Privacy Policy & Data Governance
Transparent data collection, strict subprocessor controls, and zero credential retention for live crawls and AI workflows.
Privacy at a Glance
Clear, unambiguous architectural boundaries separating operational telemetry from your proprietary data.
What We Collect & Use
Verified account email & identity data
Provided by our authentication service to maintain workspace access and account security.
Read-only Search Console metrics (with user consent)
Search impressions, clicks, queries, and indexing state explicitly authorized via OAuth.
Public page crawl metadata & schema
Publicly accessible headers, HTML tags, status codes, and structural markup of audited sites.
Sanitized MCP tool execution logs (90-day max)
Outcome status codes and connection timestamps for security debugging and abuse prevention.
What We NEVER Collect or Store
Full credit card numbers (handled via Stripe)
All billing operations are processed directly by Stripe; our servers never touch or store card numbers.
Passwords, API secrets, or master tokens
Authentication uses cryptographically signed session tokens; raw credentials are never persisted.
Raw prompts, payload bodies, or private code repos
MCP tools and backend crawlers deliberately exclude raw prompt payloads, repository code, or internal tokens.
Private site data for third-party AI training
Customer crawl data, audit reports, and fix guides are never contributed to foundational AI model training sets.
1. Status and Privacy Posture
The trading identity (SEO Dispatch), available operator details (Operator details declared in platform settings), website domain (seodispatch.app), and monitored contact addresses that apply to this policy are displayed above and below. Product availability is controlled separately from the completeness of those published details.
SEO Dispatch is designed to follow the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) as a product baseline where they apply. This policy does not claim regulatory or legal approval.
Contracting & Operator Identification
SEO Dispatch · seodispatch.app
2. Information We Collect
We collect only the information reasonably necessary to operate the service, perform site audits, generate Fix Guides, and authenticate authorized users:
- Account and authentication information: Email address, verified identity data supplied by the authentication provider, account status, and security events.
- Workspace and operational SEO data: Workspace, membership, site, property, Search Console, analytics, crawl, keyword, ranking, audit, opportunity, Guide, verification, and report data needed for features you request.
- MCP client registrations: Selected workspace grants, optional Start Guide work permission, connection and last-use times, outcome codes, and sanitized audit metadata.
- Billing references: Billing customer, subscription, promotion, tax, and transaction identifiers supplied by Stripe. SEO Dispatch does not receive or store full card numbers.
- Communications: Support correspondence, waitlist and marketing consent records, unsubscribe records, and product feedback.
- Technical and security telemetry: Timestamps, bounded event metadata, rate-limit identifiers derived from a keyed hash, and logs needed to operate and protect the service.
3. Information Deliberately Excluded from MCP Audit Records & AI Safeguards
Operative Legal Covenant
MCP audit records must not contain access or refresh tokens, credentials, Guide Markdown, prompts, evidence bodies, request or response payload bodies, raw IP addresses, or integration secrets. A user-selected AI client may receive the Guide or other bounded data the user authorises at request time; that client's handling is governed by its own terms and privacy policy.MCP audit records explicitly strip access tokens, credentials, prompts, payload bodies, and raw IP addresses.
Customer site content and audit reports are never used to train foundational AI models.
External AI clients only receive the bounded data explicitly authorized at request time, governed by that client's separate terms.
4. How and Why We Use Information
- Provide authentication, workspaces, audits, Guides, reporting, integrations, billing, support, and user-requested AI or MCP workflows.
- Authorise access, enforce workspace boundaries and user choices, prevent abuse, investigate incidents, maintain auditability, and comply with law.
- Measure reliability, feature use, cost, and product performance using the minimum data reasonably needed.
- Send transactional messages and, only with a valid basis and functional unsubscribe, direct marketing.
5. Processors and Disclosures (Subprocessors)
Expected providers include Supabase for authentication and database hosting, Vercel for application hosting, Stripe for billing, configured AI providers for requested generation, Google services for user-authorised Search Console or analytics access, and the AI clients and integrations a user chooses. We disclose only what is reasonably needed for the selected function, security, support, or legal obligation.
| Provider | Role / Function | Data Involved | Location |
|---|---|---|---|
| Supabase | Authentication & primary DB hosting | Account identity, encrypted metadata | Australia / US |
| Vercel | Application edge hosting & routing | Transient request logs, cached pages | Global Edge |
| Stripe | Payment processing & tax compliance | Customer billing IDs, transaction IDs | United States |
| Google Cloud | Search Console API & analytics sync | Search impressions, click counts | United States |
We maintain and update processor, purpose, contractual-role, and overseas-recipient information as service providers and data flows change. We will not replace that information with a vague statement that data may be processed globally.
6. Overseas Disclosure
Some processors or user-selected clients may process information outside Australia. SEO Dispatch assesses appropriate contractual and security measures and publishes the countries or regions reasonably likely to receive personal information. A user may also intentionally direct information to an overseas AI client they select.
7. Retention and Deletion Schedule
We retain customer data only as long as necessary to fulfill the requested feature set or satisfy tax, accounting, dispute, and regulatory requirements:
| Data Category | Retention Period | Deletion Trigger |
|---|---|---|
| Public Audit Reports | 30 Days (cached for 24h) | Automatic rolling purge |
| MCP Tool Audit Logs | 90 Days | Automatic rolling purge |
| Rate-Limit Hashes | Max 48 Hours | Automatic ephemeral reset |
| Idempotency Records | 7 Days | Automatic purge |
| Active Workspace Data | Duration of active subscription | Deleted upon account closure |
Billing and legal acceptance records: Retained for the statutory duration reasonably required for taxation, accounting, dispute, fraud prevention, and legal obligations. Acceptance records constitute immutable evidentiary history and are never used for marketing.
Support, security, and consent records: Maintained strictly for the documented operational, legal, or consent purpose and then deleted or de-identified.
8. Security Posture & Controls
Controls include authenticated server boundaries, least-privilege database access, row-level security, encrypted transport, restricted service credentials, bounded inputs and outputs, rate limits, revocation, and sanitized auditing.
No online service can promise absolute security. Users must protect their accounts and connected-client access and report suspected misuse promptly.
9. Access, Correction, Deletion & Complaints
You may request access to or correction of personal information, disconnect integrations, revoke AI-client access, unsubscribe from marketing, or request account closure. We will verify identity and respond within a reasonable period, subject to lawful exceptions and records that must be retained.
Data Subject Access Requests (DSAR) & Rectification
Submit inquiries or requests for personal information access, correction, or deletion under the Australian Privacy Principles.
10. Direct Marketing & Spam Act
Marketing messages will identify the sender, use recorded consent or another lawful basis, and provide a functional unsubscribe method consistent with the Spam Act 2003 (Cth). Transactional and security messages may still be sent where needed to provide or protect an account.
11. Incident Response & Data Breaches
We will maintain an incident process to contain and assess suspected breaches. Where the Notifiable Data Breaches (NDB) scheme applies and an eligible data breach is identified, the operator will notify affected individuals and the OAIC as required by law.
Breach Containment & Vulnerability Disclosure
Direct channel for security researchers and customers to report suspected vulnerabilities or incidents.
Office of the Australian Information Commissioner
Direct regulatory escalation and external dispute resolution under the Australian Privacy Act.
12. Changes & Contact
Material changes will be versioned and, where required, presented for renewed electronic acceptance. Use the privacy contact displayed with the operator details.