Privacy Policy
Last updated: April 18, 2026
Who We Are
GEO Fix is a product of The Boring SEO Company (“we,” “us,” or “our”), operated at geo.theboringseo.co. This policy explains how we collect, use, and protect your information when you use GEO Fix.
Information We Collect
Account information: When you sign up or purchase a plan, we collect your email address. We use magic link authentication, so we never store passwords.
Website data: When you scan a URL, we crawl the publicly accessible pages of that website and analyze their content structure, schema markup, meta tags, and text. We store the audit results so you can access them later.
Payment information: Payments are processed through Stripe. We do not store your credit card number, CVC, or billing address on our servers. Stripe handles all payment data securely under their own privacy policy.
Usage data: We track which features you use (scans, fix generations, content calendar) to enforce plan limits and improve the product. We do not use third-party analytics trackers on the dashboard.
How We Use Your Information
- To provide the GEO Fix service: running scans, generating fixes, delivering content calendars
- To send you scan results and service-related emails (magic links, audit reports)
- To process payments and manage your subscription
- To improve the product based on aggregate usage patterns
Data Storage and Security
Your data is stored on Vercel's infrastructure (Vercel Blob storage) with HTTPS encryption in transit and at rest. Audit data, generated fixes, and account information are stored in cloud object storage. We use signed cookies for session management and HMAC-SHA256 for token verification.
Data Sharing
We do not sell your data. We do not share your personal information with third parties except:
- Stripe: for payment processing
- Resend: for transactional emails (magic links, scan results)
- AI providers (Anthropic, OpenAI): page content from scanned URLs is sent to AI APIs to generate content fixes. This content is publicly accessible web content, not private data.
Your Rights
You can request deletion of your account and all associated data at any time by emailing alex@theboringseo.co. We will process deletion requests within 30 days.
Rights under the GDPR (European residents)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate personal data
- Request deletion of your personal data (“right to be forgotten”)
- Restrict or object to our processing of your personal data
- Data portability: receive your data in a structured, machine-readable format
- Withdraw consent at any time where we rely on consent as the lawful basis
- Lodge a complaint with your local data protection authority
Our lawful bases for processing are performance of a contract (running the service you purchased), legitimate interests (product improvement and security), and consent (transactional emails you signed up to receive). To exercise any of these rights, email alex@theboringseo.co.
Rights under the CCPA/CPRA (California residents)
If you are a California resident, you have the right to know what personal information we collect, disclose, or sell; request deletion of your personal information; correct inaccurate personal information; and opt out of the sale or sharing of your personal information. GEO Fix does not sell or share personal information as those terms are defined under the CPRA, and we do not use cross-context behavioral advertising. You may exercise any of these rights by emailing alex@theboringseo.co. We will not discriminate against you for exercising these rights.
Data retention
We retain account information and audit results while your account is active and for up to 12 months after cancellation to allow you to reactivate. Billing records are retained for up to 7 years to comply with tax and accounting obligations. You can request earlier deletion at any time.
International data transfers
GEO Fix is operated from the United States and stored on Vercel infrastructure. If you access the service from outside the United States, your data is transferred to, stored in, and processed in the United States. Where required, we rely on Standard Contractual Clauses and our subprocessors’ compliance frameworks for cross-border transfers.
Children’s privacy
GEO Fix is not directed to children under 16 and we do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please email us and we will delete it.
Do Not Track
We do not currently respond to “Do Not Track” browser signals because we do not engage in cross-site tracking or behavioral advertising.
Cookies
We use a single session cookie (geofix_session) for authentication. It is HTTP-only, secure, and expires after 30 days. We do not use advertising cookies or third-party tracking cookies.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the service after changes constitutes acceptance.
Contact
For privacy-related questions, contact us at alex@theboringseo.co.