1. Introduction & Scope

Sitemap.xml ("we", "our", or "us") is committed to transparency regarding how we handle information. This document outlines our data collection practices, sharing protocols, security standards, and your rights under applicable privacy laws including GDPR, CCPA/CPRA, and LGPD.

This policy applies to all users of our platform, APIs, SDKs, browser extensions, and hosted services. By using Sitemap.xml products, you acknowledge and agree to the practices described herein.

â„šī¸ Note for Enterprise Clients

Enterprise agreements may include Data Processing Agreements (DPAs) and custom retention schedules. These terms supplement, and in case of conflict, supersede this general disclosure.

2. Data We Collect

2.1 Directly Provided Information

We collect information you explicitly provide when registering, configuring projects, or contacting support:

  • Account details (email, organization name, billing information)
  • API keys, webhook endpoints, and authentication tokens
  • Manual sitemap submissions and URL exclusion lists
  • Support tickets and communication logs

2.2 Automatically Collected Data

When you interact with our platform, we automatically receive and record:

  • Domain URLs and subdomains you authorize us to scan
  • Crawl metadata (HTTP status codes, content types, last-modified timestamps)
  • API usage metrics, rate limits, and endpoint latency
  • Device and browser telemetry for dashboard analytics (no PII stored)
âš ī¸ Important: We Do Not Store Page Content

Sitemap.xml only indexes structural metadata required for sitemap generation. We do not cache, store, or analyze the actual content of your web pages, nor do we use your site's content for training machine learning models.

3. How We Use Your Data

Your information is processed strictly to deliver and improve our services:

  • Service Operation: Generating, updating, and hosting XML/HTML sitemaps per your configuration.
  • Indexing Submissions: Pushing URL updates to search engine APIs (Google, Bing, Yandex, Baidu) on your behalf.
  • Platform Integrity: Detecting abuse, preventing API abuse, and ensuring fair resource allocation.
  • Product Improvement: Aggregated, anonymized telemetry to optimize crawl efficiency and API throughput.
  • Communications: Sending security alerts, service notices, and compliance updates. Marketing emails require explicit opt-in.

4. Third-Party Disclosures & Integrations

We only share or transmit data with third parties when necessary for service delivery, legal compliance, or with your explicit consent:

  • Search Engines: URL lists and metadata are submitted exclusively to major search engine indexing APIs as configured in your dashboard.
  • Cloud Infrastructure: AWS, Cloudflare, and edge CDN providers for hosting, DDoS protection, and global delivery. All vendors are SOC 2 Type II certified.
  • Billing & Payment: Stripe and Paddle process transactions. We never store full credit card numbers.
  • Analytics & Monitoring: Datadog and Sentry are used for uptime tracking and error debugging. Session replay is disabled by default.

Data is never sold, rented, or shared with data brokers. Cross-border transfers comply with EU Standard Contractual Clauses (SCCs) and Swiss adequacy decisions.

5. Security & Encryption Standards

We implement industry-leading security controls to protect your data and configurations:

  • Encryption: AES-256 for data at rest; TLS 1.3 for data in transit. API keys are hashed using bcrypt before storage.
  • Access Control: Role-based access control (RBAC), mandatory 2FA for admin accounts, and principle of least privilege for internal teams.
  • Infrastructure: Isolated VPCs, automated vulnerability scanning, and quarterly third-party penetration testing.
  • Incident Response: 24/7 security monitoring with a documented incident response plan. Customers will be notified within 72 hours of any confirmed breach affecting their data.
# Security headers applied to all API endpoints Strict-Transport-Security: max-age=31536000; includeSubDomains Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' X-Content-Type-Options: nosniff X-Frame-Options: DENY

6. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access & Portability: Request a copy of all personal data we hold in a machine-readable format.
  • Rectification: Update or correct inaccurate account or billing information.
  • Erasure: Delete your account and associated data, subject to legal retention requirements.
  • Opt-Out: Manage marketing communications and analytics preferences via your dashboard or by replying to emails.
  • Restriction & Objection: Limit processing activities or object to automated decision-making where applicable.

California residents: You have additional rights under the CCPA/CPRA, including the right to know, delete, and opt-out of the sale or sharing of personal information. We do not sell personal data.

7. Data Retention & Deletion

We retain data only as long as necessary to fulfill the purposes outlined in this policy:

  • Active Accounts: Configuration data, API keys, and sitemap history are retained indefinitely while your account is active.
  • Cancelled Accounts: All user data is permanently deleted within 30 days of account cancellation, except billing records retained for 7 years per tax compliance requirements.
  • Support Logs: Retained for 24 months for quality assurance and dispute resolution.
  • Aggregated Metrics: Anonymized usage data may be retained indefinitely for product research and infrastructure planning.

Upon deletion requests, we purge data from primary databases, backups, and CDN caches within 90 days. You may request immediate cache purging by submitting a formal deletion request.

8. Contact & Data Requests

For questions about this policy, to exercise your rights, or to report a security concern, please contact us through the appropriate channel:

📧 Privacy & Data Requests

privacy@sitemap.xml

Response within 5 business days

🔒 Security & Vulnerabilities

security@sitemap.xml

Bug bounty program available

📋 Legal & Compliance

legal@sitemap.xml

DPAs, SCCs, and audit requests

Sitemap.xml Inc. â€ĸ 100 Innovation Drive, Suite 400 â€ĸ San Francisco, CA 94105 â€ĸ United States