Privacy Policy
Last updated:
This policy explains what personal data Visqio stores, why, for how long, and what you can ask us to do with it. It covers this website and the platform at app.visqio.com.
1.What we store
- Invite requests (this website): name, company, work email, use case, IP address and submission time.
- Accounts: name, email, password hash (argon2id), role, session records (IP, user agent, timestamps).
- Search data you authorise: Google Search Console metrics and URL Inspection results for your properties, and an encrypted Google refresh token.
- Tracking configuration and results: keywords, URLs, locations, SERP snapshots from licensed providers, diagnostics, alerts and reports.
- Audit logs: who changed what and when, with IP and request id.
- Phishing evidence you capture: screenshots and HTTP headers of third-party hosts.
This website sets no analytics or advertising cookies. The platform uses one session cookie strictly required for login. The invite form may load Cloudflare Turnstile to filter bots.
2.Why we store it
To review access requests, run the service you signed up for, keep it secure (audit logs, rate limiting, session control) and meet legal obligations. We do not sell personal data and do not use it for advertising.
3.How long we keep it
- Search Console metrics and SERP snapshots: 16 months, matching Google's own history window.
- Reports: 30 days after generation, then deleted.
- Sessions: until they expire or are revoked; expired invitations are pruned nightly.
- Invite requests: until reviewed and for 12 months after, so duplicate requests can be recognised.
- Audit logs: retained for the life of the organization plus what security or law requires.
- Everything else: deleted within 30 days of an organization deletion request.
4.Sub-processors
- Google (Search Console API, URL Inspection API) — data you authorise.
- DataForSEO — licensed SERP snapshots; receives keywords and locations, never your Google data.
- Cloudflare — TLS, DNS and bot filtering (Turnstile).
- Resend — transactional email (invitations, password resets, alerts, admin notifications).
- Telegram — only if you opt in to alert delivery there.
5.Security
Organizations are isolated at the query layer; Google tokens are encrypted with AES-256-GCM; passwords are hashed with argon2id; every mutation is audit-logged. Details are on the Security page.
6.Your rights
You can ask us to access, correct, export or delete your personal data, and to withdraw a Google authorisation at any time. Where the GDPR or a similar law applies, you also have the right to object to processing and to lodge a complaint with a supervisory authority. We answer requests within 30 days.
7.Contact
Privacy requests: privacy@visqio.com.