interest (Art. 6(1)(f)) — abuse prevention and service security
Worker names, roles, and CDM recordsLegal obligation — CDM 2015 (Art. 6(1)(c))
Worker sign-off records, certificationsLegal obligation — CDM 2015, RIDDOR 2013 (Art. 6(1)(c))
Incident and injury descriptionsLegal obligation + employment law (Art. 6(1)(c), Art. 9(2)(b))
IP addresses in sign-offsLegitimate interest — document authenticity (Art. 6(1)(f))
Optional AnalyticsConsent (Art. 6(1)(a)) — a separate, renewable choice managed through Cookie preferences
Advertising tags and first-party acquisition attributionConsent (Art. 6(1)(a)) — a separate, renewable Advertising choice; not inferred from Analytics consent
Analytics and Advertising consent-choice evidenceLegal obligation and legitimate interests (Art. 6(1)(c) and (f)) — recording and enforcing what was chosen, when, and under which disclosure version
Google Ads / Google Data Manager conversion matching (click IDs and hashed email)Consent (Art. 6(1)(a)) — matching or upload is enabled only when ad-user-data consent is granted
Microsoft Advertising UET conversion measurementConsent (Art. 6(1)(a)) — browser UET measurement is enabled only after the separate Advertising choice is allowed
Google Ads address-withdrawal suppression recordLegitimate interests (Art. 6(1)(f)) — keeping a confirmed withdrawal effective across lead or account deletion without retaining the raw email address
Billing dataContract performance (Art. 6(1)(b))
Minimum paid transaction and accounting recordLegal obligation (Art. 6(1)(c)) — company, accounting and tax record-keeping
Audit and security logsLegitimate interest — fraud prevention (Art. 6(1)(f))
Account-deletion anti-resurrection recordLegitimate interests (Art. 6(1)(f)) — preventing delayed or replayed billing events from recreating an erased account, and supporting billing, fraud and legal audit

4. How we use your data

  • To generate and store CDM-compliant construction documents (RAMS, CPP, Site Inductions, Emergency Plans)
  • To provide worker sign-off links and record digital attendance at safety briefings
  • To track certification expiry and send alerts if you enable notifications
  • To produce audit-ready compliance packs for HSE inspectors or principal contractors
  • To maintain audit trails of document generation and access
  • To process payments and manage subscriptions
  • To respond to sales enquiries and arrange a requested Business walkthrough
  • To measure and improve the service using analytics

We do not sell personal data. Where you consent, we use limited first-party acquisition attribution to understand which of our own campaigns and referrals produce enquiries and customers. That first-party processing does not itself authorise an upload to Google. Where you consent, we also use limited advertising conversion data for Google Ads matching and campaign measurement. We do not use your construction documents, worker records, incident data, or project safety information for advertising or build advertising profiles from that content.

5. Cookies and analytics

We use cookies and similar technologies to operate the service and understand how it is used. When you first visit the site, we show a cookie consent banner. You can allow or decline Analytics, Advertising and Personalised advertising separately, accept all, or reject all. Personalised advertising is a distinct choice from Advertising: it controls whether Google can build a remarketing audience from your visit, not campaign measurement. Each choice is current for up to 180 days and can be changed at any time. For a full list of cookies we use, see our Cookie Policy.

Essential cookies

Required for the site to function — authentication sessions and security tokens. We also use first-party preference cookies only to remember and enforce the Analytics, Advertising and Personalised advertising choices you make.

Analytics cookies

We use Google Analytics (GA4), PostHog, and Microsoft Clarity to understand how people use the site — which pages are visited, where users drop off, how features are used, and where the interface needs improvement. Microsoft Clarity provides heatmaps and session recordings on the live site only after you allow Analytics. If you decline Analytics, we do not configure or send events to Google Analytics, Google Analytics cookies are not set, Microsoft Clarity is not loaded, and PostHog analytics are disabled. If you separately allow Advertising, the shared Google tag may still load for Google Ads while analytics_storage remains denied.

First-party acquisition attribution

After you allow Advertising, an arrival URL containing campaign, referral or advertising click parameters may be stored with the first and latest source, landing page, referrer and a pseudonymous visitor identifier in first-party local storage and in our service. This carries the source through a lead, signup or checkout journey, measures our own marketing and helps prevent duplicate referral credit. If you have not allowed Advertising, we do not write that acquisition data to browser storage or our attribution capture service, and our lead and checkout endpoints ignore client-supplied attribution. This is separate from Google Data Manager matching, which also requires ad-user-data consent.

Advertising cookies

If you arrive via a Google Ads campaign, the Google Ads tag (AW-18049615348) can measure whether the visit leads to a signup or paid subscription. If you arrive via Microsoft Advertising, Microsoft UET can measure a Business walkthrough request, signup, checkout and paid-subscription events. Where configured, Meta Pixel can measure page views for advertising and retargeting. These providers are controlled only by the separate Advertising choice, not by Analytics consent. Their libraries are not loaded until Advertising is allowed.

If you separately grant ad-user-data consent, we may create a privacy-minimised conversion-matching record containing the relevant Google click identifier and a SHA-256 hash of your normalised email address, together with the conversion stage, time, transaction identifier and value. This consented record may be sent to Google Ads through Google Data Manager to match an ad interaction with a valid lead, qualified lead, or paid customer and to improve campaign measurement. We do not place the raw email address in this record. For a submission where ad-user-data consent is not granted, the Google matching record contains neither a click identifier nor an email hash and cannot be uploaded.

Declining Analytics stops optional browser and consented server-side product analytics. Declining Advertising prevents your browser from granting advertising consent on later submissions and removes advertising identifiers from that browser. For a signed-in billing owner, we also keep each current purpose-specific choice, its disclosure version and change time on the product account. Declining Advertising makes unsent matching records linked to that user permanently unmatchable and creates a server-side Google Ads suppression barrier for the verified address. Allowing Advertising later can re-enable browser advertising tags, but it does not clear that barrier or authorise new Google Data Manager matching for the address. A separate, verified Google Ads regrant request would be required. A signed-out one-off setup-service checkout has no account at that point, so any consented completion measurement uses only the choice captured for that checkout. For an existing Site Control enquiry or Business walkthrough request, use the separate one-time confirmation process in our Cookie Policy. Confirmation revokes the stored ad-user-data consent for every matching request linked to the verified email address and permanently removes the matching keys from unsent records. It cannot recall data already submitted to Google.

To keep a confirmed Google Ads withdrawal effective if a related enquiry, lead or account is later deleted, we retain a separate suppression record containing only one or more domain-separated, keyed HMAC-SHA-256 digests of the normalised email address. It does not contain the raw email address, advertising click identifiers, campaign parameters or the content of your enquiry. We keep the suppression record, and the cryptographic key history needed to recognise it, for as long as needed to prevent Google Ads matching from being silently restored. Allowing Advertising again does not remove it. A later Google Ads regrant would require a separate, verified request; contact [email protected] if you want us to review that choice.

This one-time process is specific to Google Ads matching. It does not by itself withdraw your request for us to contact you, erase first-party campaign or UTM attribution, or change Microsoft Advertising identifiers. Those uses remain subject to their own consent choices and your data-protection rights.

Browser Microsoft UET measurement and any server-side Microsoft Business-outcome upload are different purposes. Allowing Advertising permits UET in the browser; it does not authorise a server-side Microsoft offline conversion upload. That separate feature is disabled and would require its own specific choice and disclosure before use.

6. AI processing

When you upload a Pre-Construction Phase Plan (PCPP) or similar document, the text content is sent to our AI infrastructure provider to extract project information. The AI models run under a Data Processing Agreement. Uploaded text may include names and project details mentioned in the document. We minimise the amount of text sent and do not send documents containing sensitive personal health data to AI models.

AI processing logs are retained for 90 days then automatically deleted.

7. Third-party processors

We use the following service providers and sub-processors. The table describes their purpose and the safeguards that apply or are made available for the service:

ProcessorPurposeSafeguards
DigitalOcean App PlatformApplication hosting and computeEU SCCs
DigitalOcean Managed PostgreSQLPostgreSQL database hostingEU SCCs
ClerkUser authentication and session managementEU SCCs
StripePayment processing and subscription managementPCI DSS Level 1, EU SCCs
DigitalOcean SpacesFile storage for generated PDFs and uploaded photosEU SCCs
Google AnalyticsWebsite analytics and conversion measurementConsent Mode v2, EU SCCs
Google Ads / Google Data ManagerConsented advertising conversion matching and campaign measurementConsent Mode v2, EU SCCs
PostHogProduct analytics and session replayUS cloud hosting (Virginia); Data Privacy Framework, including the UK Extension; SCCs and UK Addendum
ExpoMobile app updates and optional push-notification deliveryData Processing Agreement and international-transfer safeguards
Microsoft ClarityWebsite analytics, heatmaps, and session recordingsConsent API v2, EU SCCs
Microsoft AdvertisingConsented browser UET campaign and conversion measurementUET consent mode, EU SCCs
Meta PixelAdvertising measurement and retargeting, where configuredConsent-gated; Meta's published privacy and international-transfer terms
ResendTransactional email deliveryEU SCCs
GotenbergPDF generation from HTML templatesSelf-hosted (London region)

Our PostHog project uses PostHog's US cloud in Virginia. PostHog's published DPA says that data may be processed in the US and elsewhere outside the protected area. It identifies the EU-US Data Privacy Framework, including the UK Extension, together with Standard Contractual Clauses and the UK Addendum as international-transfer mechanisms.

8. Data retention

Data typeRetention period
CDM documents (RAMS, CPP, Site Induction)6 years after project completion
Worker sign-off records (including IP addresses)Duration of the project plus 6 years
RIDDOR incident logs6 years (minimum 3 years under RIDDOR 2013)
Permits to work6 years after permit expiry
Worker certifications6 years after worker leaves the project
AI processing logs90 days
Audit/security logs2 years
User account dataDuration of subscription + 30 days after cancellation
Non-paid Business sales enquiries and opportunities12 months after the last activity, or earlier when a valid erasure request is actioned
Paid Business opportunity contact and sales-workflow detailsRemoved or anonymised 12 months after the last activity. This includes the linked sales enquiry, contact and qualification details, appointment information, campaign and advertising attribution (including whether an ad click was present), and operator free text.
Minimum paid Business transaction recordUp to 7 years from the transaction. The retained record is limited to the payment date, amount, currency, product and status, with the minimum Stripe reference and, where still needed, an internal account reference for company, accounting and tax records. It does not extend the retention of campaign or advertising attribution, advertising identifiers, appointment details or operator free text.
Analytics data14 months (Google Analytics default)
Analytics and Advertising consent preferencesBrowser choices expire after 180 days and must be renewed. Current account or lead evidence follows the same maximum age and is replaced or withdrawn when you change the choice. An old all-in-one acceptance is not migrated into a new grant.
First-party acquisition attributionRaw capture events: 90 days. Attribution copied into an enquiry or Business opportunity is removed no later than 12 months after its last activity, including where a minimum paid transaction record remains. Attribution copied into an account follows that account's retention lifecycle, or is removed earlier when a valid erasure request is actioned.
Google Ads conversion matching records (click IDs and hashed email)90 days, or earlier when a valid withdrawal or erasure request is actioned
Google Ads address-withdrawal suppression recordFor as long as needed to keep a confirmed withdrawal effective. Allowing Advertising again does not remove it; any later Google Ads regrant requires a separate, verified request. The record contains keyed email digests, not the raw email address.
Microsoft Advertising browser identifiers1 day to 13 months, depending on the UET identifier
Account-deletion anti-resurrection recordUp to 7 years after account deletion

9. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data (subject to legal retention obligations — CDM and RIDDOR records may be exempt for the periods above)
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — decline Analytics, Advertising, or both through Cookie preferences. An Advertising decline stops new browser advertising and new browser-granted matching and, when signed in as billing owner, updates the account choice and suppresses unsent matching records; use the one-time process in our Cookie Policy for an existing Site Control lead or Business walkthrough request, turn off notification emails, or contact us for another consent request

To exercise any right, contact [email protected]. We will respond within 30 days.

If you are a worker whose name appears in a sign-off record, contact the site manager or principal contractor — they are the Data Controller for that record, not The Site Book.

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

10. Deleting your account

You can delete your account at any time from Settings → Delete Account. The deletion process removes your user record, records owned solely through that user and any linked Site Control lead record. Where an account or a compliance record is shared with other users, account-scoped business and compliance records may remain available to those users or be retained for the legal periods in Section 8; your user link is removed or anonymised. Contact us if you need confirmation of the scope for a shared account. A minimum paid Business transaction record may remain for up to 7 years from the transaction, but its campaign or advertising attribution, appointment details, operator free text and other sales-workflow data are not retained for that longer period. This action cannot be undone. To prevent a delayed or replayed paid Stripe event from recreating the erased user, we retain one separate privacy-minimised tombstone containing the opaque user ID and a domain-separated, keyed HMAC-SHA-256 digest of the normalised email address. It stores no raw email and expires after a maximum of 7 years. It is used only for account anti-resurrection and billing, fraud or legal audit.

11. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Access is controlled by Clerk authentication with session tokens. We conduct periodic security reviews and maintain access logs. If we become aware of a data breach that poses risk to individuals, we will notify the ICO within 72 hours and affected users without undue delay. For full details, see our Security & Data Protection page.

12. International transfers

Some of our sub-processors are based outside the UK and EU. Where data is transferred internationally, we rely on EU Standard Contractual Clauses (SCCs) or equivalent safeguards as set out in the table above. We do not transfer data to countries without adequate protection unless appropriate safeguards are in place.

13. Changes to this policy

We may update this policy. We will notify users of material changes by email or in-app notice. Continued use after notification constitutes acceptance.

14. Contact

Data Protection enquiries: [email protected]
General support: [email protected]

REDCLAN VENTURES LTD (Company No. 17142372) • Registered in England and Wales • Trading as The Site Book