SiteGuard privacy policy
Version 2026-09-16.3, dated September 16, 2026.
The operator of https://site-guard.org is Individual Entrepreneur Igor Evgenievich Saraev, Russian taxpayer number 745322853944.
Current service status
A plan can be purchased only when the dashboard shows an enabled link to the hosted Prodamus payment page. At all other times public payments are disabled.
The contact form accepts a name, phone number, email or messenger handle, and an enquiry. Do not send payment credentials, usernames, passwords, or other secrets.
Data processed
When the website is viewed, the server may process the IP address, request date and time, requested URL, User-Agent, technical error logs, and necessary session/CSRF cookies. Registration and dashboard use may process a name, email address, locale, time zone, security settings, monitored domains, check results, incidents, and notification preferences. A contact form processes the submitted contact details, enquiry, preferred contact method, and consent.
Form monitoring processes configured CSS selectors, synthetic test values, bounded step diagnostics, backend confirmations, and a screenshot of the visible page only when a check fails. Integration secrets are encrypted at rest and one-time probe tokens expire. Users must not put real customer data, passwords, payment details, or other production secrets into synthetic test fields.
CRON/heartbeat monitoring processes the task name and schedule, linked website, ping time, technical outcome, exit code, and a keyed payload fingerprint used only to detect conflicting retries. Free-form diagnostic messages are not stored. The original token is displayed only when issued; a cryptographic digest is retained for later authentication.
IP restriction processes user-supplied IP addresses and networks, emergency addresses, trusted reverse proxy settings, and configuration-generation history. SiteGuard generates Nginx or Apache text but does not connect to the customer's hosting or apply it automatically.
Until a separate independent security review is approved, Password Vault accepts descriptive metadata and audits access to it only; entering, importing, revealing, or storing passwords, private keys, and recovery codes is technically blocked. Support tickets process messages, SLA records, staff actions, and encrypted references to an approved external vault. Actual secrets must never be submitted in a ticket.
Payments
At checkout, SiteGuard sends Prodamus the order identifier, selected plan and amount, user email, and technical notification and return URLs. Card number, expiry date, and CVV/CVC are entered only at Prodamus and are never received by SiteGuard. We retain the order amount and currency, status, payment and subscription identifiers, bounded failure diagnostics, accepted document versions, the indicative currency quote shown and its rate version, and a receipt link if the provider supplies one.
Purposes and sharing
Technical data is used to serve and secure the website, diagnose errors, and answer direct enquiries. Infrastructure hosting providers may process it only as needed to operate the website. Payment data needed for hosted checkout, fiscal processing, and subscription management is shared with Prodamus. Disclosure may also occur when required by law. Advertising analytics are not used.
Retention and rights
Technical data is retained only as long as needed to operate and protect the website or meet a mandatory legal requirement. Payment and consent history is retained for mandatory accounting and dispute periods; SiteGuard does not retain card data. You may ask about processing, request applicable correction, restriction or deletion, and withdraw consent where processing relies on it. Withdrawal does not undo lawful prior processing and may make parts of the service unavailable.
Form-check history and failure screenshots are available and physically retained only for the plan and system retention period, after which they are deleted. Deleting a monitor stops future checks; its audit history remains only until the applicable retention period expires.
Heartbeat history, support tickets, temporary-access approvals, and staff-operation records are retained for the published operational period and as needed to perform the agreement, investigate incidents, and protect both parties. Audit events may outlive an active setting when needed to prove a prior action.
Contact
For data-processing enquiries: directolog.i@yandex.ru.