Privacy without the fog

Your website is public. Your choices still matter.

Here’s the plain-English version of what we collect to run scans, deliver reports, process payments, and answer you—and what stays in your control.

Ask a Privacy Question

The short version

What we collect—and why.

Last updated: September 20, 2026. We collect the details you enter and information from the public website you ask us to review. Required cookies keep requested features working. Optional analytics stays off unless you accept it, and Stripe hosts payment entry.

What you choose to share

Starting a Free One-Page Trust & Security Scan or paid Full-Site Website Trust & Security Scan can involve sharing a business name, website URL, category, town, email address, and what you want to improve. If you contact us, we receive your name, email, message, and any optional business name or website you add.

What we save from a scan

We save the details you enter, information reviewed from public websites, scan and report results, payment status, and follow-up requests so the service can work and improve. Scan records may include page addresses and redirects; HTTPS and certificate details; browser protections; cookies; insecure content or forms; third-party files; check times and errors; and results from services such as Google. Results cover only what was public when the scan ran. They do not verify the business or guarantee that the website is safe.

When outside services help

Scans make read-only requests to the public website you enter. Private access links and addresses containing query strings or page fragments are not accepted. When available, the public page address or business search terms may go to Google PageSpeed Insights or the Google Places API. Paid reports may also send the query-free public page address to Google Web Risk for a threat-list check. These services may fail or return unclear results, and Google Web Risk can miss threats or flag a safe page.

Hosting and request data

Amazon Lightsail hosts TrustFrame, and Cloudflare helps deliver and protect it. They, along with normal server logs, may process your IP address, date and time, requested page, browser or device details, and security events. TrustFrame creates a one-way code from your IP address and uses it for about 30 minutes to limit repeated contact-form requests. The code may remain in service records after that window, as described under Retention and your requests. The saved message itself does not include your IP address.

Required cookies

A required session cookie keeps forms and checkout working and helps protect requests. Another browser setting remembers your cookie choice. Both support features you request, so they stay active whether or not you allow analytics.

Google Analytics is optional

Google Analytics loads only on public marketing pages and only if you accept optional analytics. It does not load on scanning, tokenized report, or checkout pages. Eligible product milestones may stay in the required session and be sent later from a public page if you have consented. Analytics may receive that public page and referring-page path, device and browser details, approximate location, and the approved event type. We remove query strings and page fragments and exclude submitted website addresses, email addresses, report or checkout codes, report text, and contact messages. You can change your choice through Cookie settings.

Stripe payments

Stripe hosts the payment form and processes checkout and payment details. We keep the order status, amount and currency, email associated with the payment, and Stripe’s order and payment reference numbers so we can provide support. Your full card number never comes to TrustFrame.

Email delivery

When email delivery is turned on, our email service receives the recipient address, subject, and message needed to send a contact notification or report email. If your message reaches us by email, your address is included so we can reply. The contact message is still saved if delivery fails.

Shareable report links

Purchased reports open through a long, hard-to-guess link that we ask search engines not to list. That link is not a password and cannot guarantee privacy. Anyone with the full link may be able to view the report, so share it only with people you trust.

Retention and your requests

We keep scan requests, reports, purchase references, messages, and service records so reports remain available, payments can be supported, abuse can be prevented, and business records can be maintained. Contact TrustFrame to request access, correction, or deletion. There is no self-service delete button or fixed published deletion schedule. We may retain limited information in backups or where needed for payments, security, abuse prevention, or disputes.

You stay in control

Manage analytics. Choose what you share. Ask us directly.

Use Cookie settings to accept or decline optional analytics, leave optional fields blank, and keep report links to yourself. Contact TrustFrame with questions about a report or information you entered, or to request access, correction, or deletion. We’ll review the request and explain any legal or practical limits that apply.

Contact TrustFrame