SiteTrust Privacy Policy

SITE TRUST, LLC dba SITETRUST

Privacy Policy

Version 3.0 · Effective Date: July 1, 2026

IMPORTANT NOTICE TO USERS: This Privacy Policy governs how Site Trust, LLC dba SiteTrust collects, uses, stores, shares, and protects personal information in connection with the Trusted Site plans, SiteTrust Consent, the Trust Center platform, the Certified Trust Advisor (CTA) program, and related professional services. By accessing or using SiteTrust's services, you agree to this Privacy Policy. If you do not agree, please discontinue use of our services and contact us to request data deletion.

1. Who We Are

Site Trust, LLC dba SiteTrust ("SiteTrust," "we," "our," or "us") is an AI trust certification company. We address the hidden risks of websites, undisclosed AI and tracking without consent, through the Trusted Site plans (Disclose, Verify, and Audit, plus Enterprise engagements). Our services include:

  • Certification under the SiteTrust Standard, with one trust seal and a public registry of independently verified listings (registry listing begins at the Verify plan).

  • SiteTrust Consent, our consent management service: consent-first banner, tracker blocking, timestamped consent records, and evidence reports, included in every plan.

  • The Trust Center platform, a secure environment where clients access plan deliverables, policies, evidence reports, dashboards, and their current customer agreements.

  • The Certified Trust Advisor (CTA) program, SiteTrust's independent sales and advisory channel.

  • AI Risk Coverage, offered separately in SiteTrust's capacity as a licensed insurance producer (currently licensed in Ohio). Insurance is never part of a certification plan.

SiteTrust operates as a data controller for our own service delivery, and as a data processor or service provider in two contexts: content clients upload to the Trust Center, and visitor consent records we process for clients through SiteTrust Consent (governed by the SiteTrust Consent Data Processing Agreement, the "DPA"). This policy addresses each role.

Data Controller Contact: Site Trust, LLC dba SiteTrust | Attn: Legal | 2725 Abington Road, Suite 202, Fairlawn, Ohio 44333 | wecare@sitetrust.com

2. Scope of This Policy

This policy applies to visitors to sitetrust.com and affiliated domains; prospective clients and CTAs; client organizations and their representatives using the Trust Center; CTAs in the program; applicants for AI Risk Coverage; and users of SiteTrust-operated software and tools. It does not apply to: (a) the data practices of certified client companies operating under their own privacy policies (clients are responsible for their own privacy compliance, including policies generated from SiteTrust templates); or (b) visitors to client websites whose consent records SiteTrust processes on the client's behalf, which are governed by the client's privacy policy and the DPA.

3. Information We Collect

3.1 Information You Provide Directly

When you register, purchase a plan at checkout, complete an assessment, upload documents to the Trust Center, complete CTA training, apply for AI Risk Coverage, or contact us, we may collect: name, email address, job title, company name, business address, phone number, professional credentials, payment card information (processed by our payment processor), insurance application information (Section 3.4), and content you upload or enter.

3.2 Information We Collect Automatically

When you access our website or platform: device and browser information, IP address and approximate location (city/region), pages visited and navigation paths, referring URLs, and session identifiers, collected through server logs, cookies, and similar technologies (Section 11). Our own site runs SiteTrust Consent: non-essential technologies do not fire before you consent.

3.3 Information from Third Parties

We may receive information from: CTAs who refer you (referral context and contact information, with the compensated nature of referrals disclosed per FTC guidance); identity verification services (CTA credentialing); publicly available sources (business verification); and integration partners where you authorized sharing.

3.4 Insurance Application Information

If you apply for AI Risk Coverage, we collect the information needed to quote and place coverage: business operations details, revenue ranges, AI use descriptions, claims history, and underwriting responses. This information is collected under a separate application, shared with carriers, brokers, and underwriters as described in Section 7.3, and handled subject to applicable insurance laws. Certification assessment data is not shared with insurers without your consent (Section 8.2).

4. AI-Specific Data Processing Disclosures

AI TRANSPARENCY COMMITMENT: SiteTrust uses AI systems in the delivery of certain services. We are committed to full transparency about how AI is used, what data enters AI systems, and how that data is protected. As a company whose business is AI trust, we hold ourselves to the same disclosure standard we certify.

4.1 How AI Is Used in Service Delivery

AI Use CaseDescription and Data Involved
Regulatory intelligence (Trust Signal Briefing)AI-assisted research and synthesis of legislation, enforcement, and guidance. Processes publicly available regulatory text; does not process personal data.
Certification assessment supportAI tools assist in analyzing client-submitted documents and assessment responses against the SiteTrust Standard. Processes business documents and policy text submitted by client representatives.
Consent evidence reportingAutomated testing and reporting of tracker behavior on client sites. Processes site technical data and visitor consent records under the DPA.
Trust Center content deliveryOrganizing and surfacing templates, tools, and resources. Processes metadata and usage patterns; uploaded document content is not processed by AI without explicit client opt-in.
CTA program toolsAI-assisted proposal and summary tools processing inputs provided by the CTA.
Customer supportAI may assist in routing and initial responses; human agents review all substantive inquiries.

4.2 Adaptive AI Systems

Where adaptive AI tools are in use, we monitor for behavioral drift, maintain version control for models used in service delivery, notify affected users of material changes in AI behavior that could affect their certification status, and maintain human oversight of all AI-assisted certification decisions. SiteTrust does not use AI systems that make fully autonomous decisions affecting certification status.

4.3 AI Vendor Disclosure

SiteTrust uses third-party AI service providers, listed in our AI System Inventory, available on request to clients and CTAs. Vendors are subject to due diligence, data processing agreements, and security assessment. We update this policy and provide at least 30-day notice of material AI vendor changes.

4.4 No AI-Driven Certification Decisions

SiteTrust does not make final certification determinations through automated processing alone. All certification awards, seal issuances, and revocations are reviewed and confirmed by a qualified SiteTrust professional. You may request human review of any assessment finding that adversely affects your certification status (Section 9).

5. Trust Center Data Handling

The Trust Center is the secure platform where clients and authorized CTAs access plan deliverables, dashboards, training resources, and the current versions of the customer agreements that apply to their Services. Client-uploaded documents are stored encrypted and access-controlled, logically isolated by account, accessed by SiteTrust staff only to deliver contracted services or support, never shared with other clients or used for marketing, and processed by AI only with explicit client opt-in. The compliance dashboard aggregates the client's own data within its isolated environment; SiteTrust may use aggregated, de-identified insights across the platform for any lawful business purpose, including improving standards and tools and publishing benchmark insights, with no individual client identifiable.

5.1 CTA Access to Client Data

A client may authorize a CTA to access specified Trust Center materials. CTAs can access only what the client explicitly shares, may use and download it only within the engagement, may not share or retain it beyond the engagement without written client authorization, and are bound by the confidentiality obligations of the CTA Program Agreement. Clients may revoke CTA access at any time in account settings, effective immediately. Violations may result in CTA decertification.

6. How We Use Information

PurposeLegal BasisDetails
Service deliveryContract performanceProcessing plan purchases, delivering certifications and SiteTrust Consent, Trust Center access, CTA engagements
Account managementContract performanceAccounts, authentication, access control, support
Certification assessmentContract performanceAnalyzing submitted documents and assessments against the SiteTrust Standard
Insurance quoting and placementContract performance; consentProcessing AI Risk Coverage applications and sharing with carriers and brokers (Section 7.3)
Regulatory intelligenceLegitimate interestProducing the Trust Signal Briefing and regulatory digest
Product improvement and developmentLegitimate interestAnalyzing, developing, and improving our services, standards, tools, and new offerings, using account, usage, and interaction data
Protecting rightsLegitimate interest; legal obligationEnforcing our agreements, collecting amounts owed, establishing and defending legal claims, and protecting SiteTrust, our clients, and the public
Legal complianceLegal obligationComplying with law, lawful requests, required records
SecurityLegitimate interestDetecting and preventing fraud, unauthorized access, incidents
MarketingConsent (where required)Newsletters, events, and updates to opted-in subscribers; unsubscribe any time
Other purposesAs permitted by law; consentPurposes consistent with the context in which the information was collected, purposes disclosed at collection, or purposes you consent to
EU processingGDPR Art. 6(1)(b)(c)(f)Contractual necessity, legal obligation, and legitimate interests per activity

Service and account communications (renewal reminders, billing and legal notices, security alerts, and material policy updates) are part of the Services, are not marketing, and are sent as needed regardless of marketing preferences.

7. How We Share Information

SiteTrust does not sell or share personal information for cross-context behavioral advertising. We share information only as follows:

7.1 Service Providers

Vendors processing data on our behalf under data processing agreements, limited to the services they deliver: cloud hosting, AI service providers (Section 4.3), payment processors, email and communication platforms, identity verification, and legal, accounting, and professional services firms.

7.2 Certified Trust Advisors

With explicit client authorization, per Section 5.1, under CTA confidentiality obligations.

7.3 Insurance Carriers and Brokers

When you apply for AI Risk Coverage, your application information is shared with the carriers, brokers, and underwriters involved in quoting and placing coverage, and with regulators as insurance law requires. Their use of that information is governed by their own privacy notices and applicable insurance law.

7.4 The Public Registry

SiteTrust publishes a public registry of certified companies at the Verify plan and above: company name, certification status, plan cadence, and verification dates. Every client's seal links to a certificate view showing current status. Clients consent to this publication when purchasing a plan that includes it and may request removal upon plan termination.

7.5 Legal Requirements; Business Transfers; Aggregated Data

We may disclose information as required by law, court order, or government request, with notice to affected users where permitted; in connection with a merger, acquisition, or sale of substantially all assets, with notice of any material policy changes; and as aggregated or de-identified information. SiteTrust owns aggregated and de-identified data it creates and may use and disclose it for any lawful purpose, including benchmarking, market intelligence, published research, and development of standards and services, provided it cannot reasonably identify any individual or specific client.

8. Automated Decision-Making and Profiling

For individuals subject to GDPR Article 22: SiteTrust does not make decisions based solely on automated processing that produce legal or similarly significant effects without human review.

8.1 AI-Assisted Analysis

Automated tools generate preliminary findings only; a qualified professional reviews all findings before they are communicated; you may request an explanation of any automated finding that influences an assessment, and human-only review of your certification assessment (Section 9).

8.2 Risk Scoring

The compliance dashboard and the Insurability Readiness Score are diagnostic tools for the client's own use, based on transparent criteria tied to the SiteTrust Standard. They are not certification determinations and are not shared with third parties, including insurers or regulators, without client consent.

8.3 No Behavioral Advertising Profiles

SiteTrust does not engage in behavioral profiling for targeted advertising and does not build profiles for sale to data brokers or advertisers.

9. Your Rights

RightHow to Exercise
AccessRequest a copy of the personal information we hold about you.
CorrectionRequest correction of inaccurate or incomplete information.
DeletionRequest deletion, subject to legal retention obligations.
Portability (GDPR)Request your data in a structured, machine-readable format.
Restriction / objection (GDPR)Request limits on processing, or object to legitimate interest processing.
Human review of automated findingsRequest qualified human review of any AI-assisted finding that materially affects your certification status.
California rights (CCPA/CPRA)Request disclosure, correction, or deletion, and opt out of sale or sharing. SiteTrust does not sell or share personal information; we honor Global Privacy Control (GPC) browser signals as a valid opt-out where required.
Colorado rights (CPA)Opt out of profiling in furtherance of decisions producing legal or similarly significant effects.
Marketing opt-outUnsubscribe any time via the link in any marketing email or by contacting us.

To exercise any right, contact wecare@sitetrust.com with the subject "Data Rights Request." We respond within 30 days or the period required by law, and may first require verification of your identity and, for agent requests, proof of authorization. The rights above apply only to the extent granted by the law of your jurisdiction; we may decline or limit a request where an exception applies or where a request is manifestly unfounded, repetitive, or excessive, in which case we may alternatively charge a reasonable fee as the law allows. Exercising a right does not affect fees owed for Services, and this policy itself creates no rights beyond those provided by applicable law.

10. Data Retention

Data CategoryRetention PeriodBasis
Active client account dataActive plan + 3 yearsContract performance; disputes
Certification records7 years from certification dateLegal obligation; audit trail
Trust Center uploaded documentsEngagement + 1 year, or earlier on requestContract performance
Visitor consent records (processed for clients)Per the DPA: 5-year default from record creationClient compliance evidence; DPA
CTA program recordsCTA status + 5 yearsLegal obligation; disputes
Insurance application recordsAs required by applicable insurance lawLegal obligation
Payment and billing records7 yearsTax and financial compliance
AI processing logs2 years from assessment dateQuality assurance; disputes
Marketing preferencesUntil opt-out or account closureConsent; legitimate interest
Website analytics data13 months rollingLegitimate interest
Legal hold dataDuration of proceeding or inquiryLegal obligation

The periods above are defaults. SiteTrust may retain information longer where reasonably necessary to comply with law, resolve disputes, enforce agreements, defend legal claims, maintain security, or preserve evidence, and may retain de-identified data indefinitely. When retention ends, data is securely deleted or anonymized. Clients may request earlier deletion of uploaded documents, subject to minimum legal retention; we confirm deletion within 30 days of a valid request.

11. Cookies and Tracking Technologies

sitetrust.com runs SiteTrust Consent, the same consent layer we provide to clients: non-essential categories default to off, accept and decline carry equal prominence, and consent can be changed or withdrawn at any time through the persistent cookie settings control. We honor GPC signals. Categories in use:

Cookie TypePurpose and Details
Strictly necessarySession authentication, security tokens, access control. Cannot be disabled without impairing core functionality.
FunctionalPreferences and settings within the Trust Center, persisting across sessions.
AnalyticsPrivacy-first analytics that do not share data with advertising networks; loads only after consent.
No advertising cookiesSiteTrust does not use advertising cookies, retargeting pixels, or third-party tracking for advertising purposes.

12. Cross-Border Data Transfers

SiteTrust is headquartered in the United States, and personal data is processed and stored in the United States. For transfers of EU, EEA, UK, or Swiss personal data, we rely on: EU Standard Contractual Clauses (Commission Implementing Decision 2021/914); the UK International Data Transfer Addendum; and, to the extent SiteTrust self-certifies under the EU-US Data Privacy Framework, its requirements. Clients requiring executed transfer documentation should contact wecare@sitetrust.com with the subject "EU Transfer Agreement." For AI systems used in EU-facing service delivery, we maintain the transparency documentation the EU AI Act's applicable provisions require, available on request to EU clients.

13. Data Security

Our security program includes encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, multi-factor authentication for Trust Center access, periodic security assessments and penetration testing, incident response procedures with defined notification timelines, vendor security assessments, and employee security training. No security system is impenetrable. If a breach creates risk to affected individuals, we will notify affected parties and regulators within the timeframes applicable law requires (72 hours under GDPR; as required by applicable state breach laws). Report security concerns to wecare@sitetrust.com.

14. Children's Privacy

SiteTrust's services are intended for business professionals and are not directed to individuals under 18. We do not knowingly collect personal information from minors and will delete any we learn of promptly; contact wecare@sitetrust.com if you believe a minor's information was collected.

15. Changes to This Privacy Policy

We review this policy regularly against regulatory developments and service changes. For material changes we post the updated policy with a new effective date and notify active clients and CTAs by email at least 30 days before the changes take effect; non-material clarifications are effective on posting. The current version is always available on sitetrust.com and in the Trust Center customer profile; continued use after the effective date constitutes acceptance. A version history is available upon request. This Privacy Policy is a disclosure notice, not a contract: it does not create contractual rights or remedies, does not expand any rights beyond those applicable law provides, and creates no third-party beneficiary rights.

16. How to Contact Us

Contact PurposeContact Information
Privacy inquiries and data rights requestswecare@sitetrust.com (subject: "Data Rights Request")
EU/UK transfer documentationwecare@sitetrust.com (subject: "EU Transfer Agreement")
Security incidentswecare@sitetrust.com
CEO / Data Protection LeadVincent Fisher | wecare@sitetrust.com
Mailing addressSiteTrust | 2725 Abington Road, Suite 202, Fairlawn, Ohio 44333

EU and UK users may lodge a complaint with their local data protection authority; we encourage you to contact us first so we can address your concern directly.