Privacy Policy
What QueryCatch collects and stores, how long we keep it, who we share it with, and your rights.
Our Privacy Commitment
Only What Features Need
Reports are fetched live; we keep only what the features you use need, for as long as stated below
You Stay in Control
Changes to your site only happen when you or an admin ask for them, and AI assistant changes can be undone
Protected in Transit and at Rest
Encrypted connections, encrypted database storage, and each organisation's data kept to its own members
Your Rights
Ask to see, correct or delete your personal information at any time
Quick Navigation
Key Privacy Notice
Most of your reports are fetched live from Google, WordPress, Shopify and your other platforms and are not stored. Features that need to keep data, such as saved audits, keyword lists, generated content and the history of AI assistant changes, are listed below with how long we keep it.
We never sell your data or share it with other customers.
Introduction
QueryCatch ("we", "our", or "us") is committed to protecting your privacy and being transparent about how we handle data. This Privacy Policy explains what we collect, what we store and for how long, who we share it with, and your rights.
Most of what you see in QueryCatch, such as your Google Search Console and Google Analytics dashboards, is fetched live from the platforms you connect. Some features do need to keep data to work, such as saved site audits, keyword lists, client reports and a monthly summary of your Google figures, content you generate and the history of changes an AI assistant made. Those are listed below, with how long we keep them.
This Privacy Policy applies to all users of the QueryCatch platform. By using QueryCatch, you acknowledge that you have read and understood it. If you do not agree with our practices, please do not use our services.
How QueryCatch Handles Your Data
We keep as little of your business data as the features you use need.
Fetched live and not stored:
- Google Analytics reports on the dashboard
- Google Search Console reports on the dashboard, apart from a short-lived cache (see below)
- Google Ads, Google Tag Manager and Google Merchant Center data, apart from changes you submit for approval
Stored because a feature needs it (details under 'Information We Collect'):
- Results of site audits and scans you run, so you can see them again without re-running them
- Page analyses from the QueryCatch analyser script, if you install it on your site
- Keyword lists, saved reports, saved competitors and their analyses
- Client reports you create in Reports, and a monthly summary of each connected profile's Google Analytics and Search Console figures, so reports can reach back further than the 16 months Google keeps
- Content you create or generate in QueryCatch (blog topics and drafts, brand guidelines) and changes waiting for approval
- A record of every change an AI assistant made to your site, with the previous value, so it can be undone
- If you use the QueryCatch CRM and forms: the visitors, events, form submissions and contacts it collects on your website
Your data is used to provide QueryCatch to you. We do not sell it, and we do not share one customer's data with another.
Information We Collect
1. Account Information:
- Email address (for authentication and communication)
- Full name (for account identification)
- Password: it passes through our server once when you sign up or change it, is handed to our authentication provider, and is stored only as a hash
- Account creation date and last log in time
2. Connections to Your Platforms:
- OAuth tokens for the services you connect (Google and Shopify), and the site, property, account or store you selected
- For WordPress: the username and application password you enter (not your WordPress login password; you can revoke it in WordPress)
- For CRM email sent through your own mail server: its settings and password (stored encrypted)
- Depending on the permissions you grant, these let QueryCatch read data and, for features that change your site (such as updating meta titles, image alt text or product descriptions), write to it
3. Subscription and Billing Information:
- Billing email, subscription status and history, and references to invoices and payments
- Card details, billing address and tax IDs are collected and held by Stripe, not by us. We never store card numbers
4. Website and Business Data Kept by Features:
- Search Console responses, cached for about a day to keep reports fast
- In your browser: recently viewed Search Console and Analytics reports, cached for up to 24 hours
- Site audit and scan results: page URLs, titles, headings, meta titles and descriptions, image alt text, product and collection text, links, structured data and speed scores, plus counts from up to 30 past scans
- Page analyses from the QueryCatch analyser script on your site: page URL (including any query string), title, meta description, headings, keywords, image and link samples and technical checks; for error pages and redirects, the address the visitor came from (referrer)
- Keyword lists built from your product and collection text and your published pages
- Saved SEO audit reports and their history, shared report links, saved competitors and competitor analyses
- Client reports you create in Reports: the figures from Google Analytics and Search Console (totals, channels, top pages and search terms), their notes, and any share links (we store only a fingerprint of each link, not the link itself)
- A monthly summary of each connected profile's Google Analytics and Search Console figures (totals, channels, top 50 pages, top 25 search terms and top 25 pages from Google search), saved once each month's figures are final
- Report settings: the Google Analytics event you choose to count as an enquiry, its label and start date
- Technical SEO snapshots: QueryCatch fetches the pages listed in your website's sitemap (as "QueryCatchBot") and records each page's status, title, meta description, headings, canonical and noindex tags, structured data types, word count, image alt text and links. These page details, and the list of pages to check, are deleted when the snapshot finishes or fails; the finished scorecard is saved with the report
- Blog topics, blog drafts and published post details, brand guidelines, and approval requests (the current and proposed values of what you want to change)
- Scheduled report settings and a record of each send, including recipients' names and emails
- Team invitations (the invitee's email), CRM email settings, templates and notification recipients, and a log of emails sent
- Shopify store details (domain and name) and the store pages we notified search engines about (IndexNow)
- AI assistant connections, including the name and return address each assistant registered with, and the record of changes AI assistants made (see 'AI Assistants')
5. Data About Your Website's Visitors (only if you use the QueryCatch CRM, tracking or forms):
- See 'Data About Your Website's Visitors' below
6. Partner Programme (only if you join it):
- See 'Partner Programme' below
7. Usage Metadata:
- Features accessed and frequency of use
- Integration connection/disconnection events
- Server logs for troubleshooting
- Performance metrics of the QueryCatch application
8. Support and Communication:
- Support ticket content, attachments and history
- Email communications with our team
- Feedback and feature requests
What We Don't Collect or Keep
To be clear about the limits:
- Google Analytics data is fetched when you view it. The only copies we keep are the monthly summaries and saved client reports used by Reports (see 'Information We Collect')
- We don't store your Google or Shopify passwords; those connections use tokens you can revoke at Google or Shopify
- We don't request or store your Shopify customers' or orders' data
- We don't store full payment card numbers
- We don't sell your data, use it for advertising, or share one customer's data with another
- We don't use your business data to train AI models
How We Use Collected Information
We use the information we collect solely to:
1. Service Operation:
- Authenticating your access to QueryCatch
- Maintaining secure connections to your integrated platforms
- Providing the features you use, including the saved results, generated content and change history described above
- Processing subscription payments
- Providing customer support
2. Service Improvement:
- Understanding feature usage to improve our interface
- Identifying and fixing technical issues
- Developing new features based on usage patterns
3. Communication:
- Sending important service updates
- Responding to support requests
- Notifying about billing or account changes
- Marketing communications (only with your consent)
We will NEVER:
- Sell your information to third parties
- Use your business data for competitive analysis
- Share your performance metrics with other users
- Create aggregated datasets from your business information
Data Security
We protect the data we hold with:
- Encryption in transit (HTTPS) for all connections to QueryCatch
- Google connection tokens and CRM mail server passwords encrypted with AES-256 by our application, and data held on our database provider's encrypted storage
- Access controls: profile data is visible only to that profile's members, and changes need the admin role
- Database rules that stop one customer's session reading another's data, and server-only access to sensitive tables
- Automated backups by our database provider
If a data breach affects your personal information, we will notify you and, where required, the relevant authorities, as the law requires.
Third-Party Services and Integrations
QueryCatch integrates with third-party platforms and uses service providers to run the service.
Platforms You Connect:
- Google Search Console, Google Analytics, Google Ads, Google Tag Manager and Google Merchant Center
- WordPress and Shopify
These are accessed with the permissions you grant, to show your data and, for features that change your site, to make the changes you ask for.
Service Providers That Process Your Data on Our Behalf:
- Supabase: database and authentication (data stored in Sydney, Australia)
- Railway: hosting for the application and our analysis service
- Google Gemini: AI features. When you use an AI feature (meta titles and descriptions, image alt text, product and collection content, Merchant Center product fields, blog topics, strategy and drafts, heading and keyword suggestions, an AI summary of an audit, or the notes in a client report), the text, product details and images, brand guidelines, keywords (which may come from your Search Console data), audit data, or a report's figures, page names and search terms it needs are sent to Google's Gemini API to generate the result
- QueryCatch analysis service: our own service that extracts keywords and topics from page content, fetches and analyses competitor pages, groups your search queries, generates blog topics from your search queries and brand guidelines, and produces traffic forecasts from your Analytics sessions
- Google PageSpeed Insights: your page addresses, to measure speed
- IndexNow: your store's page addresses, to notify search engines of changes
- Resend: email delivery: account, invitation, ticket, approval and shared-report emails, scheduled reports, partner emails, and CRM form notifications and automatic replies to your website's visitors
- Your own mail server, if you set one up for CRM email
- Favicon services (such as icon.horse and Google's favicon service): website domains, to show site icons
- Google Sign-In, if you sign in with Google
- The Australian Business Register, to check partners' ABNs
- Stripe: subscription payments
- Shopify: billing for the QueryCatch Shopify app
- PayPal: partner programme payouts
Each provider has its own privacy policy. We only send each one what its job needs.
AI Assistants
You can connect an AI assistant (such as Claude) to QueryCatch. It can only read a profile's data once a profile admin has switched on AI assistant access for that profile.
What happens when you connect one:
- You approve the connection on a QueryCatch consent page. We store a record of the connection (which assistant, when, and which version of the consent page you approved), the name and return address the assistant registered with, and secure hashes of its access tokens, never the tokens themselves
- When your assistant asks for data, QueryCatch sends only what that request needs, for profiles you can access, to the assistant you connected. From then on, that data is handled by your assistant's provider under your agreement with them, not by QueryCatch
- If a profile admin allows it, an assistant can make changes to your connected site or store, such as meta titles or image alt text. We record each change with its previous and new value, who asked for it and through which assistant, so it can be reviewed and undone. These records are kept for 12 months
- Our server logs record which tool was used, by which account and assistant, for which profile, when and with what result, without the content of the request or the response. These logs are kept by our hosting provider
- Starting audits, speed tests or keyword refreshes through an assistant stores their results like the same features in the dashboard, and is counted against daily limits
You can revoke a connection at any time in Profile settings → AI assistants. It stops working immediately; the record of the connection is kept until you delete your account.
Data About Your Website's Visitors
If you install QueryCatch's tracking or forms script on your website, or use the CRM, QueryCatch collects data about your website's visitors on your behalf:
- Visits and page views: an anonymous visitor ID, pages viewed, page titles, referrer, campaign (UTM) parameters, device type, screen size, scroll depth and time on page. We do not record IP addresses, browser, operating system or location
- Form submissions: the fields your visitors submit (which may include their name, email address, phone number and message), with the pages they viewed beforehand. If you turn on automatic replies, we email the visitor through Resend or your own mail server
- Contacts and deals you create or that come from form submissions: name, email, phone, company and any notes or custom fields
The QueryCatch analyser script, if you install it, records each page's content signals and, for error pages and redirects, the visitor's referrer.
You decide whether to collect this data and are responsible for telling your visitors about it and obtaining any consent your local law requires. We process it only to provide these features to you and use it for no other purpose. Contacts and deals can be deleted in the CRM (a deleted contact's form submissions are kept); visits, page views and submissions are kept until your profile is deleted.
Partner Programme
If you join the QueryCatch partner programme, we collect what we need to verify you and pay commissions:
- Your name, email, phone, date of birth, company, ABN and GST status, and address
- Payout details: your PayPal email (and the PayPal connection), or bank account name, BSB and account number
- Payouts, payout documents and an audit log of payout events
We check ABNs with the Australian Business Register and pay through PayPal or bank transfer. Bank details are shown masked in emails to our team. This data is kept while you are a partner and as required for tax records.
Data Retention
We keep different data for different periods:
Account and Profile Data:
- Account data: kept while your account exists. To delete your account, email privacy@querycatch.com and we'll delete it within 30 days
- Profile data, including everything listed under 'Website and Business Data Kept by Features' and our billing records for the profile, is deleted immediately when a profile owner deletes the profile
- Stripe keeps its own payment and invoice records as tax law requires
Connections:
- Our copies of tokens and credentials are deleted when you disconnect. To revoke access at the provider as well, remove QueryCatch in your Google, Shopify or WordPress settings
Website and Business Data:
- Search Console cache, and PageSpeed results for technical snapshots: deleted after about a day
- Analyser page analyses: deleted after 180 days without an update; pages that keep being visited stay current
- Site audit and scan results, keyword lists: replaced each time you run them, with counts from up to 30 past scans; kept until the profile is deleted
- Saved audit reports: kept until you delete them or the profile is deleted
- Shared report links: deleting a link stops access; the shared copy is kept until the profile is deleted
- Client reports and their notes: kept until you delete them or the profile is deleted. Their share links stop working when they expire (after 90 days at most), are switched off, or the report is deleted, or when the subscription ends
- Monthly summaries of Google Analytics and Search Console figures: kept until the profile is deleted
- Technical snapshot page details and the list of pages to check: deleted when the snapshot finishes or fails
- Competitor analyses, blog topics and drafts, brand guidelines, approval requests and CRM data: kept until the profile is deleted (items you can delete in the app are removed when you delete them)
AI Assistants:
- Records of changes AI assistants made: 12 months
- Connection records: kept until you delete your account, including after you revoke a connection
- Daily usage counts: removed after about 35 days
Support:
- Support tickets: kept until you delete them or the profile is deleted
- Emails with our team: kept as long as needed to help you
Your Privacy Rights
Depending on your location, you have various rights regarding your personal information:
Universal Rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request corrections to inaccurate personal information
- Deletion: Request deletion of your account and associated data
- Portability: Receive your account data in a machine-readable format
- Objection: Object to certain processing of your information
GDPR Rights (European Users):
- Right to restrict processing of your data
- Right to withdraw consent at any time
- Right to lodge a complaint with supervisory authorities
- Right to know the source of your personal data
CCPA Rights (California Users):
- Right to know what personal information is collected
- Right to know if personal information is sold (we don't sell data)
- Right to opt-out of sale of personal information
- Right to non-discrimination for exercising privacy rights
Australian Privacy Rights:
- Rights under the Australian Privacy Principles (APPs)
- Right to complain to the Office of the Australian Information Commissioner
- Right to access and correct personal information
To exercise any of these rights, contact us at privacy@querycatch.com. We'll respond within 30 days.
International Data Transfers
QueryCatch is operated from Australia and serves users globally.
- Our database is hosted in Sydney, Australia
- Some service providers listed above (such as Google Gemini, our hosting provider and our email provider) may process data in other countries
- All transfers are encrypted in transit
By using QueryCatch from outside Australia, you consent to your information being transferred to and processed in Australia and the countries of our service providers.
Children's Privacy
QueryCatch is not intended for use by children under 18 years of age.
- We do not knowingly collect information from children under 18
- If we discover we've inadvertently collected data from a child, we'll delete it immediately
- Parents/guardians who believe we may have collected information from their child should contact us
Business services like QueryCatch are designed for adult business owners and professionals. Users must be 18 or older to create an account.
Marketing and Communications
We believe in respectful, relevant communication:
Types of Communications:
- Service updates and important announcements (essential)
- Billing and account notifications (essential)
- Product updates and new features (optional)
- Marketing and promotional emails (optional, opt-in required)
- Educational content and SEO tips (optional)
Managing Preferences:
- Unsubscribe links in all marketing emails
- Email privacy@querycatch.com to update preferences
- Essential service emails cannot be opted out of while maintaining an account
We will never:
- Sell your email address to third parties
- Send spam or unrelated promotional content
- Share your contact information with partners without consent
Legal Compliance and Disclosure
While we prioritize your privacy, we may need to disclose information in certain circumstances:
Legal Obligations:
- To comply with valid legal processes (subpoenas, court orders)
- To protect the rights and safety of QueryCatch and our users
- To investigate potential violations of our Terms of Service
- To prevent fraud or security issues
- As required by applicable laws and regulations
Business Transfers:
- If QueryCatch is acquired or merged, your information may be transferred
- We'll notify you before any transfer that changes this privacy policy
- You'll have the option to delete your account before any transfer
Transparency:
- We'll notify you of legal requests unless prohibited by law
- We challenge overly broad or invalid legal requests
Changes to This Privacy Policy
We may update this Privacy Policy as our service evolves:
- Material changes will be notified via email and in-app notifications
- The 'Last Updated' date at the top always reflects the most recent version
- Your continued use after changes constitutes acceptance
- You can always access previous versions by contacting us
We encourage you to review this policy periodically. If you disagree with any changes, you may close your account.
Contact Us
For privacy-related questions or to exercise your rights:
Privacy Team:
- Email: privacy@querycatch.com
- Response time: Within 5 business days
Data Protection Officer:
- Email: dpo@querycatch.com
- For formal privacy rights requests and compliance matters
General Support:
- Email: support@querycatch.com
- Website: https://querycatch.com/contact
QueryCatch Pty Ltd
Australia
Regulatory Authorities:
- Australia: Office of the Australian Information Commissioner (OAIC)
- EU: Your local Data Protection Authority
- California: California Privacy Protection Agency
Privacy Summary - The Simple Version
Here's our privacy approach in plain language:
- Dashboards are fetched live from Google and your other platforms. We keep copies only where a feature needs them, such as client reports you save and a monthly summary of your Google figures for those reports
- Some features keep data so they work: saved audits, keyword lists, content you generate, and the history of AI assistant changes. We tell you above what, and for how long
- If you use our CRM or tracking scripts, we collect your website visitors' data for you, and you decide whether to use them
- AI features send the text they need to Google's Gemini; AI assistants you connect receive the data you ask them about
- You can delete your data and your account at any time
- We never sell your information or use it for advertising
- Your data is stored in Australia, and we're subject to Australian privacy law
Privacy Questions or Requests?
We're here to help with any privacy concerns or to process your data rights requests.
Privacy Team: privacy@querycatch.com
Data Protection Officer: dpo@querycatch.com
Response Time: Within 5 business days for general inquiries, 30 days for formal requests