1. Who we are & how to contact us
The Service is operated by Glint Sites (“Glint”), a registered sole proprietorship based in Waterloo, Ontario, Canada.
For any privacy question, or to exercise the rights described below, contact us at [email protected]. We aim to respond within one month. The data controller of record is Aaron Kang, operating as Glint Sites.
2. Information we collect
We collect only what we need to run the Service. The categories are:
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, optional full name, optional avatar, your theme preference, and your account role. | You, at sign-up and in settings. |
| Authentication data | Your password (hashed and stored by our auth provider - we never see it) and session tokens stored in your browser. | You / your browser. |
| Billing data | Subscription status, plan, and billing identifiers. Card numbers are entered directly with our payment processor; we never receive or store your full card details. | You, via Stripe. |
| Content you create | The prompts and chat messages you send to the AI, the business details you provide, the websites generated for you (including saved versions), and images you upload. | You, while using the Service. |
| Usage & technical data | Generation activity and quota counters, error and job logs, and technical request data such as IP address, browser/device type and timestamps processed by our hosting infrastructure for security and delivery. | Automatically. |
| Domain data | If you buy a domain through us, the domain name, order and registration status, and the registrant contact details required to register it in your name (name, optional company, postal address, email, phone) - shared with our registrar partner and kept out of public WHOIS by the included privacy service, where the domain ending supports it (a small number of endings do not permit WHOIS privacy). | You / our registrar partner. |
Visitors to sites our customers publish. For each published site we operate a lightweight, cookieless page-view counter on behalf of the site owner. It records the page path, country, referrer, and device type of each visit, aggregated into daily counts, plus a pseudonymous visitor identifier derived from a hash that changes every day - we do not store visitors’ raw IP addresses in analytics and we do not track visitors across sites. If a visitor submits a contact form on a published site, we store the submitted details (such as name, email and message) and deliver them to that site’s owner, who is responsible for them from there.
Children. The Service is not directed to children. You must be at least 16 years old to use Glint, and we do not knowingly collect personal information from anyone under that age.
3. How and why we use your information
We use your information to:
- create and manage your account and authenticate you;
- generate, edit, host and publish your websites and store your images;
- process payments, subscriptions and domain purchases;
- provide support and respond to your requests;
- keep the Service secure, prevent abuse, and enforce usage limits;
- comply with our legal obligations (for example, tax record-keeping).
Legal bases (GDPR / UK GDPR). We rely on: performance of a contract for sign-up, generation, hosting, billing and domain orders; legitimate interests for security, fraud and abuse prevention, and enforcing our free-tier limit; and legal obligation for required record-keeping. We do not use your account for the core Service on the basis of consent, so you are never asked to “consent” to receive the Service itself.
AI & model training. Your prompts and content are sent to our AI provider only to generate and edit your site. We do not use your content to train our own models, and we do not permit our AI providers to use your content to train theirs.
5. International data transfers
Our providers are located primarily in the United States, so your information may be transferred outside your country (including from the EU, UK or Canada). Where required, we rely on appropriate safeguards: the EU–US and UK Data Privacy Framework for certified providers, and Standard Contractual Clauses (plus the UK Addendum) with the others. Canadian transfers are made on the basis of comparable protection and this transparency notice. You can request details of the safeguards in place by contacting us.
6. How long we keep your information
We keep your account and content for as long as your account is active. When you delete your account, we delete your account data, sites, chat history and uploaded images. We retain limited billing and transaction records for as long as required for tax and legal purposes.
When you delete a site or your account, the site stops being served immediately, and the published-site files and any public copies of your images are queued for purge from our storage, normally completing within about 48 hours.
7. Your privacy rights
Depending on where you live, you have some or all of the following rights: access a copy of your information, correct it, delete it, restrict or object to certain processing, and receive a portable copy. You also have the right to withdraw consent where we rely on it.
- EU / UK (GDPR): the rights above, and the right to lodge a complaint with your data protection authority.
- California (CCPA/CPRA) & other US states: the right to know, delete, correct, and opt out of sale/sharing. We do not sell or share your personal information, and we will not discriminate against you for exercising your rights.
- Canada (PIPEDA): the right to access and correct your information and to challenge our handling of it; you may also complain to the Office of the Privacy Commissioner of Canada.
To exercise any right, email [email protected]. You can delete your account at any time from your account settings; deletion is immediate and permanent. Because your login email cannot currently be changed in-app, contact us to correct it.
9. Security & breach notification
We use reputable infrastructure providers and reasonable technical and organisational measures to protect your information. No system is perfectly secure, but if a breach creates a real risk of harm to you, we will notify you and the relevant authorities as required by law (within 72 hours where GDPR/UK GDPR applies, and as required under PIPEDA).
10. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the “Last updated” date; material changes will be communicated to you. Continued use of the Service after an update means you accept the revised policy.