Privacy policy
What we collect, why we are allowed to hold it, who else touches it, and how to get it back or get rid of it.
In effect from 21 September 2026. Published by SEOGrowPilot.
1.Who we are and what this covers
SEOGrowPilot is software that analyses a website, estimates what a change to it is worth in pounds, makes approved changes, and measures the result. This policy covers seogrowpilot.com, the application behind it, and the client portals and white-label domains served by the same system.
For the account data of the person signing up — name, email, sign-in records, billing details — we are the data controller. For the data about a customer's own website and its visitors, which reaches us because the customer connected it, the customer is the controller and we are their processor: we act on their instructions and do not decide what that data is used for.
Questions, requests and complaints go to privacy@seogrowpilot.com and are answered by a person.
2.What we collect
Account data. Name, email address, hashed password, two-factor secret if enabled, the organisation and role you hold, and a record of sign-ins including approximate time, IP address and browser. Passwords are stored as bcrypt hashes and cannot be read back, by you or by us.
Website data. The content of pages we crawl on a website you have connected, its structure, its performance, and the issues found in it. We crawl only domains added to an account, and a crawl identifies itself.
Connected service data. What you authorise us to read — described in clause 3.
Commercial figures you enter. Average order value, lead value, conversion rate and revenue goals. These are entered by you and are what every pound figure in the product is derived from. They are not obtained from anywhere else.
Billing data. Plan, invoices, payment status and credit balance. Card numbers never reach our servers: payment details are handled entirely by Stripe or PayPal, who are the ones storing them.
Usage records. Which features ran, when, how long they took, and how many AI tokens they consumed — including when the work ran on your own provider key, because you are entitled to see what the platform did on your account even when we did not bill you for it.
We do not run advertising trackers, we do not sell data to anyone, and we do not operate a data broker relationship of any kind.
3.Accounts you connect
The product is only useful once it can see a website's real numbers, and every connection is made by you, through the provider's own consent screen, and can be withdrawn there without asking us.
- Google Search Console — read-only. Queries, clicks, impressions, average position, and which pages are indexed.
- Google Analytics — read-only. Sessions, sources, conversions and revenue, at the level your property records them.
- Google Business Profile and Google Ads — only if you connect them, and only for the account you choose.
- Your CMS or hosting — WordPress, Shopify, Webflow, FTP, SFTP or a REST API. This is the only category with write access, because making an approved change is the point of it.
- Social accounts, where you connect them, for publishing and for reading back what a post did.
- Your own AI provider keys, if you would rather the token cost landed on your provider bill than ours.
Every credential and token is encrypted with AES-256-GCM before it is stored, under versioned keys. None is ever returned by any interface or API, to you or to us. Deleting a connection destroys the stored credential.
The audit log records that a credential was added, tested or removed, and which fields it had. It never records the value, because the log is append-only by design and a secret written to it could not afterwards be removed.
4.Google user data, and the Limited Use rules
SEOGrowPilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means Google data reaching us through those scopes is used only to provide and improve the features you connected it for — the audit, the forecasts, the reports and the measurement of a change we made. Specifically, it is not used for advertising, it is not sold, it is not transferred to anyone except as needed to provide the service or where the law compels us, and it is not used to train generalised artificial intelligence models. No human at SEOGrowPilot reads it except where you have asked us for support and we need to, where it is necessary for security or to comply with the law, or where the data has been aggregated and de-identified.
The scopes we request are webmasters.readonly for Search Console and analytics.readonly for Analytics, both of which are read-only; the sign-in option additionally uses openid, email and profile purely to establish who you are. Business Profile, Google Ads and YouTube scopes are requested only if you choose to connect those products.
You can review and revoke this access at any time at myaccount.google.com/permissions, independently of your SEOGrowPilot account.
5.Why we are allowed to hold it
Performing our contract with you, for anything needed to run the account you are paying for — the analysis, the changes, the reports, the billing.
Legitimate interests, for keeping the service secure, preventing abuse, and understanding in aggregate which features are used. Where we rely on this, we have considered whether it overrides your interests, and you may object.
Consent, for connecting a third-party account and for marketing email. Either can be withdrawn, and withdrawing it does not affect anything done beforehand.
Legal obligation, for keeping accounting records.
7.How long it is kept
Account and website data is kept while the account is open. When an account is closed, it is deleted within thirty days, other than the two exceptions below.
Billing records are kept for six years, because tax law requires it.
The audit log is append-only and hash-chained: the database refuses updates and deletions to it, which is what makes it worth anything as a record. Entries therefore survive the deletion of the account they describe. They contain what happened, when, and by whom — never credential values, and never the content of a customer's pages.
Deletion on request is carried out by us rather than by an automated pipeline. If you ask, we do it and we confirm when it is done.
8.Your rights
Under UK GDPR you can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, object to processing based on legitimate interests, ask us to restrict processing while a dispute is resolved, and ask for your data in a portable form. Export is built into the product and stays available even on an account that is past due — we do not hold data hostage over a bill.
Write to privacy@seogrowpilot.com. We answer within one month. There is no charge.
If you are unhappy with how we handled it, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, but you are not obliged to.
10.Children
This is business software and is not directed at children. We do not knowingly hold data about anyone under 18. If you believe we have, tell us and it will be deleted.
11.Changes to this policy
The date at the top is the date this version took effect. If a change materially affects how your data is handled, we will email account holders before it takes effect rather than quietly reissuing the page.
Anything unclear, ask: hello@seogrowpilot.com for general questions, privacy@seogrowpilot.com for anything about your data.