Privacy Policy
Last updated: 25 September 2026
This policy explains what personal data Check My Sitemap ("we", "us") collects when you use checkmysitemap.com, why, and the choices you have.
What we collect
- Your Google account basics. When you sign in with Google we receive your name, email address and a Google account identifier. We do not receive your password, contacts, files or any other Google data.
- What you submit. The website addresses you ask us to audit, and the audit results. These come from publicly available web pages.
- Payment records. Payments are processed by Stripe. We receive the payment status, amount, currency and Stripe reference numbers. We never see or store your card details.
- Technical data. A single session cookie that keeps you signed in, and standard server logs (IP address, browser user agent, time of request) used to keep the service secure.
How we use it
- To sign you in and keep your reports private to your account.
- To run the audits you request and show you the results.
- To email you about your audits (started, finished or failed).
- To process payments for full reports.
- To prevent abuse, for example by limiting how many audits an account can run.
We do not sell your data, use it for advertising, or send marketing emails.
Google user data
We use the name and email address from your Google account only to identify you when you sign in and to send you notifications about your own audits. Check My Sitemap's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We don't transfer this data to others except as needed to provide the service (see below), and we don't use it for advertising.
Who processes data for us
- Hostinger hosts our servers and database.
- Stripe processes payments.
- Google provides sign-in.
- Our email provider delivers notification emails.
Some of these providers may process data outside the European Economic Area. Where they do, they rely on safeguards recognised under EU law, such as the European Commission's Standard Contractual Clauses.
Legal basis (EU/UK GDPR)
We process your data to provide the service you asked for (contract), and to keep the service secure and prevent abuse (our legitimate interests).
Cookies
We use one strictly necessary cookie to keep you signed in. We don't use analytics or advertising cookies.
How long we keep it
We keep your account and audit reports until you ask us to delete them. Server logs are kept for a limited period for security purposes and then deleted.
Your rights
You can ask us to access, correct, export or delete your personal data, or object to how we process it. If you are in the EU you can also complain to your data protection authority; in Ireland, that is the Data Protection Commission (dataprotection.ie).
Security
Data is sent over HTTPS, reports are only visible to the account that created them, and access to our servers is restricted.
Children
The service is not directed at children under 16.
Changes
If we change this policy we'll update the date at the top of this page.