Document version: 1.3
Effective date: 2026-05-19
If a translated version differs from the English version, the English version prevails.
This notice describes how the service works and how personal data is processed. For privacy requests, use the privacy contact listed below.
Controller: Francesco Perra
Privacy contact: postmaster@siteofsites.org
Contact details: postmaster@siteofsites.org
If you choose to sign in with Google, we receive and process the Google account identifier required to authenticate you, your email address and whether Google reports that the email address is verified. We use this information only to create or access your SiteOfSites account. We do not store Google access tokens or refresh tokens.
| Purpose | Legal basis |
|---|---|
| Account creation and management | Performance of the requested service/contract |
| Authentication and account security | Service performance and legitimate interest in security |
| Publishing URLs, descriptions, tags and groups | Performance of the requested service |
| Votes, reject votes, ranking and search quality | Service performance and legitimate interest in quality and anti-abuse |
| Reports and moderation | Legitimate interest and legal obligations where applicable |
| URL safety checks and Web Risk | Legitimate interest in service and user safety |
| Rate limits and suspicious IP events | Legitimate interest in security and abuse prevention |
| Transactional emails | Performance of the requested service |
| Privacy requests | Legal obligation |
| Technical/session/auth/antiforgery cookies | Technical necessity for the requested service |
| User reports, account moderation and account suspension | Legitimate interest in community safety, abuse prevention and enforcement of the Terms, and legal obligations where applicable |
Reporter identity is not shown publicly. Qualitative reports that may be forwarded to content owners are available only to authenticated users. For these reports, the report description may be forwarded to the owner of the reported content only when the reporter explicitly chooses to share that description. The reporter identity, email, username and technical anti-abuse data are not shared with the owner through this flow.
For legal, safety or abuse cases, SiteOfSites may keep logs and may avoid sharing details when disclosure would create legal, security or anti-abuse risks.
Reports against users are handled as account safety and moderation reports. The reported user may receive a general notice if an account restriction or suspension is applied, but reporter identity and technical anti-abuse data are not shared. Detailed report information may be withheld when disclosure would create privacy, safety, legal or anti-abuse risks.
SiteOfSites may use internal anti-abuse and trust signals to help prevent false reports, spam, manipulation and other abusive behavior. These signals are not public and are used only for service safety, moderation, rate limiting and abuse prevention.
Some actions may be automatic or semi-automatic, such as temporary hiding after a confirmed Web Risk result, after multiple independent reports, or after community reject-vote thresholds are reached. These actions may limit public visibility but do not represent a legal judgment or certification about the external site.
User reports may lead to manual account moderation actions, including temporary or permanent account suspension, restoration after review, login invalidation and anti-abuse restrictions connected to suspended-account activity.
For security reports, SiteOfSites may send the reported URL to external reputation or safety providers such as Google Web Risk. Reporter identity, email, username, IP hash and report description are not sent to the provider. Results may be cached to reduce calls and abuse.
Data may be processed by hosting providers, SMTP/email providers, URL safety providers, technical logging services and competent authorities when required by law.
Technical cleanup is handled by configurable cleanup procedures. Retention values must be set in production configuration and reviewed periodically.
Where applicable, users may request access, rectification, deletion, restriction, objection, portability and withdrawal of consent where consent is used. Users may also lodge a complaint with a competent data protection supervisory authority. Use postmaster@siteofsites.org for privacy requests.
Accounts may be disabled and anonymized. When available, users may choose whether to remove content they created or keep it in anonymized form. Some data may remain in anonymized or pseudonymized form, or in security/moderation logs, when needed for abuse prevention, legal obligations or service protection.
SiteOfSites uses technical cookies needed for session, authentication, remember-me login and antiforgery protection. It also uses the sos_culture functionality cookie to remember the selected language for one year. These cookies are required to provide the service, preserve language preferences and protect requests. If analytics, advertising or non-technical tracking are introduced in the future, this policy will be updated and consent will be requested where required.
The service is not intended for minors under 18.
This policy may change over time. Relevant changes may require users to accept the updated legal documents again.