A Site can handle information about its visitors in several ways. ZeroTwo has no Sites setting that writes or publishes a privacy policy for you, and ZeroTwo's own Privacy Policy at zerotwo.ai/privacy does not mention Sites. This article lists what a Site can handle so that a policy you write for it is accurate. It is general information, not legal advice.
What ZeroTwo handles for your visitors
- Sign-in. Every visitor to a Site that is not set to Anyone with the link has to sign in with their ZeroTwo account. Once a visitor signs in, ZeroTwo issues a Site session that is valid for one hour. ZeroTwo can pass the signed-in visitor's account ID and email address to your Site's code, and may include their name. If your Site stores or displays any of these, it holds that information.
- People you add. When you add a viewer by email address in the share dialog, ZeroTwo keeps that address so it knows who may open the Site. If you select Send invitation, ZeroTwo emails that person the Site link.
- Messages your Site's code logs. ZeroTwo keeps the log messages that your Site's code writes, and its Sites tools can read them back when ZeroTwo diagnoses a problem with your Site. It keeps the most recent 2,000 events per Site. If your code writes visitor details to its logs, those details end up there.
- Traffic counts. The Analytics tab shows Unique visitors and Page views as totals and a chart, not as a list of individual people. The figures come from page-view records that hold the page path, a visitor identifier, the visitor's country, the host name of the page that referred them, a device class, the response status and the cache state. Only HTML pages are recorded, and records whose device class is a bot are left out of the counts.
What your own Site collects
Anything else comes from what you asked ZeroTwo to build.
- Forms, accounts and records. A Site can have a database for structured records and file storage for uploads. Whatever visitors submit and your Site saves there is information you hold.
- Other services. If the Site sends visitor information to an outside service, for example through an API key you added under Environment variables, or to an HTTP service you registered under Private HTTP services, that service receives it.
- Cookies and browser storage. ZeroTwo's Sites instructions tell it to use browser storage only for device-local preferences or explicitly local state. If you ask for more, note what your Site stores in the visitor's browser.
Where the Site is hosted
ZeroTwo hosts Sites on Cloudflare: your Site's code runs on Cloudflare Workers, and the page-view records behind the Analytics tab are kept in Cloudflare Analytics Engine.
Things to decide when you write one
- Who runs the Site and how visitors can reach you.
- Which information the Site collects, from the lists above, and why.
- Who receives it: your hosting and any outside service the Site calls.
- Cookies and other browser storage, if your Site uses any.
- How long you keep what the Site stores, and how a visitor asks you to delete or correct it. The Delete site confirmation only says it deletes the Site and its published files, so check what happens to stored data before you promise visitors an outcome.
- The date you last changed the policy.
To add it, open the Site's page, select Edit to reopen its chat, ask ZeroTwo to add a Privacy page and a link to it on every page, and give it your text. Ask ZeroTwo to publish again so the change is live. For publishing and sharing, see How do I build, publish and manage a website with ZeroTwo Sites? and for what stays your responsibility, see What am I responsible for as a ZeroTwo Site owner?