Privacy Policy
Effective Date: September 1, 2020 | Last Updated: July 2, 2026
WebTrek ("we", "us", or "our") operates the website at webtrek.io and the tools available on it, including Website Architecture for AI Search. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over your data — regardless of where you live in the world.
If you have any questions, email us at [email protected].
-
Who We Are (Data Controller)
WebTrek is the data controller for personal data collected through this website. You can reach us at [email protected].
-
What Data We Collect and Why
We only collect data that is necessary to provide our services.
a. Account data (when you sign in with Google)
- What: Your name and email address, provided by Google after you grant permission.
- Why: To create your account, remember your purchases, and let you access your reports.
- Legal basis (GDPR): Contract — this data is necessary to provide the service you requested.
b. Website URLs you submit
- What: The URL you enter when requesting a Website Architecture for AI Search analysis.
- Why: To crawl and analyze your website and generate your report.
- Legal basis (GDPR): Contract — necessary to deliver the paid service.
c. Payment confirmation
- What: A payment session ID from Stripe confirming that a purchase was made. We do not receive, see, or store your card number, bank details, Apple Pay credentials, or any payment instrument data — Stripe handles all of that.
- Why: To add Blueprint Credits to your account after payment. Blueprint Credits are a one-time purchase (no subscription) and are valid for 12 months from the date of purchase.
- Legal basis (GDPR): Contract — necessary to process your purchase.
d. Blueprint scan results
- What: The AI-generated report produced for your website, stored so you can view it again.
- Why: To display your report history and let you track how many Blueprint Credits you have used and have remaining.
- Legal basis (GDPR): Contract.
e. Privacy consent record
- What: The date and time you agreed to this Privacy Policy.
- Why: To keep a record of your consent as required by data protection law.
- Legal basis (GDPR): Legal obligation.
f. Usage and technical data (collected automatically)
- What: Pages visited, time on page, IP address, browser type, and operating system — standard web server logs and analytics.
- Why: To understand how the site is used, fix bugs, and improve performance.
- Legal basis (GDPR): Legitimate interest. We have a legitimate interest in keeping our services secure and improving them.
g. Contact form messages
- What: Your name, email address, and the content of messages you send us.
- Why: To respond to your enquiry.
- Legal basis (GDPR): Legitimate interest (responding to contact you initiated).
-
Cookies and Session Storage
We use:
- Session cookie: A signed cookie that keeps you logged in. It contains only your internal user ID — not your name, email, or any sensitive data. If you choose "stay logged in", this cookie lasts up to 60 days.
- Browser local storage: We store a note of which sign-in method you used last (e.g. Google) so we can show you a helpful reminder on your next visit. No sensitive data is stored here.
- Analytics cookies: We may use third-party analytics (such as Google Analytics) to understand aggregate traffic patterns. These do not identify you personally.
You can clear cookies and local storage at any time through your browser settings. Clearing the session cookie will sign you out.
-
Third-Party Services We Use
We share your data with the following third parties only as necessary to operate the service:
- Google (Sign-In): Handles authentication. When you sign in with Google, Google shares your name and email with us after you grant permission. Google's privacy policy applies to the sign-in process: policies.google.com/privacy.
- Stripe (Payments): Processes all payments. Stripe receives your payment details directly — we never see them. Stripe is PCI-DSS certified. Stripe's privacy policy: stripe.com/privacy.
- OpenAI (AI Analysis): We send the text content of pages on your website to OpenAI's API to generate your Blueprint report. We do not send your name, email, or payment data to OpenAI. OpenAI's privacy policy: openai.com/policies/privacy-policy.
- Hosting provider: Our servers may be located in the United States. If you are in the EU or EEA, your data may be transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) and the data transfer mechanisms approved by the European Commission for such transfers.
We do not sell, rent, or share your personal data with any third party for marketing purposes.
-
How Long We Keep Your Data
- Account data (name, email): Kept for as long as your account exists. If you delete your account, we delete this data within 30 days.
- Blueprint scan results: Kept for 12 months, then deleted.
- Payment records: Kept for 7 years to comply with financial and tax regulations.
- Server logs: Kept for up to 90 days.
-
Your Rights
Depending on where you live, you have the following rights over your personal data. To exercise any of them, email us at [email protected].
Rights for everyone
- Access: Ask us what personal data we hold about you.
- Deletion: Ask us to delete your account and personal data. We will do so within 30 days, except where we are required to keep certain data by law (e.g. payment records).
- Correction: Ask us to correct inaccurate data.
- Portability: Ask us to send you a copy of your data in a common format.
Additional rights for EU / EEA residents (GDPR)
- Object to processing: Where we rely on legitimate interest as our legal basis, you can object to that processing. We will stop unless we have compelling legitimate grounds.
- Restrict processing: Ask us to pause processing your data in certain circumstances (e.g. while you contest accuracy).
- Withdraw consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: You have the right to lodge a complaint with the data protection authority in your EU/EEA country. A list of authorities is available at edpb.europa.eu.
Additional rights for California residents (CCPA / CPRA)
- Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Delete: Request deletion of your personal information (subject to legal retention requirements).
- Opt out of sale: We do not sell personal information. We have not sold personal information in the past 12 months.
- Non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
-
Security
We take reasonable technical and organisational measures to protect your data. Authentication is handled by Google — we never receive or store your Google password. Payments are handled by Stripe — we never receive or store your card details. Our session cookies are cryptographically signed and set to HTTP-only. No method of online data storage is 100% secure, but we do our best to keep your data safe.
-
Children
Our services are not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
-
Changes to This Policy
We may update this policy from time to time. When we make significant changes, we will update the "Last Updated" date at the top and, where practical, notify registered users by email. Continued use of our services after changes take effect constitutes acceptance of the updated policy.
-
Contact Us
For any privacy-related questions, data access requests, or deletion requests, please email us at [email protected]. We aim to respond within 30 days.