Skip to content
SEO Orbiter
MonitoringField guidePricingOpen workspace
Contents1. Controller and contact2. Website visits and hosting3. Account and use4. Google Search Console5. Technical website checks6. Email and support7. Payment8. Error diagnosis9. Website analytics and cookies10. Retention and deletion11. Recipients and international processing12. Your rights
SEO ORBITER · PRIVACY

Your data, clearly explained.

This policy describes how personal data is processed when you use SEO Orbiter. Last updated: 13 September 2026.

1. Controller and contact

Alexander Zotz, trading as SEO Orbiter, Am Hang 4, 86570 Inchenhofen, Germany. For privacy requests: support@seoorbiter.com.

2. Website visits and hosting

When you visit the website, we process technically necessary connection data, including your IP address, time of access, requested resource, browser information and error status. This supports delivery, security and troubleshooting. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a secure, reliable service. We use Vercel for hosting and delivery. Application functions are configured to run in Frankfurt; this does not mean that all provider data is processed exclusively in Germany.

3. Account and use

For sign-in and service delivery, we process your email address, account association, selected websites, settings and subscription status. Supabase provides authentication and data storage. The legal basis is Article 6(1)(b) GDPR for a contract with you, or Article 6(1)(f) GDPR for business contacts to conduct the business relationship.

4. Google Search Console

When you connect Google, we receive the read-only permissions you grant, your Google account identity and accessible Search Console properties. We process search metrics, queries, pages, countries, devices and available indexing information to provide reports and investigations. Access tokens are processed on the server; refresh tokens needed for continued access are stored encrypted. We do not modify your website or Search Console.

Access supports the features you request on the contractual basis described above. Google data is not sold, used for personalised advertising or used to train general-purpose AI models. Use and transfer of Google API data comply with the Google API Services User Data Policy, including its Limited Use requirements. You can revoke the connection in the app or your Google account.

5. Technical website checks

We check selected public URLs on websites you authorise. We store technical observations such as HTTP status, page titles, canonical URLs, indexing directives and content fingerprints, together with resulting incidents. HTML is fetched for analysis but is not permanently stored as complete raw content. Do not use URLs containing access tokens or confidential information in their parameters.

6. Email and support

Resend handles transactional emails, including sign-in and enabled incident notifications. It processes recipient addresses, message content and sending status. IONOS hosts the support mailbox. Support requests contain the information you provide; we use it to handle your request under Article 6(1)(b) or (f) GDPR. Acceptance for sending and delivery are different technical states.

For online cancellations and withdrawals, we store your identifying details, the declaration, receipt time and confirmation. We send confirmation to the email address you provide and our processing team. This supports contract administration, legal obligations and evidence of receipt under Article 6(1)(b) and (c) GDPR. A declaration does not trigger an automated decision on disputed claims.

7. Payment

When you purchase a subscription, Stripe processes payment and billing data. We receive customer and subscription identifiers, your plan and payment status, but not your complete card details. The legal bases are contract performance and statutory retention obligations under Article 6(1)(b) and (c) GDPR.

8. Error diagnosis

We use Sentry for server-side technical error diagnosis. Minimised error events include the error type and technical stack information. Session replay, advertising tracking and performance tracing are not intended. Our filters remove user associations, request content, cookies, breadcrumbs and free-text error messages before transmission. The legal basis is Article 6(1)(f) GDPR for resolving technical faults.

9. Website analytics and cookies

We use Vercel Web Analytics to understand visits to our public pages and improve the website. It provides aggregate page-view and visitor statistics, including referrers, approximate location, browser and device information. Vercel uses a request-derived hash for visitor measurement, with visitor sessions discarded after 24 hours, rather than third-party tracking cookies. We remove URL query parameters and fragments and exclude private workspace, authentication callback and checkout routes from page-view events. We do not send account identities, Search Console data or custom analytics events. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is understanding and improving our public website. See Vercel’s analytics privacy information.

Sign-in uses necessary session cookies. The demo, when explicitly started, stores selections and actions for up to 24 hours in signed HTTP-only cookies. This storage supports the requested feature under section 25(2)(2) TDDDG. We do not use optional advertising tracking on the website. If technologies requiring consent are introduced, they will only be activated after the relevant consent.

10. Retention and deletion

Scheduled cleanup removes technical field snapshots after 90 days, change events after 180 days and performance data after 480 days. Account, incident and related email data are retained for service delivery and follow-up. Deleting a website removes its associated monitoring data. Disconnecting Google removes local credentials and pauses affected monitoring.

You can request full account deletion and access to your data through our privacy contact. Billing data subject to statutory retention is kept for the required period. Backups and provider logs have their own deletion cycles and are distinct from immediate deletion in the active database.

11. Recipients and international processing

The named providers receive data as needed for their tasks. Processing on our instructions requires data processing agreements. Processing outside the EEA must meet Articles 44 et seq. GDPR, for example through applicable adequacy decisions or standard contractual clauses. An EU server location alone does not exclude international support access.

12. Your rights

Subject to statutory conditions, you have rights of access, rectification, erasure, restriction, portability and objection. Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. You can withdraw consent with effect for the future. You may complain to a data protection supervisory authority, in particular the Bavarian State Office for Data Protection Supervision.

We do not make automated decisions with legal or similarly significant effects under Article 22 GDPR. SEO observations support decisions; they do not prove a particular cause of ranking changes.

© 2026 SEO Orbiter
SEO monitoringSearch Console monitoringSEO alertsSEO incident monitoringAbout SEO OrbiterField guidePrivacy & data controlsSupportLegal noticeTermsWithdrawal policyCancel subscriptionWithdraw from contract