Private Access

This site is currently invite-only. Enter the access password to continue.

© 2024 Squish. All rights reserved.

Legal

Privacy Policy

Last updated: October 2026  ·  Effective: April 12, 2026  ·  Questions? privacy@squish.co or

Your privacy matters to us. We don't sell your data — ever. This policy explains exactly what we collect, why, who we share it with, and your rights.

01Overview

Squish operates squish.co and provides domain registration, web hosting, email services, and WordPress security tools (Squish Site Patrol). This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our services.

02Data We Collect

CategoryExamplesPurpose
Account DataName, email address, password (hashed)Authentication, account management
Contact DataPhone number, company name, billing addressBilling, support, WHOIS
Payment DataLast 4 digits, card type, billing zipPayment processing (via Stripe)
Domain DataRegistered domains, WHOIS registrant infoDomain registration & management
Usage DataPages visited, features used, search queriesService improvement, AI assistant
Site Patrol DataWordPress site URL, scan results, login events, blocked IPsSecurity monitoring & reporting
AI Visibility DataPublic pages we scan on your site; your business's name, category, city and main service, whether you give them to us or we read them from your site, and the area we ask answer engines to search from; the questions we ask AI answer engines about businesses like yours, and each engine's result (whether it named you, which sites it cited); Search Console Generative AI reports you upload (impressions by page, country, device and date, with no search queries or clicks); for sites we host, daily counts of requests from ChatGPT's fetchers and the pages they fetched most (no IP addresses or raw log lines)AI Visibility reports & monitoring
Technical DataIP address, browser type, device infoSecurity, fraud prevention
Support DataTicket content, chat logsCustomer support

We do not collect full credit card numbers. Payment card data is processed exclusively by Stripe.

03How We Collect It

  • Directly from you — when you create an account, purchase, or contact support
  • Automatically — IP address, browser info, session data when you use our site
  • From our AI assistant — queries submitted to Squish Assistant
  • From third parties — Firebase (Google/Apple sign-in), Stripe

04How We Use It

  • Provide, operate, and maintain Squish services
  • Process payments and manage billing
  • Register and manage domain names on your behalf
  • Send transactional emails (receipts, renewal notices, support)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations including ICANN requirements
  • Send product updates (you may opt out at any time)

We do not use your data to train third-party AI models or sell insights to advertisers.

05Data Sharing

We do not sell your personal data. We share data only with service providers who help us operate, domain registries as required by ICANN, legal authorities when required by law, or with your explicit consent.

06Third-Party Services

CategoryExamplesPurpose
Firebase (Google)Authentication & user managementEmail, name, UID
StripePayment processingBilling info, payment method
NameSiloDomain registrationRegistrant contact info
SalesforceCustomer relationship managementName, email, support history
Anthropic (Claude)AI assistant; AI Visibility answer checksChat messages, name, email; for AI Visibility, search questions built from your business category, city and service, and the area to search from
PerplexityAI Visibility answer checksSearch questions built from your business category, city and service, and the area to search from
Microsoft (via Pax8)Microsoft 365 mailboxes & licensingAdmin contact, domain, mailbox names
ResendTransactional email deliveryEmail address, message content
RailwayBackend application hostingData processed by our services
CloudflareCDN, DNS & securityIP address, request metadata
DigitalOceanWeb hosting infrastructureHosted content, server logs
Bunny.netCDN & WAF for hosted sites, parked domains & redirectsIP address, request metadata
Amazon Web ServicesManaged AWS hosting engagementsHosted content, server logs

The full subprocessor list, with each vendor's own compliance program, is maintained on our Trust page.

07Data Retention

  • Account data — retained while your account is open. Ask us to delete it and, if you have no active services with us, we do so within 30 days. If you still hold a domain, site or mailbox here, we'll tell you what needs to transfer out or be cancelled first: deleting the account underneath a domain would orphan it, and that domain is yours, not ours (billing records and assistant transcripts excepted, above)
  • Billing records — 7 years for legal compliance. One shorter exception: when a payment is declined, the record of the failed attempt and of our retries is kept for 1 year after the last activity on it, then deleted automatically. A payment that does go through is a billing record like any other. Your customer record at Stripe, our payment processor, is a billing record too: if you ask us to delete your account, we keep it for the same 7 years, but we remove any saved cards from it
  • Domain registrant data — duration of registration plus 1 year (ICANN)
  • Support tickets — kept while open and for 2 years after closing. After that, your name, email address, phone number and the text of your messages are removed from the ticket. Its dates and status are kept
  • AI assistant transcripts — retained indefinitely. These are the record of what our assistant said to you, and we keep them to establish, exercise or defend legal claims. Sensitive values are stripped automatically before storage — card numbers, SSNs, phone numbers, email addresses and API keys never reach the log, and your IP is stored only as a one-way hash
  • Website builder projects — retained indefinitely. Your Faber build conversation and the site content it produced. Unlike the assistant transcripts above, these are not stripped of contact details — the phone number and email address you asked us to put on your site are the content, so removing them would destroy the thing you built. Treat a builder project as what you published rather than as a private log. We keep it as the record of what was built and agreed
  • Security and abuse records — retained for 1 year, then deleted automatically. Failed sign-ins, permission denials, attempts to reach another customer's data, and rejected webhook signatures. Each records the account and IP involved. We keep them to protect other customers and to investigate abuse, and we cannot delete them on request before the year is up: an account able to erase its own security history is exactly the account most likely to want to
  • Staff access records — retained indefinitely. Every time a member of Squish staff opens your account, or reveals a credential belonging to your server, we write down who did it, when, and against which account. This is a different thing from the security records above: those are about people attacking us, and this one is about us. We keep it for the same reason and we cannot delete it on request — a record of who looked at your data is worth nothing if the looking can be erased afterwards. You can see these entries yourself on your account's activity timeline
  • Operational logs — retained for 12 months. The technical record of what our servers did: requests, errors, and the steps that led to them. We keep it so an incident discovered weeks after it started can still be reconstructed. Passwords, API keys and access tokens are stripped automatically before storage, but these logs are not stripped of email addresses — an operations log that cannot say which account an error belonged to cannot be used to fix it. Twelve months is long enough to investigate something found late, and short enough to be a real limit rather than an open-ended one
  • AI Visibility data — retained while your account is open. When you ask us to delete it, we delete the history of scans of your site, of the questions we asked answer engines and their results, your Search Console uploads, and the ChatGPT visit counts for sites we host. Cancelling AI Visibility on its own does not delete this history. One exception: if you bought AI Visibility on its own rather than with hosting, its subscription is a billing record and is kept for 7 years like any other, and that record also holds your latest report: your grade, the most recent answer-engine results (the questions, which engines named you and which sites they cited instead), your business details and the area we searched from. Search Console uploads are kept by count rather than by time: we hold the newest 12 for each domain and remove the oldest as each new one arrives. We keep the numbers from an upload, never the file itself
  • Uptime and outage records — retained for 24 months. The measured downtime behind our 99.9% uptime commitment, so a service-credit claim can be checked by both sides after the fact. Twenty-four months is long enough to answer any claim under the Terms and is a real limit rather than an open-ended one
  • Erasure records — retained for 2 years. When we delete an account at your request, we write down that we did it: the date, what was removed, what was kept and why, and who ran it. This record does not contain your name or email address — the account is identified by a one-way hash, the same way your IP is in the assistant transcripts above. So it can confirm your deletion happened if you come back and ask, and cannot be used to identify you if you never do. We keep it because a deletion nobody can evidence is indistinguishable from one that never ran, and two years covers the window in which anyone would query it

08Security

We implement TLS/HTTPS for all data in transit, encrypted storage for sensitive information, access controls, regular security audits, and PCI-DSS compliant payment processing via Stripe.

If you believe your account has been compromised, tell us immediately — email privacy@squish.co, or for a number you can chase. Either route goes to the top of the pile.

09Your Rights

You may request access, correction, deletion, or portability of your data, or object to processing for marketing purposes. Email privacy@squish.co, or if you'd rather have a case number to follow. We respond within 30 days either way.

Five things we cannot delete on request, and we would rather say so plainly than surprise you later: billing records, including your customer record at Stripe (with any saved cards removed), which we are required to keep for seven years; AI assistant transcripts, which we retain as the record of what our assistant told you so that either of us can rely on it in a dispute; security and abuse records, which we keep for a year to protect other customers and which would be worth little if the account they concern could remove them; staff access records, which say when one of us opened your account and would be worth as little if you could erase them afterwards; and website builder projects, which are the record of what we built for you.

Deleting an account also creates one small record rather than removing one. We note that the deletion happened, when, and what it covered — identified by a one-way hash rather than by your name or email — and we keep that for two years. It is how we can tell you your deletion actually ran if you ever ask.

One thing we will not delete yet: an account that still holds a live domain, site or mailbox. Removing it would cut the registrant link ICANN requires and leave a domain you paid for with nobody attached to renew it. Transfer it out or cancel it and we'll close the account straight after — we're protecting the asset, not keeping your data.

California residents have additional rights under CCPA. EU/EEA residents have rights under GDPR.

10Cookies

We use essential cookies (required for sign-in), Google Analytics cookies to understand how the site is used, and preference cookies (theme, language). Essential and preference cookies are set because the site cannot work without them; analytics is the only category that is ever optional.

If you are in the EEA, the UK or Switzerland, analytics cookies are off until you accept them. We ask once, on your first visit, and remember the answer for a year. If your browser sends a Global Privacy Control signal we treat that as a decline and never ask. Elsewhere analytics runs by default and you can turn it off here at any time.

You can also control or block cookies through your browser settings, and Google offers a browser add-on to opt out of Analytics at tools.google.com/dlpage/gaoptout.

11Children's Privacy

Squish services are not directed to individuals under 18. We do not knowingly collect data from children. Email privacy@squish.co if you believe a child has provided information.

12Policy Changes

We will notify you of material changes via email and update the effective date. Continued use after changes constitutes acceptance.

13Contact Us

  • Squish LLC — an Arizona limited liability company
  • Privacy & data requests: privacy@squish.co — answered within 30 days
  • Prefer a tracked case? — same team, but you get a case number to follow
  • Website: squish.co
© 2026 Squish. All rights reserved.