Privacy Policy
This policy explains what information GlobeSync ("we", "us") collects when you use our website-care platform (the "Service"), how we use it, and the choices you have.
1. Information we collect
- Account information — your name, email address, password (stored hashed), company name, time zone and billing status. Payment card details are collected and stored by our secure payment processor, never on our servers.
- Website data — the URLs you add, monitoring results (response times, status codes, certificate details), audit findings, WordPress inventory and activity collected through the connector plugin, backups of your website files and database, and form submissions your websites capture.
- Search data — keyword rankings, estimated traffic and related metrics for the websites and keywords you choose to track.
- Usage and technical data — log entries, IP address, browser type, pages visited within the Service and actions taken, used for security and to operate the Service.
- Communications — messages you send through the contact form or to support.
2. Google user data (Analytics & Search Console)
If you connect Google Analytics or Google Search Console, we request read-only access (the analytics.readonly and webmasters.readonly scopes) to the properties you select. We use this data only to display traffic, engagement and search-performance information inside your dashboard and in the reports you generate. We do not sell Google user data, use it for advertising, or share it with third parties except as needed to provide the Service to you. You can disconnect at any time from the website's Google settings or from your Google Account permissions page; disconnecting deletes the stored tokens and stops further collection.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use information
- To provide, maintain and secure the Service: monitoring, alerts, backups, audits, search intelligence, AI insights and reports.
- To send service emails — incident alerts, reports, account and billing notices — and, if you opt in, product updates.
- To prevent abuse, enforce our Terms and comply with legal obligations.
- To improve the Service using aggregated, de-identified usage statistics.
AI Insights are generated from your website data (audit findings, monitoring results, search metrics). The data sent to generate them is limited to what is needed for the insight and is not used to train models.
4. How we share information
We share information only with service providers that help us run the Service — hosting and storage, email delivery, payment processing, search-data and AI processing — under contracts that restrict their use of the data to providing services to us. We may disclose information when required by law or to protect the rights, safety or property of our users or the public. We do not sell personal information.
Within your account, data is visible to the team members and clients you invite, according to the roles you give them.
5. Data retention
- Monitoring, audit and search history are kept for as long as your account is active, subject to the retention periods of your plan.
- Backups are kept for the retention period of your plan and then deleted.
- After an account is cancelled, its data is kept read-only for 30 days for export, then deleted. Security and billing logs may be kept longer where the law requires.
6. Security
We use encryption in transit (TLS) and at rest for backups and credentials, role-based access control, audit logging, rate limiting and regular updates. Connector communication with your WordPress sites is signed and authenticated. No system is perfectly secure; please use a strong, unique password and keep your team list current.
7. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal information, object to or restrict processing, or lodge a complaint with a supervisory authority. Account owners can export and delete most data from within the Service; for anything else, contact us at the address below and we will respond within 30 days.
8. Cookies
We use strictly necessary cookies to keep you signed in and to protect forms against cross-site request forgery, plus a local preference for the pricing page's billing-cycle toggle. We do not use advertising or cross-site tracking cookies.
9. Children
The Service is intended for business use and is not directed at children under 16. We do not knowingly collect their personal information.
10. International transfers
Your information may be processed in countries other than your own. Where required, we use appropriate safeguards such as standard contractual clauses with our providers.
11. Changes to this policy
We may update this policy from time to time. We will post the new version here and, for material changes, notify account owners by email or in the Service.
12. Contact us
Privacy questions or requests: arsalan.ahmed@globesign.com or our contact page.