Privacy

Privacy Policy

What we collect, why, and how we protect it — in the plainest terms we can manage.

Last updated: [DATE]

This is a starting-point template that reflects how the product currently works. Replace the [COMPANY] / [JURISDICTION] placeholders and have it reviewed by a qualified lawyer before you rely on it.

1. Who we are

WEB-AUDIT (“we”, “us”) is operated by [COMPANY], based in [JURISDICTION]. This policy explains what personal data we process when you use our website-auditing service and how we protect it. For any privacy question, contact us at hello@web-audit.me.

2. What we collect

We keep data collection to the minimum needed to run a scan:

  • Scan input — the URL you submit and the target site’s public responses.
  • Technical data — your IP address and basic request metadata, used for rate limiting and abuse prevention.
  • Contact data — only if you email us (your address and message).

We do not require an account to run a free scan, and we do not sell personal data.

3. How we use it, and on what legal basis

Where the GDPR applies, each purpose below has its own lawful basis under Article 6:

  • Running the scan you asked for and generating your report — performance of a contract with you (Art. 6(1)(b)); for a signed-out scan, our legitimate interest in delivering the service you requested (Art. 6(1)(f)).
  • Creating and maintaining your account, and taking payment for Pro — performance of a contract with you (Art. 6(1)(b)).
  • Rate limiting, abuse prevention, and keeping the service available — our legitimate interest in operating and securing the service (Art. 6(1)(f)).
  • Replying to you when you email us — our legitimate interest in answering enquiries (Art. 6(1)(f)).
  • Non-essential cookies (preferences, analytics) — your consent (Art. 6(1)(a)), asked for through our cookie banner and withdrawable at any time; see the Cookie Policy. Strictly-necessary cookies do not rely on consent.
  • Meeting legal obligations, such as keeping records of a payment — Art. 6(1)(c).

We do not use your data for automated decision-making with legal or similarly significant effects, and we do not sell it.

4. How long we keep it

How long a report is kept depends on how it was created. A scan run without an account is deleted automatically after 24 hours. If you have a free account, we keep your 3 most recent reports for 30 days. Reports you have unlocked, or that were run on a paid plan, are kept until you delete them — you can delete any report yourself from your dashboard, and deleting your account removes them all. Rate-limiting counters are held in memory only, for the length of the limiting window — one hour for scan requests, 15 minutes for sign-in and account requests — and are discarded when that window expires; they are not written to the database. Any email correspondence is kept only as long as needed to deal with your enquiry and any follow-up.

5. Sharing

We run our own scanning engine and do not send your scan through third-party scanning APIs. We use no advertising networks, ad pixels, or third-party analytics trackers, so there is no vendor in those categories to name. We share personal data only with the following categories of recipient, each acting as our processor under contract:

  • Hosting and infrastructure [HOSTING PROVIDER], which runs the servers and database the service operates on.
  • Payment processing Stripe, which handles Pro checkout, the billing portal, and subscription records. Card details go to Stripe directly and are never stored by us. When you delete your account we instruct Stripe to cancel the subscription and delete the customer record.
  • Email delivery [EMAIL PROVIDER], used only for transactional messages such as email verification and password resets. We do not send marketing email.

We may also disclose data where legally required. Where we or our processors transfer data outside your region, we rely on [TRANSFER MECHANISM: Standard Contractual Clauses / adequacy decision / Data Privacy Framework — OPERATOR TO CONFIRM].

6. Your rights

Depending on your location (including the EU/EEA and Canada), you may have the right to access, correct, delete, or restrict processing of your personal data, and to object or lodge a complaint with your data protection authority. To exercise any right, email hello@web-audit.me. You can also delete individual reports, and your whole account, yourself from your dashboard. If we refuse a request we will tell you why, and you may appeal by replying to that decision at the same address — we will have the appeal reviewed and respond to you in writing.

7. California privacy rights

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we have collected about you, to receive a copy of it, to correct it, to delete it, and not to be treated differently for exercising any of those rights.

We do not sell or share personal information as the CCPA defines those terms, and we have not done so in the preceding 12 months. We run no advertising or cross-context behavioural tracking, so there is nothing to opt out of and we therefore provide no “Do Not Sell or Share My Personal Information” link. We do not knowingly collect personal information from minors.

To make a request, email hello@web-audit.me from your account address. We will confirm receipt within 10 business days and respond within 45 days, extending once by a further 45 days where a request is complex — we will tell you if that happens. An authorised agent may make a request on your behalf with proof of authorisation.

8. Cookies

We use a minimal set of cookies. See our Cookie Policy for the full breakdown.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above.