^ PRIVACY POLICY
How we handle your data.
Pagelift is built to audit landing pages, not people. This policy explains what we collect, why, how long we keep it, and the rights you have under the GDPR.
Last updated: 2026-01-01
1. Data controller
Pagelift is currently operated by an independent founder based in Paris, France. Any personal data collected through pagelift.space is processed under the founder's responsibility.
For any privacy-related request, contact us at the email address listed below. Publisher details are available on the Legal notice page.
- Pagelift · ChrisJ Paradis
- Paris, France
- service@pagelift.space
2. What we collect and why
We only process data we need to deliver the audit service, keep the site secure, and comply with our obligations.
| Data | Purpose | Legal basis |
|---|---|---|
| Account email and password hash | Create and secure your account | Contract (GDPR Art. 6(1)(b)) |
| Uploaded page screenshot | Generate your Lift Report | Contract (GDPR Art. 6(1)(b)) |
| Audit results and history | Let you access your past reports | Contract (GDPR Art. 6(1)(b)) |
| Billing details (via payment processor) | Process subscription payments and invoices | Contract + legal obligation |
| Server logs (IP, user agent, timestamps) | Security, abuse prevention, debugging | Legitimate interest (GDPR Art. 6(1)(f)) |
| Support messages you send us | Answer your request | Legitimate interest |
| Analytics events (if you consent) | Understand which features help most | Consent (GDPR Art. 6(1)(a)) |
| Marketing attribution (if you consent) | Measure the effectiveness of our ads | Consent (GDPR Art. 6(1)(a)) |
3. Screenshots you upload
When you upload a landing-page screenshot, the image is sent to OpenAI's API (GPT-4o vision) so we can generate your Lift Report. Under OpenAI's API data policy, API inputs and outputs are not used to train OpenAI's models, and are retained by OpenAI for up to 30 days for abuse and misuse monitoring before deletion.
On the anonymous demo path (pagelift.space/demo), we do not store your screenshot on our servers at all — it is passed through to the audit engine and discarded once your report is returned.
For signed-in accounts, we store your screenshot privately in your workspace so you can re-open the report and compare scores over time. You can delete an individual audit at any time from your history, or delete your account (which erases every screenshot and audit within 30 days).
4. Retention
We keep personal data only as long as we need it for the purpose it was collected.
| Data | Retention |
|---|---|
| Uploaded screenshot | Deleted after your Lift Report is generated |
| Lift Report contents (scores, rewrites) | Kept while your account is active, then deleted 30 days after account closure |
| Account data | Kept while your account is active, then deleted 30 days after account closure |
| Billing and invoices | 10 years, to meet French accounting obligations |
| Server and security logs | 12 months maximum |
| Support messages | 3 years from the last contact |
| Analytics events (with consent) | 13 months maximum |
5. Recipients and transfers
Personal data is accessed by the Pagelift founder and by the sub-processors we rely on to operate the service (hosting, email delivery, payment processing, error monitoring).
Where data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses or an equivalent legal mechanism. A current list of sub-processors is available on request.
6. Your rights under the GDPR
As a data subject in the European Union, you have the following rights. You can exercise any of them by writing to us; we respond within one month.
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure — ask us to delete your data where legal grounds allow.
- Right to restriction of processing — ask us to pause processing in specific cases.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on our legitimate interests, including profiling.
- Right not to be subject to solely automated decisions producing legal effects.
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing.
7. Right to lodge a complaint
If you consider that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the French supervisory authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, 75007 Paris, cnil.fr.
8. Security measures
- Encryption of data in transit via TLS across all endpoints.
- Encryption of data at rest on our infrastructure providers.
- Least-privilege access controls and audit logs for internal systems.
- Automatic deletion of uploaded screenshots after audit generation.
- Regular dependency and infrastructure security updates.
- Incident response process with notification obligations under GDPR Art. 33–34.
9. Cookies
We use a minimum of cookies. Details, categories, and durations are documented on our Cookies page, where you can also change your consent at any time.
10. Changes to this policy
We may update this policy to reflect changes to the service or the law. The date at the top of the page indicates the most recent revision.
These pages are templates for a pre-launch product. They are not legal advice. We will have them reviewed by counsel before charging customers.