Privacy
What we hold, why, and how to make us delete it.
Written to be read. If anything here is unclear, that is a fault in the page and we would like to know about it.
Not ready to publish. The operator’s legal name
and registered address are not filled in. Set them in
tools/build_site.py and rebuild before this domain is made
public — a privacy policy that does not identify the controller does
not do its job.
Last updated 19 September 2026.
Who we are
Plumbline is operated by [LEGAL ENTITY NAME], of [REGISTERED ADDRESS], [JURISDICTION]. For anything in this policy, write to hello@plumbline-lb.com.
Two different relationships
This matters, because it decides who is answerable for what.
For your agency’s own account, we are the controller. Your name, your email address, your sign-in — we decide how those are used, and this policy governs them.
For the sites you ask us to watch, we are a processor acting for you. You are the controller. We check the sites you nominate, store the results, and act on your instructions. If a screenshot of your client’s site contains a member of their staff, that person’s relationship is with you, and we handle it on your behalf.
A Data Processing Agreement covering the second relationship is available to any customer who asks.
What we collect
- Your account
- Email address, a hashed password (Argon2id — we never store the password itself), the name of your agency, and which of your colleagues you have invited.
- The sites you monitor
- Their addresses, the client you grouped them under, and the verification token proving you control them.
- Check results
- For every check: when it ran, whether it passed, and the request we made with the response we received. This evidence is the product — a result you cannot inspect is not one you should believe.
- Screenshots
- Pictures of the public pages we check, as any visitor would see them. These may incidentally contain personal data — a name, a photograph, a testimonial on a homepage. We do not look for it and we do not index it, but it is in the image, which is why the retention limit below exists.
- Where your alerts go
- The email addresses you nominate, and a Slack webhook if you set one up. The webhook is encrypted at rest and is never shown back to you or written to a log.
- If you join the waitlist
- Your email address, your agency name if you give it, and a rough count of the sites you look after.
- Ordinary server logs
- IP addresses and requests, kept briefly, for security and debugging.
What we never collect
- Card or bank details. No payment processor is in use, and when one is, card numbers will not reach our servers.
- Anything from inside your clients’ systems. We have no access to them and ask for none.
- Anything from behind a login on the sites we watch.
- Analytics about your browsing. This website runs none.
Why we are allowed to hold it (lawful basis)
- Performance of a contract — your account, the sites you asked us to watch, the results, the alerts. Without these there is no service.
- Legitimate interests — server logs and security measures, to keep the service running and to stop it being abused.
- Consent — the waitlist. You asked to hear from us, and you can ask us to forget you at any time.
- Legal obligation — anything we are required to keep, such as records relating to tax once we are charging money.
How long we keep it
These are the periods the system actually enforces, not aspirations.
- Check results — 13 months
- So that a monthly report always has a full year to compare against.
- Screenshots — 90 days
- Except one attached to an incident that is still open, or one you approved as a baseline to compare future checks against. This shorter period exists precisely because of the incidental personal data described above.
- A deleted client — purged within 30 days
- Delete a client and everything belonging to them goes: sites, results, screenshots, incidents, reports.
- Your account
- Kept while the account is open. Ask us to close it and the same thirty-day purge applies to all of it.
- Waitlist entries
- Kept until you ask us to remove you, or until we conclude we are never going to get to you — whichever comes first.
Who else sees it
A short list, on its own page: sub-processors. In summary: Render hosts everything, in Frankfurt; a mail provider delivers the email we send. We do not sell data, we do not share it for advertising, and there is no analytics provider on any page of this site.
We would disclose data if legally compelled. If that happens and we are permitted to tell you, we will.
Where it is
The application, the worker and the database run in Frankfurt, Germany, inside the EU. If that ever changes, or if a sub-processor outside the EU or UK is added, this page and the sub-processors page will say so before it happens, with the safeguard relied on named.
Cookies
This website sets no cookies at all and runs no analytics, which is why you were not asked to consent to anything.
The application at app.plumbline-lb.com sets one strictly
necessary cookie to keep you signed in. It is HttpOnly,
Secure and SameSite, it carries no tracking,
and there is no version of a signed-in application that works without
one.
Your rights
If you are in the UK or the EU, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete it;
- restrict what we do with it, or object to it;
- hand it to you, or to someone else, in a portable format.
Write to hello@plumbline-lb.com. We will respond within one month. We will not charge you and we will not ask you why.
If a screenshot we hold contains a picture of you and you are not our customer, write to the same address. You do not need to know which agency asked us to check the page — tell us the address of the page and we will find it.
If you think we have handled your data badly, you are entitled to complain to a data protection supervisory authority in your country. We would rather you told us first, but that is your right and not conditional on anything.
If something goes wrong
If there is a breach affecting personal data we hold, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell affected customers directly — including when we do not yet have the full picture. A late notification that is complete is worse than an early one that is honest about its gaps.
Changes to this policy
The date at the top is the last time it changed. If we change something that matters — a new sub-processor, a longer retention period, a new category of data — account owners get an email. We will not make a material change quietly and rely on you re-reading the page.