SEOPlan.com

Privacy Policy

How SEOPlan.com handles website usage, customer billing, enquiries, and audit submissions.

Last updated August 31, 2026.

Who controls your information

The legal operator of SEOPlan.com is the controller for account, enquiry, website-use, and service-administration data. Stripe acts independently for some payment processing and also processes billing data for SEOPlan.com. Cloudflare, hosting, email-delivery, and technical service providers may process limited data on our instructions to operate and secure the service.

Information we process

We process account identifiers, name, email address, company details, email-verification and authentication records, plan and subscription status, audit allowance and usage, managed domains, monitoring schedules and alerts, team invitations and roles, API-key prefixes and cryptographic hashes, API usage timestamps, private reports, support enquiries, security logs, device and network information, and public website addresses submitted for analysis. Do not submit passwords, private network addresses, confidential documents, or unnecessary personal information.

Why we process it and the legal basis

  • Provide the account, audit, subscription, and support service: performance of a contract or steps requested before a contract.
  • Process payments, invoices, tax records, fraud prevention, and mandatory records: contract and legal obligations.
  • Protect accounts, prevent abuse, diagnose failures, and improve service reliability: legitimate interests in operating a secure and effective service.
  • Respond to privacy requests and legal claims: legal obligations and legitimate interests.
  • Optional marketing or non-essential analytics: consent where required. Consent can be withdrawn without affecting earlier lawful processing.

Customer accounts and billing

Stripe processes checkout, payment methods, invoices, tax information, fraud signals, and subscription management. SEOPlan.com receives customer and subscription identifiers, payment status, plan, billing period, and limited invoice information, but does not receive full card details.

Team access and customer API

Workspace owners can invite team members and assign roles. Invitation email, role, acceptance state, and membership history are processed to administer shared access. Scale customers can create read-only API keys. A complete API secret is displayed once; SEOPlan.com stores only a keyed cryptographic hash, a short identifying prefix, creation and last-use times, and revocation state. API responses are restricted to the owning workspace. Customers are responsible for protecting and revoking exposed keys.

Website audits and private reports

The crawler requests public webpages on the submitted domain and records technical findings. Anonymous reports use an unguessable access token exchanged for a secure browser cookie; only a cryptographic hash of the token is stored. Signed-in customers can retrieve reports assigned to their account. Submitted URLs and report findings are normally retained for up to 30 days and can be deleted sooner.

Recipients and international transfers

Information is disclosed only to authorized personnel, processors needed for hosting, Cloudflare security and Turnstile, transactional email delivery, support, and Stripe billing, professional advisers where necessary, and authorities where the law requires it. Some providers may process information outside the European Economic Area. Where required, transfers must rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Provider-specific locations and safeguards must be maintained in the operator’s processor register.

Retention

Private audit reports normally expire after 30 days. Contact enquiries are normally deleted after 24 months unless an earlier deletion request applies or a longer period is needed for a contract, dispute, security investigation, or legal record. Team invitation records are retained while pending and membership records while access is active, followed by a limited revocation history for security and dispute handling. Active API-key records remain until revoked; revoked hashes and security-use records are retained only for a proportionate security period. Account and subscription records are kept while the account is active and then only as long as necessary for legal, tax, fraud-prevention, and claim periods. Security logs are kept for a limited period proportionate to the risk.

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time and may lodge a complaint with the Lithuanian State Data Protection Inspectorate or another competent supervisory authority. Identity may need to be verified before a request is completed.

Cookies and similar storage

Essential cookies and browser storage may be used for WordPress authentication, private report access, security, load balancing, and account preferences. Non-essential analytics or advertising technologies must not be activated until the required information and consent controls are in place. Cloudflare Turnstile may process device and network signals to distinguish legitimate submissions from abuse.

Automated decisions, children, and security

Automated audit scoring provides technical guidance and does not make a legal or similarly significant decision about a person. The service is intended for business users and is not directed to children. We use access controls, encryption in transit, input validation, rate limits, expiration controls, backups, and monitoring; no internet service can promise absolute security.

Changes and contact

Material changes will be reflected on this page and, where appropriate, communicated through the account or service email. Use the protected contact form for privacy requests and identify the request clearly.