Salta al contenuto principale
GeoReady App Privacy Policy

Privacy Policy

Last updated: August 5, 2026

This policy covers app.geoready.dev, the GeoReady application: accounts, audits you run, subscriptions and product analytics. The public website is covered by the privacy policy on geoready.dev.

Data controller

Juan Camilo Auriti

Email: juancamilo.auriti@gmail.com

Write to that address to exercise any of the rights described below. We answer within one month, as the GDPR requires.

What we process, and why

1. Account data

Your email address and a hashed password (we never store the password itself), plus your plan, subscription status, account role and the dates the account was created and last updated. This is what lets you log in and use the app.

Legal basis: performance of the contract (GDPR art. 6(1)(b)).

2. Sessions and security

For each active session we store a hashed refresh token, the IP address, the browser user agent and a short device hint (for example “Chrome / macOS”), so you can see and revoke your own sessions. We also log login attempts — email, IP address, user agent, whether the attempt succeeded — and count consecutive failures in order to lock an account temporarily after repeated failed logins.

Legal basis: legitimate interest in securing accounts against unauthorised access and credential-stuffing (GDPR art. 6(1)(f)), and art. 32 security obligations. This data is never used for profiling or marketing.

3. Domains and audits

The domains you add, the audit reports generated for them, monitoring history, alerts you configure, AI visibility snapshots, source packs, report share links and any API keys you create. Audits fetch publicly available pages of the domain you submit; we do not log into your site and do not read anything that is not publicly served.

Legal basis: performance of the contract (GDPR art. 6(1)(b)).

4. Payments

Subscriptions are handled by Stripe. Card details never reach GeoReady servers — you enter them on Stripe’s own checkout page. We store the Stripe customer and subscription identifiers, your plan and its status; Stripe collects your name, email, billing address and payment method directly, and processes transaction and fraud-detection signals.

Legal basis: performance of the contract (GDPR art. 6(1)(b)); legal obligations on accounting and fraud prevention (art. 6(1)(c) and 6(1)(f)).

5. Product analytics — only with your consent

If you accept analytics, PostHog records which parts of the app you use, so we can tell what to fix. Until you accept, PostHog runs in cookieless mode: it captures no events and writes neither a cookie nor local storage. On the payment confirmation page only, and again only with analytics consent, Google Analytics 4 records that a subscription completed, with the plan, its price and a transaction reference.

That Analytics property is linked to Google Ads, so the completed subscription is imported into that advertising product as a conversion and attributed to the campaign you arrived from. The conversion is only reported after the payment has been verified server-side with Stripe, so a page reload or an abandoned checkout does not produce one. No advertising cookie is set, no advertising tag is loaded, and no remarketing audience is built. Decline analytics or marketing and Google receives those signals as denied, which limits the measurement accordingly.

Legal basis: consent (GDPR art. 6(1)(a); ePrivacy Directive art. 5(3)). Withdraw it at any time from the cookie preferences panel — the button at the bottom left of every page.

6. Benchmark statistics

To publish aggregate statistics on how sites score, we record one row per audit containing a keyed hash of the domain (not reversible to the domain by a third party), the top-level domain, the score and the date. Published figures are aggregate only: no individual domain, score or account is identifiable in them.

Legal basis: legitimate interest in measuring and publishing aggregate research on AI search visibility (GDPR art. 6(1)(f)). You can object — see “Your rights”.

7. Service emails

We send emails the service requires: email verification, password reset, team invitations, alerts you configured and monitoring digests. These are not marketing and are sent because you asked for the service or set up the alert. Marketing emails are separate and require the consent you give on geoready.dev.

Legal basis: performance of the contract (GDPR art. 6(1)(b)).

8. Server logs

The infrastructure logs IP addresses, request paths, response codes and timestamps, as any web server does, to investigate errors and abuse.

Legal basis: legitimate interest in operating and securing the service (GDPR art. 6(1)(f)).

Who else processes your data

We use a small number of providers. Each acts as a processor under a data processing agreement, except where noted.

Provider Purpose Where Role
Stripe Subscription payments, invoicing, fraud prevention Ireland / United States Processor for the payment; own controller for fraud prevention
PostHog Product analytics (only with consent) EU Cloud — Frankfurt, Germany Processor
Google Ireland Limited Analytics 4, on the payment confirmation page only (only with consent) Ireland / United States Processor
Google Ads Receives the subscription conversion imported from Analytics, to attribute the sale to a campaign (only with consent) Ireland / United States Processor
Resend Delivery of service emails United States Processor
Hosting provider Servers, database, backups, server logs European Union Processor

We do not sell personal data, and we do not share it with data brokers. One sharing arrangement does exist and is worth stating plainly: the Google Analytics 4 property is linked to Google Ads, so the subscription conversion measured on the payment confirmation page — with your analytics consent — is made available to that advertising product to attribute the sale to a campaign. No advertising cookie is set anywhere in the application, no advertising tag is loaded, and no remarketing audience is built from your account.

Transfers outside the EU

The application, its database and PostHog analytics are hosted in the European Union. Some providers are established in the United States, so a transfer can occur for those services. Where it does, it relies on:

  • the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023 (decision 2023/1795), where the provider is certified under it — Stripe and Google both state they are, Google for both Analytics and Ads; and
  • the European Commission’s Standard Contractual Clauses, together with the UK Addendum where relevant, as the fallback mechanism.

Ask us at the address above and we will tell you which mechanism applies to a given provider.

How long we keep it

  • Account data: for as long as the account exists. Delete the account and it is removed.
  • Audits, domains, reports: for as long as the account exists, or until you delete them.
  • Sessions: until the session expires or you revoke it.
  • Login attempt records: kept for a limited period for abuse prevention, then deleted.
  • Billing records: retained as long as tax and accounting law requires, which for Italy is ten years, even after the account closes.
  • Analytics data: retained by PostHog and Google under their own retention settings; we set GA4 to the shortest available retention. The conversion imported into Google Ads follows that product's own conversion windows.
  • Benchmark rows: retained indefinitely in hashed, aggregate form, as research data.
  • Server logs: rotated, typically kept 14–30 days.
  • Consent choice: stored on your device for 6 months, or until the policy version changes.

Your rights

Under the GDPR you have the right to:

  • know what we hold about you and get a copy of it (art. 15);
  • have inaccurate data corrected (art. 16);
  • have data erased (art. 17) — note that billing records must be kept for the statutory period;
  • restrict processing while a dispute is resolved (art. 18);
  • receive your data in a portable, machine-readable format (art. 20);
  • object to processing based on legitimate interest, including the benchmark statistics (art. 21);
  • withdraw consent to analytics at any time, without affecting processing already carried out lawfully (art. 7(3));
  • not be subject to solely automated decisions with legal or similarly significant effects (art. 22) — we make none.

If you believe we have handled your data wrongly you can complain to your national data protection authority. In Italy that is the Garante per la protezione dei dati personali.

Children

GeoReady is a professional tool and is not directed at children. We do not knowingly create accounts for anyone under 16.

Cookies and local storage

For the full inventory — every cookie and storage key, its purpose, provider, legal basis and duration — see the Cookie Policy.

Changes

We update this policy when what we actually do changes. The date at the top says when. If a change affects what you consented to, the cookie banner asks again rather than assuming the old answer still applies.