← Thrivematic

Privacy Policy

Last updated 18 September 2026

This policy explains what Thrivematic (“Thrivematic”, “we”, “us”) does with personal information. It covers two different groups of people, and the difference matters:

1.Information we collect from business owners

What you give us

  • Business details entered in the sign-up wizard or corrected from a scan: business name, trading address and any additional locations, phone number, business email, opening hours, services, service areas, contractor or trade licence number, logo, and social media links.
  • Account credentials for your site dashboard: an email address and a password. The password is stored only as a salted hash and we cannot read it.
  • Payment information, handled entirely by Stripe. We never see or store your card number. We keep the Stripe customer and subscription identifiers, the plan, and its status.
  • Anything you add later through the dashboard: page content, uploaded images, custom code, redirects, and form definitions.

What we collect automatically

  • Your existing website, if you give us its address. We fetch its public pages the way a search engine would and read what is published there: business name, contact details, services, opening hours, licence number, social links, photographs, and the analytics tags it loads. We do not log in, submit forms, or reach anything behind a password.
  • Technical data. IP address and request metadata, used to apply rate limits, block abuse, and keep server logs. Our hosting provider retains request logs on our behalf.
  • Your public Google Business Profile, when you choose to connect one: the profile name and address we matched, the star rating, review count, and review text with reviewer display names. All of it is already public on Google.

Cookies

We use only cookies that are strictly necessary. There is no advertising, profiling, or third-party analytics cookie on the Thrivematic platform, so there is no consent banner.

  • A sign-in cookie that keeps you logged in to your dashboard.
  • A security token used to verify that form submissions come from our own pages.
  • During the pre-launch period, a cookie recording that you entered the access password.

Websites we generate for customers may load analytics tags that the business owner supplies, such as Google Analytics. Those are the business’s own tools and are covered by the business’s privacy policy, not this one.

2.Why we use it, and our legal basis

PurposeLegal basis (UK/EU GDPR)
Building, publishing and hosting your websitePerformance of our contract with you
Reading your existing site so you do not retype itPerformance of a pre-contract request you made
Running your dashboard and your loginPerformance of our contract with you
Taking payment and handling failed paymentsPerformance of our contract, and legal obligation for records
Service emails: password resets, receipts, renewal problemsPerformance of our contract with you
Rate limiting, abuse prevention, security loggingOur legitimate interest in keeping the service available and safe
Keeping an audit record of administrative actionsOur legitimate interest in accountability, and legal obligation

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train artificial intelligence models. See the next section for what our AI sub-processor is and is not permitted to do.

3.How your website content is generated

Thrivematic writes your site using Anthropic’s Claude API. The text we send is the business information you provided or confirmed, plus the public text of the website you asked us to read. Your dashboard password, your payment details and your site visitors’ form submissions are never sent.

Photographs come from a stock library. We search it with generic descriptions of the trade, for example “roofer installing shingles”. No information about you or your business is sent to the photo provider.

Anthropic processes this data on our instructions to return your content, and under our agreement it is not used to train their models. Automated generation has no legal or similarly significant effect on you, and you can edit or replace every word and image afterwards.

4.Who we share it with

We share personal information only with the service providers below, each acting on our instructions under a contract. We do not sell or rent it to anyone.

ProviderWhat it doesWhat it receives
VercelHosting and content deliveryAll traffic, request logs, IP addresses
NeonOur databaseEverything stored about your account and site
Amazon Web ServicesImage storage and backupsUploaded and generated images, site backups
AnthropicWrites your site contentYour business details and your public site text
FreepikStock photographyGeneric trade search terms only
StripePayments and invoicesYour name, email, and payment details you enter with them
ResendSends our service emailsRecipient email address and message content
Google (Places API)Finds your Google Business ProfileYour business name and address, or a profile you select
SerpApiRetrieves your public Google reviewsYour Google place identifier
DataForSEOSearch-visibility snapshotThe website address you submitted
UpstashRate limitingA derived key based on IP address
US Census BureauTurns your address into map coordinatesYour business address

We will also disclose information if the law requires it, to enforce our terms, to protect someone from harm, or to a buyer if the business is sold, in which case we will tell you first.

5.Where it is stored

Our infrastructure and our providers are based in the United States, so your information is stored and processed there. If you are in the United Kingdom or the European Economic Area, transfers rely on the UK Addendum and the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies.

6.How long we keep it

  • While your subscription is active, we keep your account and site for as long as you use the service.
  • If payment stops, your site goes offline after roughly 30 days, is archived, and is permanently deleted about 30 days after that. We email you before each step.
  • When you close your account or we delete a site, we remove the pages, images, logins, forms and form submissions, page history, redirects and custom code. Images are deleted from storage at the same time.
  • Backups and site archives in our storage are kept as a safety net after deletion and are removed on our storage retention schedule. Ask us if you need them destroyed sooner.
  • An administrative audit record of actions such as creation, suspension and deletion is kept after the account is gone. It holds the domain, the action, the date and who performed it, because we need to be able to show what happened.
  • Invoices and payment records are kept by us and by Stripe for the period tax law requires.
  • Temporary caches of a scan or a generated draft expire within one hour.

7.Your rights

Depending on where you live you can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or send it to another provider. You can also withdraw consent where we relied on it, and complain to your data protection regulator. In the United Kingdom that is the Information Commissioner’s Office.

If you are a California resident, you may request access to, deletion of, and details about the personal information we collect, and you will not be treated differently for asking. We do not sell or share personal information as those terms are defined by California law.

Two of these are built into the product: your dashboard lets you edit your business details at any time, and we can export your entire site as a downloadable archive before deleting it. For anything else, email privacy@thrivematic.ai. We answer within 30 days and may need to verify who you are first.

8.If you contacted a business through a site we host

When you submit a contact form on a website built with Thrivematic, your message goes to that business. They decide why they collect it and how long they keep it, so they are responsible for it under data protection law. We only store it and pass it on.

Please direct requests to see or delete your enquiry to the business itself, using the contact details on their site. If you cannot reach them, write to privacy@thrivematic.ai and we will pass the request on and help where we can.

9.Security

Traffic is encrypted in transit. Passwords are stored as salted hashes. Credentials you give us for your own email provider are encrypted before they are stored. Access to production systems is limited to people who need it, administrative actions are logged, and dashboards are protected against cross-site request forgery. No system is perfectly secure, but if a breach affects you we will notify you and the relevant regulator as the law requires.

10.Children

Thrivematic is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, contact privacy@thrivematic.ai and we will delete it.

11.Changes to this policy

If we change this policy we will update the date at the top. For changes that materially affect how we use your information, we will email account holders before the change takes effect.

12.Contact us

Write to privacy@thrivematic.ai.


Thrivematic · Privacy Policy · Terms of Service