How We Use Your Information
1. Introduction
At Sitemap.xml, we are committed to transparency and responsible data stewardship. This document outlines how we collect, process, store, and use information when you interact with our platform, APIs, and support services.
We design our data practices to align with your goals as a developer or business owner. Our systems are built to process only what is necessary to deliver reliable sitemap generation, indexing optimization, and platform analytics.
2. Information We Collect
We collect information to maintain the integrity and performance of our services. This falls into three primary categories:
- Account & Profile Data: Email address, username, billing details, and organization name for authentication and service management.
- Platform & Usage Data: API keys, request logs, URL submission history, crawl frequency preferences, and dashboard interaction metrics.
- Technical & Infrastructure Data: IP addresses, device/browser fingerprints, error logs, and performance telemetry required to secure our network and optimize delivery.
🔒 Note on Third-Party Data
We do not scrape or collect personal data from your website's visitors. We only process the URLs, metadata, and sitemap structures you explicitly authorize us to manage.
3. How We Use Your Information
Your data is utilized strictly to power our core services and improve platform reliability:
- Service Delivery: Generating, updating, and submitting XML/HTML sitemaps to search engines and indexing pipelines.
- Platform Optimization: Analyzing request patterns to improve API throughput, reduce latency, and prevent abuse.
- Security & Compliance: Detecting unauthorized access, verifying API credentials, and maintaining audit logs for regulatory compliance.
- Customer Support: Responding to tickets, debugging integration issues, and providing technical guidance.
- Product Development: Aggregating anonymized usage trends to develop new features, improve documentation, and prioritize roadmap items.
We do not use your information for behavioral advertising, sell your data to brokers, or share it for marketing purposes without explicit consent.
4. Sharing & Third-Party Services
We partner with trusted infrastructure and service providers to operate securely. Data is only shared when necessary to fulfill your requests or maintain platform functionality:
- Cloud Hosting & CDN: AWS, Cloudflare, and Fastly for secure storage, distribution, and DDoS protection.
- Analytics & Monitoring: Datadog and Sentry for error tracking, uptime monitoring, and performance diagnostics.
- Billing & Payments: Stripe and Paddle for secure transaction processing. We never store full card details.
- Search Engine APIs: Direct submission pipelines to Google Search Console, Bing Webmaster Tools, and Yandex Webmaster.
All third-party vendors are bound by strict data processing agreements and undergo regular security audits. We do not grant partners ownership or unrestricted access to your data.
5. Security & Data Retention
We implement industry-standard technical and organizational measures to protect your information:
- End-to-end TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest in our databases and backups
- Role-based access control (RBAC) and multi-factor authentication for internal systems
- Regular penetration testing and automated vulnerability scanning
Retention Policy: We retain active account data for the duration of your subscription. Upon cancellation, data is scheduled for secure deletion within 30 days, except where required for legal compliance, billing disputes, or security investigations. Archived logs may be retained in anonymized form for up to 12 months.
6. Your Rights & Choices
Depending on your jurisdiction, you may have the right to:
- Access, export, or correct your personal data via the dashboard or support request
- Request deletion of your account and associated data
- Opt out of non-essential communications (we will always send service/transactional alerts)
- Lodge a complaint with a relevant data protection authority
To exercise these rights, log into your account settings or contact our privacy team directly. We will respond to valid requests within 30 business days.
7. Policy Updates
As our platform evolves, we may update this document to reflect changes in technology, regulations, or business practices. Material changes will be communicated via email or in-app notification at least 14 days before they take effect. Continued use of our services after updates constitutes acceptance of the revised terms.
8. Contact Us
If you have questions about how we use your information, need assistance with data requests, or want to discuss compliance requirements, please reach out:
📧 Privacy & Support Team
Email: privacy@sitemap.xml
Security Reports: security@sitemap.xml
Mailing: Sitemap.xml Inc., 100 Tech Plaza, Suite 400, San Francisco, CA 94105