Privacy Policy
We don't store your business data. QueryCatch fetches and displays your SEO metrics without creating copies.
Our Privacy Commitment
No Data Storage
We don't store your SEO metrics, analytics, or business data on our servers
View-Only Access
We only fetch and display data from your connected platforms
Bank-Level Security
Account data encrypted with AES-256 and TLS 1.3
Global Compliance
GDPR, CCPA, and Australian Privacy Principles compliant
Quick Navigation
Key Privacy Notice
QueryCatch operates on a unique no-storage model. We fetch your data from Google, WordPress, Shopify, and other platforms when you need it, display it for your analysis, and don't keep copies. Your business data remains in your control on the platforms you trust.
We only store: Account credentials • OAuth tokens • Billing information
Introduction
QueryCatch ("we", "our", or "us") is committed to protecting your privacy and ensuring transparency about how we handle data. This Privacy Policy explains our unique approach to data handling - we do not store your business data.
IMPORTANT:
QueryCatch operates as a data processor and display interface. We fetch and display your data from connected platforms (Google Search Console, Google Analytics, WordPress, Shopify, Kinsta) but do not store, own, or retain your business metrics, SEO data, or analytics information on our servers.
This Privacy Policy applies to all users of the QueryCatch platform and describes what limited information we do collect, how we protect it, and your rights regarding your data.
By using QueryCatch, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.
Our No-Storage Data Philosophy
QueryCatch is designed with privacy-by-design principles. We believe your business data should remain yours, which is why we've built our platform to operate without storing your sensitive business information.
How QueryCatch Works:
- We establish secure API connections to your existing platforms (Google, WordPress, Shopify, etc.)
- When you access QueryCatch, we fetch your data in real-time from these platforms
- We process and display this data in our interface for your analysis
- Once you close your session or navigate away, the data is not retained on our servers
- We do not create databases of your SEO metrics, search performance, or business analytics
This approach ensures that your sensitive business data remains under your control within the platforms you already trust, while we simply provide a unified interface to view and analyze it.
Information We Actually Collect
While we don't store your business data, we do collect limited information necessary to operate the service:
1. Account Information:
- Email address (for authentication and communication)
- Full name (for account identification)
- Password (encrypted using industry-standard bcrypt hashing)
- Account creation date and last login time
2. Authentication Tokens:
- OAuth tokens for connected services (Google, WordPress, Shopify)
- API keys for service integrations (stored encrypted)
- Refresh tokens to maintain connections
- These tokens only grant us permission to fetch data, not to modify it
3. Subscription and Billing Information:
- Billing name and address
- Payment method details (processed by our payment provider, we only store last 4 digits)
- Subscription status and history
- Tax identification numbers where required
4. Usage Metadata:
- Features accessed and frequency of use
- Integration connection/disconnection events
- Error logs for troubleshooting (without sensitive data)
- Performance metrics of the QueryCatch application
5. Support and Communication:
- Support ticket content and history
- Email communications with our team
- Feedback and feature requests
Data We Explicitly Do NOT Store
To be absolutely clear, QueryCatch does NOT store the following types of data on our servers:
- SEO Performance Data: Search impressions, clicks, CTR, rankings from Google Search Console
- Analytics Data: Traffic, conversions, user behavior from Google Analytics
- Content Data: Your website content, meta titles, descriptions, or images
- E-commerce Data: Product information, sales data, customer information from Shopify
- WordPress Data: Posts, pages, media library content
- Keyword Data: Search queries, keyword rankings, or competition data
All this data is fetched on-demand from your connected platforms and displayed in real-time without being stored in our databases. We act purely as a viewing interface for data that remains in your control.
How We Use Collected Information
The limited information we collect is used solely for:
1. Service Operation:
- Authenticating your access to QueryCatch
- Maintaining secure connections to your integrated platforms
- Processing subscription payments
- Providing customer support
2. Service Improvement:
- Understanding feature usage to improve our interface
- Identifying and fixing technical issues
- Developing new features based on usage patterns
3. Communication:
- Sending important service updates
- Responding to support requests
- Notifying about billing or account changes
- Marketing communications (only with your consent)
We will NEVER:
- Sell your information to third parties
- Use your business data for competitive analysis
- Share your performance metrics with other users
- Create aggregated datasets from your business information
Data Security
We implement industry-standard security measures to protect the limited data we do collect:
Technical Security Measures:
- All data transmission is encrypted using TLS 1.3 or higher
- API tokens and sensitive data are encrypted at rest using AES-256
- Regular security audits and vulnerability assessments
- Web Application Firewall (WAF) protection
- DDoS protection through cloud infrastructure
Access Controls:
- Multi-factor authentication available for all accounts
- Role-based access control for team members
- Regular review of access permissions
- Automatic session timeout after inactivity
Infrastructure Security:
- Hosted on SOC 2 compliant infrastructure
- Regular automated backups of account data (not business data)
- Disaster recovery procedures in place
- Incident response plan for security events
Data Breach Response:
In the unlikely event of a data breach affecting account information, we will:
- Notify affected users within 72 hours
- Provide details about what information was compromised
- Take immediate steps to secure the breach
- Cooperate with relevant authorities as required
Third-Party Services and Integrations
QueryCatch integrates with several third-party services. Here's how data flows through these integrations:
Platform Integrations:
- Google Search Console: We fetch search performance data using read-only API access
- Google Analytics: We retrieve analytics data using read-only API access
- WordPress: We access post/page metadata through REST API with your credentials
- Shopify: We fetch product and store data using Shopify's API with your permission
- Kinsta: We may access hosting metrics if you provide API access
Important:
These integrations operate on a fetch-and-display basis. We request data from these platforms when you access QueryCatch but do not store it.
Service Providers We Use:
- Supabase: For authentication and account data storage (NOT business data)
- Payment Processor: For handling subscription payments (PCI compliant)
- Email Service: For transactional emails and support communications
- Analytics: We may use privacy-focused analytics to understand platform usage
Each third-party service has its own privacy policy. We only work with providers who maintain high security and privacy standards.
Data Retention
We retain different types of data for different periods:
Account Data:
- Active accounts: Retained while your account is active
- Cancelled accounts: Basic account data retained for 30 days, then deleted
- Billing records: Retained for 7 years as required by tax law
Authentication Tokens:
- Active tokens: Retained while integrations are connected
- Revoked tokens: Deleted immediately upon disconnection
- Expired tokens: Automatically purged from our systems
Support Communications:
- Support tickets: Retained for 2 years for quality assurance
- Email communications: Retained for 1 year
Business Data Reminder:
- Your SEO, analytics, and business data is NEVER stored, so there's no retention period
- Each time you log in, data is fetched fresh from your connected platforms
Data Deletion:
You can request deletion of your account and associated data at any time. Upon account deletion:
- Account information is removed within 30 days
- Authentication tokens are revoked immediately
- Billing records are retained only as legally required
- You'll need to create a new account to use the service again
Your Privacy Rights
Depending on your location, you have various rights regarding your personal information:
Universal Rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request corrections to inaccurate personal information
- Deletion: Request deletion of your account and associated data
- Portability: Receive your account data in a machine-readable format
- Objection: Object to certain processing of your information
GDPR Rights (European Users):
- Right to restrict processing of your data
- Right to withdraw consent at any time
- Right to lodge a complaint with supervisory authorities
- Right to know the source of your personal data
CCPA Rights (California Users):
- Right to know what personal information is collected
- Right to know if personal information is sold (we don't sell data)
- Right to opt-out of sale of personal information
- Right to non-discrimination for exercising privacy rights
Australian Privacy Rights:
- Rights under the Australian Privacy Principles (APPs)
- Right to complain to the Office of the Australian Information Commissioner
- Right to access and correct personal information
To exercise any of these rights, contact us at privacy@querycatch.com. We'll respond within 30 days.
International Data Transfers
QueryCatch is operated from Australia but serves users globally. Here's how we handle international data:
Data Location:
- Account data is stored in secure data centers in Australia
- We may use content delivery networks (CDNs) for faster global access
- Support may be provided from various locations by our team
Transfer Safeguards:
- We use Standard Contractual Clauses for transfers outside Australia
- All data transfers are encrypted in transit
- We only work with service providers who ensure adequate data protection
Your Consent:
By using QueryCatch from outside Australia, you consent to the transfer of your account information to Australia for processing. Remember, your business data is never transferred to us - it remains with your original platforms.
Children's Privacy
QueryCatch is not intended for use by children under 18 years of age.
- We do not knowingly collect information from children under 18
- If we discover we've inadvertently collected data from a child, we'll delete it immediately
- Parents/guardians who believe we may have collected information from their child should contact us
Business services like QueryCatch are designed for adult business owners and professionals. Users must be 18 or older to create an account.
Marketing and Communications
We believe in respectful, relevant communication:
Types of Communications:
- Service updates and important announcements (essential)
- Billing and account notifications (essential)
- Product updates and new features (optional)
- Marketing and promotional emails (optional, opt-in required)
- Educational content and SEO tips (optional)
Managing Preferences:
- Unsubscribe links in all marketing emails
- Communication preferences in account settings
- Email privacy@querycatch.com to update preferences
- Essential service emails cannot be opted out of while maintaining an account
We will never:
- Sell your email address to third parties
- Send spam or unrelated promotional content
- Share your contact information with partners without consent
Legal Compliance and Disclosure
While we prioritize your privacy, we may need to disclose information in certain circumstances:
Legal Obligations:
- To comply with valid legal processes (subpoenas, court orders)
- To protect the rights and safety of QueryCatch and our users
- To investigate potential violations of our Terms of Service
- To prevent fraud or security issues
- As required by applicable laws and regulations
Business Transfers:
- If QueryCatch is acquired or merged, your information may be transferred
- We'll notify you before any transfer that changes this privacy policy
- You'll have the option to delete your account before any transfer
Transparency:
- We'll notify you of legal requests unless prohibited by law
- We publish transparency reports about data requests when possible
- We challenge overly broad or invalid legal requests
Changes to This Privacy Policy
We may update this Privacy Policy as our service evolves:
- Material changes will be notified via email and in-app notifications
- Minor changes may be made without notification but will be noted in the changelog
- The 'Last Updated' date at the top always reflects the most recent version
- Your continued use after changes constitutes acceptance
- You can always access previous versions by contacting us
We encourage you to review this policy periodically. If you disagree with any changes, you may close your account.
Contact Us
For privacy-related questions or to exercise your rights:
Privacy Team:
- Email: privacy@querycatch.com
- Response time: Within 5 business days
Data Protection Officer:
- Email: dpo@querycatch.com
- For formal privacy rights requests and compliance matters
General Support:
- Email: support@querycatch.com
- Website: https://querycatch.com/contact
QueryCatch Pty Ltd
Australia
Regulatory Authorities:
- Australia: Office of the Australian Information Commissioner (OAIC)
- EU: Your local Data Protection Authority
- California: California Privacy Protection Agency
Privacy Summary - The Simple Version
Here's our privacy approach in plain language:
- We DON'T store your business data - we just fetch and display it
- We DO store your account info (email, name) and login tokens
- Your SEO metrics stay in Google, your content stays in WordPress/Shopify
- We use bank-level encryption for the data we do store
- You can delete your account anytime and we'll remove your data
- We never sell your information or use it for advertising
- We're subject to Australian privacy laws and respect international standards
Think of QueryCatch like a secure window to view your existing data - we don't make copies of what you're looking at.
Privacy Questions or Requests?
We're here to help with any privacy concerns or to process your data rights requests.
Privacy Team: privacy@querycatch.com
Data Protection Officer: dpo@querycatch.com
Response Time: Within 5 business days for general inquiries, 30 days for formal requests