This Privacy Policy explains how SiteLog ("we", "us", "our") collects, uses, stores, and discloses personal information when you use our website at sitelog.uk and our SiteLog mobile application (collectively, the "Service"). By using the Service you agree to the practices described in this policy.
1. Who we are
SiteLog is a construction site management platform operated by Crintea LTD. We are the data controller for the personal information described below. We are registered with the UK Information Commissioner's Office (ICO) under registration reference C1968621. Contact details are at the bottom of this page.
2. What information we collect
2.1 Account information
When your administrator creates an account for you, we collect:
- Full name
- Email address
- Role (worker, admin, superadmin, master admin)
- Company affiliation
2.2 Location data
The SiteLog mobile application can capture your device location, but only in the foreground and only at the moment you carry out a specific action:
- At the point of an action - when you take a site photo, sign a compliance form, or submit a timesheet, your current location is captured at that single moment to verify the action took place on site.
We do not track your location continuously and we do not collect location in the background or while the app is closed or your phone is locked. Location is used solely for on-site verification and to show where a captured item was recorded on your team's internal project map. We never share location data with third parties for advertising or any commercial purpose.
2.3 Photos and uploaded files
When you take or upload site photos, signature images, or other files through the Service, we collect and store the file along with metadata (timestamp, GPS coordinates, the project and worker it relates to). Photos are visible only to authorised users in your company.
2.4 Operational data
We record information about your use of the Service necessary for it to work, including:
- Timesheet entries (project, date, hours, status)
- Compliance task submissions (form answers, signatures, GPS, timestamp)
- Job session activity (which stage of work you are in)
- Project assignments
2.5 Device and technical information
We may automatically collect basic technical information when you use the Service, such as device type, operating system, app version, and approximate IP-derived region for security and diagnostic purposes.
3. How we use your information
We use the information we collect to:
- Provide the Service and let you sign in
- Verify on-site attendance for compliance and payroll purposes
- Show where site actions were recorded on the project map for authorised members of your company
- Allow administrators to review and approve timesheets, photos, and compliance submissions
- Send in-app and push notifications when tasks are assigned, timesheets are approved, or other events occur
- Maintain the security and integrity of the Service
- Comply with legal obligations
4. Lawful basis for processing (UK and EU users)
We rely on the following lawful bases under the UK GDPR and EU GDPR:
- Contract — processing necessary to perform the employment- or contractor-related services that your company has engaged us for (timesheets, compliance, attendance verification).
- Legitimate interests — verifying that work occurred on site, preventing fraud, and providing administrators with the operational visibility they need.
- Consent - for device location capture and push notifications, which are requested on first use and can be revoked at any time in your device settings.
- Legal obligation — where we are required to retain records for tax, employment, or health and safety law.
5. Data sharing
We do not sell your personal information. We share data only as follows:
- Within your company — your name, photos, location, timesheets, and compliance submissions are visible to administrators and authorised members of the company you work for.
- Service providers - we use Supabase (database hosting, located in the European Union, Ireland) and Cloudflare R2 (file storage) to run the Service. Each provider is bound by a data processing agreement and processes data only on our instructions.
- HM Revenue and Customs (HMRC) - where your company uses SiteLog's tax features (Making Tax Digital for VAT and CIS), we transmit the relevant return figures to HMRC through their official APIs on your authorised instruction. HMRC also requires us to send technical "fraud prevention" header data with each request (such as your public IP address, a device identifier, and screen, window and timezone information). This is mandated by HMRC to help prevent fraud and is sent only to HMRC.
- Legal requirements - we may disclose information if required by law, court order, or to protect the rights, property, or safety of users or others.
6. Data retention
We retain your personal information for as long as your account is active and for a reasonable period afterwards to comply with legal, tax, and audit requirements (typically up to 6 years for employment and tax records). Location history older than 12 months is automatically deleted unless required for an ongoing dispute.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your information ("right to be forgotten")
- Object to or restrict processing
- Receive a copy of your data in a portable format
- Withdraw consent (e.g. for location tracking or notifications) at any time
- Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk
To exercise any of these rights, contact us at the email below. Note that some data may be retained where we have a legal obligation to keep it (e.g. completed timesheets for tax purposes).
8. Security
We implement appropriate technical and organisational measures to protect your information, including encryption in transit (HTTPS), encryption at rest, role-based access controls, and Supabase's row-level security policies. No system is perfectly secure, but we work to minimise risk.
9. Children
The Service is intended for working adults and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Where your data is stored and international transfers
Your account and operational data are stored in the European Union (Supabase, Ireland) and your files are stored on Cloudflare R2. The EU benefits from a UK adequacy decision, so no additional transfer mechanism is required for UK users. Where any provider processes data outside the UK and EU, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses.
11. Cookies and analytics
We use a small number of essential cookies and similar storage that are strictly necessary to run the Service — for example to keep you signed in and to operate the live demo. These do not require consent.
We only use analytics or marketing cookies with your consent. When you first visit our website you are asked to choose "Accept all" or "Essential only"; nothing non-essential runs until you accept, and you can change your choice at any time via the cookie banner. If you accept, we may record coarse, non-identifying information such as the referring site and campaign parameters to understand which channels bring people to SiteLog.
12. Live demo
Our "Try it live" demo drops you into a private, pre-populated sample company so you can explore the platform without signing up. Each demo is isolated to you — no other visitor can see it — and everything in it is permanently deleted when you leave or after a period of inactivity. We do not ask for any personal details to start a demo. For product analytics we keep only coarse, non-identifying session information (such as approximate country from your connection, session duration, and — with your consent — referrer and campaign parameters). We do not store your IP address against the demo, and any data you enter while exploring is destroyed with the demo.
13. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect when. For material changes (such as new categories of data) we will notify you within the app or by email.
14. Contact us
Email: hello@sitelog.uk
Postal address: Crintea LTD, United Kingdom
ICO registration reference: C1968621