Privacy Policy
AussieAEO complies with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Operated by TraceData Australia, based in Melbourne, Victoria.
What we collect
We collect your email address (for account access), any business details you choose to give us during onboarding (business name, state and business type), the details you confirm before a scan runs (your main service, your main service area and, if you give them, a specialist service and a nearby city or region), the URLs you submit for scanning, and diagnostic metadata about scan and visibility results (scores, questions, citations, issue counts and timestamps).
To produce your audit we also store a copy of the public page content we fetch from the website you submit — the page HTML and the text extracted from it, for a small number of pages. We keep it so a paid audit and a verification re-scan can be generated from the same pages your free scan measured, rather than re-fetching your site each time.
We record a small amount of first-party usage data — for example when you open the schema editor, or ask about hands-on help — so we can tell which parts of the product are actually used. It is stored in our own database against your account.
Your report can name other businesses. When ChatGPT or Gemini recommends someone else for one of your buyer questions, we keep that business’s name and the page the answer cited, because that is the evidence for your result. Where such a business is a sole trader, their name may itself be personal information; we hold it only as part of your dated report and do not use it for anything else.
How we use it
Emails are used for authentication and for service messages about your scans and purchases. We do not send marketing email. Submitted URLs, scraped public content and generated buyer questions are processed to generate your audit and grounded visibility benchmark, then stored so you can view dated evidence in your dashboard.
Before a scan runs, the business details you type are screened for abusive content by OpenAI’s moderation service, so that our search budget cannot be spent on them.
Third-party processors
To operate the service we share limited data with the following processors:
- Firecrawl — fetches the public page content of the URLs you submit, on our behalf and from its own infrastructure.
- OpenAI — receives scraped public page content for fix-pack generation, the buyer questions used for grounded web-search checks, and the business details you type, which its moderation service screens.
- Google Gemini — receives buyer questions for Google-grounded visibility checks.
- Supabase — hosts our database, authentication, and account records.
- Stripe — processes payments and receives your email address so a purchase can be matched to your account; we never see or store your full card details.
- Google OAuth — used if you choose to sign in with Google.
- Cloudflare — provides the Turnstile bot check shown before a scan runs, and receives the technical information needed to complete that check.
- Lovable — hosts and deploys the application, sends account emails such as sign-in links, carries the Google sign-in flow, and relays our payment requests to Stripe through its connector gateway.
Overseas disclosure
Several of the processors above operate outside Australia, principally in the United States. By using the service you acknowledge that your personal information and the page content we fetch may be disclosed to, and stored or processed by, those overseas recipients. Where information is handled overseas it may not be subject to the same protections as the Australian Privacy Principles.
Cookies and analytics
We do not run third-party advertising or analytics trackers. The usage data described above is recorded in our own database, not by an outside analytics service. We use the storage necessary to keep you signed in and to operate the bot check described above.
How we protect it
Account data and scans are held in our Supabase database behind row-level security, so a signed-in customer’s queries can only reach their own rows. Access to production data and to third-party service keys is limited to the operator, and the site is served over HTTPS. No system is perfectly secure, and we do not claim otherwise.
If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Data retention
We do not delete scan data on a schedule. Your scans, and the page content stored with them, are kept for as long as your account exists, so your dashboard keeps showing dated evidence of what changed. You may request deletion at any time by emailing us: deleting your account removes your profile, your scans and the stored page content together, and we will do this within 30 days, except where retention is required for tax, accounting, or legal obligations (typically up to 7 years for payment records).
Your rights
Under the APPs you may request access to, correction of, or deletion of personal information we hold about you, and you may make a privacy complaint. Contact TraceData Australia at support@aussieaeo.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes to this policy
We may update this policy from time to time. The current version is always posted on this page, with the date it was last changed shown below.
Last updated: 14 September 2026
