Privacy Policy

How structuredpages.com and Hosted Builder handle personal data, cookies, payments, analytics, and AI keys.

Last updated: July 31, 2026

This notice describes data handled on the marketing site (structuredpages.com), Hosted Builder accounts and workspaces, and related Control Deck features. It is a factual description of current practice, not legal advice.

1. What this site is

Structured Pages publishes catalog demo pages and sells Hosted Builder access (staging workspace, Control Deck, static export). Casual browsing of public pages does not require an account.

2. Data we collect

A. Hosted Builder accounts (when you sign up at /account/start or log in)

  • Email address
  • Password stored as a one-way hash (not plaintext)
  • Workspace slug / metadata linking your account to a staging workspace
  • Stripe customer ID (when billing is created)
  • Session cookies and CSRF cookies used to keep you signed in and protect account forms

Purpose: authenticate you, provision and operate your workspace, and manage billing status.

B. Payments (Stripe)

Payment card details are collected and processed by Stripe. We do not store full card numbers on our servers. We store the Stripe customer ID (and related subscription/status metadata Stripe returns) so we can recognize paid access and open the Stripe billing portal.

Purpose: charge the annual Hosted Builder fee and manage subscription state.

C. Contact / hire / sales inquiries (/contact/ and similar forms)

  • Name, email, optional company, message, and related form fields you submit
  • Stored as first-party lead records in operator ops storage (e.g. sales_contact leads) for follow-up in Control Deck

Purpose: respond to hire requests and product questions. We do not sell these lists.

D. Analytics on the marketing site (self-hosted Umami)

The marketing SSR site may load a self-hosted Umami tracker (script served from our infrastructure, e.g. templates.structuredpages.com). It records page-view style usage (paths, referrers, basic technical metadata such as browser/device signals Umami collects). It is not Google Analytics and is not injected into Hosted Builder tenant workspaces or static exports by default.

Purpose: understand which marketing pages are used so we can improve the product site.

E. Anthropic API keys (optional, Control Deck)

If you (or the operator) enable AI import / repair / Deepen features, an Anthropic API key may be saved under Control Deck → Integrations in operator secrets storage (data/ops/secrets.json on that install), or supplied via environment variable. That key is used to call Anthropic's API with catalog/content you choose to process. Calls are billed to the Anthropic account tied to that key.

Purpose: optional AI-assisted import and enrichment. Without a key, those features stay off; manual import still works.

F. Catalog / workspace content you create

Entity data, uploads, and site settings in a Hosted Builder workspace are stored to run your staging site and exports. You own that content; we host it while the service is active.

G. Server and security logs

Standard web/server logs may include IP address, user agent, requested URL, and response codes. Control Deck / platform admin activity may also be logged for security and operations.

Purpose: operate the service, debug failures, and mitigate abuse. Retention follows normal server administration practice; logs are not a marketing profile database.

3. Lawful bases (draft — pending operator review)

The following is draft engineering wording, not legal advice. The operator should review and confirm (or revise) these bases with counsel before treating them as final.

  • Hosted Builder accounts, passwords, workspace metadata, and Stripe billing identifiers: GDPR Art. 6(1)(b) — processing necessary for the performance of a contract (providing Hosted Builder access and billing) or to take steps at the request of the data subject prior to entering into a contract.
  • Contact / hire form submissions: Art. 6(1)(b) — steps prior to a contract / responding to a request you initiated, or Art. 6(1)(f) legitimate interests in following up on sales and hire inquiries where no contract yet exists.
  • Server logs, Control Deck admin audit trails, and similar security/operations records: Art. 6(1)(f) — legitimate interests in securing the service, debugging failures, and preventing fraud or abuse.
  • Optional Anthropic API calls (when you configure a key): Art. 6(1)(b) — necessary to provide the AI-assisted features you enable under the Hosted Builder contract.
  • Self-hosted Umami analytics and optional Sentry error events: purposes are described above; the precise Art. 6 basis (and any ePrivacy consent requirements) for analytics remain subject to operator legal review and are not asserted as settled in this draft.

4. Processors and systems we use

System Role
Stripe Payment processing, customer/subscription records
Resend Transactional email (welcome messages, password-reset links, contact-form notifications to the operator inbox)
Anthropic Optional AI API calls when an Anthropic key is configured
Sentry Optional application error tracking (server-side; configured to avoid sending default PII and to scrub secrets)
Self-hosted Umami (our VPS / tunnel) First-party analytics on the marketing SSR site
Hosting / VPS / reverse proxy Serves the site and stores application data on disk

Customer-chosen analytics snippets pasted into a workspace (Control Deck branding) are the customer's responsibility and are not the marketing-site Umami tracker.

5. Cookies

  • Account session and CSRF cookies on /account/* (required for login and form safety)
  • Umami may set its own first-party analytics cookie/storage as implemented by that tracker on the marketing site

We do not run a separate advertising cookie network on the marketing site.

6. Sharing

We share data with the processors above only as needed to run the service (e.g. Stripe for payment, Anthropic when AI features are used). We do not sell personal data.

7. Retention

  • Workspace / catalog data on Hosted Builder volumes: while the subscription is active; promptly deleted when the subscription ends (see Terms — there is no post-cancellation export window)
  • Account records (email, Stripe IDs, status): retained while needed for billing, fraud prevention, and legal obligations; may be anonymized on erasure request while keeping non-identifying billing metadata
  • Contact leads: until handled or removed on request (including permanent deletion when requested)
  • Analytics events: per our Umami retention settings (default purge of events older than 14 months)
  • Logs: per normal server retention

8. Your requests

Email [email protected] to ask what we hold about you, correct an account email, or request deletion of contact-lead or account data where feasible. Some records (e.g. Stripe payment history, security logs) may be retained as required for billing, fraud prevention, or legal obligations. Operators may use scripts/erase-account-data.js for first-party anonymization/deletion, then complete the script's manual checklist for Stripe, Resend, Sentry, and Umami.

9. Changes

We may update this notice when collection practices change. The "Last updated" date will change when we do.

Clear