Privacy Policy
Last updated 18 September 2026
This policy explains what Thrivematic (“Thrivematic”, “we”, “us”) does with personal information. It covers two different groups of people, and the difference matters:
- Business owners who use Thrivematic. You sign up, we build and host your website. For your information we are the controller: we decide how it is used, and this policy applies in full.
- Visitors to a website we host for a business. When you fill in a contact form on one of those sites, that business decides what happens with your enquiry. We are its processor: we store and deliver the message on their behalf. Ask that business for their own privacy policy, and see Section 8.
1.Information we collect from business owners
What you give us
- Business details entered in the sign-up wizard or corrected from a scan: business name, trading address and any additional locations, phone number, business email, opening hours, services, service areas, contractor or trade licence number, logo, and social media links.
- Account credentials for your site dashboard: an email address and a password. The password is stored only as a salted hash and we cannot read it.
- Payment information, handled entirely by Stripe. We never see or store your card number. We keep the Stripe customer and subscription identifiers, the plan, and its status.
- Anything you add later through the dashboard: page content, uploaded images, custom code, redirects, and form definitions.
What we collect automatically
- Your existing website, if you give us its address. We fetch its public pages the way a search engine would and read what is published there: business name, contact details, services, opening hours, licence number, social links, photographs, and the analytics tags it loads. We do not log in, submit forms, or reach anything behind a password.
- Technical data. IP address and request metadata, used to apply rate limits, block abuse, and keep server logs. Our hosting provider retains request logs on our behalf.
- Your public Google Business Profile, when you choose to connect one: the profile name and address we matched, the star rating, review count, and review text with reviewer display names. All of it is already public on Google.
Cookies
We use only cookies that are strictly necessary. There is no advertising, profiling, or third-party analytics cookie on the Thrivematic platform, so there is no consent banner.
- A sign-in cookie that keeps you logged in to your dashboard.
- A security token used to verify that form submissions come from our own pages.
- During the pre-launch period, a cookie recording that you entered the access password.
Websites we generate for customers may load analytics tags that the business owner supplies, such as Google Analytics. Those are the business’s own tools and are covered by the business’s privacy policy, not this one.
2.Why we use it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Building, publishing and hosting your website | Performance of our contract with you |
| Reading your existing site so you do not retype it | Performance of a pre-contract request you made |
| Running your dashboard and your login | Performance of our contract with you |
| Taking payment and handling failed payments | Performance of our contract, and legal obligation for records |
| Service emails: password resets, receipts, renewal problems | Performance of our contract with you |
| Rate limiting, abuse prevention, security logging | Our legitimate interest in keeping the service available and safe |
| Keeping an audit record of administrative actions | Our legitimate interest in accountability, and legal obligation |
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train artificial intelligence models. See the next section for what our AI sub-processor is and is not permitted to do.
3.How your website content is generated
Thrivematic writes your site using Anthropic’s Claude API. The text we send is the business information you provided or confirmed, plus the public text of the website you asked us to read. Your dashboard password, your payment details and your site visitors’ form submissions are never sent.
Photographs come from a stock library. We search it with generic descriptions of the trade, for example “roofer installing shingles”. No information about you or your business is sent to the photo provider.
Anthropic processes this data on our instructions to return your content, and under our agreement it is not used to train their models. Automated generation has no legal or similarly significant effect on you, and you can edit or replace every word and image afterwards.
4.Who we share it with
We share personal information only with the service providers below, each acting on our instructions under a contract. We do not sell or rent it to anyone.
| Provider | What it does | What it receives |
|---|---|---|
| Vercel | Hosting and content delivery | All traffic, request logs, IP addresses |
| Neon | Our database | Everything stored about your account and site |
| Amazon Web Services | Image storage and backups | Uploaded and generated images, site backups |
| Anthropic | Writes your site content | Your business details and your public site text |
| Freepik | Stock photography | Generic trade search terms only |
| Stripe | Payments and invoices | Your name, email, and payment details you enter with them |
| Resend | Sends our service emails | Recipient email address and message content |
| Google (Places API) | Finds your Google Business Profile | Your business name and address, or a profile you select |
| SerpApi | Retrieves your public Google reviews | Your Google place identifier |
| DataForSEO | Search-visibility snapshot | The website address you submitted |
| Upstash | Rate limiting | A derived key based on IP address |
| US Census Bureau | Turns your address into map coordinates | Your business address |
We will also disclose information if the law requires it, to enforce our terms, to protect someone from harm, or to a buyer if the business is sold, in which case we will tell you first.
5.Where it is stored
Our infrastructure and our providers are based in the United States, so your information is stored and processed there. If you are in the United Kingdom or the European Economic Area, transfers rely on the UK Addendum and the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies.
6.How long we keep it
- While your subscription is active, we keep your account and site for as long as you use the service.
- If payment stops, your site goes offline after roughly 30 days, is archived, and is permanently deleted about 30 days after that. We email you before each step.
- When you close your account or we delete a site, we remove the pages, images, logins, forms and form submissions, page history, redirects and custom code. Images are deleted from storage at the same time.
- Backups and site archives in our storage are kept as a safety net after deletion and are removed on our storage retention schedule. Ask us if you need them destroyed sooner.
- An administrative audit record of actions such as creation, suspension and deletion is kept after the account is gone. It holds the domain, the action, the date and who performed it, because we need to be able to show what happened.
- Invoices and payment records are kept by us and by Stripe for the period tax law requires.
- Temporary caches of a scan or a generated draft expire within one hour.
7.Your rights
Depending on where you live you can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or send it to another provider. You can also withdraw consent where we relied on it, and complain to your data protection regulator. In the United Kingdom that is the Information Commissioner’s Office.
If you are a California resident, you may request access to, deletion of, and details about the personal information we collect, and you will not be treated differently for asking. We do not sell or share personal information as those terms are defined by California law.
Two of these are built into the product: your dashboard lets you edit your business details at any time, and we can export your entire site as a downloadable archive before deleting it. For anything else, email privacy@thrivematic.ai. We answer within 30 days and may need to verify who you are first.
8.If you contacted a business through a site we host
When you submit a contact form on a website built with Thrivematic, your message goes to that business. They decide why they collect it and how long they keep it, so they are responsible for it under data protection law. We only store it and pass it on.
Please direct requests to see or delete your enquiry to the business itself, using the contact details on their site. If you cannot reach them, write to privacy@thrivematic.ai and we will pass the request on and help where we can.
9.Security
Traffic is encrypted in transit. Passwords are stored as salted hashes. Credentials you give us for your own email provider are encrypted before they are stored. Access to production systems is limited to people who need it, administrative actions are logged, and dashboards are protected against cross-site request forgery. No system is perfectly secure, but if a breach affects you we will notify you and the relevant regulator as the law requires.
10.Children
Thrivematic is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, contact privacy@thrivematic.ai and we will delete it.
11.Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect how we use your information, we will email account holders before the change takes effect.
12.Contact us
Write to privacy@thrivematic.ai.
Thrivematic · Privacy Policy · Terms of Service