Security
How we protect your account and your site
This page is maintained by WebDesignForFree to answer the security and privacy questions we are asked most often. It is a description of our practices, not an independent certification.
Accounts and access
- Sign in with email and password; passwords are never stored in plain text.
- Email addresses are verified before an account becomes fully active.
- Every site is scoped to its owner's account, and access rules are enforced on the server.
Data in transit and at rest
- The builder, the dashboard and every published site are served over HTTPS.
- Custom domains get certificates provisioned automatically once DNS is verified.
- Uploaded logos and photos are stored in managed object storage, served through our own endpoints.
What we collect and why
We store what is needed to build, edit, publish and bill for your website — account details, the business information you enter, your generated site and its revisions. See the Privacy Policy for the full description.
Processors we rely on
- Managed database, authentication and storage for account and site data.
- AI providers, which receive the business details you submit in order to generate copy.
- Stripe for payments — card details are handled by Stripe and never reach our servers.
- Email delivery for verification, password resets and payment confirmations.
Shared responsibility
We secure the platform, the builder and the hosting of your published site. As the site owner you are responsible for the content you publish, the contact details you display, the people you give account access to, and keeping your own domain registrar account secure.
Report a vulnerability
Email security@webdesignforfree.com with steps to reproduce and the impact you observed. Please give us a reasonable window to fix the issue before disclosing it, and avoid testing that degrades service or touches other people's data.
