Legal

Privacy Policy

Last updated

This policy covers three groups of people (visitors to this site, account holders in the application, and visitors to our customers’ websites), and our role is different for each. The short version: the edge software records no IP addresses and sets no cookies, model providers cannot train on your content, and we do not sell personal data.

1. Who we are

SiftServe (“SiftServe”, “we”, “us”) is operated by NextON Consulting FZE, a Free Zone Establishment registered in the United Arab Emirates, with its registered address at BC 5 RAK Business Park, Al Nakheel, P.O. Box 328029, Ras Al Khaimah, UAE. SiftServe makes websites readable to AI agents: it generates an agent-readable version of a customer’s site, the customer approves it, and our edge software serves that version to AI traffic.

For any question about this policy or about your personal data, write to info@siftserve.com.

2. Scope and roles

This policy covers three groups of people, and our role differs for each:

  • Visitors to siftserve.com (our marketing site and blog). We are the data controller.
  • Account holders on app.siftserve.com (the SiftServe application). We are the data controller.
  • Visitors to our customers’ websites. When a customer deploys SiftServe on their domain, our edge software processes traffic data on that customer’s behalf. For this data we are a data processor; the customer is the controller. Section 3.3 describes what we process. If you want this data corrected or deleted, contact the website operator; we will assist them as described in the Data Processing Addendum in our Terms of Service.

3. Information we collect

3.1 Visitors to siftserve.com

We use Google Analytics 4 to understand how the site is used. Google Analytics sets cookies and collects device information, approximate location derived from your IP address, and page interaction data. Google’s own privacy policy governs its processing of this data.

The “Ask AI” panel on siftserve.com runs entirely in your browser using Chrome’s built-in on-device model. Questions you type there are not sent to us or to any third party.

If you book a call through the link on our site, you leave siftserve.com and interact with Google Calendar under Google’s terms.

We do not collect your name, email address, or any other directly identifying information from ordinary browsing of siftserve.com.

3.2 Account holders on app.siftserve.com

Account data. When you sign in with Google, we receive your email address, name, Google account identifier, and profile picture URL under the openid email profile scopes. When you register with a username and password, we store your email, username, name, and a salted password hash (we never store the password itself). We also record your last sign-in time and whether an administrator has approved your account.

Session data. We keep you signed in with a session token valid for 12 hours, held in a cookie and in your browser’s local storage. The application sets no other cookies and loads no third-party analytics, advertising, or tracking scripts.

Team data. If you invite someone to a domain, we store their email address, their role, and who invited them.

Content you provide. Domains you register, sitemap URLs, brand guidelines, company profile information, fact-bank entries, review comments, and questions you submit to the Investigate feature. Company profiles may include information about identified people, such as named experts, credentials, and attributed testimonials. You are responsible for having the right to provide that information; it is rendered into pages that are published publicly as part of the service.

Integration credentials. API tokens and storage credentials you connect (for example Cloudflare API tokens, S3-compatible access keys, Azure SAS tokens, or backlink-provider API keys). These are encrypted at rest, are used only to operate the integrations you configure, and are never displayed back in full after you save them.

Payment data. We do not collect or process payment information. The service currently has no billing system.

3.3 Visitors to our customers’ websites

When our edge software runs on a customer’s domain, it records, for each request it handles: the page requested and its query string, the served variant, the requesting user agent, the referring page, HTTP status and timing, and network-level metadata (country, city, region, autonomous system number and operator, connection protocol). This applies to identified AI crawlers and to ordinary page views.

Our edge software does not record IP addresses and does not set cookies or any other identifier on visitors’ devices. It cannot recognise a returning visitor. Customer-facing dashboards display this data only in aggregate.

This data is stored in the customer’s own Cloudflare account and relayed to our analytics warehouse, where it is retained for two years (Section 8).

A note on infrastructure logs. Like nearly every internet service, the cloud platforms that run SiftServe (Google Cloud and Cloudflare) record IP addresses in their standard infrastructure request logs. We do not use these logs for analytics or profiling.

4. How we use information

We use personal data to operate the service: authenticating you, running crawls and generating agent-readable pages, showing analytics dashboards, providing support, securing the platform, and meeting legal obligations. We use marketing-site analytics to understand and improve siftserve.com.

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not send marketing email.

5. AI processing

Generating agent-readable pages and answering Investigate queries involves sending customer website content, and in some cases page screenshots, to large-language-model providers: OpenAI, Anthropic, and Google (Gemini). We use these providers through their business APIs, under terms that do not permit them to train their models on the submitted content. Approved agent-readable pages are hosted at publicly reachable URLs by design, so that AI systems can fetch and cite them.

Account data (your email, name, and credentials) is not sent to model providers.

6. Subprocessors and third-party services

We use the following subprocessors to provide the service:

ProviderPurposeLocation
Google Cloud PlatformApplication hosting, database, analytics warehouse, secret storage; edge and CDN serving for specific customer deploymentsIndia (asia-south1); regional deployments where offered
CloudflareEdge serving, page storage (R2), edge analyticsGlobal network
Microsoft AzureEdge and CDN serving and storage for specific customer deployments; optional publishing targetPer-deployment region
Amazon Web ServicesEdge and CDN serving and storage for specific customer deployments; optional publishing targetPer-deployment region
OpenAILanguage-model processing of customer site contentUnited States
AnthropicLanguage-model processing of customer site contentUnited States
Google (Gemini API; Google Identity)Vision-model processing of page screenshots; sign-in with GoogleUnited States / global

We will post changes to this list at siftserve.com/privacy and, for customers with a Data Processing Addendum in place, give notice as described there.

Services you connect with your own credentials (for example your Cloudflare account, your object storage, or your Ahrefs or Semrush subscription) are your own vendor relationships, governed by your agreements with those providers.

7. International transfers

Our primary infrastructure is in India (Google Cloud, asia-south1 region), with page storage and edge serving on Cloudflare’s global network. We plan to offer regional deployments for customers in the EU, UK, and US; where a customer selects one, their customer content and visitor telemetry are hosted in that region.

Where personal data originating in the EEA, the UK, or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum where applicable, including in our agreements with the subprocessors listed above.

8. Retention

  • Account data: kept while your account is active, and deleted on request (Section 10.3).
  • Customer content (crawled snapshots, generated page versions, published copies, profiles): kept while the domain is configured. Deleting a domain removes its content, including the publicly hosted copies. Job history is retained for audit purposes with its link to the deleted domain removed.
  • Visitor telemetry (Section 3.3): retained in our analytics warehouse for two years from collection, then deleted.
  • Session tokens expire after 12 hours.

9. Security

Data in transit is encrypted with TLS. Databases run on private networks. Stored integration credentials are encrypted at rest, and platform secrets are held in a dedicated secret store. Access to production systems is limited to authorised personnel. Passwords are stored as salted PBKDF2 hashes. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

10. Your rights and choices

10.1 European Economic Area and United Kingdom

If the GDPR or UK GDPR applies to you, you have the right to access, correct, delete, and receive a copy of your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. Our legal bases are: performance of a contract (operating your account and the service), legitimate interests (securing the platform, improving the service, marketing-site analytics), and consent where required. You may lodge a complaint with your supervisory authority.

10.2 United States

If you are a California resident, you have the right to know what personal information we collect, to delete it, to correct it, and to be free from discrimination for exercising these rights. We do not sell personal information and have not sold it in the preceding twelve months. Residents of other US states with comparable privacy laws have equivalent rights to access, correct, and delete their data.

10.3 Exercising your rights

Email info@siftserve.com from the address associated with your account. We handle access, export, correction, and deletion requests manually and will respond within 30 days. Deletion covers your account record, your content, and analytics data associated with your account. We may retain information we are legally required to keep, and we will tell you if so.

For data our edge software processes on a customer’s behalf (Section 3.3), direct your request to the website operator; we will assist them in fulfilling it.

11. Children

The service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact info@siftserve.com and we will delete it.

12. Changes to this policy

When we change this policy, we will update the date at the top and post the new version at siftserve.com/privacy. For material changes affecting account holders, we will give notice in the application or by email before the change takes effect.

13. Contact

SiftServe
NextON Consulting FZE
BC 5 RAK Business Park, Al Nakheel

P.O. Box 328029

Ras Al Khaimah, United Arab Emirates

info@siftserve.com

Terms of ServicePrivacy PolicyAbout