B BumpUpSEO
How it works Sample report Pricing FAQ Get audit · £79
Legal

Privacy Policy

Effective: 27 May 2026  ·  Last updated: 27 May 2026

On this page
  1. Who we are
  2. What we collect
  3. Why we process it
  4. Who we share it with
  5. International transfers
  6. How long we keep it
  7. How we protect it
  8. Your rights (UK and EU)
  9. Your rights (US)
  10. Cookies and tracking
  11. Children
  12. Changes to this policy
  13. Complaints
  14. Contact us

Short version: We collect your email, the URL you want audited, and your payment. We use that to deliver your audit and send you the report. We do not sell your data, ever. You can delete your data at any time by emailing hello@bumpupseo.com.

1. Who we are

This policy applies to BumpUp SEO, an independent SEO audit service based in the United Kingdom. We are the data controller for the personal data described in this policy. We can be reached at hello@bumpupseo.com.

We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR. All privacy enquiries are handled directly by the business owner at the email address above.

2. What personal data we collect

We deliberately collect as little as possible. The only personal data we process is:

CategoryWhat it isHow we get it
Contact data Your email address. You enter it at checkout.
Audit input The website URL you submit for auditing, the target market and goal you select. You enter it at checkout.
Payment data Card details and billing country. We never see or store your full card number; this is handled by Stripe. You enter it on the Stripe checkout page.
Transaction record Stripe customer ID, payment intent ID, amount, currency, timestamp, and the last four digits of your card. Returned to us by Stripe after payment.
Audit output The PDF report we generate from publicly available pages on the URL you submitted. Generated by our system.
Technical data IP address, browser user agent, request timestamps. Used for security and rate limiting only. Collected automatically by our cloud infrastructure when you visit the site.

We do not collect: marketing-tracking identifiers, advertising IDs, social profiles, demographics, location beyond country-level, or any special category data (health, religion, ethnicity, etc.).

3. Why we process it (and our lawful basis)

Under Article 6 of the UK GDPR, every purpose below is tied to a specific lawful basis:

PurposeData usedLawful basis (Art. 6)
Take payment for the audit you ordered. Payment data, email. Contract (Art. 6(1)(b)), necessary to perform our contract with you.
Generate and deliver your audit report. Audit input, email. Contract (Art. 6(1)(b)).
Send transactional emails (receipt, download link, delivery confirmation). Email. Contract (Art. 6(1)(b)).
Keep tax and accounting records. Transaction record, email. Legal obligation (Art. 6(1)(c)), HMRC requires records to be kept for 6 years.
Protect the site from abuse, fraud, and DDoS. Technical data. Legitimate interests (Art. 6(1)(f)), securing our service. You can object; see Section 8.
Respond to support emails you send us. Email and message content. Legitimate interests (Art. 6(1)(f)), answering customer queries.

We do not send marketing emails. We do not profile you. We do not make automated decisions that produce legal or similarly significant effects about you.

4. Who we share your data with

We do not sell, rent, or trade your personal data. We use a small number of carefully chosen sub-processors to run the service. Each one is bound by contract to process your data only on our instructions and to protect it appropriately. The categories of recipient are:

Category of recipientWhat they do for usWhere they process
Cloud infrastructure provider Hosts the website, the orders database, and the PDF storage. Provides security and abuse protection. Global edge network with primary data centres in the EU and US.
Payment processor (Stripe Payments Europe Ltd.) Processes your card payment. Stripe is the controller of your full card data and is named here because they take the card directly on their hosted checkout page. Ireland (EU) with global card-network routing.
Audit generation runtime Executes the audit generation process. Receives only the crawl data of your website. United States.
Large language model API Generates the analytical text of your audit report. Receives only the crawl data of your website, not your email. The provider's terms confirm that paid API inputs and outputs are not used to train their models. United States.
Transactional email provider Delivers your receipt and your audit download link. United States.

The specific names of our infrastructure, runtime, model, and email vendors are available on written request to hello@bumpupseo.com, and they will always be disclosed when you exercise a data subject access request.

We may also disclose your data if we are required to by law, court order, or a binding regulator request (for example, HMRC for tax records).

5. International data transfers

Some of our sub-processors are based in or transfer data to the United States, which the UK government and European Commission do not treat as offering equivalent data protection by default.

Where we transfer your personal data outside the UK or EEA, we rely on:

  • The UK Extension to the EU-US Data Privacy Framework, where the receiving company is certified under it; or
  • The UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with UK Addendum, as appropriate.

You can request a copy of the safeguard used for any specific transfer by emailing hello@bumpupseo.com.

6. How long we keep your data

DataRetention periodWhy
Email and audit input 24 months from purchase So we can answer support questions and reissue your download link if needed.
Generated audit PDF 24 months from purchase So you can re-download. Deleted on request earlier.
Transaction record 6 years from end of tax year Required by HMRC under Section 12B of the Taxes Management Act 1970.
Technical logs (IP, user agent) 30 days Security and abuse investigation only.
Support email correspondence 24 months from last reply So we have context for follow-up issues.

You can ask us to delete your data sooner. We will, except where we are legally required to keep the transaction record for tax purposes; in that case the record is locked and used only for tax and accounting.

7. How we protect your data

  • All site traffic is encrypted in transit with TLS 1.2 or above.
  • Data at rest is encrypted at the storage layer.
  • Administrative access uses unique credentials and short-lived signed tokens.
  • Card numbers and CVCs never reach our servers; Stripe handles them under PCI DSS Level 1.
  • We follow the principle of least data: we only collect what we need to deliver the audit.

No system is perfectly secure. If we suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify you without undue delay, as required by Articles 33 and 34 of the UK GDPR.

8. Your rights (UK and EU residents)

Under the UK GDPR and EU GDPR you have the right to:

  • Be informed about what we do with your data. This policy is how we do that.
  • Access a copy of the personal data we hold about you.
  • Rectification if any of it is inaccurate.
  • Erasure (the "right to be forgotten") where we no longer have a lawful reason to keep it.
  • Restrict processing in certain circumstances.
  • Data portability for data you provided to us, in a machine-readable format.
  • Object to processing based on legitimate interests.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make any such decisions.

To exercise any of these rights, email hello@bumpupseo.com. We will respond within one calendar month, free of charge. We may need to verify your identity first; we will only ask for what is strictly necessary to do so.

9. Your rights (US residents)

BumpUp SEO is a small UK business and does not currently meet the thresholds for full coverage under the California Consumer Privacy Act (CCPA/CPRA) or the comprehensive privacy statutes of other US states. We nonetheless give US customers the following rights as a matter of policy:

  • Right to know what categories of personal information we collect and the purposes for which we use them. They are listed in Sections 2 and 3 above.
  • Right to delete your personal information, subject to the legal retention exception in Section 6.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell or share your personal information for cross-context behavioural advertising. There is nothing to opt out of.
  • Right to non-discrimination. We will not deny service, charge a different price, or provide a lesser service if you exercise any of these rights.

To exercise any of these rights, email hello@bumpupseo.com with the subject line "US Privacy Rights Request" and tell us which state you reside in.

10. Cookies and tracking

We use only the cookies and storage that are strictly necessary to operate the site and process your order. This includes:

  • A security cookie set by our cloud infrastructure provider for bot detection.
  • Payment-fraud-prevention cookies set by our payment processor during checkout.
  • Session storage used to keep you signed in if you access an admin area.

Under the Privacy and Electronic Communications Regulations (PECR), strictly necessary cookies do not require consent. We do not use analytics cookies, advertising cookies, or any tracking pixels.

11. Children

The service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of the page always reflects the current version. Where the change is material (for example, a new sub-processor or a new purpose of processing), we will email customers whose data is still active in our systems before the change takes effect.

13. Complaints

If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve it. You also have the right to complain to a supervisory authority:

  • UK: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
  • EU: Your local Data Protection Authority. A list is available on the European Data Protection Board website.
  • California: California Privacy Protection Agency.

14. Contact us

For any privacy question, request, or concern, email hello@bumpupseo.com. Please put "Privacy" in the subject line so we can route it correctly. We aim to acknowledge all privacy requests within 5 working days and to resolve them within one calendar month.

B BumpUpSEO

Senior-level SEO audits, delivered automatically. A fixed-price alternative to agency retainers.

Product

How it works Sample report Pricing FAQ

Company

About LinkedIn

Resources

Blog ROI calculator BumpUp vs agency BumpUp vs freelancer Customer story Sample report

Legal

Privacy Policy Terms and Conditions

Contact

hello@bumpupseo.com
© 2026 BumpUp SEO. All rights reserved. Made by loomly.co.uk