1. Introduction
This Privacy Policy explains how CloudMySite collects, uses, stores, discloses, and protects information when you use CloudMySite websites, dashboards, hosting, AI tools, newsletter tools, forms, support, documentation, APIs, and related services.
This Privacy Policy applies to cloudmysite.com, cloudmysite.ai, newsletter.cloudmysite.com, docs.cloudmysite.com, support.cloudmysite.com, CloudMySite dashboards, APIs, forms, and related services that link to this policy.
2. Our Role: Controller, Business, Processor, and Service Provider
For account, billing, support, website visitor, product usage, marketing, and security data, CloudMySite generally acts as the data controller or business that determines how and why the data is processed.
For subscriber lists, imported contacts, newsletter campaign recipients, customer website visitors, form submissions, customer store data, and other data you process through CloudMySite on behalf of your own users or customers, you are generally the controller/business and CloudMySite acts as your processor/service provider.
If you need a Data Processing Addendum (DPA), CloudMySite should provide one at Data Processing Addendum or through your account or order process.
3. Information We Collect
CloudMySite may collect the following categories of information depending on how you use the Services.
3.1 Account and Identity Information
Name, email address, phone number, business name, login credentials, authentication details, workspace role, profile settings, organization details, and account preferences.
3.2 Billing and Transaction Information
Plan, invoice, payment status, billing address, tax information, subscription status, order history, refunds, credits, usage charges, and payment processor tokens or references. CloudMySite should not directly store full payment card numbers unless expressly stated and PCI-compliant.
3.3 Workspace, Team, and Permission Information
Workspace IDs, team member emails, roles, invitations, ownership details, project permissions, audit events, login activity, admin actions, and collaboration history.
3.4 Website, Hosting, and Deployment Data
Site names, repositories, uploaded files, generated pages, templates, domains, DNS configuration, SSL status, deployment logs, build logs, assets, static files, database records, storage paths, traffic logs, request logs, error logs, and related metadata.
3.5 AI Inputs and Outputs
Prompts, instructions, uploaded files, generated websites, generated images, logos, favicons, copy, pages, newsletter drafts, design preferences, conversation context, AI job metadata, status, and results.
3.6 Newsletter and Email Data
Publications, campaigns, subject lines, content, templates, subscriber lists, imported CSV/TSV data, tags, segments, automations, unsubscribe status, suppression lists, bounce/complaint data, delivery logs, opens/clicks where enabled, sender domains, DNS records, and email authentication status.
3.7 Forms, Leads, and Submissions
Form IDs, field labels, submitted values, IP address, user agent, timestamps, Turnstile/CAPTCHA signals, honeypot data, spam signals, source page, and delivery status.
3.8 Store, Shopping, and Product Data
If you use shopping or product features, CloudMySite may process product names, descriptions, prices, images, order metadata, customer information, checkout metadata, fulfillment notes, return/refund status, and payment processor references. Customers using CloudMySite to operate a store are responsible for their own customer privacy disclosures.
3.9 Support and Communications
Support tickets, bug reports, chat messages, emails, call notes, attachments, screenshots, diagnostic information, feedback, survey responses, and internal support notes.
3.10 Device, Usage, Analytics, and Security Information
IP address, device identifiers, browser type, operating system, pages viewed, referring URLs, timestamps, log events, cookies, analytics events, approximate location, session data, feature usage, performance metrics, abuse signals, and security telemetry.
3.11 Third-Party Integration Data
Data from or sent to connected services such as GitHub, Cloudflare, AWS, domain providers, payment processors, email providers, AI providers, analytics tools, authentication providers, support systems, or other integrations you authorize.
4. How We Use Information
CloudMySite uses information to:
- Provide, operate, maintain, secure, and improve the Services.
- Create and manage accounts, workspaces, roles, billing, support, and subscriptions.
- Host, deploy, publish, and serve websites and content.
- Generate AI-assisted content, images, websites, logos, favicons, drafts, and design outputs.
- Send newsletters and transactional emails on behalf of customers.
- Process subscriber imports, unsubscribes, bounces, complaints, and suppression lists.
- Provide forms, lead capture, spam filtering, Turnstile/CAPTCHA checks, and delivery features.
- Process orders, returns, refunds, billing, taxes, and payment disputes.
- Diagnose bugs, monitor performance, prevent abuse, investigate security incidents, and enforce policies.
- Communicate about support, security, billing, product updates, legal notices, and service announcements.
- Analyze product usage, improve features, conduct research, and develop new products.
- Comply with law, legal process, audits, reporting, and regulatory obligations.
5. Legal Bases for Processing
Where GDPR, UK GDPR, or similar laws apply, CloudMySite may rely on one or more legal bases, including:
- Performance of a contract to provide the Services.
- Legitimate interests, such as security, fraud prevention, support, product improvement, and business operations.
- Consent, such as certain marketing communications, cookies, or optional features.
- Legal obligations, such as tax, accounting, compliance, law enforcement, and dispute handling.
Customers are responsible for identifying and documenting their own legal bases for processing subscriber, lead, store customer, and website visitor data they collect through CloudMySite.
6. How We Share Information
CloudMySite may share information with:
- Cloud infrastructure, CDN, storage, database, DNS, security, and hosting providers.
- Payment processors and billing providers.
- Email delivery, validation, abuse monitoring, and deliverability providers.
- AI model, image generation, inference, moderation, and related providers.
- Analytics, logging, monitoring, and error tracking providers.
- Support, ticketing, communication, CRM, and documentation providers.
- Domain registrars, DNS providers, repository providers, and deployment platforms.
- Professional advisors, auditors, insurers, legal counsel, and compliance vendors.
- Law enforcement, regulators, courts, or other parties where required by law or necessary to protect rights and safety.
- Acquirers or successors in connection with a merger, acquisition, financing, restructuring, or sale of assets.
- Other users in your workspace according to roles and permissions you configure.
CloudMySite does not sell subscriber lists uploaded by customers. CloudMySite does not use customer subscriber lists to send CloudMySite marketing unless the subscriber separately interacts with CloudMySite or gives permission.
7. Subprocessors and Third-Party Providers
CloudMySite uses subprocessors and service providers to operate the Services. The list should be maintained at Subprocessors.
The list may include, depending on current architecture and configuration:
- Cloudflare for CDN, Workers, Pages, DNS, R2, D1, KV, Turnstile, analytics, security, and hosting-related services.
- Amazon Web Services for email delivery, cloud infrastructure, storage, queues, APIs, logs, compute, or related services.
- GitHub for source repositories, deployments, and customer-connected code workflows.
- AI/model/image providers used by CloudMySite AI features, such as Alibaba Cloud/DashScope or other providers configured by CloudMySite.
- Payment processors such as Stripe, PayPal, Razorpay, or other processors actually used by CloudMySite.
- Analytics, monitoring, error tracking, support, email, and communication providers actually used by CloudMySite.
The subprocessor page should include provider name, purpose, location if known, data type, and link to provider privacy/DPA page. Keep it editable as vendors change.
8. Cookies and Tracking
CloudMySite may use cookies, local storage, pixels, and similar technologies to:
- Keep you signed in.
- Remember preferences.
- Secure accounts and prevent fraud.
- Analyze website and product usage.
- Measure performance and diagnose errors.
- Support marketing, attribution, or advertising where enabled.
You can manage cookies through your browser or CloudMySite cookie settings where available. Some cookies are necessary for the Services to work.
CloudMySite publishes a Cookie Policy describing categories of cookies, purposes, and choices.
9. Customer Websites, Newsletters, and Forms
If you use CloudMySite to publish a website, newsletter, form, unsubscribe page, shopping page, or other customer-facing experience, you are responsible for providing your own privacy notices, consent language, terms, cookie notices, email disclosures, return/refund terms, and legal policies to your visitors, subscribers, customers, and end users.
CloudMySite may provide default templates, but you must review and customize them for your business and legal requirements.
10. Email Compliance and Unsubscribes
CloudMySite processes unsubscribe requests, suppression lists, bounces, complaints, and delivery events to provide newsletter and email services, comply with email laws, protect sender reputation, and prevent abuse.
Customers must not remove, bypass, hide, or interfere with unsubscribe mechanisms required by CloudMySite or law.
CloudMySite may retain suppression data as necessary to ensure unsubscribed contacts are not emailed again through the Services.
11. AI Data Handling
CloudMySite may process prompts, uploaded files, generated outputs, and related metadata to provide AI features, troubleshoot, prevent abuse, and improve the Services.
AI data may be sent to third-party AI providers, image providers, infrastructure providers, or moderation services as necessary to fulfill your request.
Do not submit sensitive personal data, regulated data, confidential information, trade secrets, payment card data, health information, children's data, or government IDs into AI features unless your plan and agreement expressly allow it and appropriate safeguards are in place.
12. Data Security
CloudMySite uses administrative, technical, and organizational safeguards designed to protect information, such as access controls, authentication, encryption where appropriate, logging, provider security controls, network protections, and abuse monitoring.
No method of transmission or storage is completely secure. You are responsible for securing your account, passwords, API keys, secrets, domains, DNS records, repositories, team access, and customer systems.
13. Data Retention
CloudMySite retains information for as long as reasonably necessary to provide the Services, comply with law, resolve disputes, enforce agreements, prevent abuse, maintain security, process billing, support customers, and maintain backups.
Example retention rules to implement or document:
- Account and billing records: retained while the account is active and as needed for tax, accounting, fraud prevention, and legal purposes.
- Workspace and project data: retained while active; may be deleted after cancellation, inactivity, or nonpayment according to product rules.
- Free/trial inactive projects: may be archived or deleted after 6 months of inactivity with notice where feasible.
- Newsletter suppression/unsubscribe data: retained as needed to honor opt-outs and prevent unlawful sending.
- Logs and security data: retained for security, debugging, compliance, and abuse prevention, typically for a limited period unless needed longer.
- Backups: may persist for a limited period after deletion before being overwritten.
14. International Transfers
CloudMySite and its providers may process information in the United States and other countries where CloudMySite or its subprocessors operate. Where required, CloudMySite will use appropriate transfer safeguards, such as contractual protections or other lawful mechanisms.
15. Your Privacy Rights
Depending on your location and applicable law, you may have rights to:
- Access personal information.
- Correct inaccurate information.
- Delete information.
- Obtain a copy of information.
- Restrict or object to certain processing.
- Withdraw consent where processing is based on consent.
- Opt out of certain marketing communications.
- Opt out of sale, sharing, targeted advertising, or profiling where applicable.
- Limit use of sensitive personal information where applicable.
- Appeal a denied privacy request where applicable.
To exercise rights, contact [email protected] or use account settings where available.
CloudMySite may need to verify your identity and authority before fulfilling requests. Some data may be retained where permitted or required for legal, security, fraud prevention, billing, dispute, backup, or compliance reasons.
16. California Privacy Notice
Where the CCPA/CPRA applies, California residents may have rights to know/access, delete, correct, opt out of sale/share, limit certain uses of sensitive personal information, and be free from discrimination for exercising privacy rights.
CloudMySite should disclose categories of personal information collected, categories of sources, purposes, categories of recipients, retention periods, and whether information is sold or shared as those terms are defined by California law.
Draft position for MVP:
- CloudMySite does not sell customer subscriber lists.
- CloudMySite does not sell personal information for money.
- If CloudMySite uses targeted advertising or analytics that constitute "sharing" under California law, CloudMySite should provide a "Do Not Sell or Share My Personal Information" mechanism.
- Sensitive personal information should be used only as necessary to provide Services, security, compliance, or support unless otherwise disclosed.
TODO: Add a visible footer link if legal counsel confirms CCPA/CPRA applies or if ad/analytics sharing is enabled.
17. Texas and Other U.S. State Privacy Notices
Where applicable, residents of Texas and other U.S. states with consumer privacy laws may have rights to access, correct, delete, obtain a copy, opt out of targeted advertising/sale/profiling, and appeal certain decisions.
CloudMySite should provide a privacy request workflow and maintain internal records of request handling.
18. GDPR, UK GDPR, and EEA/UK Users
Where GDPR or UK GDPR applies, individuals may have rights of access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority.
If CloudMySite processes personal data on behalf of a customer, the customer is responsible for responding to requests from its own visitors, subscribers, form submitters, and store customers unless the DPA states otherwise. CloudMySite will provide reasonable assistance as required by the DPA.
19. Children's Privacy
The Services are not directed to children under 13, and CloudMySite does not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to CloudMySite, contact [email protected] so CloudMySite can take appropriate action.
Customers may not use CloudMySite to operate child-directed services or collect children's personal information unless they have all required parental consent, notices, legal bases, security controls, and written approval from CloudMySite.
20. Marketing Communications
CloudMySite may send you product updates, newsletters, promotions, events, and other marketing communications if permitted by law. You can opt out by using the unsubscribe link or contacting CloudMySite.
CloudMySite may still send transactional, service, billing, security, legal, and account-related messages.
21. Legal Requests and Safety
CloudMySite may disclose information when required by law, subpoena, court order, government request, or legal process, or when CloudMySite believes disclosure is necessary to protect users, the public, CloudMySite, providers, or others from fraud, abuse, security threats, illegal activity, or harm.
22. Business Transfers
If CloudMySite is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality and legal protections.
23. Changes to This Privacy Policy
CloudMySite may update this Privacy Policy from time to time. Updated versions will be posted with a new effective date. CloudMySite may also notify users through email, dashboard notices, or other reasonable means where required.
24. Contact
Privacy questions and requests may be sent to: