LegalPrivacy Policy

Privacy Policy.

Read the Sitewrap Privacy Policy for information about personal data, analytics, cookies, IP masking, retention, security logs, and data rights.

Privacy-aware operations Masked analytics Consent-gated storage Security retention windows

Last updated: 29 May 2026

1. Who we are

This Privacy Policy explains how CREA SPACE LTD processes personal data in connection with Sitewrap, the website available at sitewrap.io, and the Sitewrap dashboard and related services.

CREA SPACE LTD is located at 20-22 Wenlock Road, London, N1 7GU, United Kingdom. You can contact us about privacy matters through the contact page or by email at hello@sitewrap.io.

2. Scope of this policy

This policy applies to visitors of the Sitewrap website, users of the Sitewrap dashboard, and individuals whose data may be processed when a customer uses Sitewrap in front of their website.

Where Sitewrap processes data on behalf of a customer, the customer is usually the controller and Sitewrap acts as processor. The customer's own privacy policy should explain how that customer uses Sitewrap on its website.

3. Personal data we process

Depending on how Sitewrap is used, we may process account data, contact details, billing or subscription information, support messages, website configuration data, request logs, security events, deployment records, audit logs, form submissions if enabled by a customer, and analytics or engagement signals.

Request and security data may include IP addresses, user agent strings, URLs, timestamps, status codes, referrers, device type, country-level location derived from IP, cache/source information, and other technical information needed to operate, secure, and troubleshoot the service.

  • Account and dashboard data: email address, role, authentication/session metadata, tenant/site access, and activity logs.
  • Website operations data: domains, routes, cache state, deployment history, redirects, A/B test configuration, forms, and leads if configured.
  • Analytics data: request metadata, page views, engagement such as scroll depth and time on page, and masked or coarse user identifiers.
  • Security data: firewall events, blocked IPs, suspicious probes, rate-limit events, and diagnostic logs.

4. IP addresses and visitor identifiers

IP addresses can be personal data. Sitewrap is designed to reduce unnecessary exposure of full IP addresses in analytics views. Request-log and analytics screens show masked or coarsened IP addresses by default, such as an IPv4 /24-style value or an IPv6 /48-style value.

Full IP addresses may still be processed where needed for security, abuse prevention, fraud prevention, rate limiting, firewall operation, diagnostics, origin protection, or legal compliance. Full IP visibility should be limited to authorized security and support workflows.

6. Purposes and lawful bases

We process personal data to provide and secure Sitewrap, authenticate users, operate websites at the edge, deliver support, improve reliability, prevent abuse, process payments where applicable, comply with legal obligations, and communicate about the service.

Depending on context, our lawful bases may include performance of a contract, legitimate interests in operating and securing the service, consent for optional analytics or persistent visitor storage, and compliance with legal obligations.

7. Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, including service operation, security, diagnostics, compliance, and dispute resolution.

Operational analytics should use anonymized or coarsened data where possible. Full IP data used for security, abuse prevention, firewall operation, or diagnostics should be kept for short retention windows appropriate to the risk and customer configuration, for example 7 to 30 days unless a longer period is required for security, legal, or contractual reasons.

8. Sharing and subprocessors

We may use trusted service providers for hosting, storage, email delivery, analytics, monitoring, payment processing, security, and customer support. These providers process data only as needed to provide their services to us.

We do not sell personal data. We may disclose data if required by law, to protect the rights and security of Sitewrap, our customers, or others, or in connection with a business transaction such as a merger or acquisition.

9. International transfers

Sitewrap may be operated using infrastructure and service providers located in different countries. Where personal data is transferred internationally, we use appropriate safeguards where required, such as contractual protections or recognized transfer mechanisms.

10. Your rights

Depending on your location and the context of processing, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent where processing is based on consent.

If your data is processed by a Sitewrap customer on that customer's website, you should usually contact that customer first. We will assist customers with data-rights requests where required.

11. Security

We use technical and organizational measures designed to protect personal data, including access controls, secure sessions, operational logging, tenant separation, and security monitoring. No online service can guarantee absolute security, but we work to reduce risk and respond to issues responsibly.

12. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will be posted on this page with the date it was last updated.

Ready to wrap your website with Sitewrap?

Add speed, visibility, security, and deployment control without replacing the site you already have.