Data & Trust

What happens to the information you give us

You are sharing a business idea, a real address, and financial details. That deserves a straight answer about where it goes, who sees it, and what we will never do with it.

What happens, step by step

01

You fill in the score form

Business description, address, email, rent, unit size, ticket size. This goes to our server over an encrypted HTTPS connection.

02

Stripe handles your payment

You are redirected to Stripe Checkout. Your card details are entered directly on Stripe's servers - SiteMetriq never sees them, never stores them, and cannot access them.

03

Payment confirmation triggers report generation

Stripe sends a webhook to SiteMetriq confirming payment. At this point your business inputs are used to query government datasets and generate the report. The report is stored in our database in Singapore.

04

Report is emailed to you

Delivered via Resend to the email you provided, typically within 60 seconds of payment. The report is also accessible via a secure link.

05

Your data stays in Singapore

Report data is stored in Supabase on AWS ap-southeast-1 (Singapore region). It is not replicated internationally except where Stripe or Resend require it for their own operations.

What we do

Use your business inputs to generate your report
Store your email to deliver the report and for payment records
Analyse aggregated, anonymised patterns across reports to calibrate the scoring engine
Retain payment records as required by law

What we never do

Sell your data to any third party
Share your business concept or address with landlords, agents, or property firms
Use your inputs to train external AI models or sell to data brokers
Add your email to a marketing list without your explicit opt-in
Serve advertising - there are no advertisers in this product
See or store your card details (Stripe handles all of this)

Who touches your data

These are the only third-party services that handle your data. No others.

Payment processing

PCI DSS Level 1 certified. Card data never touches SiteMetriq's servers.

Database (Singapore region)

SOC 2 Type II. Data stored on AWS ap-southeast-1.

Email delivery

Used only to send your report. No marketing access.

Web hosting

Hosts the SiteMetriq platform. Logs are standard access logs, retained 30 days.

About payment security

Card payments are handled entirely by Stripe, which is PCI DSS Level 1 certified - the highest level of payment security certification. When you enter your card details, you are on Stripe’s servers, not SiteMetriq’s. SiteMetriq receives only a payment confirmation from Stripe. Your card number, CVV, and expiry date are never transmitted to or stored by SiteMetriq.

How long we keep it

Report data (address, business details, generated report)24 months
Email address36 months of inactivity, or until you delete it
Payment records7 years (legal requirement)
Server access logs30 days

Request deletion of your data

Email privacy@SiteMetriq.sg and we will delete your report data and email address within 7 days. Payment records are excluded where required by tax law.

We will confirm deletion by email when complete.

For the full legal detail: Privacy Policy  ·  Terms of Service

Questions not answered here? Email contact@sitemetriq.sg - we respond personally.