Privacy
What we hold, and what we do with it.
Written against an audit of the running system, not a template, including the parts that do not flatter us. Every processor named here was confirmed in the code.
On this page
- We never sell your data, never share it for advertising, and never let a model provider train on your content.
- We hold what the work requires: your account, your site’s content and search data, and credentials for the platforms you connect, all encrypted before they reach our database.
- Card details never touch our servers. They go from your browser to Stripe.
- Deletion today is manual. Ask through the contact form and we delete the account, the workspace, and every stored credential within a month, and pass it through to our sub-processors.
- Analytics are off until you accept them. No Google script loads and no identifier is stored before you answer, and you can change your mind from any page.
This summary is for orientation only. The numbered sections below are the operative terms.
Who we are and what this covers
SearchHandled LLC is a Delaware limited liability company operating the SearchHandled service at searchhandled.com and the customer console at searchhandled.com/app (together, the “Service”). In this policy “we”, “us”, and “our” mean SearchHandled LLC; “you” means the person reading it.
This policy covers three groups of people, and it matters which one you are, because we hold different data about each:
- Customers
- People who create a workspace, connect a site, and use the Service. We are the controller of your account data and the processor of the site, search, and content data you authorize us to work with.
- Enquirers
- People who submit the contact form or request an email-delivered Growth Map without creating an account. We are the controller of what you send us.
- Third parties whose details appear on a page we analyze
- Our crawler reads customer websites, and those pages sometimes carry names, phone numbers, postal addresses, and author bylines. We did not collect that from you and we have no relationship with you, but we hold it, so section 16 explains what happens to it.
Because we publish no postal or email address, every privacy request, question, and complaint runs through one route: the contact form, with the topic set to “Privacy or data request”. It reaches a person, not a queue.
Definitions
These terms are used throughout with the meanings given here.
- Workspace
- The tenant that holds your sites, settings, connections, and generated content. One workspace per account today.
- Growth Map
- The analysis we produce from a website: what it ranks for, what it does not, and what work would change that. Anonymous Growth Maps are delivered only to the email address the requester supplies; they are not displayed in the public browser session.
- Connection
- An authorization you grant us to read from or write to a third-party platform: Google Search Console, Google Analytics, Bing Webmaster Tools, or a CMS.
- Crawl
- Our automated retrieval of pages from a website in order to analyze them.
- Sub-processor
- A third party that processes personal data on our behalf, or that we necessarily transmit personal data to in order to run a feature. Section 8 lists all of them.
- Personal data
- Information relating to an identified or identifiable person. Where this policy says “personal information”, it means the same thing under US state law.
What we collect
Set out by category, with the actual fields rather than a summary of them.
Account and identity data
Collected when you create an account, and required to have one.
- Email address, used as your login identity.
- Password signup creates a pending account and sends a single-use email-verification link. Product and account routes remain unavailable until that link is used. A password reset you request also establishes inbox control; Google sign-in establishes it from Google’s signed identity claim.
- Full name.
- A password, which we never store in readable form. We retain only a one-way password verifier.
- If you sign in with Google: your Google account identifier, email address, name, and whether Google has verified that address. We request no Google permissions for sign-in beyond identity: no access to your Gmail, Drive, or calendar.
- A protected session cookie and the account state needed to end active sessions when you sign out or secure the account.
Workspace and strategy data
Collected during onboarding and editable afterwards. Much of it is free text you write, and we use it to shape the work.
- Site domain, platform, business model, growth stage, team size, and your stated goal and role.
- Publishing mode, selected plan, billing interval, and the number of sites selected.
- Free-text strategy fields: target audience, brand voice, compliance notes, and seasonality.
- Structured strategy fields: target markets, content languages, service locations, conversion goals, and named competitors.
Connection credentials and grants
When you connect a platform, we store what is needed to keep using it on your behalf, and nothing more.
- For Google Search Console and Google Analytics, the authorization grant and selected property information needed to make read-only requests.
- For Bing Webmaster Tools, the authorization and selected site information needed to read the reporting data you request.
- For publishing destinations, the destination identity and authorization needed to create or update content on your instruction.
Credentials and grants in this category are protected separately from ordinary application data and are never returned to the browser after setup. See section 12.
Site content and crawl data
To analyze a site we retrieve its pages and keep what the analysis needs: titles, meta descriptions, canonical URLs, heading structure, opening body text, prose samples, and near-duplicate line comparisons, all keyed to the URL they came from.
The crawler also extracts entity and contact details that appear on the page (organization names, phone numbers, postal addresses, geographic coordinates, opening hours, and author bylines) because their presence and consistency is part of what determines whether a page is trusted by search engines. Where those belong to a person rather than a business, they are personal data, and section 16 covers them.
Search and analytics data from your connected accounts
From Search Console: the queries your site appears for, the pages that appear, and their impressions, clicks, average position, and click-through rate. From Google Analytics 4: landing-page engagement, sessions, conversions, and revenue metrics where you record them.
This is aggregate reporting data about your site. We do not receive, and do not ask for, your visitors’ individual analytics records.
Generated content and change history
Drafts we produce for you (title, slug, body, and publication decision) together with the published URL once a draft goes live. Separately, an append-only change log recording what we published to your site and when we submitted it for indexing. That log has no deletion path by design; it is the record that lets you audit us.
Enquiry and lead data
When you submit the contact form we receive your name, email address, company, website, topic, primary goal, what you have already tried, and your message.
Two different things then happen to it, and the difference is worth stating: your name, email, website, and goal are stored in our database as a lead record. Your message, your “already tried” note, and your company name are not stored in our database at all: they exist only in the notification email that reaches the person who answers you.
Growth Map runs, including anonymous ones
Every Growth Map is recorded durably: the submitted URL and host, the run’s status and progress, how many pages were crawled, and the complete analysis result. If the run was started without an account, the record also carries the anonymous browser identifier described below.
For an anonymous run, polling returns progress and completion state but not the completed analysis. We store the delivery address you gave us, the run it relates to, the host analyzed, and whether the send succeeded, even though you may have no account with us. The report is sent only to that address as an email with a PDF attachment.
Product analytics and device data
A randomly generated identifier stored in your browser, described in section 7, together with the pages you view on our marketing site and the product events you trigger, such as starting a Growth Map or completing signup.
When you create an account, that anonymous identifier is linked to your workspace in our product-analytics tool. From that point the activity recorded before you signed up is associated with your account. If you would rather it were not, clear your browser storage before signing up, or ask us and we will unlink it.
Billing data
Your Stripe customer identifier, subscription identifier, plan tier, billing interval, site count, subscription status, current period end, and whether a cancellation is pending.
We never see, receive, or store your card number. Card details go from your browser to Stripe directly and do not pass through our servers.
Security and abuse-control data
Short-lived security records used to prevent automated abuse, protect password recovery, and investigate suspicious access. These records may be associated with an address, account, browser, or network identifier and are retained only as long as the security purpose requires.
At signup we check your chosen password against a public breach corpus. This is done using k-anonymity: we send the first five characters of a SHA-1 hash of the password and compare the returned range locally. The password itself, and any hash that could be reversed to it, never leaves our server.
Server logs
Our hosting and application services keep short-lived access and error logs containing request metadata, network information, response status, and a support correlation identifier. Sensitive URL parameters and message content are excluded from routine logs.
We use those logs to maintain availability, investigate abuse, and locate a specific failure you report. Hosting-platform retention is short and measured in days rather than months.
Where it comes from
- From you directly: account details, onboarding answers, contact submissions, and anything you type into the assistant or paste in as source material.
- From your browser automatically: the pages you visit on our site, the events you trigger, and the identifier described in section 7.
- From your website: by crawling it, at your instruction or on submission of its URL to the Growth Map.
- From platforms you connect: Google Search Console, Google Analytics, Bing Webmaster Tools, and your CMS, using the authorization you granted and only within its scope.
- From Stripe: your subscription state, by webhook, after a payment event.
- From search-data providers: ranking and keyword data about queries and domains you ask us to look at. These describe public search results, not people.
Why we use it, and our lawful basis
Under the UK GDPR and EU GDPR we must have a lawful basis for each purpose. This table is that record. Where the basis is legitimate interests, we have carried out a balancing assessment and will share it on request.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and operate your account | Account and identity data | Performance of a contract |
| Produce Growth Maps, plans, and drafts | Workspace, crawl, search, and analytics data | Performance of a contract |
| Publish to destinations you connect | Generated content, connection credentials | Performance of a contract |
| Measure whether published work produced outcomes | Search Console and Analytics data, attributed sales you record | Performance of a contract |
| Take payment and manage subscriptions | Billing data, email address | Performance of a contract |
| Send transactional email: password resets, reports you requested | Email address, report contents | Performance of a contract |
| Answer your enquiry | Enquiry and lead data | Legitimate interests: responding to someone who contacted us |
| Send an optional monthly performance digest | Email address, your site’s performance data | Consent, withdrawable in one click from any digest |
| Measure our own website with Google Analytics | Page views, referrer, product events, the analytics cookies in section 7 | Consent, withdrawable from any page |
| Join your product events into one session | The sh_anon_id identifier described in section 7 | Consent, withdrawable from any page |
| Count traffic and conversions without an identifier | Page and event counts, with no persistent id attached | Legitimate interests: knowing whether the site works |
| Record how the Service is used, so we can find where people get stuck | A consent-gated, masked replay of public-page structure and interaction. All rendered text and inputs are masked; account, submitted-value, and payment surfaces are blocked | Consent, withdrawable from any page |
| Prevent abuse, credential stuffing, and fraud | Hashed rate-limit keys, reset-request IP, honeypot results | Legitimate interests: securing the Service; legal obligation where applicable |
| Keep an auditable record of changes made to your site | Change log | Legitimate interests: accountability to you; legal obligation where applicable |
| Comply with law and defend legal claims | Whatever is relevant to the matter | Legal obligation; legitimate interests |
We do not use your data for advertising, we do not build a marketing profile of you, and we do not run behavioural advertising anywhere on our site.
What we never do with it
- We do not sell your personal data. We have never sold it, and we hold no arrangement under which it could be sold.
- We do not share it for cross-context behavioural advertising, as California defines that term.
- We do not build or sell an aggregate data product derived from customer sites, search data, or performance figures.
- We do not permit our language-model providers to train on your content: see section 9 for exactly what that commitment rests on.
- We do not use your Search Console or Analytics data for anything other than the features you enabled, as Google’s Limited Use requirements oblige.
- We do not request access to your customers’ records, orders, or billing data on any platform you connect.
Cookies and browser storage
Everything the Service stores in your browser, in full. There is nothing here we have not listed. The “Needs consent” column is the operative one: those two are not written unless you accept analytics, and they are deleted if you later decline.
| Name | Type | Purpose | Needs consent | Lifetime |
|---|---|---|---|---|
| __Host-sh_session (sh_session outside production) | Cookie | Keeps you signed in. HttpOnly, Secure, SameSite=Lax. Not readable by JavaScript. | No: strictly necessary | 7 days, refreshed on use |
| NEXT_LOCALE | Cookie | Remembers your chosen language. | No: strictly necessary | 1 year |
| sh.consent | localStorage | Your answer to the analytics question, so a decline is remembered rather than re-asked. | No: it is the record of the answer | Until you clear browser storage |
| _ga, _ga_G-7TXVTX3Y32 | Cookie | Google Analytics. Distinguishes browsers so page views can be counted. | Yes | Set by Google, typically 2 years |
| sh_anon_id | localStorage | A random identifier that lets us join your product events into one session before you have an account. | Yes | Until you clear browser storage |
| ph_* (PostHog) | localStorage and cookie | Recognises your browser across consented visits so separate recordings are one person. PostHog is not loaded and creates no identifier unless you accept analytics. | Yes | Set by PostHog, typically 1 year |
| sh.session | localStorage | Your account email, name, identifier, workspace record, and session expiry, so the console renders without a round trip. The session token itself is deliberately not stored here. | No: strictly necessary | Until sign-out or expiry |
| sh.console.collapsedNavGroups | localStorage | Which console navigation groups you folded shut. | No: strictly necessary | Until you clear browser storage |
| sh.growth-map.<run> | sessionStorage | An access token for a Growth Map run you started, so you can return to it in the same tab. | No: strictly necessary | Until the tab closes |
| sh.checkout.selection | sessionStorage | The plan and interval you chose, carried into checkout. | No: strictly necessary | Until the tab closes |
Analytics, stated accurately
Google Analytics does not run until you accept it. The tag is not loaded, no request reaches Google, and no cookie is set before you answer the banner. Declining is recorded and remembered; it is not re-asked on every page. The same gate governs our own sh_anon_id identifier, because first-party does not mean exempt.
You can change your mind at any time. Every page with a footer carries a “Cookie choices” control; the console and the sign-in pages have no footer, so the one here is the route from those: .
Withdrawing is one click and takes effect immediately: we delete sh_anon_id, expire the Google Analytics cookies, and instruct the tag to stop setting new ones. Google’s script cannot be unloaded from a page that is already open, so it stops collecting rather than disappearing until you navigate or reload.
Where advertising is concerned there is nothing to consent to. Ad storage, ad personalization, and ad user data are set to denied permanently rather than offered as a second question, because we run no advertising products at all.
Session recording is behind the same consent gate as Google Analytics. Before you accept, the PostHog module is not loaded, no remote configuration is fetched, and no replay or event payload is sent. After you accept, every rendered text node and every form input is masked before it leaves the browser; authenticated account screens, submitted-value surfaces, and payment areas are blocked outright. Withdrawing consent stops further capture and clears the active identity. You can ask us to delete earlier consented recordings at any time using the contact route in section 11.
Vercel Web Analytics is not behind the banner, and we would rather explain why than quietly include it. It sets no cookie and stores nothing on your device, so the rule that requires consent for cookies has nothing to attach to; it counts page views and product events under legitimate interests. Those events record what happened and never who it happened to: which plan was chosen, which free tool was run, whether a checkout completed. They carry no identifier, no email address, and not the website address you asked us to analyse. It is loaded only on searchhandled.com; the www host redirects before application code runs. On any other host, including previews and local development, neither tool is loaded at all.
If you decline, funnel events still reach our own servers without any identifier attached. That means we can see that a page was viewed and cannot see that it was you. The measurable consequence is on our side: our conversion funnel degrades to a traffic count, which is the correct cost of a decline.
URL redaction
Analytics receives only approved acquisition parameters and the page information needed for measurement. Other URL parameters and fragments are removed before an event leaves the browser, and an event we cannot safely reduce is dropped.
This minimization applies to every browser analytics destination we use and prevents recovery, checkout, connection, and session material from entering analytics logs.
Sub-processors and other recipients
The complete list, derived from the deployed system rather than from an intention. It is longer than most policies of this kind because it is honest about services that run without configuration and about the fallback tiers that activate the moment a key is added.
Always active
| Recipient | Purpose | What it receives |
|---|---|---|
| Supabase (AWS us-east-1, USA) | Application database | The entire application dataset: accounts, hashed passwords, workspaces, subscriptions, leads, funnel events, drafts, crawl results, and encrypted connection credentials |
| Vercel (USA) | Application hosting and Web Analytics | All request traffic; for analytics, the redacted page path and product events carrying no identifier and no customer website address |
| Google Analytics (Google, USA) | Website analytics on our marketing site, only after you accept analytics | Redacted page URL, title, referrer, and product events, with advertising signals disabled. Nothing at all before you accept |
| Google Suggest (Google) | Keyword expansion | The seed keyword you research, and the permutations generated from it. This is an unauthenticated public endpoint and runs with no configuration on our side |
| Have I Been Pwned (USA) | Breached-password check at signup | The first five characters of a SHA-1 hash of your chosen password, with padding. Never the password, never a reversible hash |
| Resend (USA) | Transactional email delivery | Recipient address, subject, and the full body of the message, including the entire contact enquiry, requested Growth Map report and attachment, and password-reset links |
| Stripe (USA) | Payments and subscription billing | Your email address, workspace identifier, plan and price selection. Card data goes from your browser to Stripe and never reaches us |
Active when you use the corresponding feature
| Recipient | Purpose | What it receives |
|---|---|---|
| Anthropic (USA) | Primary language model | Prompts containing crawled page text, your strategy and compliance notes, assistant messages you type, source material you supply, and draft bodies |
| OpenAI (USA) | Language-model fallback and AI-citation sampling | The same class of prompt, when the primary provider fails or is unconfigured |
| Google Gemini (Google, USA) | Language-model fallback and image generation | The same class of prompt; image-generation briefs |
| Perplexity, xAI (USA) | AI-citation sampling, when enabled | Brand and topic prompts used to test whether your brand is cited in AI answers |
| DataForSEO (Cyprus/USA) | Licensed search-results and ranking data | Keywords, your domain, competitor domains, brand names, and location, language, and device settings |
| Serper.dev, Brave Search | Alternative search-results providers, when configured | Query strings |
| Google Search Console, Google Analytics (Google) | Reading your own properties, under the grant you gave | Your OAuth tokens and the API calls needed to read your data |
| Google Identity Services (Google) | Sign in with Google | The sign-in event; Google returns your identifier, email, and name |
| Microsoft Bing Webmaster Tools | Reading your Bing search data | Your Bing API key and site URL |
| IndexNow | Telling search engines a page changed | Your domain, your IndexNow key, and the published URLs. One submission is redistributed by the protocol to Bing, Yandex, Seznam, and Naver |
| PostHog (USA) | Product analytics, server-side error reporting, and session recording | Event names, your workspace identifier, and scrubbed properties. Emails, tokens, API keys, database URLs, prompts, and page text are redacted before sending. PostHog also runs a recorder in your browser: it captures the structure of the pages you visit and where you click, with all text and form inputs masked and the payment form excluded entirely. It does not capture what you type |
Publishing destinations you choose
When you connect a destination and approve a draft, the title, slug, excerpt, and full body are sent to it, authenticated with the credential you supplied. Webflow and Notion are third-party services and are therefore sub-processors. WordPress, Ghost, Shopify, and a generic webhook publish to infrastructure you control, so the recipient is you.
Nothing publishes to a destination you have not connected, and nothing publishes outside the publish mode you selected.
Others
We may also disclose personal data to professional advisers under confidentiality, to a regulator or court where we are legally required to, and to an acquirer in the event of a merger or sale of the business, in which case we will tell you before your data becomes subject to a different policy.
A current sub-processor list, a data processing agreement, and answers to a security questionnaire are available on request through the contact form.
Artificial intelligence and language models
The Service is built on large language models, so it matters what reaches them.
What goes into a prompt
- Text crawled from the site being analyzed, including opening body copy, headings, and metadata, and the contact and entity details published on those pages.
- Your workspace strategy fields, including compliance notes, verbatim.
- Messages you type into the assistant, together with your Growth Map opportunities, saved keywords, and content plan.
- Raw source material you supply for an article, within the limits shown in the product.
- Draft bodies, for review and revision.
- Search Console query phrases and performance movements, when producing refresh recommendations.
What never goes into a prompt
Your password or its hash. Your session tokens. Your connection credentials. Your card or billing details. Contact-form messages, which reach our database and our inbox but are never sent to a model.
Training, retention, and where the commitment sits
Our model providers operate under commercial API terms that prohibit training on customer content submitted through their APIs, and Google’s API policy separately prohibits using Search Console or Analytics data to train generalized models. That is what our commitment rests on, and we would rather say so precisely than imply we have engineered something we have not.
We keep limited usage and cost metadata for model requests without keeping the prompt or completion text in that accounting record.
Providers may retain API traffic briefly for abuse monitoring under their own terms. We have not negotiated a zero-retention arrangement with any provider, and we will not describe one until we have.
Automated decisions
Content we generate passes evidence, safety, duplication, and publishing-policy checks before it can be published. Higher-risk or insufficiently supported work is held or blocked, and today every draft reaches you for approval regardless. We do not publish the exact detection rules or thresholds because doing so would make the controls easier to evade. No decision producing legal or similarly significant effects on a person is made by automated means.
International transfers
We are a US company and our infrastructure is in the United States. Our database runs in AWS’s us-east-1 region in Northern Virginia; our product analytics runs on PostHog’s US cloud.
If you are in the United Kingdom, the European Economic Area, or Switzerland, using the Service means your personal data is transferred to the United States and to the sub-processors listed in section 8, some of which operate in other countries.
For those transfers we rely on the UK and EU Standard Contractual Clauses, together with the UK Addendum where applicable, incorporated into our agreements with sub-processors, and on the EU-US and UK-US Data Privacy Framework where a given sub-processor is certified under it. A copy of the transfer mechanism relied on for any specific sub-processor is available on request.
How long we keep it
This section describes what the system actually does today. Two things in it are commitments we keep manually rather than automatically, and they are marked as such.
| Data | Retention | Mechanism |
|---|---|---|
| Account, workspace, sites, connections | Until you ask us to delete it | Manual on request |
| Crawl results, Growth Maps, drafts, rank history | Until you ask us to delete it | Manual on request |
| Change log and publication history | Retained for the life of the workspace, and not editable by us or by you | By design: it is the record that lets you audit our actions |
| Leads and contact enquiries | Until you ask us to delete them | Manual on request |
| Contact-form message text | Not stored in our database at all; it exists only in the notification email | By design |
| Growth Map report email addresses | Until you ask us to delete them | Manual on request |
| Password-reset tokens and the IP that requested them | Deleted about one day after the token expires | Automatic |
| Rate-limiting counters | Deleted after roughly two rate-limit windows | Automatic |
| Server access and error logs | Days, set by our hosting platform. Query strings are never written to them | Automatic, by the platform |
| Language-model usage ledger | Retained for cost accounting; contains no prompt or completion text | By design |
| Billing records | Retained as long as required by tax and accounting law, typically seven years | Legal obligation |
How we protect it
- Passwords are protected with a modern, one-way password-verification scheme and are never stored, logged, or transmitted in recoverable form.
- Third-party credentials are encrypted separately from ordinary application data, with key material restricted to the server environment. The Service does not fall back to plaintext storage when protection is unavailable.
- Traffic runs over TLS. Data at rest is encrypted by our hosting provider.
- Database and infrastructure access follow least-privilege and separation-of-duty controls. Production application access is separated from migration and administrative access.
- Session cookies use browser security protections and are not readable by application scripts. Account-security actions can invalidate existing sessions.
- Error and analytics reports are minimized and scrubbed before they leave our systems. Reports that cannot be safely scrubbed are dropped rather than sent.
- Authentication, recovery, and public-write surfaces are rate-limited and monitored for abuse.
We deliberately avoid phrases like “bank-level” or “military-grade” encryption. They are marketing terms with no technical definition behind them.
No system is perfectly secure. If you believe you have found a vulnerability, report it through the contact form marked “Security or vulnerability”. Please describe credentials rather than including working ones.
Your rights
If you are in the UK, the EEA, or Switzerland, the following rights apply to you. We extend the substance of them to everyone, wherever you are, because operating two standards is how mistakes happen.
- Access
- A copy of the personal data we hold about you, and the information in this policy specific to your case.
- Rectification
- Correction of anything inaccurate. Most account and workspace fields you can correct yourself in the console.
- Erasure
- Deletion of your personal data, subject to the exceptions set out under “Deletion, stated honestly” below.
- Restriction
- A pause on our processing while a dispute about accuracy or legitimate interests is resolved.
- Portability
- The data you gave us, in a structured, machine-readable format, for you or for another provider.
- Objection
- An objection to processing based on legitimate interests, including profiling. If you object, we stop unless we can show compelling grounds that override your interests.
- Withdraw consent
- Where we rely on consent (analytics, and the monthly digest), withdrawal at any time, without affecting what happened before. Analytics is withdrawn from the footer of any page; the digest from a link in any digest.
- Complain
- A complaint to your supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority in your country of residence or work. We would appreciate the chance to put it right first, but you do not have to come to us before going to them.
How to exercise them
Use the contact form and select “Privacy or data request”. Tell us which right you are exercising and enough for us to find your records: the email address on the account, or the site domain.
We respond within one month. If a request is complex or you have made several, we may extend that by two further months, and we will tell you within the first month if we do. We do not charge a fee unless a request is manifestly unfounded or excessive, and we will say so before doing anything rather than after.
We may ask you to verify your identity before we act. That is a protection for you: erasure requested by the wrong person is not reversible.
Deletion, stated honestly
Self-serve account deletion is not built yet. Deletion today is manual: you ask through the contact form, and we delete the account, the workspace, and every stored credential, and pass the request through to the sub-processors that hold any part of it. We treat that as an obligation with a one-month clock on it, not a favour.
Some things survive a deletion request, and you should know which. Billing records are retained where tax law requires it. The change log entries recording what was published to your site are retained, because they are the audit record of actions taken on your behalf. And pages we published to your own site stay yours and stay published: they are on your infrastructure, and deleting our copy does not and should not take them down.
California privacy rights
This section applies to California residents and uses the terms of the CCPA as amended by the CPRA.
Categories collected in the last twelve months
| CCPA category | Collected | Examples in our case |
|---|---|---|
| Identifiers | Yes | Name, email address, account identifier, Google account identifier, IP address on a password-reset request, persistent browser identifier |
| Customer records information | Yes | Name and email associated with a paid subscription |
| Commercial information | Yes | Plan purchased, subscription state, billing interval |
| Internet or network activity | Yes | Pages viewed on our site, product events, referrer |
| Geolocation data | No | We do not collect precise geolocation. Location settings you choose for search research describe a market, not you |
| Professional or employment information | Yes | Your role, team size, and business model, where you provide them |
| Inferences | Limited | Recommendations about your site’s content. We draw no inferences about your personal characteristics |
| Sensitive personal information | No | We do not collect it, do not ask for it, and do not use it to infer characteristics. See the caution in section 3 |
| Biometric, education, protected classifications, audio or visual data | No | Not collected |
Sale, sharing, and your California rights
Californians have the right to know what we collect and why, to access and to receive a portable copy, to delete, to correct inaccuracies, to limit the use of sensitive personal information (which does not arise here, since we collect none), and not to be discriminated against for exercising any of it. We do not offer financial incentives in exchange for personal information.
An authorized agent may make a request on your behalf with written permission; we will ask you to verify that you granted it. Exercise any of these rights through the contact form under “Privacy or data request”. We do not require you to create an account to make a request.
Other US state privacy rights
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states with comprehensive privacy laws in force have rights to confirm processing, access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects.
We do not conduct targeted advertising, do not sell personal data, and do not profile people in a way that produces legal or similarly significant effects, so those opt-outs have nothing to act on. The remaining rights are exercised the same way as everyone else’s: through the contact form.
Where a state gives you the right to appeal a refused request, you may appeal by submitting the form again marked “appeal”. We will respond within the period your state’s law allows and, if we still refuse, tell you how to contact your attorney general.
People we hold data about who are not our customers
Three groups fall into this category, and a policy that only addressed account holders would be ignoring them.
People whose details appear on a page we crawl
Our crawler reads public web pages and extracts the contact and identity details published on them (organization names, phone numbers, postal addresses, opening hours, and author bylines) because their presence and consistency is part of what search engines assess. Where those details identify a person, we are processing personal data on the basis of legitimate interests: analysing a website that our customer owns or has instructed us to examine.
We collect this from public pages only. We do not attempt to enrich it, we do not build profiles from it, we do not combine it across sites to identify individuals, and we do not sell it. If your details appear in our systems because they are published on a site we analysed, you can ask us to delete them, and we will.
People who contact us without an account
If you submit the contact form or ask for a Growth Map report by email, we hold your address and what you told us. We use it to answer you. It is not added to a marketing list, and we do not send you anything you did not ask for.
Visitors to sites we publish to
We have no relationship with the visitors to our customers’ websites and we do not receive their individual analytics records. The Search Console and Analytics data we read is aggregate reporting about pages and queries.
Children
The Service is a business tool sold to businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under sixteen.
We do not operate an age gate, because nothing about the Service is attractive to or usable by a child, and asking every business customer for a date of birth would collect more personal data than it protected. If you believe a child has provided us with personal data, tell us through the contact form and we will delete it.
Changes to this policy
We will update this policy when what we do changes. The effective date and version number at the top of this page always reflect the current text.
For a material change (a new category of data, a new purpose, a new sub-processor that receives content, or anything that reduces your rights) we will give account holders reasonable notice by email before it takes effect, and where the law requires consent for the change we will ask for it rather than assume it. Continuing to use the Service after a non-material change means the updated policy applies.
We do not maintain a public archive of previous versions today. If you need the text as it stood on a particular date, ask and we will send it.
How to reach us
SearchHandled LLC is the controller of the personal data described in this policy. For any privacy question, request, or complaint, use the contact form and select “Privacy or data request”. It reaches the people who built the Service.
We are small, so an ordinary question may take a day or two. A data-rights request is treated on the statutory clock described in section 13, not on that one.
We have not appointed a data protection officer, because our processing does not meet the threshold that requires one. We have not appointed an EU or UK representative under Article 27; if you are a supervisory authority who needs a contact point, use the same form and we will respond directly.
Questions about this document, or want to exercise a data right? Use the contact form and pick “Privacy or data request”.
Questions
Plain language should survive a real conversation.
Contact us with questions about data access, publishing control, or service scope.

