Privacy Policy
SEOverts Privacy Policy
Effective date: August 6, 2026 Version: 1.1
This Privacy Policy explains how Meerkat 9000 LLC, a South Carolina limited liability company ("Company," "SEOverts," "we," "us," or "our"), collects, uses, discloses, and protects personal data in connection with the SEOverts SEO intelligence and ads optimization platform (the "Service").
This Policy is written to be read alongside our Terms of Service, Cookie Policy, US State Privacy Rights Notice, Data Processing Addendum, and Sub-processor List.
1. Our Two Roles: Controller and Processor
The Service involves two distinct data relationships, and our role differs in each:
-
Customer and Member account data: we are the controller. When organizations ("Customers") and the individuals they invite ("Members") register for, configure, and use the Service, we determine the purposes and means of processing their account, billing, usage, and support data. For that data, we are the controller (or, under US state laws, the "business"), and this Privacy Policy describes how we handle it.
-
Integration Data: we are the processor. When a Customer connects a third-party account (an "Integration", for example Google Search Console, Google Analytics 4, Google Business Profile, PageSpeed Insights, Meta Ads, Google Ads, or TikTok Ads), the Service retrieves data from that account on the Customer's behalf ("Integration Data"). To the extent Integration Data contains personal data (for example, information about a Customer's website visitors or ad audiences within analytics reports), the Customer is the controller and we act as the Customer's processor (or "service provider"), processing it on the Customer's behalf and on its documented instructions under our Data Processing Addendum.
The remainder of this Policy primarily describes our processing as a controller of Customer/Member data, while explaining our processor role where relevant.
2. Personal Data We Collect
As a controller of Customer/Member data, we collect:
- Account and identity data: name, business name, email address, password (stored hashed), role, and Organization/Website configuration.
- Billing data: subscription, plan, Credit-usage, and transaction metadata. Card details are collected and stored by our payment processor, Stripe; we do not store full card numbers. We receive limited billing information (such as the last four digits, card brand, billing status, and Stripe customer/subscription identifiers).
- Integration data: OAuth tokens and account identifiers for the Integrations you connect, and the Integration Data the Service retrieves at your direction (such as Search Console queries and impressions, GA4 metrics, Google Business Profile data, PageSpeed results, and ad account campaign and spend data).
- SEO and ads metrics: keyword rankings, SERP data, backlink data, site-audit results, competitor-tracking data, and ads performance metrics, sourced from our SEO data provider (DataForSEO) and from your Integrations. These are primarily data about websites and campaigns rather than individuals.
- Usage, device, and log data: IP address, browser and device information, pages and features used, timestamps, referring URLs, and diagnostic and error data (via our error-monitoring provider).
- Cookies and similar technologies: as described in our Cookie Policy. Our first-party analytics are cookieless.
- Support and communications data: the content of messages you send us and our correspondence.
- Waitlist data: if you ask to be notified before launch, the email address you enter, an optional website domain, the page you submitted the form from, and the timestamps of your signup and of the emails we send you.
We do not intentionally collect special categories of data or government identifiers, and you should not submit them through the Service except as strictly necessary and lawful.
Pre-Launch Waitlist
If you join the SEOverts waitlist, we collect your email address (required) and, if you choose to give it, your website domain. We use them for exactly two messages: an immediate confirmation that you are on the list, and one announcement when SEOverts opens. We do not use waitlist data for any other marketing, we do not sell or share it, we do not use it for advertising, targeting, or measurement, and we do not add it to an account or a profile. Our legal basis is your consent (Art. 6(1)(a)), given when you submit the form. You can withdraw it at any time using the one-click unsubscribe link in every waitlist email, or by emailing privacy@getseoverts.com; withdrawal does not affect processing carried out before you withdrew. We delete waitlist records at the earliest of 30 days after you unsubscribe, 30 days after the launch announcement is sent, or 18 months after you signed up if that announcement has not been sent. If you later open an account and then delete it, we delete any waitlist record for the same address at the same time.
3. How and Why We Use Personal Data (and Legal Bases)
As a controller of Customer/Member data, we use personal data to:
| Purpose | GDPR / UK GDPR legal basis (Art. 6) |
|---|---|
| Provide, operate, and maintain the Service and your account | Performance of a contract (Art. 6(1)(b)) |
| Retrieve and display Integration Data and SEO/ads metrics you request | Performance of a contract (Art. 6(1)(b)) |
| Process subscriptions, billing, Credits, and payments | Performance of a contract (Art. 6(1)(b)) |
| Authenticate users and secure the Service; prevent fraud and abuse | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable |
| Provide customer support and respond to requests | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Monitor, debug, and improve the Service and develop new features | Legitimate interests (Art. 6(1)(f)) |
| Send service and transactional communications | Performance of a contract (Art. 6(1)(b)) |
| Send marketing communications (where applicable) | Consent (Art. 6(1)(a)) or legitimate interests, as permitted by law; opt-out available |
| Operate the pre-launch waitlist and send the launch announcement you asked for | Consent (Art. 6(1)(a)); withdrawable at any time |
| Optional analytics/advertising cookies and tags | Consent (Art. 6(1)(a)) |
| Comply with legal obligations and enforce our Terms | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object as described in Section 10.
As a processor of Integration Data, our legal basis is the Customer's instruction and the DPA; the Customer is responsible for establishing the lawful basis for connecting each Integration and using its data.
4. Google API Data: Limited Use Disclosure
SEOverts' use and transfer to any other app of information received from Google APIs, including Google Search Console, Google Analytics 4 (GA4), and Google Business Profile, will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:
- use Google user data only to provide or improve user-facing features of the Service that are prominent and visible to you (such as your rankings, analytics, and audit dashboards);
- do not transfer or sell Google user data to third parties, except as necessary to provide those user-facing features, to comply with applicable law, or as part of a merger or acquisition with notice to you;
- do not use Google user data for advertising, including serving, targeting, or measuring ads; and
- do not use Google user data to train generalized artificial-intelligence or machine-learning models.
Human access to Google user data is limited to narrow cases permitted by the policy (for example, with your explicit consent, for security or abuse investigation, or to comply with law).
5. Meta and TikTok Platform Data
Data the Service retrieves from the Meta Ads and TikTok Ads APIs is handled in accordance with those platforms' applicable platform and developer data terms. We use that data only to provide the Service's ads monitoring and optimization features to you, and we do not sell it or use it for our own advertising. By connecting a Meta or TikTok Integration, you agree to comply with the applicable Meta and TikTok platform terms in your own use of that data.
6. Integration Tokens: Encryption and Deletion on Disconnect
OAuth tokens and other Integration credentials are encrypted at rest using AES-256-GCM. They are used only to retrieve the Integration Data needed to provide the Service to you. When you disconnect an Integration, we delete the associated tokens and credentials, and the Service stops retrieving new data from that source. Previously retrieved metrics may persist in your dashboards until deleted per our retention practices (Section 8) or your instructions.
7. Cookies and Analytics
We use cookies and similar technologies as described in our Cookie Policy. In summary:
- Strictly necessary cookies (authentication/session) are always on.
- Analytics: we use Plausible, a cookieless analytics tool that does not track individuals across sites and does not set cookies; it is used on an aggregate basis. Optional analytics such as Google Analytics run only with your consent.
- Marketing: optional Meta Pixel and Google advertising signals run only with your consent, and we honor Google Consent Mode v2 and the Global Privacy Control (GPC).
You can manage choices via the cookie banner and "Cookie Settings." See the Cookie Policy and the US State Privacy Rights Notice for opt-out details.
8. Disclosures and Sub-processors
We do not sell Customer/Member personal data for money. We disclose personal data to:
- Sub-processors and service providers who process data on our behalf to provide the Service, including Supabase (database, authentication, hosting), Stripe (payments), Cloudflare (hosting/CDN), Resend (email), Upstash (queues and rate limiting), Sentry (error monitoring), and DataForSEO (SEO data retrieval), under contractual confidentiality and data-protection obligations. Our current sub-processors are listed in the Sub-processor List.
- Professional advisors (legal, accounting, audit) under confidentiality.
- Authorities and others where required to comply with law, respond to lawful requests, enforce our Terms, or protect the rights, safety, and property of the Company, our users, or the public.
- Acquirers in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or successor protections.
Data obtained from Google APIs is disclosed only as permitted by the Limited Use requirements (Section 4). Enabling optional advertising tags on our own website (e.g., Google or Meta) may constitute "sharing" or "cross-context behavioral advertising" under certain US state laws; see the US State Privacy Rights Notice for how to opt out.
9. International Data Transfers; Data Retention
We are based in the United States and may process and store data in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA) or Addendum to the SCCs, and the Swiss addendum, as applicable. You may request information about these safeguards using the contact details below.
We retain personal data only as long as necessary for the purposes described in this Policy, to provide the Service, to comply with legal, tax, accounting, and regulatory obligations, to resolve disputes, and to enforce our agreements. As a controller, we generally retain account data for the life of the account and for a limited period afterward, and retain certain records longer where required by law. As a processor, retention of Integration Data is governed by the Customer's instructions and the DPA; Integration tokens are deleted on disconnect (Section 6). When data is no longer needed, we delete or de-identify it. Waitlist records are deleted at the earliest of 30 days after unsubscribe, 30 days after the launch announcement, or 18 months after signup (Section 2, Pre-Launch Waitlist).
10. Security
We implement technical and organizational measures designed to protect personal data, including encryption in transit, AES-256-GCM encryption of Integration tokens at rest, access controls and least-privilege permissions, tenant isolation enforced in the application and reinforced by database row-level security, network and edge protections, logging and monitoring, and secret-management practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. A summary of our measures is set out in Annex II of the DPA.
11. Your Privacy Rights (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights regarding personal data for which we are the controller, subject to applicable law:
- Access: obtain confirmation of and a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion ("right to be forgotten") in certain circumstances.
- Restriction: restrict processing in certain circumstances.
- Portability: receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection: object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent: where processing is based on consent, withdraw it at any time (without affecting prior processing).
- Lodge a complaint: complain to your local data-protection supervisory authority.
To exercise these rights, contact privacy@getseoverts.com. We will respond within the time required by law. Where personal data appears in Integration Data, the Customer is the controller; we will assist the Customer as its processor.
For US state privacy rights (California/CCPA-CPRA, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others), see the US State Privacy Rights Notice.
12. Children's Privacy
The Service is intended for business users and is not directed to children. We do not knowingly collect personal data from children under 16 (or the applicable age of digital consent in your jurisdiction). If you believe a child has provided us personal data, contact privacy@getseoverts.com and we will take appropriate steps to delete it.
13. Automated Decision-Making
We do not use Customer or Member personal data to make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. The Service applies automated analysis to provide its functionality (for example, generating SEO audit findings, rank-tracking alerts, abuse and rate-limiting controls, and ads budget Recommendations), but these are operational features about websites and campaigns rather than automated decisions about individuals within the meaning of Article 22 of the GDPR. In particular, ads budget Recommendations are advisory only and are applied to your ad accounts only after your explicit approval and within the budget caps you set.
14. "Do Not Track" and Browser Signals
Some browsers transmit "Do Not Track" or similar signals. There is no industry-standard response to legacy "Do Not Track" signals, and we do not respond to them. However, we do honor the Global Privacy Control (GPC) and other recognized universal opt-out mechanisms as an opt-out of sale/sharing and targeted advertising, as described in our Cookie Policy and US State Privacy Rights Notice.
15. Third-Party Websites and Platforms
Our websites may link to websites and platforms we do not operate, including the third-party platforms behind your Integrations (Google, Meta, TikTok, and others). This Policy does not cover those third parties, which have their own privacy practices; your use of a connected platform remains governed by that platform's own terms and privacy policy.
16. EU/UK Representative (Article 27)
Where required by Article 27 of the GDPR or UK GDPR, we will designate a representative in the European Union and/or the United Kingdom. [EU/UK Article 27 Representative: placeholder; contact details to be published here.] Until designated, you may contact us at privacy@getseoverts.com.
17. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will bump the version, post the updated Policy with a new effective date, and provide notice, which may include a re-acceptance prompt where applicable. Your continued use after the effective date constitutes acceptance of the updated Policy.
18. Contact Us
- Privacy requests: privacy@getseoverts.com
- General legal: legal@getseoverts.com
- Data Protection Officer / privacy contact: dpo@getseoverts.com (placeholder)
- Mailing address: Meerkat 9000 LLC, [Address], South Carolina, USA