Legal

Privacy Policy

Last updated September 23, 2026

Who We Are and What This Policy Covers

seothumb.com is an independent, remote-first search engine optimization company registered in the United States. For the purposes of the EU and UK General Data Protection Regulation, seothumb.com is the data controller for the personal data described below.

This policy covers:

  • The website at seothumb.com, including every page reachable from the navigation and footer.
  • The audit request form on our contact page, and the email, call bookings and document exchange that follow from it.
  • Records we hold about prospects, client contacts and newsletter subscribers.

This policy does not cover personal data held inside a client's own systems that we are given access to during an engagement, such as Google Analytics 4 properties, Google Search Console accounts, CRM records or raw server logs. In those cases the client is the controller and we act as a processor, bound by the signed agreement and its data processing terms. It also does not cover third-party sites we link to, including the documentation sources cited elsewhere on this site.

Privacy contact: privacy@seothumb.com

Information We Collect

We collect three kinds of information, and nothing else.

1. Information you give us directly. The audit request form asks for your name, work email address, company name, website domain, an approximate monthly revenue band, current organic sessions per month, your primary goal, and an optional message. Every field except domain and email is optional, and a rough answer is fine. If you book a scoping call we also receive the time slot you chose and any notes you add to the booking. If you email us, we hold that email thread and any attachments you send.

2. Information collected automatically when you browse. Through Google Analytics 4 we record pages viewed, the referring source, approximate city-level location derived from your IP address, device type, browser, screen size, session timestamps, and events such as clicking a call-to-action. Our hosting provider records standard server log data including IP address, user agent and requested URL. None of this is linked to your name unless you have also submitted the form.

3. Information from client systems during an engagement. Once you become a client we usually request read access to Google Search Console, Google Analytics 4, your CMS, and in some cases raw server or CDN log files. Log files contain visitor IP addresses and user agents. We use them for crawl-budget and bot-behaviour analysis only.

We do not collect payment card details on this website. Invoices are issued and paid through a third-party accounting and payments provider that holds those details directly. We do not buy contact lists, scrape prospect data, or enrich your record with data bought from a data broker.

Under the GDPR and UK GDPR we must have a lawful basis for each use. Ours are:

  • Answering your enquiry and producing the free technical SEO audit. Data: form fields, email thread, your domain. Basis: taking steps at your request prior to entering a contract, and our legitimate interest in responding to business enquiries.
  • Delivering a paid engagement. Data: client contact details, account access, deliverables and correspondence. Basis: performance of a contract.
  • Invoicing, bookkeeping and tax records. Data: billing contact, company details, invoice history. Basis: legal obligation, and performance of a contract.
  • Understanding how the site is used so we can improve it. Data: analytics events as described above. Basis: consent where consent is legally required for the cookies involved, and our legitimate interest in maintaining a functioning website otherwise.
  • Security, fraud prevention and abuse mitigation. Data: server logs, form submission metadata. Basis: legitimate interests.
  • Occasional follow-up about an enquiry you started. Basis: legitimate interests. Marketing email unrelated to your enquiry is sent only with your consent, and every message carries a one-click unsubscribe.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your data to train machine learning models, our own or anyone else's.

Cookies and Analytics

This site sets a small number of cookies and no advertising cookies at all.

  • Preference cookie (first-party, 12 months). Stores your colour-scheme choice and whether you have dismissed the cookie notice. It holds no personal data and no identifier that can be traced back to you.
  • Google Analytics 4 cookies (_ga and _ga_<property-id>, first-party, 24 months). These store a randomly generated client ID so repeat visits in the same browser are counted as one session series rather than several people.

Analytics configuration, stated plainly: Google Signals is disabled, advertising personalisation is disabled, there is no remarketing audience, no Google Ads link, no Meta pixel, no LinkedIn insight tag and no third-party advertising cookie of any kind. Google Analytics 4 uses your IP address to derive coarse location and then discards it; IP addresses are not logged or stored in the property. Event-level data retention in the property is set to 14 months.

Your controls. Where consent is required in your region, analytics cookies are not set until you accept, and you can change or withdraw that choice at any time through the cookie notice link in the footer. You can also block or delete cookies in your browser settings, or install the Google Analytics opt-out browser add-on published by Google. Blocking analytics cookies does not break anything on this site.

We honour the Global Privacy Control signal. If your browser sends it, we treat that as an opt-out of analytics and of any sale or sharing of personal information, which in our case is already none.

Third Parties That Process Your Data

We keep the vendor list short on purpose. Each of the following categories processes personal data on our instruction, under a written data processing agreement, and is not permitted to use it for its own purposes:

  • Website hosting and CDN. Serves the site and retains server access logs, including IP addresses, for a short rolling window.
  • Analytics. Google Analytics 4, configured as described above.
  • Form handling and transactional email delivery. Receives your form submission and routes it to us, and sends the confirmation email.
  • Email and productivity suite. Where your enquiry lands as an email, and where audit documents are stored and shared.
  • Customer relationship management. Holds prospect and client contact records and the history of our conversation.
  • Call scheduling. Holds the name, email and time slot for booked scoping calls.
  • SEO tooling used in delivery. Crawlers, rank trackers, backlink indexes and log-file analysis tools. These process URLs and performance data; where a client's log files are uploaded, they may briefly process visitor IP addresses.
  • Accounting, invoicing and payment processing. Holds billing details and invoice history.

We also disclose personal data where we are legally compelled to, for example by a valid court order or regulatory request, and we will tell you when we are permitted to do so. If the business is ever sold or merged, client and prospect records may transfer to the acquiring entity, which would remain bound by this policy until it gives you notice of any change.

We have not sold or shared personal information in the preceding 12 months, and we have no plans to.

How Long We Keep Your Data

Retention is time-boxed, not indefinite:

  • Enquiries that do not become engagements: 24 months from our last contact, then deleted from the CRM and from email.
  • Free audit deliverables and the crawl data behind them: 12 months, then deleted. You can ask for deletion sooner and we will action it.
  • Active client records: for the duration of the engagement.
  • Client contracts, invoices and financial records after an engagement ends: 6 years from the final invoice, because tax and company-records law requires it.
  • Client account access: revoked within 5 business days of the engagement ending.
  • Google Analytics 4 event data: 14 months.
  • Server access logs: 30 days.
  • Newsletter subscribers: until you unsubscribe, plus a minimal suppression record kept indefinitely so we do not accidentally email you again.
  • Backups: overwritten on a rolling 90-day cycle, so deleted records can persist in backup for up to 90 days before they are gone permanently.

Your Rights Under GDPR and UK GDPR

If you are in the UK, the EU or the EEA, you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data where we no longer have a lawful reason to keep it.
  • Restrict processing while a dispute about accuracy or legitimate interests is resolved.
  • Port the data you gave us to another provider in a structured, machine-readable format.
  • Object to processing based on legitimate interests, and to object to direct marketing at any time, with no justification needed.
  • Withdraw consent at any time where consent is the basis, without affecting processing that already happened.
  • Complain to your supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA it is the data protection authority for your country. We would rather you raised it with us first, but you are not obliged to.

To exercise any of these, email privacy@seothumb.com from the address we hold for you, or tell us which address the record is under. We verify identity by replying to the address on file rather than asking you for identity documents. We respond within 30 days, and if a request is genuinely complex we will tell you inside that window and take up to 60 further days. There is no fee unless a request is manifestly excessive or repetitive, in which case we will quote a reasonable administrative cost before doing anything.

Your Rights Under CCPA, CPRA and Other US State Laws

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what we collect and why, to receive a copy, to correct inaccurate information, to request deletion, to opt out of the sale or sharing of personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of those rights.

In the preceding 12 months we have collected the following CCPA categories: identifiers (name, email address, IP address), commercial information (the services you enquired about), and internet or network activity (pages viewed, referrer, device and browser data). We have not collected biometric data, geolocation more precise than approximate city, government identifiers, or any category the CPRA defines as sensitive personal information. We have not sold or shared personal information, and we do not use or disclose sensitive personal information for any purpose that would trigger the right to limit.

Submit a request to privacy@seothumb.com. We confirm receipt within 10 business days and respond within 45 days, with one 45-day extension if needed, and we will tell you if we take it. An authorised agent may submit on your behalf with written permission that we can verify with you directly. We honour Global Privacy Control browser signals as a valid opt-out.

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comparable privacy laws have substantially similar rights, including the right to appeal a refused request. Use the same email address and the same process, and if we decline a request you may appeal by replying to our decision. We will respond to an appeal within 45 days and tell you how to escalate to your state attorney general.

International Data Transfers

We are based in the United States and most of our processors are too, so personal data submitted from the UK, the EEA or elsewhere is transferred to and stored in the United States.

Where personal data leaves the UK or the EEA, we rely on one or more of the following safeguards:

  • Standard Contractual Clauses approved by the European Commission, with the UK International Data Transfer Addendum where the export is from the UK.
  • The EU-US Data Privacy Framework and its UK Extension, where the receiving processor is certified under it.
  • Your explicit consent, in the narrow cases where no other mechanism applies and we have told you about the risk first.

We carry out a transfer risk assessment before adding a new processor that will hold EEA or UK personal data. You can request a copy of the safeguards in place for any specific processor by emailing privacy@seothumb.com.

Children's Privacy

This is a business-to-business website. It is not directed at children, we do not market to children, and we do not knowingly collect personal data from anyone under 16, or under 13 in the United States where the Children's Online Privacy Protection Act applies.

If you believe a child has submitted information through this site, email privacy@seothumb.com and we will delete the record and any associated analytics identifier we can trace, normally within 5 business days.

How We Keep Your Data Secure

Concrete measures rather than reassuring adjectives:

  • The site is served over HTTPS with TLS 1.2 or higher, and HTTP requests are redirected.
  • Every account that touches client or prospect data requires multi-factor authentication, and credentials are held in a shared password manager, never in a spreadsheet or a message thread.
  • Client platform access is requested at the lowest level that will do the job, which is usually read-only in Google Analytics 4 and restricted in Search Console. Write access to a CMS is requested only when we are implementing changes ourselves.
  • Access is revoked within 5 business days of an engagement ending, and we send you confirmation when it has been.
  • Work devices use full-disk encryption. Client data is not stored on personal devices or personal cloud accounts.
  • Data at rest in our hosting, email and CRM providers is encrypted by those providers as standard.
  • We do not transfer client exports over unencrypted channels, and we do not post client data into third-party tools that are not on the processor list above.

No system is completely secure, and we will not claim otherwise. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it and notify you directly without undue delay, telling you what happened, what data was involved and what we are doing about it.

Changes to This Policy

We update this policy when our practices change, when we add or remove a processor, or when the law requires it. The date at the top always reflects the current version.

For material changes, meaning anything that alters what we collect, why we collect it, who we share it with, or how long we keep it, we will email active clients and anyone who submitted an enquiry in the previous 12 months at least 14 days before the change takes effect. Minor changes such as wording corrections or a new contact address are published without notice.

Previous versions are archived. If you want to see what this policy said on a particular date, email privacy@seothumb.com and we will send you that version.

How to Contact Us About Privacy

For any privacy question, data-subject request, complaint or correction:

  • Email: privacy@seothumb.com
  • General enquiries: our contact page
  • Response time: within 5 business days for general questions, within the statutory windows set out above for formal requests.

Our registered postal address is available on request and is included on every invoice. If you need it in advance of becoming a client, ask and we will send it.

Related pages: Terms of Service and Disclaimer.

Questions about this page? Email hello@seothumbs.com. These pages describe our policies in plain English; they are not legal advice to you.