Table of Contents
1. Information We Collect
1.1 Account information
When you register, we collect your full name, username, email address, and password (hashed with bcrypt — we cannot read your password). An optional profile photo.
1.2 Google sign-in data
When you choose "Sign in with Google", we receive from Google: your full name, email address, Google ID, and profile photo. We do not access Gmail or other Google data beyond your basic profile.
1.3 Tracking data from your website
When you embed the ClickSentinel tracking script, it records:
- IP address of visitors (used to look up geolocation, ISP, and detect VPN/proxy via ip-api.com)
- User-Agent — browser and operating system
- Page URL and the button/element that was clicked
- Timestamp of the event, Referrer, and UTM parameters (source/medium/campaign/term/content)
- Quality score (0–100), bot/VPN/datacenter classification, duplicate and velocity flags
You (the Customer) are the data controller. We are the data processor acting on your behalf. You are responsible for notifying and obtaining consent from end users as required by applicable law.
1.4 Google Search Console data
When you connect Google Search Console, we access (read-only) and store:
- The list of GSC properties you have verified ownership of
- Search performance data: keywords, URLs, impressions, clicks, position (by day)
- Sitemap status and URL inspection results
- OAuth access token and refresh token (encrypted before storage)
We only read GSC data for properties you authorize. We do not perform any write operations on GSC.
1.5 SEO Audit data
When you run an SEO audit, we crawl your website publicly and store the analysis results: scores, technical issues, Core Web Vitals (via Google PageSpeed Insights API), meta tags, URL structure, and page content. This data belongs to you.
1.6 Heatmap data
When heatmap tracking is enabled, the script records: click coordinates (X/Y), page scroll depth, rage click events (rapid repeated clicks in a small area), and session timeline. This data is not linked to the personal identity of your website's visitors.
1.7 Prospect audit data
When a visitor uses the "Free SEO Check" tool on our website, we collect: the URL to analyze and their email address (to deliver results). IP addresses are stored as anonymous hashes to prevent abuse.
1.8 System logs and feedback
Login IP addresses, access timestamps, and in-dashboard actions (audit log). Beta feedback you submit via the in-app widget (feedback type, content, page context).
2. How We Use Your Information
We use the information we collect to:
- Provide the Service: Process tracking data, run SEO analysis, generate reports, and send alerts.
- Account security: Verify identity and detect suspicious login activity.
- Process payments: Manage subscriptions and invoices.
- Customer support: Respond to technical support requests.
- Product improvement: Analyze aggregated, anonymized data to improve our scoring algorithms and fraud detection.
- Legal compliance: Fulfill requests from law enforcement when required.
We do not use your data to serve advertising, train third-party AI models, or sell information to any party.
3. Cookies & Tracking Technologies
3.1 ClickSentinel dashboard cookies
- Session cookie (required): Maintains your logged-in state.
- CSRF token: Protects against Cross-Site Request Forgery attacks.
- Locale cookie: Saves your selected language (vi/en).
- Preferences (localStorage): Saves UI preferences (dark/light mode) — not sent to our servers.
We do not use advertising cookies or track you across other websites.
3.2 Google OAuth cookies
When you sign in with Google, Google sets its own authentication cookies. Google's cookie policy applies to that interaction.
3.3 ClickSentinel tracking script on your website
The script you embed on your website may use localStorage on your website to detect duplicate clicks within a session. You are responsible for disclosing this in your own cookie policy and obtaining end-user consent.
4. Information Sharing
We do not sell, rent, or share personal information for commercial purposes. We share data only in these cases:
4.1 Technical service providers
- ip-api.com: Receives visitor IP addresses to look up geolocation, ISP, and detect VPNs/proxies/datacenters. Results are cached on our servers for 24 hours.
- Google PageSpeed Insights API: Receives the URL of pages you audit to analyze performance and Core Web Vitals.
- Google (OAuth2 & Search Console API): Authenticates Google login and reads GSC data under the permissions you grant.
- Hosting/cloud providers: Data storage in secure environments.
- Transactional email services: Account notifications, alerts, and audit delivery.
Partners only access the information necessary for their function and are bound by strict confidentiality agreements.
4.2 Legal requirements
We may disclose information pursuant to a court order or mandatory legal requirement. Where permitted, we will notify you in advance.
5. Data Security
- Transport encryption: TLS 1.2+ for all HTTPS connections.
- Encryption at rest: Google OAuth tokens are encrypted before database storage; other sensitive data is encrypted at rest.
- Passwords: Hashed with bcrypt — not reversible.
- API keys: Stored as SHA-256 hashes — shown only once at creation.
- Access control: Principle of least privilege — staff access only the data they need.
- Audit log: All CRUD operations and login/logout events are recorded.
If you suspect your account has been compromised, change your password immediately and contact [email protected].
6. Data Retention & Deletion
6.1 Retention periods
- Click events (Free plan): 30 days from the date recorded.
- Click events (Starter plan): 90 days from the date recorded.
- Click events (Pro plan): 12 months from the date recorded.
- GSC data: Retained while connected; deleted when you disconnect.
- SEO audit results: Retained in your history; can be deleted manually. Public prospect audits are automatically deleted after 48 hours.
- Account information: Retained for the duration of the account.
- Login logs: 30 days.
- Payment history: 7 years as required for accounting/tax purposes.
6.2 Account deletion
When you delete your account, your data will be permanently deleted within 30 days. You may request immediate deletion at [email protected]. Payment history is retained as required by law.
7. Your Rights
- Right of access: Request a copy of the data we hold about you.
- Right to rectification: Update inaccurate information via dashboard or email.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data.
- Right to restrict processing: Request a temporary halt to data processing.
- Right to data portability: Export your data in JSON/CSV format.
- Right to withdraw GSC consent: Disconnect Google Search Console at any time from your settings.
Submit requests to [email protected] — we respond within 15 business days.
8. International Data Transfers
Your data may be processed on servers located in Vietnam or other countries where our service providers operate (including Google and Stripe). We ensure compliance with appropriate data protection mechanisms when transferring data across borders.
9. Children
The Service is not intended for anyone under 18 years of age. If we discover that a person under 18 has provided us with personal information, please contact [email protected] for immediate deletion.
10. Policy Changes
For material changes, we will send an email notification and display a dashboard banner at least 30 days before the changes take effect. The effective date is noted at the top of this page.
11. Contact
- Privacy email: [email protected]
- Security email: [email protected]
- General support: [email protected]
- Response time: 3 business days (up to 15 business days for data rights requests)
This Policy is governed by the laws of the Socialist Republic of Vietnam.