Privacy First

Privacy Policy

We don't store your business data. QueryCatch fetches and displays your SEO metrics without creating copies.

Last Updated: January 21, 2025
Version: 1.0

Our Privacy Commitment

No Data Storage

We don't store your SEO metrics, analytics, or business data on our servers

View-Only Access

We only fetch and display data from your connected platforms

Bank-Level Security

Account data encrypted with AES-256 and TLS 1.3

Global Compliance

GDPR, CCPA, and Australian Privacy Principles compliant

Key Privacy Notice

QueryCatch operates on a unique no-storage model. We fetch your data from Google, WordPress, Shopify, and other platforms when you need it, display it for your analysis, and don't keep copies. Your business data remains in your control on the platforms you trust.

We only store: Account credentials • OAuth tokens • Billing information

1

Introduction

QueryCatch ("we", "our", or "us") is committed to protecting your privacy and ensuring transparency about how we handle data. This Privacy Policy explains our unique approach to data handling - we do not store your business data.

IMPORTANT:

QueryCatch operates as a data processor and display interface. We fetch and display your data from connected platforms (Google Search Console, Google Analytics, WordPress, Shopify, Kinsta) but do not store, own, or retain your business metrics, SEO data, or analytics information on our servers.

This Privacy Policy applies to all users of the QueryCatch platform and describes what limited information we do collect, how we protect it, and your rights regarding your data.

By using QueryCatch, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.

2

Our No-Storage Data Philosophy

QueryCatch is designed with privacy-by-design principles. We believe your business data should remain yours, which is why we've built our platform to operate without storing your sensitive business information.

How QueryCatch Works:

  • We establish secure API connections to your existing platforms (Google, WordPress, Shopify, etc.)
  • When you access QueryCatch, we fetch your data in real-time from these platforms
  • We process and display this data in our interface for your analysis
  • Once you close your session or navigate away, the data is not retained on our servers
  • We do not create databases of your SEO metrics, search performance, or business analytics

This approach ensures that your sensitive business data remains under your control within the platforms you already trust, while we simply provide a unified interface to view and analyze it.

3

Information We Actually Collect

While we don't store your business data, we do collect limited information necessary to operate the service:

1. Account Information:

  • Email address (for authentication and communication)
  • Full name (for account identification)
  • Password (encrypted using industry-standard bcrypt hashing)
  • Account creation date and last login time

2. Authentication Tokens:

  • OAuth tokens for connected services (Google, WordPress, Shopify)
  • API keys for service integrations (stored encrypted)
  • Refresh tokens to maintain connections
  • These tokens only grant us permission to fetch data, not to modify it

3. Subscription and Billing Information:

  • Billing name and address
  • Payment method details (processed by our payment provider, we only store last 4 digits)
  • Subscription status and history
  • Tax identification numbers where required

4. Usage Metadata:

  • Features accessed and frequency of use
  • Integration connection/disconnection events
  • Error logs for troubleshooting (without sensitive data)
  • Performance metrics of the QueryCatch application

5. Support and Communication:

  • Support ticket content and history
  • Email communications with our team
  • Feedback and feature requests
4

Data We Explicitly Do NOT Store

To be absolutely clear, QueryCatch does NOT store the following types of data on our servers:

  • SEO Performance Data: Search impressions, clicks, CTR, rankings from Google Search Console
  • Analytics Data: Traffic, conversions, user behavior from Google Analytics
  • Content Data: Your website content, meta titles, descriptions, or images
  • E-commerce Data: Product information, sales data, customer information from Shopify
  • WordPress Data: Posts, pages, media library content
  • Keyword Data: Search queries, keyword rankings, or competition data

All this data is fetched on-demand from your connected platforms and displayed in real-time without being stored in our databases. We act purely as a viewing interface for data that remains in your control.

5

How We Use Collected Information

The limited information we collect is used solely for:

1. Service Operation:

  • Authenticating your access to QueryCatch
  • Maintaining secure connections to your integrated platforms
  • Processing subscription payments
  • Providing customer support

2. Service Improvement:

  • Understanding feature usage to improve our interface
  • Identifying and fixing technical issues
  • Developing new features based on usage patterns

3. Communication:

  • Sending important service updates
  • Responding to support requests
  • Notifying about billing or account changes
  • Marketing communications (only with your consent)

We will NEVER:

  • Sell your information to third parties
  • Use your business data for competitive analysis
  • Share your performance metrics with other users
  • Create aggregated datasets from your business information
6

Data Security

We implement industry-standard security measures to protect the limited data we do collect:

Technical Security Measures:

  • All data transmission is encrypted using TLS 1.3 or higher
  • API tokens and sensitive data are encrypted at rest using AES-256
  • Regular security audits and vulnerability assessments
  • Web Application Firewall (WAF) protection
  • DDoS protection through cloud infrastructure

Access Controls:

  • Multi-factor authentication available for all accounts
  • Role-based access control for team members
  • Regular review of access permissions
  • Automatic session timeout after inactivity

Infrastructure Security:

  • Hosted on SOC 2 compliant infrastructure
  • Regular automated backups of account data (not business data)
  • Disaster recovery procedures in place
  • Incident response plan for security events

Data Breach Response:

In the unlikely event of a data breach affecting account information, we will:

  • Notify affected users within 72 hours
  • Provide details about what information was compromised
  • Take immediate steps to secure the breach
  • Cooperate with relevant authorities as required
7

Third-Party Services and Integrations

QueryCatch integrates with several third-party services. Here's how data flows through these integrations:

Platform Integrations:

  • Google Search Console: We fetch search performance data using read-only API access
  • Google Analytics: We retrieve analytics data using read-only API access
  • WordPress: We access post/page metadata through REST API with your credentials
  • Shopify: We fetch product and store data using Shopify's API with your permission
  • Kinsta: We may access hosting metrics if you provide API access

Important:

These integrations operate on a fetch-and-display basis. We request data from these platforms when you access QueryCatch but do not store it.

Service Providers We Use:

  • Supabase: For authentication and account data storage (NOT business data)
  • Payment Processor: For handling subscription payments (PCI compliant)
  • Email Service: For transactional emails and support communications
  • Analytics: We may use privacy-focused analytics to understand platform usage

Each third-party service has its own privacy policy. We only work with providers who maintain high security and privacy standards.

8

Cookies and Tracking Technologies

QueryCatch uses minimal cookies and tracking technologies:

Essential Cookies:

  • Authentication cookies to keep you logged in
  • Session cookies to maintain your preferences during use
  • Security cookies to prevent CSRF attacks

Analytics Cookies (with consent):

  • First-party analytics to understand feature usage
  • Error tracking to improve platform stability
  • Performance monitoring to ensure fast load times

We Do NOT Use:

  • Third-party advertising cookies
  • Cross-site tracking cookies
  • Behavioral targeting cookies
  • Social media tracking pixels

You can control cookies through your browser settings. Disabling essential cookies may impact platform functionality.

9

Data Retention

We retain different types of data for different periods:

Account Data:

  • Active accounts: Retained while your account is active
  • Cancelled accounts: Basic account data retained for 30 days, then deleted
  • Billing records: Retained for 7 years as required by tax law

Authentication Tokens:

  • Active tokens: Retained while integrations are connected
  • Revoked tokens: Deleted immediately upon disconnection
  • Expired tokens: Automatically purged from our systems

Support Communications:

  • Support tickets: Retained for 2 years for quality assurance
  • Email communications: Retained for 1 year

Business Data Reminder:

  • Your SEO, analytics, and business data is NEVER stored, so there's no retention period
  • Each time you log in, data is fetched fresh from your connected platforms

Data Deletion:

You can request deletion of your account and associated data at any time. Upon account deletion:

  • Account information is removed within 30 days
  • Authentication tokens are revoked immediately
  • Billing records are retained only as legally required
  • You'll need to create a new account to use the service again
10

Your Privacy Rights

Depending on your location, you have various rights regarding your personal information:

Universal Rights:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request corrections to inaccurate personal information
  • Deletion: Request deletion of your account and associated data
  • Portability: Receive your account data in a machine-readable format
  • Objection: Object to certain processing of your information

GDPR Rights (European Users):

  • Right to restrict processing of your data
  • Right to withdraw consent at any time
  • Right to lodge a complaint with supervisory authorities
  • Right to know the source of your personal data

CCPA Rights (California Users):

  • Right to know what personal information is collected
  • Right to know if personal information is sold (we don't sell data)
  • Right to opt-out of sale of personal information
  • Right to non-discrimination for exercising privacy rights

Australian Privacy Rights:

  • Rights under the Australian Privacy Principles (APPs)
  • Right to complain to the Office of the Australian Information Commissioner
  • Right to access and correct personal information

To exercise any of these rights, contact us at privacy@querycatch.com. We'll respond within 30 days.

11

International Data Transfers

QueryCatch is operated from Australia but serves users globally. Here's how we handle international data:

Data Location:

  • Account data is stored in secure data centers in Australia
  • We may use content delivery networks (CDNs) for faster global access
  • Support may be provided from various locations by our team

Transfer Safeguards:

  • We use Standard Contractual Clauses for transfers outside Australia
  • All data transfers are encrypted in transit
  • We only work with service providers who ensure adequate data protection

Your Consent:

By using QueryCatch from outside Australia, you consent to the transfer of your account information to Australia for processing. Remember, your business data is never transferred to us - it remains with your original platforms.

12

Children's Privacy

QueryCatch is not intended for use by children under 18 years of age.

  • We do not knowingly collect information from children under 18
  • If we discover we've inadvertently collected data from a child, we'll delete it immediately
  • Parents/guardians who believe we may have collected information from their child should contact us

Business services like QueryCatch are designed for adult business owners and professionals. Users must be 18 or older to create an account.

13

Marketing and Communications

We believe in respectful, relevant communication:

Types of Communications:

  • Service updates and important announcements (essential)
  • Billing and account notifications (essential)
  • Product updates and new features (optional)
  • Marketing and promotional emails (optional, opt-in required)
  • Educational content and SEO tips (optional)

Managing Preferences:

  • Unsubscribe links in all marketing emails
  • Communication preferences in account settings
  • Email privacy@querycatch.com to update preferences
  • Essential service emails cannot be opted out of while maintaining an account

We will never:

  • Sell your email address to third parties
  • Send spam or unrelated promotional content
  • Share your contact information with partners without consent
15

Changes to This Privacy Policy

We may update this Privacy Policy as our service evolves:

  • Material changes will be notified via email and in-app notifications
  • Minor changes may be made without notification but will be noted in the changelog
  • The 'Last Updated' date at the top always reflects the most recent version
  • Your continued use after changes constitutes acceptance
  • You can always access previous versions by contacting us

We encourage you to review this policy periodically. If you disagree with any changes, you may close your account.

16

Contact Us

For privacy-related questions or to exercise your rights:

Privacy Team:

  • Email: privacy@querycatch.com
  • Response time: Within 5 business days

Data Protection Officer:

  • Email: dpo@querycatch.com
  • For formal privacy rights requests and compliance matters

General Support:

  • Email: support@querycatch.com
  • Website: https://querycatch.com/contact

QueryCatch Pty Ltd

Australia

Regulatory Authorities:

  • Australia: Office of the Australian Information Commissioner (OAIC)
  • EU: Your local Data Protection Authority
  • California: California Privacy Protection Agency
17

Privacy Summary - The Simple Version

Here's our privacy approach in plain language:

  • We DON'T store your business data - we just fetch and display it
  • We DO store your account info (email, name) and login tokens
  • Your SEO metrics stay in Google, your content stays in WordPress/Shopify
  • We use bank-level encryption for the data we do store
  • You can delete your account anytime and we'll remove your data
  • We never sell your information or use it for advertising
  • We're subject to Australian privacy laws and respect international standards

Think of QueryCatch like a secure window to view your existing data - we don't make copies of what you're looking at.

Privacy Questions or Requests?

We're here to help with any privacy concerns or to process your data rights requests.

Privacy Team: privacy@querycatch.com

Data Protection Officer: dpo@querycatch.com

Response Time: Within 5 business days for general inquiries, 30 days for formal requests

Privacy Standards We Follow

GDPR Compliant
CCPA Compliant
Australian Privacy Principles
SOC 2 Infrastructure
Privacy Policy - QueryCatch