Security & Privacy
This page is maintained by Thematic Sites to answer common security and privacy questions about our managed-website service. It describes controls currently in place; it is not an independent certification or audit.
Shared responsibility
Thematic Sites is built on the Lovable Cloud platform. Lovable provides the underlying hosting, database, and authentication infrastructure. Thematic Sites is responsible for the application logic, access rules, and how your data is used inside our product. You are responsible for keeping your account credentials safe and for the content you submit through the platform.
Authentication & access
- Sign-in uses email and password, with sessions managed by the underlying auth service.
- Each client account can only view and modify its own profile, requests, credit history, and site record.
- Profile self-edits are limited to name, business name, phone, country, and email. Plan, billing, and subscription fields are managed exclusively server-side.
- Administrative operations (credit adjustments, plan changes) require trusted server-side privileges and are not exposed to the client app.
Data we collect
- Account data: name, business name, email, phone, country.
- Service data: change requests you submit, request history, credit transactions, and site status.
- Intake submissions: contact details and goals submitted through our public intake form.
- Billing data: handled by our payment processor; we store references, not full card data.
How your data is protected
- Database access is governed by row-level security. Each table enforces ownership rules so users only see their own records.
- Privileged credit and billing operations run as server-side functions with internal authorization checks, not directly from the browser.
- Intake form submissions are not readable by any signed-in or anonymous user; they are accessible only to our admin team.
- Connections to the application and database are encrypted in transit (HTTPS/TLS).
Payments
Payments and subscriptions are processed by Stripe. We do not store your full payment card details. We retain a customer/subscription reference so we can match payments to your account and reflect plan changes inside the dashboard.
Subprocessors
- Lovable Cloud — hosting, database, authentication.
- Stripe — payment processing and subscription billing.
Additional providers used by your specific managed site (e.g. domain registrar, analytics) are disclosed to you when configured.
Retention & deletion
We retain your account, request history, and credit ledger for as long as your account is active so that the service can function. If you want your account closed and your personal data deleted, contact us using the email below and we will action the request.
Your privacy rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. To exercise any of these rights, email the contact address below from the address on your account.
Reporting a security issue
If you believe you have found a security vulnerability in Thematic Sites, please report it privately by email rather than opening a public issue. We appreciate responsible disclosure and will respond as quickly as we can.
Contact
For security, privacy, or data-handling questions, contact hello@thematicsites.com.
Last reviewed: September 2026