Privacy policy
Who we are
Pagebase is a website-builder service operated from Belgium. In this policy, "Pagebase", "we", "our" or "us" refers to the service. "You" refers to anyone who visits this website, registers an account, or uses the platform.
Pagebase is the data controller for the personal data described in this policy, in the sense of Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
Data we collect
Account data
When you register, we collect your email address and a hashed password (we never see or store the plain-text password). You may optionally provide a display name, profile photo, and locale preference.
Billing data
When you subscribe to a paid plan or buy a domain, payment is processed by Stripe. Pagebase receives a Stripe customer ID, plan, billing period, and invoice metadata. We do not see, store, or process your full card number, CVC, or bank details — these stay with Stripe.
Domain registration data
When you register a domain through Pagebase, the contact information required by ICANN/EURid (your name, address, email, phone) is forwarded to our registrar (Openprovider) as required by registry policy. Pagebase stores a copy for support and compliance.
Content you create
Pages, blog posts, media, components, and any other content you build with the editor are stored on our servers so we can host and publish them. This is your data: we do not analyse, mine, or use it for any purpose other than providing the service.
Usage & technical data
To operate and protect the service, we automatically collect: IP address (truncated/pseudonymised after 24 hours), browser/user-agent string, page views, request timestamps, and basic device info. We use a privacy-friendly first-party approach — no Google Analytics, no third-party advertising trackers.
Communication
If you contact us by email or through a contact form, we keep the message and your email address to respond.
How we use your data
- Provide the service — create your account, host your sites, deliver editor functionality.
- Billing — process subscriptions, send invoices, handle refunds.
- Security — detect abuse, protect against attacks, enforce rate limits.
- Support — respond to requests and resolve issues.
- Service improvement — aggregate, anonymised analytics about feature use.
- Legal compliance — keep invoices for the legally required retention period, respond to lawful requests.
- Communication — send transactional emails (verification, password reset, billing notices). Marketing emails only with explicit opt-in, and you can unsubscribe at any time.
Legal bases (GDPR Art. 6)
- Performance of a contract — for everything required to deliver the service you signed up for.
- Legal obligation — for invoice retention (7 years under Belgian tax law) and lawful requests from authorities.
- Legitimate interest — for security logging, fraud prevention, and aggregated product analytics, balanced against your rights.
- Consent — for marketing emails and any non-essential cookies (see our cookie policy). You can withdraw consent at any time.
International transfers
Most of your data stays within the EU/EEA. When AI features are used, prompts may be processed by providers (OpenAI, Anthropic) in the United States. Such transfers are covered by the EU–US Data Privacy Framework and standard contractual clauses where applicable. AI features are opt-in and clearly marked in the editor.
How long we keep your data
- Account & content — for as long as your account is active. After deletion, we keep a 30-day grace window for recovery, then permanently erase.
- Invoices & billing records — 7 years (Belgian tax law).
- Pseudonymised access logs — 12 months.
- Backups — rolling 30-day window. Deleted data persists in backups until the rolling window has cycled out.
- Support emails — 24 months after the conversation closes.
Your rights
Under GDPR Articles 15–22 you have the right to:
- Access — get a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Erasure ("right to be forgotten") — request deletion, subject to legal retention obligations.
- Restriction — limit processing in specific situations.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Not be subject to automated decisions with legal effects (we don't make any).
You can exercise most rights yourself: download your full data export from your dashboard, edit your profile, or delete your account. For other requests, email privacy@pagebase.app. We respond within one month (extendable to three months for complex requests, with notice).
Security
We use reasonable technical and organisational measures: TLS for all traffic, password hashing with modern algorithms, limited internal access on a need-to-know basis, automatic security updates, and rate-limiting on authentication endpoints. No system is 100% secure — please use a strong, unique password and report any suspected security issue to security@pagebase.app.
Children
Pagebase is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced by email and on this page at least 30 days before they take effect. The "last updated" date at the top of this page always reflects the current version.
Complaints & contact
If you have questions or concerns, contact us first at privacy@pagebase.app — we'll do our best to resolve any issue.
You also have the right to lodge a complaint with the Belgian Data Protection Authority:
Gegevensbeschermingsautoriteit / Autorité de protection des données
Drukpersstraat 35, 1000 Brussel
dataprotectionauthority.be
contact@apd-gba.be