Privacy Policy

Last updated October 2, 2026

SEOsoft (“we”, “us”, “our”) is operated by SEOsoft, Karnataka, India. This Privacy Policy explains what personal data we collect when you use seosoft.app, why we collect it, how we use it, and the rights you have over it.

This policy applies to all visitors and registered users of seosoft.app and is designed to meet the requirements of the EU General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act 2023 (DPDP Act).

1. What data we collect

Account data

When you register, we collect your name, email address, and a hashed password. We never store your password in plain text.

Billing data

Subscription payments are processed by Paddle.com Market Limited (our Merchant of Record). We receive a transaction reference and subscription status. We do not store your card details — those stay with Paddle.

Usage data

We collect information about how you use the service, including pages visited, features used, reports generated, and tool runs. This helps us improve the product.

Marketing attribution data

When you arrive via a paid advertisement or campaign link, we capture the UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) and Google Click ID (gclid) along with your landing page. This is stored in your browser and, if you register, saved to your account so we can understand which channels drive signups. You can read more in our Cookie Policy.

Technical data

We collect your IP address, browser type, operating system, and referring URL. This data is used for security, fraud prevention, and aggregate analytics.

SEO scan data

When you run a report on a website URL, we process that URL and the resulting SEO data on your behalf. This data is stored in your account and retained while your account is active.

2. Why we collect it — legal bases

PurposeLegal basis (GDPR)DPDP basis
Providing the service and managing your accountContract (Art. 6(1)(b))Consent / Contract
Processing paymentsContract (Art. 6(1)(b))Contract
Sending transactional emails (receipts, password resets)Contract (Art. 6(1)(b))Contract
Analytics — understanding how the service is usedConsent (Art. 6(1)(a))Consent
Advertising — measuring and optimising paid campaignsConsent (Art. 6(1)(a))Consent
Marketing attribution — linking signups to campaignsLegitimate interest (Art. 6(1)(f))Legitimate use
Security, fraud prevention, and legal complianceLegitimate interest / Legal obligation (Art. 6(1)(c)(f))Legal obligation

Where we rely on consent for analytics or advertising cookies, you can withdraw that consent at any time via the cookie banner or by visiting our Cookie Policy page.

3. Third-party processors

We share data with the following third parties who process it on our behalf. Each has a Data Processing Agreement in place with us.

ProcessorPurposeData sharedLocation
Google Analytics (GA4)Website analyticsAnonymised usage data, page paths, eventsUSA (EU SCCs)
Google AdsAdvertising measurementConversion events, click IDsUSA (EU SCCs)
Google Tag ManagerTag deploymentManages when GA4 / Ads tags fireUSA (EU SCCs)
Paddle.com Market LimitedPayment processing (Merchant of Record)Email, billing address, transaction amountUK / USA
DataForSEOSEO data APIURLs you submit for analysisUSA
KlaroConsent management (open source, self-hosted)Stores your consent preference locally — no data leaves your browserYour browser

We do not sell your personal data to any third party, and we do not share it for purposes beyond those described above.

4. Cookies and tracking

We use cookies and local storage for essential functionality, analytics, and advertising. Analytics and advertising cookies are only set after you give explicit consent via our cookie banner.

For a full list of cookies, their purposes, and how to manage them, see our Cookie Policy.

5. How long we keep your data

Data typeRetention period
Account and profile dataUntil you delete your account, then 30 days before permanent deletion
Billing records7 years (legal / tax obligation)
SEO reports and scan historyWhile your account is active; deleted when your account is deleted
Marketing attribution data24 months from registration, or until account deletion
Server logs (IP, technical data)90 days
Analytics data (GA4)14 months (configured in GA4)

6. International data transfers

Some of our processors (Google, Paddle) are based in the United States. Where data is transferred outside the EU/EEA or India, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent safeguards, to ensure an adequate level of protection.

7. Your rights

Depending on where you are located, you have the following rights over your personal data:

Under GDPR (EU/EEA residents)

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — ask us to correct inaccurate data.
  • Right to erasure (“right to be forgotten”) — request deletion of your personal data where there is no compelling reason for us to keep it.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to restrict processing — ask us to pause processing of your data in certain circumstances.
  • Right to object — object to processing based on legitimate interest.
  • Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

Under the DPDP Act (Indian residents)

  • Right to information — know what personal data we process and for what purpose.
  • Right to correction and erasure — request correction of inaccurate data or erasure of data that is no longer needed.
  • Right to grievance redressal — raise a grievance with us; we will respond within a reasonable time.
  • Right to nominate — nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, contact us at support@seosoft.app or via our contact page. We will respond within 30 days. We may ask you to verify your identity before acting on a request.

If you are in the EU/EEA and believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority.

8. Security

We use industry-standard security measures including HTTPS encryption in transit, hashed password storage (bcrypt), and access controls. No method of electronic storage is 100% secure and we cannot guarantee absolute security, but we take reasonable steps to protect your data.

9. Children

Our service is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe we have done so, please contact us and we will delete the data promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised “last updated” date. Where changes are material, we will notify registered users by email.

11. Contact and Data Fiduciary

SEOsoft is the Data Controller (GDPR) and Data Fiduciary (DPDP Act) for personal data collected through seosoft.app.