Privacy Policy
Effective date: July 27 2026 · Last updated: July 27 2026
Great SEO ("Great SEO," "we," "us," or "our") operates the website and platform available at https://greatseo.app. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what choices you have. By using Great SEO, you agree to the practices described here.
1. Information We Collect
1a. Information you provide directly
Account information (name, email, hashed password, or Google OAuth details); project and configuration data (website URLs, keywords, competitor domains, target countries, settings); billing information processed by Stripe (we store only the last four digits and a Stripe token — never your full card number or CVV); white-label branding uploads on Pro; support communications; and free audit submissions (URL and email address).
1b. Information collected automatically
Usage data (pages visited, features used, quota consumption, timestamps); log data (IP address, browser type, OS, referring URL — retained 90 days); and strictly necessary and functional cookies for session management and user preferences. We do not use advertising or third-party tracking cookies.
1c. Information from third parties
Google APIs (PageSpeed Insights, Places, Custom Search) — responses stored in connection with your account; DataForSEO — competitor domain metrics returned for domains you submit; Stripe — billing and subscription events via webhook.
2. How We Use Your Information
To provide, operate, and improve the platform; authenticate accounts and enforce plan quotas; generate audits, reports, keyword data, Web Vitals scans, competitor analyses, and GBP audits for sites you submit; process payments; send transactional emails (account verification, audit completion, scheduled report delivery, quota alerts, payment confirmations, password reset, free audit results and follow-up); respond to support requests; detect and prevent fraud; and comply with legal obligations. We do not use your data to train AI models. We do not sell your personal data.
3. Legal Basis for Processing (EEA, UK, and Brazil residents)
Contract performance (providing the service you subscribe to); legitimate interests (fraud prevention, security, platform improvement); consent (marketing follow-up emails to free-audit leads — withdraw anytime via the unsubscribe link); and legal obligation (retaining billing records as required by law).
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We share data only with: service providers bound by data processing terms (Supabase — database/auth; Stripe — payments; Resend — transactional email; DataForSEO — competitor data; Google APIs); when required by law or court order; and in a business transfer (we will notify affected users before any such transfer). We do not share data with advertising networks or data brokers.
5. Data Retention
Active accounts: data retained while account is active. Deleted accounts: personal data deleted within 30 days (billing records retained up to 7 years per applicable tax law). Free audit leads: retained up to 12 months. Log data: deleted after 90 days.
6. Data Security
All data in transit encrypted via HTTPS/TLS. Passwords hashed with bcrypt. Database access restricted via Supabase row-level security. Payment data tokenized by Stripe. Administrative access governed by access controls and audit logging. In the event of a breach affecting your personal data, we will notify you as required by law.
7. Cookies
| Category | Purpose | Can you opt out? |
|---|---|---|
| Strictly necessary | Authentication, session management, CSRF protection | No — required for the service |
| Functional | Remembering preferences, last active project | Yes — via browser settings |
| Analytics | Aggregate usage statistics (if enabled) | Yes — via the cookie banner |
We do not use advertising or cross-site tracking cookies.
8. Your Rights
Depending on your location, you may have the right to: access your data; correct inaccuracies; request deletion (subject to legal retention requirements); request data portability; restrict or object to processing; and withdraw consent where processing is consent-based. Brazil residents have these rights under the LGPD. EEA/UK residents have these rights under the GDPR/UK GDPR and may lodge complaints with their local supervisory authority. To exercise any right: email roger@greatstart.com.br. We respond within 30 days.
9. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect their data. Contact roger@greatstart.com.br if you believe we have done so inadvertently.
10. Third-Party Links
We are not responsible for the privacy practices of third-party websites linked from our platform.
11. Changes to This Policy
We will notify you by email and update the "Last updated" date for material changes. Continued use after the effective date constitutes acceptance.
12. Contact
Email: roger@greatstart.com.br · Website: https://greatseo.app