Legal
Privacy Policy
Last updated: 9 June 2026
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use Pagelive (the “Service”), and the rights you have over that data under the EU General Data Protection Regulation (GDPR) and applicable Estonian law. By using the Service you acknowledge the practices described here.
We provide this policy for transparency so you can understand how the Service handles data. It is not legal advice. If you use Pagelive to collect personal data from other people — for example through an email gate — you should review your own obligations and, where appropriate, consult your own legal counsel.
1. Who we are
Pagelive is operated by Livesysx OÜ, a company registered in Estonia (EU), company registration number 14744997, VAT number EE102337053. For the personal data we handle to run the Service — your account, your published pages, billing, and product analytics — Livesysx OÜ is the data controller.
There is one important exception. When you, as a page owner, turn on an email gate and collect viewers’ email addresses through it, you are the data controller for those emails and Pagelive acts only as your processor. Section 6 explains this split in full.
For any privacy question, to exercise your rights, or to reach our data protection contact, email hello@pagelive.io.
2. What data we collect
We collect only what we need to provide and secure the Service:
- Account data — your name (if provided) and email address. Passwords are never stored in plain text; they are stored as a salted PBKDF2 hash.
- Published content — the HTML pages and related metadata (titles, slugs, settings such as expiry, password protection, or an email gate) that you publish through the Service.
- View analytics — when someone opens a page you published, we record coarse, privacy-minded, cookieless analytics: viewer IP addresses are salted and hashed and are never stored in raw form; we record coarse country only (not city or precise location), plus referrer, dwell time, and a user-agent class (e.g. browser/device category). These power your open and engagement statistics.
- Lead / viewer emails collected via email gates — if you enable an email gate on a page, viewers enter their email (and, if you require it, verify it with a one-time code) before they can view the page. We store those emails and any associated event so you can see and export your leads. You are the controller of this data; we hold it on your behalf. See section 6.
- Form replies submitted on published pages — if a page you publish contains a reply form (a form the page author marks for capture), what a visitor types into it is stored with the page and emailed to you. Replies are treated exactly like your published content: never indexed, never used to train AI, never sold or shared; you are the controller of this data and we hold it on your behalf. Visitor IPs on submissions are salted and hashed, never stored raw; coarse country only.
- Payment data — if you subscribe to a paid plan, billing is handled by our payment processor, Stripe. We do not store your full card number. We receive limited billing metadata (e.g. subscription status, last four digits, billing country) from Stripe.
- Cookies & session data — a first-party session cookie to keep you signed in, an optional password-unlock cookie for protected pages, and the bot-protection (Turnstile) check on publish. See section 13.
- Product analytics — we use cookieless, self-hosted analytics on our app and marketing sites to understand aggregate usage. See section 13.
- Support communications — if you contact us, we keep your messages and contact details to respond.
3. How and why we use your data
Where we are the controller, we process personal data on the following lawful bases under Article 6 GDPR:
- Performance of a contract — to create and operate your account, host and serve your published pages, run features you enable (such as password protection and email gates), provide analytics, and process subscriptions.
- Legitimate interests — to secure the Service (bot/abuse protection, rate limiting, content scanning), prevent fraud and misuse, monitor reliability and errors, maintain and improve the Service, and produce aggregate analytics. We balance these interests against your rights.
- Consent — where consent is required (for example certain non-essential communications); you may withdraw consent at any time.
- Legal obligation — to comply with accounting, tax, and other legal requirements.
For emails collected through an email gate, the lawful basis is determined by you, the page owner, as the controller of that data — not by us. We process those emails only on your instructions, as described in section 6.
4. Where your data is stored
Published page content is stored in Cloudflare R2 (object storage) and account, page metadata, leads, and analytics data in Cloudflare D1 (database), with a primary region in Western Europe. Pages are served from Cloudflare’s global edge network.
5. Sub-processors
We use a small number of trusted providers to operate the Service. Each acts as a processor (or, where we are your processor for gated emails, a sub-processor) under contract and processes data only on documented instructions:
- Cloudflare — hosting and compute (Workers), database (D1), object storage (R2), key-value store (KV), CDN/edge delivery, Turnstile bot protection, and SSL for custom domains.
- Stripe — payment processing and subscription billing.
- Resend — sending transactional email (e.g. sign-in, account, billing, and email-gate verification codes).
- Plausible (self-hosted) — cookieless product analytics on our app and marketing sites only; not used on your published pages.
- Sentry — server-side error monitoring, hosted in the EU region; configured to capture errors only, without personal data and without any client-side tracking.
- Better Stack — uptime and availability monitoring of our endpoints.
- Google / GitHub — optional social sign-in, used only if you choose to log in with one of these providers.
We will take reasonable steps to keep this list current. Where we replace or add a sub-processor that handles personal data we control, we will update this policy.
6. Email gates: controller vs. processor
An email gate is an optional feature that lets you, as a page owner, ask viewers to enter their email address — and optionally verify it with a one-time code — before they can view a page. This works much like a signup form, scheduling tool, or newsletter form built with another provider.
For these collected emails, you are the data controller and Pagelive is the processor. You decide which pages to gate, why you collect the emails, how you contact those people, and how long you keep their data. We store and process those emails solely to operate the gate and to make your leads available to you, acting on your instructions.
To keep this transparent for viewers, the gate displays a short notice that the email they enter is shared with the owner of the page. As the owner, you may optionally enable a consent checkbox with your own wording — for example to confirm marketing consent — where your situation requires it. You are responsible for the accuracy and lawfulness of any consent language you add.
Your responsibilities as controller. You are responsible for having a lawful basis to collect these emails and to contact those people, for providing any privacy notice they are owed, and for honouring their data-subject requests (such as access or deletion) about the data you collected. Our Terms of Service set out the warranties and indemnity that apply when you use this feature.
Our role as processor. We process gated emails only to provide the Service to you, never for our own purposes. We do not use them to market to those viewers, we do not sell them, and we do not use them to train any artificial-intelligence or machine-learning models. You can view, export, and delete collected leads from your dashboard. We retain them until you delete them, until the page is deleted, or until your account is closed, after which they are deleted or anonymised in line with section 8. If a viewer contacts us directly about data collected through your gate, we will generally direct them to you as the controller and may notify you of the request.
7. Data sharing
We do not sell your personal data, and we do not share it with third parties for their own marketing. We do not use your published content — or the personal data of the people you share pages with, including emails collected through gates — to train any artificial-intelligence or machine-learning models. We do not sell the email addresses or contact details of your page viewers or leads. We share data only with the sub-processors listed above to run the Service, with you (where you are the controller of leads collected on your pages), or where required by law, valid legal process, or to protect our rights, our users, or the public.
8. Data retention
- Account data — retained while your account is active, and for a limited period afterwards as needed to meet legal, accounting, and security obligations, then deleted or anonymised.
- Raw analytics events — pruned on a recurring schedule; only privacy-safe aggregates are retained beyond that for your statistics.
- Published pages — retained until you delete them or they expire.
- Collected leads / gated emails — retained on your behalf until you delete them, the page is deleted, or your account is closed. As controller, you set the effective retention by managing your own leads.
9. Security
We apply industry-standard safeguards: TLS encryption in transit everywhere, salted-hashed passwords (PBKDF2) and API keys, viewer IPs salted-hashed (never stored raw), tenant isolation between accounts, content served on a separate domain (pagelive.site) from the app, and bot-protection and content scanning on publish. Published pages are set to noindex by default so they are not picked up by search engines. No method of transmission or storage is completely secure, but we work to protect your data using appropriate technical and organisational measures.
10. International transfers
Our primary storage is in the EU (Western Europe). Some sub-processors — notably Stripe and Resend, and the optional OAuth providers — may process certain data outside the European Economic Area. Where that happens, the transfer is protected by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) and additional measures, so that your data continues to receive an equivalent level of protection.
11. Your rights
Subject to the GDPR, in respect of data we control you have the right to:
- access the personal data we hold about you;
- request correction (rectification) of inaccurate or incomplete data;
- request erasure (“right to be forgotten”);
- request restriction of processing;
- data portability — receive your data in a structured, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting prior lawful processing; and
- lodge a complaint with a supervisory authority — in our case the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or your local data protection authority.
To exercise any of these rights, contact hello@pagelive.io. We will respond within the timeframes required by law.
If your request concerns an email or other data you submitted through a page owner’s email gate, the page owner is the controller of that data. Please contact that owner directly. We will help where we can, but the owner — not Pagelive — decides how that data is used and is the right party to action your request.
12. Cookies and tracking on published pages
On your published pages, our view analytics are cookieless and aggregate: we do not set advertising or cross-site tracking cookies on viewers, and we do not build viewer profiles across pages. Within the app we use only first-party, functional cookies: a session cookie to keep you signed in, a password-unlock cookie so you don’t have to re-enter a page password during a session, and Cloudflare Turnstile for bot protection on publish. Our own product analytics (Plausible, self-hosted) on the app and marketing sites are also cookieless.
13. Children
The Service is not directed to children. It is intended for users aged at least 16 (or 18 where required by local law). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, where changes are material, take reasonable steps to notify you. Continued use of the Service after an update constitutes acceptance of the revised policy.
15. Contact
Livesysx OÜ, Estonia (EU) · reg. no. 14744997 · VAT EE102337053 · hello@pagelive.io