Snack SEO — Privacy Policy #
Effective date: 18 August 2026
Controller: Snack Prompt Corp, a Texas corporation
Address: 604 Canyon Creek Trail, Fort Worth, TX 76112, United States
Contact for all privacy matters: hello@snackseo.com
Service: Snack SEO — https://snackseo.com (application at https://app.snackseo.com)
Table of contents #
- Who we are and what this policy covers
- Our two roles: controller and processor
- Personal data we collect
- Data we access from connected Google accounts (OAuth)
- Google API Services User Data Policy — Limited Use disclosure
- Data we collect when we crawl your websites
- AI features and how your data is used with AI models
- Why we process your data and our legal bases
- Aggregated and de-identified data
- Who we share data with (sub-processors and other recipients)
- International transfers of data
- How long we keep data
- Security
- Cookies and similar technologies
- Marketing communications
- Your rights under the GDPR and UK GDPR
- Your rights under CCPA/CPRA and other US state laws
- Your rights under the LGPD (Brazil)
- Your rights under PIPEDA (Canada)
- How to exercise your rights
- Automated decision-making and profiling
- Children
- Third-party sites and services
- Changes to this policy
- How to contact us and how to complain
1. Who we are and what this policy covers #
Snack SEO is a multi-tenant software-as-a-service platform for search engine optimisation ("SEO") and AI-search visibility. It is operated by Snack Prompt Corp, a corporation organised under the laws of the State of Texas, United States, with its registered address at 604 Canyon Creek Trail, Fort Worth, TX 76112, United States ("Snack Prompt", "we", "us", "our").
This Privacy Policy explains how we collect, use, disclose, transfer and retain personal data when you:
- visit https://snackseo.com or any of our marketing pages, blogs or documentation;
- create an account for, or use, the Snack SEO application at https://app.snackseo.com (the "Service");
- connect a third-party account (such as Google Search Console, Google Analytics or Google Business Profile) to the Service;
- add a website, domain or brand to the Service so that we can crawl, audit, track or monitor it;
- contact us for support, sales or any other reason.
This policy applies globally. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and the Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and comparable US state privacy laws, the Brazilian Lei Geral de Proteção de Dados (LGPD), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
This policy does not replace our Data Processing Agreement, which governs our processing of personal data contained in your Client Data on your behalf.
2. Our two roles: controller and processor #
Snack SEO handles two very different kinds of data, and our legal role differs for each. This distinction matters, so please read it carefully.
2.1 We are a controller for Account Data #
"Account Data" is personal data about you and your team as our customer: your name, email address, password hash, company name, job title, billing details, support correspondence, product usage telemetry, marketing preferences and similar information. We decide why and how this data is processed, so for Account Data we are the controller (a "business" under CCPA/CPRA). Sections 3, 8 and 12–25 of this policy describe that processing.
2.2 We are a processor for Client Data #
"Client Data" is the data you or your end clients put into, or authorise us to retrieve into, the Service: the domains and URLs you add; content you upload or paste; keyword lists; competitor lists; brand and prompt configurations; data we retrieve from your connected Google Search Console, Google Analytics and Google Business Profile accounts; data our crawler collects from the websites you authorise; and any personal data that happens to be contained in any of the above (for example, an author name in a page byline, or a contact email address appearing on a crawled page).
For Client Data we act as a processor (a "service provider" under CCPA/CPRA) acting on your documented instructions. You are the controller. You are responsible for having a lawful basis for the data you place in, or route through, the Service, and for giving the notices and obtaining the consents your own privacy law requires. Our Data Processing Agreement governs this relationship and forms part of our contract with you.
2.3 Where a person visits your website #
Where our crawler or your connected analytics accounts result in us handling data about visitors to your website, we handle that data solely as your processor. We do not build profiles of your website visitors, we do not sell that data, and we do not use it for our own advertising.
3. Personal data we collect #
3.1 Data you give us #
| Category | Examples |
|---|---|
| Identity and contact data | Full name, email address, company or agency name, job title, country, time zone, profile photo (if you upload one) |
| Account credentials | Hashed password, multi-factor authentication settings, session and refresh tokens, API keys you generate |
| Workspace and team data | Workspace name, team member invitations and email addresses, roles and permissions, client or project names you create |
| Billing data | Billing name and address, VAT/tax identifiers, plan and subscription history, invoices, the last four digits and expiry of a card and its issuing country. We do not store full payment-card numbers. Card details are collected and stored by our payment processor. |
| Support and communications data | Emails, in-app messages, support tickets, bug reports, screenshots and recordings you send us, survey and interview responses |
| Content you submit | Prompts, briefs, drafts, notes, uploaded documents, feedback and anything else you type into or upload to the Service |
3.2 Data we collect automatically #
| Category | Examples |
|---|---|
| Device and connection data | IP address, browser type and version, operating system, device type, screen size, language, referring and exit URLs |
| Usage and telemetry data | Pages and features viewed, buttons clicked, reports run, crawls started, credits consumed, timestamps, session duration, feature-flag state |
| Diagnostic data | Error messages, stack traces, performance timings and breadcrumb logs captured by our error monitoring tool (Sentry). Stack traces can incidentally contain a user identifier or a URL you were viewing. |
| Security data | Sign-in attempts, IP-based geolocation at city level, security events, audit-log entries for actions taken in your workspace |
3.3 Data we receive from third parties #
- Authentication providers. If you sign in with Google, we receive your name, email address, Google account identifier and profile picture.
- Connected data sources. See section 4.
- Payment processor. Transaction status, card brand, last four digits, expiry, country, and fraud or chargeback signals.
- SEO and search data providers. DataForSEO, SerpApi and similar providers return search-engine results, keyword volumes, backlink records and SERP features. These datasets are principally about web pages and domains, but a search result or a backlink record can contain a personal name (for example, a personal blog, an author profile or a social media page).
- AI search providers. OpenAI, Anthropic, Google (Gemini), Perplexity and models accessed via OpenRouter return generated answers and citations in response to prompts we run to measure AI-search visibility. Those answers can mention named individuals.
- Publicly available sources. Company and firmographic data used to qualify sales enquiries.
3.4 Sensitive data #
We do not ask for, and the Service is not designed to hold, special-category data under Article 9 GDPR or "sensitive personal information" under the CCPA/CPRA (such as health data, biometric data, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, trade-union membership, sex life or sexual orientation, or government identifiers). Please do not upload such data to the Service or place it in prompts. If we become aware that such data has been uploaded, we may delete it.
4. Data we access from connected Google accounts (OAuth) #
This section is important, because it is the part of the Service that touches the most sensitive data you control. Connecting a Google account is always optional, and the Service remains usable without it (with reduced functionality).
4.1 What we connect to, and why #
| Connection | OAuth scope category | What we read | Why we read it |
|---|---|---|---|
| Google Search Console | Read-only Search Console data (webmasters.readonly) and, where you enable it, site listing | Verified property list; Search Analytics rows (query, page, country, device, search appearance, clicks, impressions, CTR, average position); index-coverage and URL-inspection results; sitemap status | To show your real organic performance, detect ranking and traffic movements, find keyword and page opportunities, diagnose indexing problems, and measure the effect of changes we recommend |
| Google Analytics (GA4) | Read-only Analytics data (analytics.readonly) | Property and data-stream list; aggregated report rows such as sessions, users, engagement, conversions and revenue, broken down by channel, source/medium, landing page, country and device | To connect SEO activity to sessions, conversions and revenue, and to prioritise pages by business value |
| Google Business Profile | Business Profile management/read (business.manage) | Location list and location details; business categories; reviews and review replies; performance metrics such as searches, views, calls and direction requests | To support local SEO reporting, monitor listing accuracy, and track local visibility |
We request read-only scopes wherever the Google API offers one. Where an API only exposes a broader scope (as is the case for Google Business Profile), we still use it only for the read and reporting purposes described above, and we will tell you in the consent screen before you grant it.
4.2 What we explicitly do not do with Google user data #
- We do not use Google user data for advertising, retargeting, or building advertising profiles.
- We do not sell or "share" (as those terms are defined by the CCPA/CPRA) Google user data.
- We do not use Google user data to train, fine-tune or improve generalised artificial intelligence or machine-learning models, whether our own or a third party's.
- We do not allow humans to read your Google user data except in the narrow cases listed in section 5.
- We do not write to, modify or delete anything in your Google account, other than where you explicitly ask us to perform a supported write action (for example, replying to a Business Profile review from within the Service).
- We do not access Gmail, Google Drive, Google Contacts, Google Ads or any other Google product not listed above.
4.3 How connected data is stored and separated #
Google user data retrieved for your workspace is stored in your tenant's records in our database and is protected by row-level access controls so that it is only accessible to authenticated members of your workspace with sufficient permissions. OAuth access and refresh tokens are stored encrypted at rest and are used only to refresh the connection and to make the read calls described above.
4.4 How long we keep it #
- Report rows (Search Console, Analytics, Business Profile metrics) are retained for the life of the connection plus 90 days, so that historical trend charts continue to work, unless you delete the property or workspace sooner.
- OAuth tokens are deleted within 7 days of you disconnecting the integration, revoking access at Google, or deleting the workspace.
- On workspace deletion, all associated Google user data is deleted from live systems within 30 days and purged from encrypted backups within a further 60 days.
- You can request earlier deletion of specific data at any time — see section 20.
4.5 How to revoke access — three independent routes #
You may withdraw this permission at any time, and doing so is always effective:
- In Snack SEO: open Settings → Integrations, find the connection, and click Disconnect. This deletes the stored tokens and stops all further calls.
- In your Google Account: go to https://myaccount.google.com/permissions, find "Snack SEO", and click Remove access. This revokes our tokens at source.
- By email: write to hello@snackseo.com and ask us to disconnect and delete. We will action it within 7 days and confirm to you.
Revoking access stops future retrieval immediately. Data already retrieved is deleted on the timetable in section 4.4, or sooner on request.
5. Google API Services User Data Policy — Limited Use disclosure #
Snack SEO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and in the terms Google uses:
- We limit our use of Google user data to providing or improving user-facing features that are prominent in the requesting application's user interface — namely the SEO reporting, auditing, ranking, forecasting and recommendation features of Snack SEO.
- We do not transfer Google user data to others except (a) as necessary to provide or improve those user-facing features, and only to the sub-processors listed in our Sub-processors page under confidentiality and data-protection obligations; (b) for security purposes such as investigating abuse; (c) to comply with applicable law; or (d) as part of a merger, acquisition or sale of assets, after obtaining your explicit prior consent where required.
- We do not use Google user data for serving advertisements of any kind, including personalised, retargeted or interest-based advertising.
- We do not allow humans to read Google user data, unless (a) we have your affirmative agreement for specific messages or records — for example, when you ask us to investigate a support issue and consent to us looking at the data; (b) it is necessary for security purposes such as investigating a bug, abuse, or a suspected security incident; (c) it is necessary to comply with applicable law; or (d) the data has been aggregated and anonymised such that it can no longer be associated with an individual Google account, and is used for internal operations such as capacity planning.
- We do not use Google user data to develop, train, improve or fine-tune generalised artificial intelligence or machine-learning models. Where a feature sends a limited extract of Google user data to an AI model to produce an output for you (for example, "summarise which queries lost clicks last month"), that extract is sent under contractual terms that prohibit the provider from training on it, and is used only to generate that output for you.
If you believe we are not complying with this commitment, please contact hello@snackseo.com.
6. Data we collect when we crawl your websites #
When you add a domain, we may crawl it to run technical SEO audits, extract content, check internal links, capture structured data and measure performance.
- We crawl only domains you have added and warranted that you own or are authorised to act for. Adding a domain is your representation to us that you have that authority, as set out in our Terms of Service.
- Our crawler identifies itself with a distinctive user-agent string and originates from a documented set of IP addresses, so you can allow-list or block it.
- Our crawler respects
robots.txtdirectives and applies conservative rate limits by default. You can configure crawl rate, scope and exclusions in the Service. - A crawl retrieves publicly available page content, HTTP headers, status codes, redirects, canonical and hreflang tags, structured data, images and metadata. Where a page you have authorised us to crawl contains personal data — for example, a staff directory, an author byline, a testimonial or a contact email address — we will retrieve and store that data as part of the page record. We process it solely as your processor and solely to provide the audit and content features.
- We do not attempt to bypass authentication, paywalls, CAPTCHAs or access controls. If you configure the crawler with credentials to crawl a staging or gated site, you are responsible for the lawfulness of that instruction and for the content behind it.
- Crawl artefacts (raw HTML snapshots, rendered text, screenshots) are retained for the retention period configured for your plan, and by default for 12 months, after which they are deleted or reduced to aggregate metrics.
7. AI features and how your data is used with AI models #
Snack SEO uses large language models and AI-search engines in two distinct ways.
7.1 Generative features (content briefs, drafts, recommendations, summaries) #
When you use a generative feature, we transmit your prompt together with relevant context — which may include page content, keyword data, extracts of your connected Search Console or Analytics data, and your own instructions — to one or more AI providers: OpenAI, Anthropic, Google (Gemini), or a model routed through OpenRouter.
- We use these providers under their API / enterprise terms, which provide that inputs and outputs submitted through the API are not used to train their models.
- We do not use your Client Data or your prompts to train our own models.
- Providers retain inputs and outputs for a limited period for abuse-monitoring purposes under their own policies (typically up to 30 days), after which they are deleted.
- Outputs are stored in your workspace so you can retrieve them.
Please note the accuracy and originality disclaimers in section 6 of our Terms of Service: AI output can be wrong, can be similar or identical to output generated for another user, and must be reviewed by a human before you publish it.
7.2 AI-search visibility monitoring #
To measure how a brand appears in AI-generated answers, we run prompts you configure against AI search products including ChatGPT-class models, Google Gemini, Perplexity and models accessed via OpenRouter, and we record the answers, the brands mentioned and the sources cited.
- The prompts we send are the ones you configure. Do not put personal data or confidential information into monitoring prompts — they are sent to third-party AI providers as ordinary API requests.
- The answers we record may mention named individuals; where they do, we hold that content as your processor.
- AI-search results are probabilistic. The same prompt run twice can produce materially different answers. See section 7 of our Terms of Service.
7.3 No sensitive automated decisions #
We do not use AI to make decisions that produce legal or similarly significant effects concerning any individual. See section 21.
8. Why we process your data and our legal bases #
Where we act as controller (Account Data), we rely on the following legal bases under the GDPR and UK GDPR.
| Purpose | Data used | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Creating and administering your account; authenticating you | Identity, contact, credentials | Performance of a contract (Art. 6(1)(b)) |
| Providing the Service, including running crawls, retrieving connected data, generating reports and AI outputs | Account Data; Client Data (as processor) | Performance of a contract (Art. 6(1)(b)); for Client Data, your instructions under the DPA |
| Taking payment, invoicing, tax and accounting | Billing data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Providing support and responding to enquiries | Support and communications data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) — running a responsive business |
| Securing the Service, preventing fraud and abuse, enforcing our terms and rate limits | Security, device and usage data | Legitimate interests (Art. 6(1)(f)) — protecting our platform, our customers and third parties; legal obligation (Art. 6(1)(c)) |
| Monitoring performance and errors, debugging, capacity planning | Diagnostic and usage data | Legitimate interests (Art. 6(1)(f)) — keeping the Service working |
| Improving and developing the Service; building aggregate benchmarks and indices | Usage data; aggregated and de-identified data (see section 9) | Legitimate interests (Art. 6(1)(f)) — improving a product our customers pay for |
| Service and transactional emails (receipts, security alerts, outage notices, material changes) | Identity and contact data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Marketing emails and product announcements | Identity, contact, marketing preferences | Consent (Art. 6(1)(a)) where required by law; otherwise legitimate interests (Art. 6(1)(f)) in marketing to existing customers about similar services, subject always to an easy opt-out |
| Analytics and advertising cookies on our marketing site | Cookie and engagement data | Consent (Art. 6(1)(a)) |
| Establishing, exercising or defending legal claims; complying with lawful requests | Any relevant data | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your interests or fundamental rights. You may object to that processing — see section 16. You may request a summary of the relevant assessment at hello@snackseo.com.
9. Aggregated and de-identified data #
We may create aggregated, statistical and de-identified datasets from usage of the Service — for example, benchmark averages for click-through rate by search position, the frequency with which particular domains are cited by AI answer engines, or aggregate crawl-health statistics across our customer base.
- These datasets are produced so that they do not identify you, your workspace, your clients or any individual, and we do not attempt to re-identify them.
- We use them to operate, secure, benchmark, improve and market the Service, and to build product features such as industry benchmarks.
- As between you and us, aggregated and de-identified data is our property.
- Once data has been aggregated and de-identified in this way it is no longer personal data, and this Privacy Policy's rights sections do not apply to it.
We will not publish aggregated statistics in a form that would allow a specific customer, workspace or client site to be identified without that customer's consent.
10. Who we share data with (sub-processors and other recipients) #
We do not sell personal data, and we do not "share" personal data for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA.
10.1 Sub-processors #
We use a limited set of vendors to run the Service. Each is bound by a written contract that requires them to process data only on our instructions, to keep it confidential, and to apply appropriate technical and organisational security measures. The current list — with the service provided, the data involved, the location of processing and the transfer safeguard — is maintained at /legal/subprocessors and is incorporated into this policy by reference.
In summary, the categories are: cloud infrastructure and database hosting (Supabase, Hetzner Online GmbH); network, DNS, CDN and object storage (Cloudflare); search and SEO data providers (DataForSEO, SerpApi); Google APIs for connected properties and generative AI (Google LLC); AI model providers (OpenAI, Anthropic, OpenRouter, Perplexity); transactional email (Resend); error monitoring (Sentry); and internal operations and record-keeping (Airtable).
You can subscribe to notifications of changes to that list — see the sub-processors page.
10.2 Other recipients #
- Your own workspace. Data you put into a workspace is visible to other members of that workspace according to the roles and permissions you configure. Workspace owners and administrators can see, export and delete content created by their members. If your employer or agency provides your account, they administer it.
- Payment processor. To take payment and manage subscriptions. Our payment processor acts as an independent controller for its own fraud-prevention and regulatory purposes.
- Professional advisers. Lawyers, accountants, auditors and insurers, under duties of confidentiality.
- Authorities. Law enforcement, regulators, courts and other public bodies where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims. Where we are legally permitted to do so, we will notify you before disclosing your Client Data so that you can seek protective relief.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to confidentiality and to this policy continuing to apply to the transferred data.
11. International transfers of data #
Snack SEO runs on infrastructure in the European Union (Hetzner Online GmbH in Nuremberg, Germany; Supabase database hosting in Frankfurt, Germany) and in the United States. Snack Prompt Corp is established in the United States. Some of our sub-processors process data in the United States and, for globally distributed services such as Cloudflare's edge network, in other countries.
This means personal data originating in the EEA, the UK, Switzerland, Brazil or Canada may be transferred to, stored in, or accessed from the United States and other countries whose data-protection laws may differ from those of your own country.
We rely on the following safeguards:
- EU Standard Contractual Clauses. Where personal data is transferred from the EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), incorporated into our Data Processing Agreement and into our contracts with sub-processors, using the modules appropriate to each transfer.
- UK International Data Transfer Addendum. For transfers from the United Kingdom, we rely on the UK Information Commissioner's International Data Transfer Addendum to the EU SCCs, or the UK IDTA.
- Swiss transfers. For transfers from Switzerland, we rely on the SCCs with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner.
- Brazil and Canada. For transfers subject to the LGPD or PIPEDA, we rely on contractual safeguards equivalent to those above, and remain accountable for data transferred to processors.
- Transfer impact assessments. We assess the laws and practices of the destination country and, where necessary, apply supplementary measures — including encryption in transit (TLS 1.2+) and at rest, access controls, minimisation of the data transferred, and a policy of challenging unlawful government access requests.
- EU data residency. Where your plan includes EU data residency, your primary database and application servers are located in the EU. Certain functions — notably AI model inference and some SEO data providers — necessarily involve transfer outside the EU; we will tell you which, and you can disable those features.
You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, by emailing hello@snackseo.com.
12. How long we keep data #
| Data | Retention |
|---|---|
| Account and workspace records | For the life of the account, and 90 days after account closure, then deleted or anonymised |
| Client Data in an active workspace | Until you delete it, or as configured in your workspace retention settings |
| Client Data after workspace or account deletion | Deleted from live systems within 30 days; purged from encrypted backups within a further 60 days |
| Google user data (Search Console, Analytics, Business Profile) | Life of the connection plus 90 days; OAuth tokens deleted within 7 days of disconnection (section 4.4) |
| Crawl artefacts (HTML snapshots, rendered text, screenshots) | 12 months by default, or as configured in your plan |
| AI prompts and outputs | Stored in your workspace until you delete them; provider-side abuse-monitoring copies deleted per that provider's policy (typically ≤30 days) |
| Invoices, payment records and tax documents | 7 years, to meet US and EU accounting and tax obligations |
| Support tickets and correspondence | 3 years from last contact |
| Security, audit and access logs | 12 months |
| Error monitoring and diagnostic events | 90 days |
| Marketing contacts and consent records | Until you unsubscribe or object, plus 3 years for proof of consent |
| Aggregated and de-identified data | Indefinitely (no longer personal data — see section 9) |
Where we are required to retain data to comply with a legal obligation, resolve a dispute or enforce our agreements, we will retain the minimum necessary for that purpose and isolate it from active processing.
13. Security #
We implement technical and organisational measures appropriate to the risk, including:
- Encryption. TLS 1.2 or higher for all data in transit; AES-256 encryption at rest for databases, object storage and backups. OAuth tokens and API credentials are encrypted with a separately managed key.
- Tenant isolation. The Service is multi-tenant. Access to Client Data is enforced at the database layer by row-level security policies keyed to workspace membership, in addition to application-layer authorisation.
- Access control. Least-privilege access for our personnel; access to production data requires named accounts, multi-factor authentication and is logged; production access is limited to a small number of engineers and reviewed periodically.
- Authentication. Password hashing with a modern memory-hard algorithm; support for multi-factor authentication and single sign-on; session and refresh token rotation.
- Backups and resilience. Encrypted automated backups with point-in-time recovery, stored in the same regional footprint as the primary data.
- Secure development. Code review, dependency and vulnerability scanning, environment separation, secrets management, and change control.
- Monitoring. Centralised logging, error monitoring, alerting and audit trails for privileged actions.
- Vendor diligence. Security and data-protection review of each sub-processor before onboarding and on material change.
- Incident response. A documented incident response plan. Where we act as processor, we will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your Client Data, with the information required by Article 33(3) GDPR to the extent available. Where we act as controller, we will notify the competent supervisory authority and affected individuals as required by law.
No system is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security, and we do not warrant that the Service will be free from unauthorised access. You are responsible for protecting your own credentials, for using multi-factor authentication, and for removing team members' access promptly when they leave.
Report a suspected vulnerability or compromise to hello@snackseo.com.
14. Cookies and similar technologies #
We use cookies and similar technologies for the following purposes:
- Strictly necessary. Authentication, session management, security, load balancing, and remembering your cookie choices. These cannot be switched off and are set on the basis of our legitimate interests / the necessity exemption, without consent.
- Functional. Remembering interface preferences such as theme, table layout and default date range.
- Analytics. Understanding which features are used and where users encounter friction, so we can improve the product.
- Marketing. On our public marketing pages only, measuring the effectiveness of campaigns and, where you consent, showing relevant advertising.
Where required by the ePrivacy Directive, the UK PECR or comparable law, we set non-essential cookies only after you consent through our cookie banner. You can change or withdraw your choices at any time via the "Cookie settings" link in the footer of https://snackseo.com. Most browsers also let you block or delete cookies; blocking strictly necessary cookies will prevent you from signing in.
We honour the Global Privacy Control (GPC) signal, which we treat as a valid opt-out of "sale" and "sharing" for the browser that sends it.
We do not use cookies inside the authenticated application at https://app.snackseo.com for advertising purposes.
15. Marketing communications #
We send two kinds of email:
- Service and transactional email — receipts, security alerts, password resets, crawl completion notices, outage and maintenance notices, and notices of material changes to our terms. You cannot unsubscribe from these while you hold an account, because they are necessary to provide the Service.
- Marketing email — product announcements, feature releases, guides and offers. You can unsubscribe at any time using the link in every marketing email, or by emailing hello@snackseo.com. Where the law requires consent, we obtain it before sending.
We do not sell or rent your email address to anyone.
16. Your rights under the GDPR and UK GDPR #
If you are in the EEA, the United Kingdom or Switzerland, you have the following rights in relation to personal data for which we are the controller:
- Access — to be told whether we process your personal data and, if so, to receive a copy of it and information about the processing.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure ("right to be forgotten") — to have your personal data deleted where one of the grounds in Article 17 applies.
- Restriction — to have processing restricted in the circumstances set out in Article 18.
- Portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests; and to object at any time and without reason to processing for direct marketing.
- Withdrawal of consent — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
- Not to be subject to solely automated decisions producing legal or similarly significant effects (see section 21).
- To complain to a supervisory authority (see section 25).
Where we act as processor for Client Data, please direct your request to the customer that controls that data (the workspace owner). If you contact us directly, we will forward your request to them and assist them in responding, but we cannot act on Client Data without their instruction.
We do not charge for responding to a request unless it is manifestly unfounded or excessive, and we will respond within one month, extendable by two further months for complex requests (we will tell you if we need the extension).
17. Your rights under CCPA/CPRA and other US state laws #
This section applies to residents of California and, as applicable, of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others).
17.1 Categories collected, sources, purposes and disclosures #
In the preceding 12 months we have collected the following categories of personal information as defined by the CCPA:
| CCPA category | Collected? | Source | Business purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers (name, email, IP, account ID) | Yes | You; authentication providers | Account, support, security, billing | Sub-processors (hosting, email, monitoring, payments) |
| Customer records (billing name, address, partial card data) | Yes | You; payment processor | Billing, tax, fraud prevention | Payment processor, accountants |
| Commercial information (plan, purchases, usage of paid features) | Yes | You; the Service | Billing, support, product analytics | Sub-processors |
| Internet or network activity (usage, telemetry, diagnostics) | Yes | Automatic collection | Operating, securing and improving the Service | Hosting, analytics, error monitoring |
| Geolocation (coarse, IP-derived city level) | Yes | Automatic collection | Security, fraud prevention, localisation | Hosting, security tooling |
| Professional or employment information (job title, company) | Yes | You | Support, account management, marketing | CRM/operations tooling |
| Inferences (segment, likely use case) | Yes | Derived from the above | Product improvement, marketing | Internal only |
| Sensitive personal information | Not intentionally collected — see section 3.4 | — | — | — |
| Biometric, health, education, audio/visual (other than support recordings you send us) | No | — | — | — |
17.2 No sale, no sharing #
We do not sell personal information and we have not sold personal information in the preceding 12 months. We do not "share" personal information for cross-context behavioural advertising, other than, on our public marketing site only and only where you consent through the cookie banner, the use of advertising cookies, which some laws treat as "sharing". You can opt out through the cookie banner, the "Do Not Sell or Share My Personal Information" link in our footer, or by sending a Global Privacy Control signal.
We do not knowingly sell or share the personal information of consumers under 16 years of age.
17.3 Your rights #
- Right to know / access — the categories and specific pieces of personal information we collected, the sources, the business or commercial purpose, and the categories of third parties to whom we disclosed it.
- Right to delete — to request deletion of personal information we collected from you, subject to statutory exceptions.
- Right to correct — to request correction of inaccurate personal information.
- Right to opt out of sale/sharing — see section 17.2.
- Right to limit use of sensitive personal information — we do not use or disclose sensitive personal information for purposes beyond those permitted by CCPA §7027(m), so no limitation is necessary; if that changes we will provide the mechanism.
- Right to non-discrimination — we will not deny you service, charge you different prices, or provide a different level or quality of service because you exercised a privacy right.
- Right to appeal (Virginia, Colorado, Connecticut, Texas and others) — if we decline your request, you may appeal by replying to our decision or emailing hello@snackseo.com with "Privacy Appeal" in the subject line. We will respond within 45 days (or 60 days where permitted) with our decision and the reasons for it, and will tell you how to contact your state attorney general if you remain dissatisfied.
We will verify your request by matching the information you provide against our records; for account holders this normally means responding from the email address on the account. You may use an authorised agent, who must provide written proof of authorisation, and we may still ask you to verify your own identity.
Where we act as a service provider for Client Data, we will refer your request to the business that controls that data.
18. Your rights under the LGPD (Brazil) #
If you are in Brazil, Law No. 13,709/2018 (LGPD) gives you the rights to: confirm that processing exists; access your data; correct incomplete, inaccurate or out-of-date data; anonymise, block or delete unnecessary or excessive data or data processed unlawfully; port your data to another provider; delete data processed with consent; obtain information about the public and private entities with which we have shared your data; be informed about the possibility of refusing consent and the consequences of doing so; revoke consent; and object to processing carried out on a legal basis other than consent where it does not comply with the law.
Our legal bases under Article 7 LGPD mirror those in section 8 (principally execution of a contract, legitimate interests, compliance with a legal obligation and, for marketing and non-essential cookies, consent). Requests: hello@snackseo.com. You may also complain to the Autoridade Nacional de Proteção de Dados (ANPD).
19. Your rights under PIPEDA (Canada) #
If you are in Canada, PIPEDA and applicable provincial legislation (including Quebec's Law 25) give you the right to access the personal information we hold about you, to challenge its accuracy and have it corrected, and to withdraw consent (subject to legal and contractual restrictions and reasonable notice). We identify the purposes for which we collect personal information at or before collection, limit collection to what is necessary for those purposes, and remain accountable for personal information transferred to third parties for processing.
We use service providers outside Canada, including in the United States and the European Union. While personal information is in another jurisdiction, it may be accessible to the courts, law enforcement and national security authorities of that jurisdiction. Requests and questions: hello@snackseo.com. You may also complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec if you are in Quebec.
20. How to exercise your rights #
Email hello@snackseo.com with the subject line "Privacy Request" and tell us:
- which right you wish to exercise;
- the email address associated with your account (or, if you have no account, enough detail for us to locate any data we hold about you); and
- the country or state you are in, so we can apply the right legal standard.
Account holders can also access, export and delete much of their data directly in the Service under Settings → Account & Data.
We will acknowledge your request promptly and respond within the time limit that applies to you: one month under the GDPR/UK GDPR (extendable by two months for complex requests), 45 days under the CCPA/CPRA (extendable by a further 45 days), 15 days under the LGPD for confirmation of processing and access, and 30 days under PIPEDA (extendable with notice).
21. Automated decision-making and profiling #
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
The Service does produce automated outputs — priority scores, opportunity rankings, forecasts, AI-generated recommendations and drafts. These are decision-support tools for your marketing work, not decisions about individuals. They should always be reviewed by a person before you act on them. We may use automated fraud and abuse signals to flag accounts for review, but any suspension or termination decision that materially affects you involves human review, and you may contest it by emailing hello@snackseo.com.
22. Children #
The Service is a business tool. It is not directed to children, and we do not knowingly collect personal data from anyone under 16 years of age. You must be at least 18 to enter into a paid subscription. If you believe a child has provided us with personal data, email hello@snackseo.com and we will delete it.
23. Third-party sites and services #
The Service links to and integrates with third-party products, including Google properties, search engines and AI providers. Once data is transmitted to a third-party service at your direction, that service's own terms and privacy policy govern its handling of the data, and we have no control over it. We are not responsible for the privacy or security practices of third-party services, and we encourage you to read their policies before connecting them. Disconnecting an integration in Snack SEO stops our access, but does not delete anything already held by that third party.
24. Changes to this policy #
We may update this policy to reflect changes in the Service, our sub-processors, or the law. The version in force is always published at https://snackseo.com/legal/privacy-policy with the effective date at the top.
- For minor or clarifying changes, we update the page and the effective date.
- For material changes — such as a new purpose of processing, a new category of recipient, or a change that reduces your rights — we will give you at least 30 days' notice by email to your account address and/or by prominent in-app notice before the change takes effect.
Continuing to use the Service after a change takes effect means you accept the updated policy. If you do not accept it, you may close your account and, where you have prepaid for an unused period, request a pro-rata refund for that period.
25. How to contact us and how to complain #
Snack Prompt Corp
604 Canyon Creek Trail
Fort Worth, TX 76112
United States
Email: hello@snackseo.com (privacy requests, data protection questions, security reports, and all other legal matters)
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Privacy matters are handled by our management, reachable at the address above.
Right to complain. If you are unhappy with how we have handled your personal data, please contact us first — we would like the chance to fix it. You also have the right to complain to a supervisory authority:
- EEA: the data protection authority of your country of residence, place of work, or the place of the alleged infringement. A list is at https://edpb.europa.eu/about-edpb/board/members_en.
- United Kingdom: the Information Commissioner's Office, https://ico.org.uk/make-a-complaint/.
- Switzerland: the Federal Data Protection and Information Commissioner.
- Brazil: the Autoridade Nacional de Proteção de Dados (ANPD).
- Canada: the Office of the Privacy Commissioner of Canada, or the CAI in Quebec.
- California: the California Privacy Protection Agency or the California Attorney General.
Snack SEO is a product of Snack Prompt Corp. See also our Terms of Service, Data Processing Agreement, Sub-processors and Acceptable Use Policy.