Short version: We collect your email, the URL you want audited, and your payment. We use that to deliver your audit and send you the report. We do not sell your data, ever. You can delete your data at any time by emailing hello@bumpupseo.com.
This policy applies to BumpUp SEO, an independent SEO audit service based in the United Kingdom. We are the data controller for the personal data described in this policy. We can be reached at hello@bumpupseo.com.
We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR. All privacy enquiries are handled directly by the business owner at the email address above.
We deliberately collect as little as possible. The only personal data we process is:
| Category | What it is | How we get it |
|---|---|---|
| Contact data | Your email address. | You enter it at checkout. |
| Audit input | The website URL you submit for auditing, the target market and goal you select. | You enter it at checkout. |
| Payment data | Card details and billing country. We never see or store your full card number; this is handled by Stripe. | You enter it on the Stripe checkout page. |
| Transaction record | Stripe customer ID, payment intent ID, amount, currency, timestamp, and the last four digits of your card. | Returned to us by Stripe after payment. |
| Audit output | The PDF report we generate from publicly available pages on the URL you submitted. | Generated by our system. |
| Technical data | IP address, browser user agent, request timestamps. Used for security and rate limiting only. | Collected automatically by our cloud infrastructure when you visit the site. |
We do not collect: marketing-tracking identifiers, advertising IDs, social profiles, demographics, location beyond country-level, or any special category data (health, religion, ethnicity, etc.).
Under Article 6 of the UK GDPR, every purpose below is tied to a specific lawful basis:
| Purpose | Data used | Lawful basis (Art. 6) |
|---|---|---|
| Take payment for the audit you ordered. | Payment data, email. | Contract (Art. 6(1)(b)), necessary to perform our contract with you. |
| Generate and deliver your audit report. | Audit input, email. | Contract (Art. 6(1)(b)). |
| Send transactional emails (receipt, download link, delivery confirmation). | Email. | Contract (Art. 6(1)(b)). |
| Keep tax and accounting records. | Transaction record, email. | Legal obligation (Art. 6(1)(c)), HMRC requires records to be kept for 6 years. |
| Protect the site from abuse, fraud, and DDoS. | Technical data. | Legitimate interests (Art. 6(1)(f)), securing our service. You can object; see Section 8. |
| Respond to support emails you send us. | Email and message content. | Legitimate interests (Art. 6(1)(f)), answering customer queries. |
We do not send marketing emails. We do not profile you. We do not make automated decisions that produce legal or similarly significant effects about you.
We do not sell, rent, or trade your personal data. We use a small number of carefully chosen sub-processors to run the service. Each one is bound by contract to process your data only on our instructions and to protect it appropriately. The categories of recipient are:
| Category of recipient | What they do for us | Where they process |
|---|---|---|
| Cloud infrastructure provider | Hosts the website, the orders database, and the PDF storage. Provides security and abuse protection. | Global edge network with primary data centres in the EU and US. |
| Payment processor (Stripe Payments Europe Ltd.) | Processes your card payment. Stripe is the controller of your full card data and is named here because they take the card directly on their hosted checkout page. | Ireland (EU) with global card-network routing. |
| Audit generation runtime | Executes the audit generation process. Receives only the crawl data of your website. | United States. |
| Large language model API | Generates the analytical text of your audit report. Receives only the crawl data of your website, not your email. The provider's terms confirm that paid API inputs and outputs are not used to train their models. | United States. |
| Transactional email provider | Delivers your receipt and your audit download link. | United States. |
The specific names of our infrastructure, runtime, model, and email vendors are available on written request to hello@bumpupseo.com, and they will always be disclosed when you exercise a data subject access request.
We may also disclose your data if we are required to by law, court order, or a binding regulator request (for example, HMRC for tax records).
Some of our sub-processors are based in or transfer data to the United States, which the UK government and European Commission do not treat as offering equivalent data protection by default.
Where we transfer your personal data outside the UK or EEA, we rely on:
You can request a copy of the safeguard used for any specific transfer by emailing hello@bumpupseo.com.
| Data | Retention period | Why |
|---|---|---|
| Email and audit input | 24 months from purchase | So we can answer support questions and reissue your download link if needed. |
| Generated audit PDF | 24 months from purchase | So you can re-download. Deleted on request earlier. |
| Transaction record | 6 years from end of tax year | Required by HMRC under Section 12B of the Taxes Management Act 1970. |
| Technical logs (IP, user agent) | 30 days | Security and abuse investigation only. |
| Support email correspondence | 24 months from last reply | So we have context for follow-up issues. |
You can ask us to delete your data sooner. We will, except where we are legally required to keep the transaction record for tax purposes; in that case the record is locked and used only for tax and accounting.
No system is perfectly secure. If we suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify you without undue delay, as required by Articles 33 and 34 of the UK GDPR.
Under the UK GDPR and EU GDPR you have the right to:
To exercise any of these rights, email hello@bumpupseo.com. We will respond within one calendar month, free of charge. We may need to verify your identity first; we will only ask for what is strictly necessary to do so.
BumpUp SEO is a small UK business and does not currently meet the thresholds for full coverage under the California Consumer Privacy Act (CCPA/CPRA) or the comprehensive privacy statutes of other US states. We nonetheless give US customers the following rights as a matter of policy:
To exercise any of these rights, email hello@bumpupseo.com with the subject line "US Privacy Rights Request" and tell us which state you reside in.
We use only the cookies and storage that are strictly necessary to operate the site and process your order. This includes:
Under the Privacy and Electronic Communications Regulations (PECR), strictly necessary cookies do not require consent. We do not use analytics cookies, advertising cookies, or any tracking pixels.
The service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, contact us and we will delete it.
We may update this policy from time to time. The "Last updated" date at the top of the page always reflects the current version. Where the change is material (for example, a new sub-processor or a new purpose of processing), we will email customers whose data is still active in our systems before the change takes effect.
If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve it. You also have the right to complain to a supervisory authority:
For any privacy question, request, or concern, email hello@bumpupseo.com. Please put "Privacy" in the subject line so we can route it correctly. We aim to acknowledge all privacy requests within 5 working days and to resolve them within one calendar month.