SiteTrust Privacy Policy
SITE TRUST, LLC dba SITETRUST
Privacy Policy
Version 3.0 · Effective Date: July 1, 2026
| IMPORTANT NOTICE TO USERS: This Privacy Policy governs how Site Trust, LLC dba SiteTrust collects, uses, stores, shares, and protects personal information in connection with the Trusted Site plans, SiteTrust Consent, the Trust Center platform, the Certified Trust Advisor (CTA) program, and related professional services. By accessing or using SiteTrust's services, you agree to this Privacy Policy. If you do not agree, please discontinue use of our services and contact us to request data deletion. |
|---|
1. Who We Are
Site Trust, LLC dba SiteTrust ("SiteTrust," "we," "our," or "us") is an AI trust certification company. We address the hidden risks of websites, undisclosed AI and tracking without consent, through the Trusted Site plans (Disclose, Verify, and Audit, plus Enterprise engagements). Our services include:
-
Certification under the SiteTrust Standard, with one trust seal and a public registry of independently verified listings (registry listing begins at the Verify plan).
-
SiteTrust Consent, our consent management service: consent-first banner, tracker blocking, timestamped consent records, and evidence reports, included in every plan.
-
The Trust Center platform, a secure environment where clients access plan deliverables, policies, evidence reports, dashboards, and their current customer agreements.
-
The Certified Trust Advisor (CTA) program, SiteTrust's independent sales and advisory channel.
-
AI Risk Coverage, offered separately in SiteTrust's capacity as a licensed insurance producer (currently licensed in Ohio). Insurance is never part of a certification plan.
SiteTrust operates as a data controller for our own service delivery, and as a data processor or service provider in two contexts: content clients upload to the Trust Center, and visitor consent records we process for clients through SiteTrust Consent (governed by the SiteTrust Consent Data Processing Agreement, the "DPA"). This policy addresses each role.
Data Controller Contact: Site Trust, LLC dba SiteTrust | Attn: Legal | 2725 Abington Road, Suite 202, Fairlawn, Ohio 44333 | wecare@sitetrust.com
2. Scope of This Policy
This policy applies to visitors to sitetrust.com and affiliated domains; prospective clients and CTAs; client organizations and their representatives using the Trust Center; CTAs in the program; applicants for AI Risk Coverage; and users of SiteTrust-operated software and tools. It does not apply to: (a) the data practices of certified client companies operating under their own privacy policies (clients are responsible for their own privacy compliance, including policies generated from SiteTrust templates); or (b) visitors to client websites whose consent records SiteTrust processes on the client's behalf, which are governed by the client's privacy policy and the DPA.
3. Information We Collect
3.1 Information You Provide Directly
When you register, purchase a plan at checkout, complete an assessment, upload documents to the Trust Center, complete CTA training, apply for AI Risk Coverage, or contact us, we may collect: name, email address, job title, company name, business address, phone number, professional credentials, payment card information (processed by our payment processor), insurance application information (Section 3.4), and content you upload or enter.
3.2 Information We Collect Automatically
When you access our website or platform: device and browser information, IP address and approximate location (city/region), pages visited and navigation paths, referring URLs, and session identifiers, collected through server logs, cookies, and similar technologies (Section 11). Our own site runs SiteTrust Consent: non-essential technologies do not fire before you consent.
3.3 Information from Third Parties
We may receive information from: CTAs who refer you (referral context and contact information, with the compensated nature of referrals disclosed per FTC guidance); identity verification services (CTA credentialing); publicly available sources (business verification); and integration partners where you authorized sharing.
3.4 Insurance Application Information
If you apply for AI Risk Coverage, we collect the information needed to quote and place coverage: business operations details, revenue ranges, AI use descriptions, claims history, and underwriting responses. This information is collected under a separate application, shared with carriers, brokers, and underwriters as described in Section 7.3, and handled subject to applicable insurance laws. Certification assessment data is not shared with insurers without your consent (Section 8.2).
4. AI-Specific Data Processing Disclosures
| AI TRANSPARENCY COMMITMENT: SiteTrust uses AI systems in the delivery of certain services. We are committed to full transparency about how AI is used, what data enters AI systems, and how that data is protected. As a company whose business is AI trust, we hold ourselves to the same disclosure standard we certify. |
|---|
4.1 How AI Is Used in Service Delivery
| AI Use Case | Description and Data Involved |
|---|---|
| Regulatory intelligence (Trust Signal Briefing) | AI-assisted research and synthesis of legislation, enforcement, and guidance. Processes publicly available regulatory text; does not process personal data. |
| Certification assessment support | AI tools assist in analyzing client-submitted documents and assessment responses against the SiteTrust Standard. Processes business documents and policy text submitted by client representatives. |
| Consent evidence reporting | Automated testing and reporting of tracker behavior on client sites. Processes site technical data and visitor consent records under the DPA. |
| Trust Center content delivery | Organizing and surfacing templates, tools, and resources. Processes metadata and usage patterns; uploaded document content is not processed by AI without explicit client opt-in. |
| CTA program tools | AI-assisted proposal and summary tools processing inputs provided by the CTA. |
| Customer support | AI may assist in routing and initial responses; human agents review all substantive inquiries. |
4.2 Adaptive AI Systems
Where adaptive AI tools are in use, we monitor for behavioral drift, maintain version control for models used in service delivery, notify affected users of material changes in AI behavior that could affect their certification status, and maintain human oversight of all AI-assisted certification decisions. SiteTrust does not use AI systems that make fully autonomous decisions affecting certification status.
4.3 AI Vendor Disclosure
SiteTrust uses third-party AI service providers, listed in our AI System Inventory, available on request to clients and CTAs. Vendors are subject to due diligence, data processing agreements, and security assessment. We update this policy and provide at least 30-day notice of material AI vendor changes.
4.4 No AI-Driven Certification Decisions
SiteTrust does not make final certification determinations through automated processing alone. All certification awards, seal issuances, and revocations are reviewed and confirmed by a qualified SiteTrust professional. You may request human review of any assessment finding that adversely affects your certification status (Section 9).
5. Trust Center Data Handling
The Trust Center is the secure platform where clients and authorized CTAs access plan deliverables, dashboards, training resources, and the current versions of the customer agreements that apply to their Services. Client-uploaded documents are stored encrypted and access-controlled, logically isolated by account, accessed by SiteTrust staff only to deliver contracted services or support, never shared with other clients or used for marketing, and processed by AI only with explicit client opt-in. The compliance dashboard aggregates the client's own data within its isolated environment; SiteTrust may use aggregated, de-identified insights across the platform for any lawful business purpose, including improving standards and tools and publishing benchmark insights, with no individual client identifiable.
5.1 CTA Access to Client Data
A client may authorize a CTA to access specified Trust Center materials. CTAs can access only what the client explicitly shares, may use and download it only within the engagement, may not share or retain it beyond the engagement without written client authorization, and are bound by the confidentiality obligations of the CTA Program Agreement. Clients may revoke CTA access at any time in account settings, effective immediately. Violations may result in CTA decertification.
6. How We Use Information
| Purpose | Legal Basis | Details |
|---|---|---|
| Service delivery | Contract performance | Processing plan purchases, delivering certifications and SiteTrust Consent, Trust Center access, CTA engagements |
| Account management | Contract performance | Accounts, authentication, access control, support |
| Certification assessment | Contract performance | Analyzing submitted documents and assessments against the SiteTrust Standard |
| Insurance quoting and placement | Contract performance; consent | Processing AI Risk Coverage applications and sharing with carriers and brokers (Section 7.3) |
| Regulatory intelligence | Legitimate interest | Producing the Trust Signal Briefing and regulatory digest |
| Product improvement and development | Legitimate interest | Analyzing, developing, and improving our services, standards, tools, and new offerings, using account, usage, and interaction data |
| Protecting rights | Legitimate interest; legal obligation | Enforcing our agreements, collecting amounts owed, establishing and defending legal claims, and protecting SiteTrust, our clients, and the public |
| Legal compliance | Legal obligation | Complying with law, lawful requests, required records |
| Security | Legitimate interest | Detecting and preventing fraud, unauthorized access, incidents |
| Marketing | Consent (where required) | Newsletters, events, and updates to opted-in subscribers; unsubscribe any time |
| Other purposes | As permitted by law; consent | Purposes consistent with the context in which the information was collected, purposes disclosed at collection, or purposes you consent to |
| EU processing | GDPR Art. 6(1)(b)(c)(f) | Contractual necessity, legal obligation, and legitimate interests per activity |
Service and account communications (renewal reminders, billing and legal notices, security alerts, and material policy updates) are part of the Services, are not marketing, and are sent as needed regardless of marketing preferences.
7. How We Share Information
SiteTrust does not sell or share personal information for cross-context behavioral advertising. We share information only as follows:
7.1 Service Providers
Vendors processing data on our behalf under data processing agreements, limited to the services they deliver: cloud hosting, AI service providers (Section 4.3), payment processors, email and communication platforms, identity verification, and legal, accounting, and professional services firms.
7.2 Certified Trust Advisors
With explicit client authorization, per Section 5.1, under CTA confidentiality obligations.
7.3 Insurance Carriers and Brokers
When you apply for AI Risk Coverage, your application information is shared with the carriers, brokers, and underwriters involved in quoting and placing coverage, and with regulators as insurance law requires. Their use of that information is governed by their own privacy notices and applicable insurance law.
7.4 The Public Registry
SiteTrust publishes a public registry of certified companies at the Verify plan and above: company name, certification status, plan cadence, and verification dates. Every client's seal links to a certificate view showing current status. Clients consent to this publication when purchasing a plan that includes it and may request removal upon plan termination.
7.5 Legal Requirements; Business Transfers; Aggregated Data
We may disclose information as required by law, court order, or government request, with notice to affected users where permitted; in connection with a merger, acquisition, or sale of substantially all assets, with notice of any material policy changes; and as aggregated or de-identified information. SiteTrust owns aggregated and de-identified data it creates and may use and disclose it for any lawful purpose, including benchmarking, market intelligence, published research, and development of standards and services, provided it cannot reasonably identify any individual or specific client.
8. Automated Decision-Making and Profiling
For individuals subject to GDPR Article 22: SiteTrust does not make decisions based solely on automated processing that produce legal or similarly significant effects without human review.
8.1 AI-Assisted Analysis
Automated tools generate preliminary findings only; a qualified professional reviews all findings before they are communicated; you may request an explanation of any automated finding that influences an assessment, and human-only review of your certification assessment (Section 9).
8.2 Risk Scoring
The compliance dashboard and the Insurability Readiness Score are diagnostic tools for the client's own use, based on transparent criteria tied to the SiteTrust Standard. They are not certification determinations and are not shared with third parties, including insurers or regulators, without client consent.
8.3 No Behavioral Advertising Profiles
SiteTrust does not engage in behavioral profiling for targeted advertising and does not build profiles for sale to data brokers or advertisers.
9. Your Rights
| Right | How to Exercise |
|---|---|
| Access | Request a copy of the personal information we hold about you. |
| Correction | Request correction of inaccurate or incomplete information. |
| Deletion | Request deletion, subject to legal retention obligations. |
| Portability (GDPR) | Request your data in a structured, machine-readable format. |
| Restriction / objection (GDPR) | Request limits on processing, or object to legitimate interest processing. |
| Human review of automated findings | Request qualified human review of any AI-assisted finding that materially affects your certification status. |
| California rights (CCPA/CPRA) | Request disclosure, correction, or deletion, and opt out of sale or sharing. SiteTrust does not sell or share personal information; we honor Global Privacy Control (GPC) browser signals as a valid opt-out where required. |
| Colorado rights (CPA) | Opt out of profiling in furtherance of decisions producing legal or similarly significant effects. |
| Marketing opt-out | Unsubscribe any time via the link in any marketing email or by contacting us. |
To exercise any right, contact wecare@sitetrust.com with the subject "Data Rights Request." We respond within 30 days or the period required by law, and may first require verification of your identity and, for agent requests, proof of authorization. The rights above apply only to the extent granted by the law of your jurisdiction; we may decline or limit a request where an exception applies or where a request is manifestly unfounded, repetitive, or excessive, in which case we may alternatively charge a reasonable fee as the law allows. Exercising a right does not affect fees owed for Services, and this policy itself creates no rights beyond those provided by applicable law.
10. Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Active client account data | Active plan + 3 years | Contract performance; disputes |
| Certification records | 7 years from certification date | Legal obligation; audit trail |
| Trust Center uploaded documents | Engagement + 1 year, or earlier on request | Contract performance |
| Visitor consent records (processed for clients) | Per the DPA: 5-year default from record creation | Client compliance evidence; DPA |
| CTA program records | CTA status + 5 years | Legal obligation; disputes |
| Insurance application records | As required by applicable insurance law | Legal obligation |
| Payment and billing records | 7 years | Tax and financial compliance |
| AI processing logs | 2 years from assessment date | Quality assurance; disputes |
| Marketing preferences | Until opt-out or account closure | Consent; legitimate interest |
| Website analytics data | 13 months rolling | Legitimate interest |
| Legal hold data | Duration of proceeding or inquiry | Legal obligation |
The periods above are defaults. SiteTrust may retain information longer where reasonably necessary to comply with law, resolve disputes, enforce agreements, defend legal claims, maintain security, or preserve evidence, and may retain de-identified data indefinitely. When retention ends, data is securely deleted or anonymized. Clients may request earlier deletion of uploaded documents, subject to minimum legal retention; we confirm deletion within 30 days of a valid request.
11. Cookies and Tracking Technologies
sitetrust.com runs SiteTrust Consent, the same consent layer we provide to clients: non-essential categories default to off, accept and decline carry equal prominence, and consent can be changed or withdrawn at any time through the persistent cookie settings control. We honor GPC signals. Categories in use:
| Cookie Type | Purpose and Details |
|---|---|
| Strictly necessary | Session authentication, security tokens, access control. Cannot be disabled without impairing core functionality. |
| Functional | Preferences and settings within the Trust Center, persisting across sessions. |
| Analytics | Privacy-first analytics that do not share data with advertising networks; loads only after consent. |
| No advertising cookies | SiteTrust does not use advertising cookies, retargeting pixels, or third-party tracking for advertising purposes. |
12. Cross-Border Data Transfers
SiteTrust is headquartered in the United States, and personal data is processed and stored in the United States. For transfers of EU, EEA, UK, or Swiss personal data, we rely on: EU Standard Contractual Clauses (Commission Implementing Decision 2021/914); the UK International Data Transfer Addendum; and, to the extent SiteTrust self-certifies under the EU-US Data Privacy Framework, its requirements. Clients requiring executed transfer documentation should contact wecare@sitetrust.com with the subject "EU Transfer Agreement." For AI systems used in EU-facing service delivery, we maintain the transparency documentation the EU AI Act's applicable provisions require, available on request to EU clients.
13. Data Security
Our security program includes encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, multi-factor authentication for Trust Center access, periodic security assessments and penetration testing, incident response procedures with defined notification timelines, vendor security assessments, and employee security training. No security system is impenetrable. If a breach creates risk to affected individuals, we will notify affected parties and regulators within the timeframes applicable law requires (72 hours under GDPR; as required by applicable state breach laws). Report security concerns to wecare@sitetrust.com.
14. Children's Privacy
SiteTrust's services are intended for business professionals and are not directed to individuals under 18. We do not knowingly collect personal information from minors and will delete any we learn of promptly; contact wecare@sitetrust.com if you believe a minor's information was collected.
15. Changes to This Privacy Policy
We review this policy regularly against regulatory developments and service changes. For material changes we post the updated policy with a new effective date and notify active clients and CTAs by email at least 30 days before the changes take effect; non-material clarifications are effective on posting. The current version is always available on sitetrust.com and in the Trust Center customer profile; continued use after the effective date constitutes acceptance. A version history is available upon request. This Privacy Policy is a disclosure notice, not a contract: it does not create contractual rights or remedies, does not expand any rights beyond those applicable law provides, and creates no third-party beneficiary rights.
16. How to Contact Us
| Contact Purpose | Contact Information |
|---|---|
| Privacy inquiries and data rights requests | wecare@sitetrust.com (subject: "Data Rights Request") |
| EU/UK transfer documentation | wecare@sitetrust.com (subject: "EU Transfer Agreement") |
| Security incidents | wecare@sitetrust.com |
| CEO / Data Protection Lead | Vincent Fisher | wecare@sitetrust.com |
| Mailing address | SiteTrust | 2725 Abington Road, Suite 202, Fairlawn, Ohio 44333 |
EU and UK users may lodge a complaint with their local data protection authority; we encourage you to contact us first so we can address your concern directly.