SiteCandor · Legal
Privacy
Short version: we store your email so we can send your report, and the audit itself so you can come back to it. We don’t sell anything to anyone.
SiteCandor is a service operated by Bozorgi Technology LLC, a Florida limited liability company doing business as SiteCandor. For data-protection law, Bozorgi Technology, LLC is the controller of the personal data this page describes, and the contact form is how to reach us about any of it.
What Data We Store About You
- Your email address, and your agreement — given with the box on the audit form — to receive your report and a few follow-up emails about it, with the version of the words you agreed to.
- The date, time, and IP address at the moment you answered that box. We keep this only as the record of what you chose.
- The web address you asked us to check, and the report we produced.
- If you answer “How did you hear about SiteCandor?” on the audit form — it is optional, and skipping it changes nothing — the answer you picked, and anything you type in the box beside “somewhere else”. We keep it with your email address to learn which places bring people here, and nothing else.
- Where your first visit came from, when your browser kept it (see Cookies and Tracking): the campaign tags in the link you followed, the website you came from and the page you landed on. We keep it with your email address, and with your subscription if you subscribe, to learn which places bring people here.
- For each free audit, the site and your email address in a normalised form — with any tag, and for Gmail the dots, removed — used only to apply the limits on how often a free audit can be run.
- If you buy something: the purchase record and the domain you bought it for. Your card details go to Stripe and never to us.
- If you subscribe to Pro: what you set up in your dashboard — the searches you track, the questions you ask AI assistants, the addresses of pages you choose to compare your own against (kept inside your saved analyses), your key pages, your site’s name — and the measurements we take for you. If you tell us how you heard about us, we keep that answer with your subscription.
- If you write to us through the contact form: your name, email, message and IP address arrive as an email to our inbox. From your dashboard: your message arrives with your email, your sites and your IP address. Either way, the message and your email are also kept with the rest of the feedback people give us — from the dashboard, with the site it was about. The IP address briefly counts toward the rate limits listed below.
- If you answer one of our questions — whether a report was useful, or what kept you from subscribing — your answer, anything you add, where we asked, and the email address and report it was about.
If Someone Else Added Your Email
A Pro subscriber can ask us to copy up to three other people on the emails we send them about their own website. If your address was added that way, here is exactly what we hold and why.
- Your email address, and nothing else. We hold no name, no profile and no account. You cannot sign in with it, because there is nothing to sign in to — you receive copies of emails and that is the whole of it.
- We ask you before we send you anything. Saving the address sends one message asking whether you want these emails. Until you say yes, nothing else reaches you. The person who added you can send that question again if it went astray, up to three more times, and never more than that.
- If you never answer, we stop after 14 days. Your address comes off the list automatically and you are not a recipient of anything. We keep one note — that this address was already asked — so nobody can remove you and add you again to send the question a second time. Ask us and we will delete that too.
- Saying no takes one click. Ignore the question and it expires. If you did say yes and change your mind, the unsubscribe link at the foot of every copy stops them — yours alone, immediately, without affecting the subscriber’s own emails.
- We never use the address for anything else. Not our own marketing, not a mailing list, not passed to anyone. It exists to copy you on one website’s alerts and for nothing besides.
If Someone Invites You to Their Team
A Pro subscriber can give other people access to chosen sites in their dashboard. If you were invited, here is what we hold and for how long.
- Your email address, who invited you, your role and your sites — and, once you accept, which of each site’s alert emails you get.
- An invite you do not accept expires after 7 days and is deleted automatically soon after. Ask us and we delete it at once.
- Your access is deleted when the site’s owner removes you, when the site itself is deleted, or when you ask us.
- We note that your address was invited, so the same account cannot keep inviting you. The note goes when that account’s subscription ends, or when you ask us.
What We Store About Your Website
An audit reads publicly reachable pages of the site you named — what any visitor’s browser would see. For every audit we keep a snapshot of the pages it read for 90 days, so we can answer “why did the audit say that?”, and then it is automatically deleted. If the site itself displays personal information — staff names, contact details — that information sits inside the snapshot for those 90 days. We analyse it; we do not extract it, use it, or contact anyone found in it.
How Long We Keep Your Data
- Your email — until you ask us to delete it, whether you have asked for free audits or subscribed. Unsubscribing stops our marketing email immediately, but it does not delete the address; deletion is its own request, below.
- What you tell us — your answers to our questions, your comments and your messages, with the email address they came from — until you ask us to delete them. We keep them so what people tell us can keep improving SiteCandor.
- Somebody else’s email, added as a contact — 14 days if they never confirm, then taken off the list automatically; a note that the address was invited stays on the subscription so the question cannot be repeated, and goes when the subscription is deleted. If they do confirm, for as long as the subscriber keeps them on the list, and it goes with everything else when the subscription is deleted.
- Team members and invites — a member’s access until the site’s owner removes them or the site is deleted; an invite nobody accepts, 7 days, then deleted automatically; the note that an address was invited, until the inviting subscription ends. Any of them sooner if that person asks.
- Your report — indefinitely. The link in its email lasts seven days and can be renewed to the same address for as long as we keep your email. An older one-page check-up’s link keeps working. Ask and we will delete a report.
- Recent readings of a site — 7 days. A free audit asked for within a week of another free audit of the same site is built from that reading instead of reading the site again, which is gentler on the site; the report says the date.
- Free audit records — 90 days after each free audit: the normalised address and site pair, and the normalised address with that audit’s reference and date. We use them only to apply the free audit’s limits.
- The follow-up schedule — about 100 days after an audit, then deleted.
- Rate-limit counters — 24 hours at most; the ones counted per IP address, and the sign-in one, last two hours. They delete themselves.
- Crawl snapshots — 90 days, so we can answer “why did the audit say that?”, then automatically deleted.
- Pro measurements — kept for as long as you are subscribed, with no maximum age, so your whole trend stays on the chart. When a subscription ends, its history is kept for 90 days in case you come back — with an email reminder two weeks before — and then deleted.
- Purchase records — kept. They are tax and accounting records.
- Server logs — one month, and kept free of email addresses in normal operation.
- Suppression records — permanently. If you unsubscribe or a message bounces, we keep just enough to guarantee we never email you again. Deleting that record would be the one deletion that could hurt you.
- Payment disputes — permanently. If you dispute a charge with your bank, we keep your email address and Stripe customer ID so that no reminder or offer from us reaches you again.
One honest caveat: our database keeps rolling backups for disaster recovery, so a deleted item can persist in those backups for up to 35 days after we delete it, before it is gone from them too.
Who Else Touches Your Data
- Amazon Web Services — hosting, storage, and sending your report and any emails you opted into. Data stays in their US East region.
- Stripe — payments, if you buy something. Your card details go to Stripe and never to us; what comes back to us is that the payment succeeded, the email and domain you gave Stripe, and any refund or dispute that follows.
- Cloudflare Turnstile — the bot check on the form. When you submit a form, our server sends Cloudflare the check’s token together with your IP address to verify it.
- DataForSEO — the data vendor behind rank tracking, search-volume figures and AI-assistant measurement. For Pro subscribers, the keywords you track, the locations you chose, the keyword ideas you look up, and the questions you wrote for AI assistants are sent to them to run — the questions word for word, passed on to the AI providers they query. Your email, IP and payment details are never sent to them.
- Anthropic — the AI provider behind three things. For every full audit, free or Pro, we send the audited website’s address and its homepage — the title, description, headings, the kinds of structured data it declares, and up to about 2,000 characters of its text — with the paths of the other pages we read, so the model can tell what kind of business it is and whether it serves a local area; that decides whether the report scores your local presence. And once, when a Pro subscription starts, we send the title, headings and opening text of the website you asked us to watch, so the model can propose searches your customers might type. And each week, for a Pro subscription, we send each answer an AI assistant gave to your questions — up to about 4,000 characters of it — with your website’s address and the question that was asked, so the model can list which other businesses that answer named. That answer is the assistant’s own text, not yours. Nothing else is sent: not your email, not your IP, and not your payment details.
- Zoho Mail — our inbox. A message you send through the contact form is delivered there, with the name, email, message and IP address the contact-form section describes.
We also use Google Analytics on the marketing pages and on free report pages to understand how people find and use the site — page views, where a visit came from, and whether the audit form was completed. On a report page, the report’s private address is replaced with a fixed placeholder before anything is sent, so the link itself never reaches Google. Analytics is switched off entirely inside the subscriber dashboard and the sign-in pages, because those are somewhere you have already arrived rather than somewhere we are learning about. The complete list of what gets set in your browser, and the switch for it, is on our cookies page.
What we do not do: advertising pixels, remarketing or audience-building, session recording, and selling or sharing your data with anybody. If you are in the EU or the UK, nothing analytics-related is stored until you say yes — a no means no analytics cookies and no stored analytics data. One precision, because this page does not round up: Google’s measurement script itself still loads after a no, and sends Google a cookieless signal that a page was viewed. It sets nothing in your browser and is not tied to you.
Our free audit emails — the one that brings your report and the follow-ups after it — note whether they were opened and whether a link in them was clicked. Amazon SES, which sends them, does this with an invisible image and by passing each link through an address on our own domain on its way to where it points, and tells us which email was opened or clicked. We count those per email to learn which emails are worth sending, and keep a note of each for up to 90 days so that an email opened twice counts once. We do not use any of it to profile you or to decide what else to send you. Sign-in links, receipts, billing notices and the emails a subscriber gets about their own site record neither, and the unsubscribe link is never tracked. Blocking remote images in your email app stops the open count.
Your Own Google Search Console and Analytics
If you connect your own Google account, your dashboard shows Google’s own figures for your website beside the ones we measure. Connecting is entirely optional, nothing else changes if you never do it, and you choose which Google account and which property.
We ask Google for two permissions and both are read-only: Search Console and Analytics. We cannot change anything in your Google account, cannot see your other websites unless you pick them, and cannot read your email, your files or anything else Google holds. What we read is the figures themselves — clicks, how often you appeared, the searches people used to find you, your average position, visits and where they came from. We never read anything about an individual visitor to your site, because those tools do not expose it.
We read it once a day while the connection is live, and we store the daily figures so your dashboard can show a trend. They are kept with the rest of your site’s history and are deleted on the same schedule, described above. Disconnecting stops the reading immediately; the figures already collected stay, so reconnecting later still shows your past.
Your Google data is never sold, never used for advertising, never shared with anyone else, and never used to train any AI model — ours or anybody else’s. We keep the key that lets us read it encrypted, and it is deleted when you disconnect or when your subscription ends, not months later.
You can disconnect at any time from Settings in your dashboard, which also withdraws our access at Google. You can do the same from your Google account directly, at myaccount.google.com/permissions.
SiteCandor’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Deleting Your Data
Every marketing email has a one-click unsubscribe and we honour it immediately. To have everything deleted, use our contact form and tell us the address you used — no forms beyond that, no retention speech. Deletion is a person acting on your request rather than a button, which is why we confirm when it is done: we delete your lead record, your reports and your audit data, and everything you told us through our questions and messages, and tell you. We keep the suppression record, as above, so that deletion cannot accidentally opt you back into email, and any payment-dispute record. If you still have a Pro subscription, it is cancelled first; everything is then deleted at once rather than after the usual 90 days.
If You Are in the EU or UK
When you ask for a free website audit, the box on the form asks for two things together: your report, and a few follow-up emails about it. Your consent is our basis for sending both; we log when, from what IP address and with which words it was given, so that claim is checkable rather than asserted. You can withdraw consent to the follow-ups at any time with the unsubscribe link in any of them — one button, no login, honoured immediately — and withdrawing does not take your report away. You have the usual rights of access, correction, deletion, restriction, objection and portability; the contact form is how to use them, and we answer within a month. You can also complain to your data-protection authority, though we would rather you told us first so we can fix it.
If somebody added your address as a contact on their subscription, the emails you receive rest on your own consent — the click you gave, and which the unsubscribe link withdraws. Before that click we hold your address for one purpose only: to ask you the question once, and to ask again if the subscriber tells us it went astray. We keep it for no other reason, use it for nothing else, and delete it after 14 days if you do not answer.
Your data lives in the United States, so using the service from the EU or UK means it is transferred there. The providers above certify under the EU–US Data Privacy Framework or offer contractual safeguards for that transfer.
If You Are in California or Another US State With a Privacy Law
We do not sell personal information, and we do not share it for cross-context advertising — there is nothing here for a “Do Not Sell” link to switch off. The rights those laws give you — to know, delete and correct — are the same ones this page already offers everyone, through the contact form, and we do not treat anyone differently for using them.
Children
The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16; if that has happened, use the contact form and we will delete it.
Changes to This Policy
If this policy changes materially we will say so on this page, with the date of the change, rather than quietly editing it.