1. Who We Are
Technical SEO Agent ("we", "us", "our") operates the Technical SEO Agent platform, a web-based technical SEO auditing, crawl analysis, monitoring and reporting tool available at technicalseoagent.com.
We are the data controller for personal data processed in connection with your use of the Service. For questions or requests relating to this policy, see the Contact section at the end.
2. Data We Collect
We collect different categories of data depending on how you interact with the Service:
| Category | Examples | Source |
| Account data |
Name, email address, password (hashed using bcrypt), agency/account name, role (Super Admin / Account Admin / User) |
Provided by you at registration, or by your account admin if you were invited |
| Billing data |
Subscription plan (Starter / Growth / Consultant / Agency), billing cycle, JS-render top-up purchases, Stripe customer ID, last four digits and brand of payment card |
You and our payment processor (Stripe) |
| Usage data |
URLs crawled, JS-renders consumed, audits run, tools used, projects created, scheduled crawl configurations, timestamps, quota counters |
Automatically collected during use |
| Crawl & audit data |
URLs, HTTP responses, page HTML snapshots, links, structured data, SEO metrics, detected issues, health scores, Core Web Vitals readings, uptime/availability checks, image metadata |
Collected by our crawler and connected APIs on your instruction |
| Google account data |
If you connect Google Search Console: your Google email, OAuth refresh/access tokens (encrypted at rest), the list of GSC properties you have verified, and the indexing/coverage/performance data we fetch from those properties on your behalf |
Google, via OAuth, with your explicit consent |
| Technical data |
IP address, browser type, operating system, referring URL, request logs |
Automatically collected via server logs |
| Communications |
Support messages, email correspondence |
Provided by you |
We do not collect full payment card details — these are handled exclusively by Stripe, our PCI-compliant payment processor.
3. How We Use Your Data
We use the data we collect for the following purposes:
- Providing the Service — running crawls, generating audit reports, monitoring uptime and Core Web Vitals, producing schema recommendations, storing results, enforcing your monthly URL and JS-render quotas, and powering your account.
- AI-assisted features — when you use AI-generated audit summaries, schema gap analysis or AI explanations of issues, the relevant crawl/page data is sent to our AI provider on a per-request basis to generate the response. AI providers do not receive your account credentials, billing information or Google OAuth tokens.
- Billing & subscription management — processing payments, sending invoices, managing plan changes, granting JS-render top-ups, and resetting your monthly quota when your subscription renews.
- Communication — sending transactional emails (account confirmations, audit completion notices, scheduled-crawl reports, password resets, billing receipts) via our email provider.
- Product improvement — analyzing aggregated, anonymized usage patterns to identify bugs and prioritize features.
- Security — detecting and preventing fraud, abuse, and unauthorized access.
- Legal compliance — fulfilling obligations under applicable laws and responding to lawful requests.
- Marketing & advertising — measuring the effectiveness of our advertising campaigns, building retargeting audiences, and identifying business visitors to our website. This processing only occurs where you have given consent via our cookie consent banner.
We do not sell your personal data to third parties. We do not use your crawl data, your Google Search Console data, or any data obtained through Google APIs to train, fine-tune or develop generalized machine learning or AI models.
4. Google API Services & Limited Use
Where you choose to connect a Google account (for sign-in or to link Google Search Console properties), Technical SEO Agent uses Google API Services. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we agree that data obtained through Google APIs will:
- Be used only to provide and improve the user-facing features of Technical SEO Agent that you have explicitly connected (for example, surfacing your Search Console coverage, performance and indexing data inside our audit reports and dashboards).
- Not be used for serving advertisements, including retargeting, personalized or interest-based advertising.
- Not be transferred to others except as necessary to provide or improve the user-facing features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to users.
- Not be used to train, fine-tune or develop generalized AI or machine learning models. Where AI features (such as AI audit summaries) are used, only the specific data needed for that single request is sent to the AI provider on your behalf.
- Not be read by humans except (a) with your explicit consent for specific data, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
The Google OAuth scopes we may request are limited to those needed for the features you enable — typically read-only access to Google Search Console (webmasters.readonly) and basic profile/email for sign-in. You can revoke our access at any time from your account settings inside Technical SEO Agent, or directly via your Google Account permissions page. When you revoke access, we delete the associated OAuth tokens promptly.
5. Legal Basis for Processing
Where applicable data protection law (including UK GDPR and the EU GDPR) requires a legal basis for processing, we rely on the following:
- Contract performance — processing necessary to provide the Service you have subscribed to.
- Legitimate interests — security monitoring, fraud prevention, and aggregated product analytics, where our interests do not override your rights.
- Legal obligation — retaining records required by tax or financial regulations.
- Consent — advertising and tracking cookies (including Meta Pixel and Incendium.ai), marketing emails, and any other non-essential processing where we ask for your consent via our cookie consent banner or other explicit opt-in mechanism.
6. Third-Party Services
We share data with the following sub-processors and service providers, who process data on our behalf:
- Stripe — payment processing for subscriptions and JS-render top-up purchases. Stripe stores your billing records and payment method. See Stripe's Privacy Policy.
- Google LLC — OAuth-based sign-in and Google Search Console API integration. We receive your Google email, profile basics, and (with your consent) read-only access to your verified GSC properties. See Google's Privacy Policy.
- Cloudflare, Inc. — we use Cloudflare for CDN, DDoS protection, browser rendering for our JS-rendering crawler, and Cloudflare Workers + Queues for the distributed task processing that powers our audits, monitoring and PageSpeed checks. URL strings and page content fetched on your behalf transit Cloudflare infrastructure. See Cloudflare's Privacy Policy.
- Resend — transactional email delivery (account confirmations, password resets, audit completion notices, billing receipts, scheduled-crawl reports). Resend processes your email address and the contents of those messages. See Resend's Privacy Policy.
- Google PageSpeed Insights API — used to fetch Core Web Vitals and Lighthouse data for the URLs you submit. The URLs you analyze are sent to Google for measurement.
- DataForSEO — used to fetch keyword data and top-ranking page lists for the projects you create. Project domains and keywords are sent to DataForSEO. See DataForSEO's Privacy Policy.
- AI provider(s) — when you use AI-assisted features (AI audit summaries, AI explanations of issues, schema gap analysis), the relevant page text and issue data is sent to our AI provider on a per-request basis to generate the response. AI providers are contractually prohibited from training their models on this data.
- Meta Platforms (Facebook/Instagram) — Meta Pixel on our marketing pages for advertising measurement and audience building. Only fires with your cookie consent. See Meta's Privacy Policy and Meta's Ad Preferences.
- Incendium.ai — B2B visitor intelligence on our marketing pages. Identifies the company/organization associated with a visitor (not named individuals). Only fires with your cookie consent. See Incendium.ai's Privacy Policy.
- Cloud hosting provider — infrastructure on which the Service runs.
We require all sub-processors to handle your data in accordance with applicable data protection law and to provide at least the same level of protection as described in this policy.
We may disclose data to law enforcement or government authorities where required to do so by law or in response to a valid legal request.
7. Cookies, Pixels & Tracking Technologies
We use cookies and similar tracking technologies on our website. These fall into two categories: essential (always active) and non-essential (only active with your consent).
Essential cookies — these are required for the Service to function and cannot be disabled:
- Session cookies — keep you logged in during your session; expire when you close your browser.
- Persistent preference cookies — remember settings such as your selected billing interval across visits.
- CSRF tokens — security cookies that protect form submissions from cross-site request forgery attacks.
Non-essential cookies & tracking — these are only loaded after you have given explicit consent via our cookie consent banner:
- Meta Pixel — a JavaScript snippet placed by Meta Platforms. It collects data about your visit (pages viewed, actions taken, browser and device information) and sends it to Meta. This data is used to measure the effectiveness of our ads on Facebook and Instagram, track conversions, and create custom and lookalike audiences for future advertising. Meta may use this data in accordance with its own policies to serve you relevant ads across its network.
- Incendium.ai — a B2B visitor identification and analytics tool. It uses your IP address and other signals to identify the company or organization you are visiting from, and records your on-site behavior (pages visited, time spent, referral source). This helps us understand which businesses are interested in our product and tailor our outreach accordingly. The tool identifies organizations, not named individuals, unless you have otherwise provided your contact details.
Consent banner. When you first visit our website, a consent banner will ask for your permission before any non-essential tracking is activated. You may accept all, reject all, or manage individual categories. You can change your preferences at any time by clearing your cookies or via the consent settings link in our footer.
Opting out. In addition to our consent banner, you can limit tracking through the following means:
- Use your browser's cookie settings to block or delete cookies.
- Install the Meta Pixel opt-out browser add-on or adjust your Meta Ad Preferences.
- Enable Global Privacy Control (GPC) or Do Not Track (DNT) signals in your browser — where we detect these signals, we will treat them as a request to disable non-essential tracking.
8. Data Retention
We retain your data for as long as your account is active, and for a limited period thereafter. Operationally we apply the following automatic pruning windows to keep your data footprint tight:
- Account data — retained for the lifetime of your account plus up to 90 days after deletion to allow for recovery.
- Raw crawled HTML — pruned automatically after 14 days.
- Audit results, links and detected issues — pruned automatically after 90 days, or sooner if you delete the project.
- Background task records — task queue records pruned after 7 days; task results after 30 days.
- Billing records — retained for up to 7 years as required for tax and accounting compliance.
- Server logs — retained for up to 90 days for security and debugging purposes.
- Session records — pruned after 24 hours of inactivity.
- Google OAuth tokens — deleted promptly when you disconnect a Google account or delete your Technical SEO Agent account.
You can request deletion of your account and associated data at any time. See the "Your Rights" section below.
9. Security
We take reasonable and appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction, or alteration. These measures include:
- Encryption of data in transit using TLS.
- Hashed storage of passwords using a secure, salted algorithm.
- Access controls limiting data access to authorized personnel only.
- Regular review of our security practices and third-party sub-processors.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you believe your account has been compromised, please contact us immediately.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data ("right to be forgotten").
- Restriction — request that we restrict how we process your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@technicalseoagent.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office at ico.org.uk).
11. International Transfers
We primarily store and process data within the UK and European Economic Area. Where data is transferred outside these regions (for example, via sub-processors such as Stripe or Cloudflare with global infrastructure), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or equivalent mechanisms.
12. Children's Privacy
The Service is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice within the Service, and will update the "Last updated" date at the top of this page.
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.