SERPFLEET · PRIVACY

Privacy Policy

Effective September 4, 2026

This policy explains how SerpFleet handles information while providing multi-site search and traffic analysis, Opportunity signals, user-requested AI SEO analysis, and paid subscriptions. You always decide whether to authorize Google data access or request an AI analysis.

1. Information we collect and process

Product sign-in uses Google openid, email, and profile information to identify your SerpFleet account and Workspace. If you separately connect Google Search Console or Google Analytics 4, SerpFleet accesses only the read-only data you authorize, including connected site or property metadata; Search Console queries, pages, clicks, impressions, CTR, and average position; and GA4 aggregate traffic and engagement metrics such as active users and sessions. For paid subscriptions, we may also process limited billing information such as plan, subscription status, billing period, transaction status, and provider references.

2. How we use information

We use this information to authenticate users; provide Portfolio, Sites, Query and Page explorers, GA4 views, synchronization, data health, deterministic Opportunity signals, and user-requested AI SEO Advisor analyses; manage subscription access and billing support for paid subscriptions; protect and isolate Workspaces; diagnose service failures; and respond to support, account, and deletion requests. We do not use Google user data for advertising, data brokerage, or marketing unrelated to SerpFleet's product functions.

3. Google API data and Limited Use

SerpFleet's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Search Console and Google Analytics connections use read-only scopes. Policy reference: Google API Services User Data Policy.

4. Google User Data Sharing and Disclosure

SerpFleet does not sell Google user data, use it for targeted advertising or data brokerage, or disclose it for marketing unrelated to SerpFleet. We disclose only the minimum information necessary to service providers that help operate requested features: cloud hosting and application infrastructure providers; managed database providers; and, only when a user requests an AI SEO Advisor analysis, third-party AI inference service providers. These providers process the data only as needed to provide the requested SerpFleet functionality and under their applicable contractual and privacy terms. We may also disclose information when required by applicable law or necessary to protect users and the service.

5. AI processing and model training

When you choose Analyze with AI, SerpFleet sends only the information needed for that request to third-party AI inference service providers: relevant GSC- or GA4-derived aggregate metrics, structured Opportunity evidence and data-health limitations, the relevant query or page context, and relevant public website content inspected for the analysis. SerpFleet does not send Google OAuth credentials, API keys, Workspace identifiers, or unrelated user data to these providers. Third-party AI inference service providers process this information only as necessary to provide and operate the AI analysis you requested, subject to their applicable contractual and privacy terms. SerpFleet does not use or transfer Google user data to develop, improve, or train generalized AI or machine-learning models.

6. Billing and payment processing

For paid subscriptions, Waffo Pancake acts as Merchant of Record and payment service for SerpFleet purchases. Waffo Pancake processes payment methods, billing details, invoices, applicable taxes, refunds, chargebacks, and subscription lifecycle information. SerpFleet does not receive or store full card numbers or complete payment credentials. We store only limited billing metadata needed for subscription access, support, and reconciliation, such as plan, subscription status, billing period, transaction status, and provider references. Waffo Pancake sends subscription lifecycle events to SerpFleet through protected webhooks.

7. Data security and protection

SerpFleet protects data in transit using HTTPS or TLS. Google OAuth credentials are encrypted before database storage using authenticated encryption, remain server-side, and are not exposed to browser clients. Application and provider secrets are managed in server-side environment settings. Workspace authorization, tenant-scoped access, and database row-level security help prevent cross-workspace access. Logging and error handling are designed not to record OAuth credentials, API keys, database credentials, full payment credentials, or complete AI provider responses. GSC and GA4 connections use read-only scopes. No method of storage or transmission is completely secure.

8. Retention, disconnection, revocation, and deletion

SerpFleet retains account, connection, synchronized metrics, Opportunity evidence, and AI analysis records for as long as needed to provide, secure, and operate the service, subject to product-defined rolling history windows and verified deletion requests. Disconnecting GSC or GA4 inside SerpFleet stops future synchronization for that source, retains existing synchronized data, and does not revoke authorization in your Google Account. Revoking SerpFleet from your Google Account stops future Google API access but does not by itself delete data already synchronized. Billing and transaction records may be retained separately where required for tax, accounting, fraud prevention, payment disputes, or other legal obligations. You may request account and data deletion at support@serpfleet.io. After verifying account and Workspace ownership, we will delete or de-identify the relevant data as appropriate, except for limited records that must be retained for security, billing, or legal obligations.

9. Your choices and controls

You may use product sign-in without connecting GSC or GA4, connect either source independently, disconnect a source in SerpFleet, revoke authorization through your Google Account, choose whether to request an AI analysis, manage a paid subscription through the Waffo Pancake Consumer Portal, and request access, correction, or deletion through support.

10. Updates and contact

We will update this page and its effective date if our data practices materially change. Contact support@serpfleet.io with privacy, billing-data, data-handling, or deletion questions.

11. Optional product analytics

With your permission, we use Google Analytics to understand use of SerpFleet itself, such as visits to standardized product pages and interactions with signup, connections, analysis and billing features. This is separate from the customer Google Analytics properties you connect for traffic reporting. Before you accept analytics, or after you reject it, we do not load the Google Analytics tag or send these events. We store your choice in your browser; you can reject or withdraw consent through Analytics preferences in the footer. After consent, Google Analytics uses pseudonymous browser identifiers and analytics cookies, not your Google email, name or Workspace identity. Our analytics cookies expire after 90 days; event data is subject to the property's configured retention. We also keep bounded browser-local suppression records to avoid repeat events, and remove them on withdrawal. We do not send customer site addresses, search terms, page content, AI inputs or outputs, credentials or payment details to product analytics. Analytics is best-effort and is not our billing or business record.

12. Error monitoring

We use Sentry to identify and fix service errors. We send restricted technical information such as a general error category, sanitized code locations, release version and environment. We remove user identity, request content, arbitrary error messages and interaction breadcrumbs before sending reports. We do not enable session replay, performance tracing or automatic console-log collection. Error monitoring is separate from optional usage analytics and supports service reliability and security. Reports are retained according to the monitoring project's configured retention and only as needed for these purposes. Contact support@serpfleet.io for privacy and deletion requests.

support@serpfleet.io