Privacy Policy
1. Who we are (data controller)
SerpTune is operated by Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy — VAT IT15237911001, REA RM-1576999, PEC [email protected] ("Redbit", "we", "us"). Given the size of our organisation we are not required to appoint, and have not appointed, a Data Protection Officer under Article 37 GDPR. For any privacy matter contact [email protected] or use our contact form.
2. Scope
This policy explains how we handle personal data when you visit serptune.com and use the SerpTune application. Read it together with our Terms of Service, our Cookie Policy, and, for business customers, our Data Processing Agreement.
3. Personal data we process (as controller)
- Identity & account: email, hashed password, locale, account status.
- Billing: company/tax details you provide, address, Wallet and transaction records. Card data is handled directly by our payment provider and is never stored by us.
- Usage: the URLs and queries you submit, the resulting analyses, and Credit movements.
- Technical & security: IP address, timestamps, request metadata, audit and security events.
- Advertising measurement (only with your consent): Meta pixel identifiers (
_fbp,_fbc) and Google Ads identifiers (_gcl_au,_gcl_aw), your IP address and browser user-agent, the page and the event concerned and, where you are signed in or registering, a SHA-256 hash of your email address and of your account identifier shared with Meta only. Your email address is never transmitted in the clear. - Usage statistics (only with your consent): Google Analytics identifiers (
_ga,_ga_<ID>), your IP address, browser data, the pages you visit and how long you stay.
We do not intentionally collect special-category (sensitive) personal data about you.
4. Where the data comes from
Directly from you (registration, forms, the URLs/queries you submit) and automatically from your use of the Service (logs and security events).
5. Purposes & legal bases (GDPR / UK GDPR)
- Operating the Service, accounts, and running analyses — performance of a contract (Art. 6(1)(b)).
- Billing, invoicing, accounting and tax — legal obligation (Art. 6(1)(c)) and contract.
- Security, fraud/abuse prevention, rate limiting, and audit logging — legitimate interests (Art. 6(1)(f)).
- Fetching and analysing publicly available web pages to produce your report — legitimate interests, balanced against the rights of the pages' publishers, who may opt out of our crawler.
- Service communications (verification, notices) — contract and legitimate interests.
- Aggregate, cookieless audience measurement (pageview counts; no cookies, no IP stored, no profiling) — legitimate interests.
- Advertising measurement through the Meta pixel with Conversions API and through the Google Ads conversion tag — your consent (Art. 6(1)(a)), which you can withdraw at any time under "Cookie preferences" in the footer, with effect for the future.
- Statistical measurement of how the site is used, through Google Analytics — your consent (Art. 6(1)(a)), a purpose separate from advertising, with its own tick box, withdrawable at any time under "Cookie preferences" in the footer, with effect for the future.
6. Pages we analyse & the data they may contain
To produce a report we fetch publicly accessible pages (Your Page and the ranking Competitors) using the SerpTuneBot crawler, extract their main text, and send that cleaned text to our AI sub-processor for analysis. Those pages may incidentally contain personal data (for example an author's name). We process such data only to generate your report, retain the raw fetched HTML for at most 48 hours, respect robots.txt and per-domain opt-out, and never use fetched content to build profiles of individuals or to train models. Where you submit pages for which you are the controller, section 13 and our DPA apply.
7. Sub-processors & recipients
- Anthropic — AI analysis of the cleaned page content (United States).
- LangChain (LangSmith) — LLM observability (token usage, cost, latency) for the analysis pipeline (EU region).
- Serper / search-results provider — retrieval of public search-engine results for your query.
- Cloudflare — CDN, DNS, WAF and bot-protection (Turnstile); a global network with EU edge.
- Revolut — payment processing.
- Fatture in Cloud (TeamSystem S.p.A., Italy) — issuing your invoice and transmitting it to the Italian Revenue Agency’s Interchange System (SdI). It receives the billing details you enter: name or company name, address, VAT number or tax code, and the amount paid.
- IONOS — hosting infrastructure (European Union, Germany).
- Redbit's self-managed transactional email system (mail.redbitapp.com) — sending service emails.
We do not sell or rent your personal data. We may disclose data to public authorities where legally required, and to professional advisers or a successor entity under confidentiality.
VAT number checks. If you buy as a business in the European Union, we submit the VAT number you provide to the European Commission’s VIES service to confirm it is valid. Without that check we cannot apply the reverse charge. The legal basis is our legal obligation to charge the correct tax (Art. 6(1)(c) GDPR); we store only the outcome of the check and the date.
Invoices. An invoice is issued when you request one at checkout or when you have provided billing details (always, for business customers); purchases without an invoice request are recorded as Italian tax law requires for direct e-commerce. Where an invoice is issued, the billing details and the invoice itself are kept for the retention period Italian tax law requires (currently ten years), even if you delete your account. Deleting your account removes your saved billing profile from SerpTune, but it cannot erase invoices already issued or fiscal records already made.
Meta (advertising measurement). If, and only if, you give the marketing consent, we transmit the events described in section 3 to Meta Platforms Ireland Limited — from your browser through the Meta pixel and from our servers through the Conversions API. Both channels carry the same event with the same identifier, so it is counted once. Meta is not our sub-processor here: for the collection and transmission of those events we and Meta act as joint controllers under Art. 26 GDPR, on the terms of Meta’s Controller Addendum, while Meta acts as an independent controller for what it does with the data afterwards. You may exercise your rights against either of us; Meta’s own information is at facebook.com/privacy/policy. If you refuse, or later withdraw, nothing is transmitted on either channel.
Google (advertising measurement). If, and only if, you give the marketing consent, the Google Ads conversion tag in your browser reports to Google Ireland Limited which of our ads brought you here and whether a registration or a purchase followed. There is no server-side channel: everything runs in your browser, and nothing loads before you consent. For this measurement we and Google act as independent controllers under Google’s Ads Data Protection Terms; Google’s own information is at policies.google.com/privacy. If you refuse, or later withdraw, the tag does not load and its cookies are deleted.
Google Analytics (statistics). This runs only if you consent to the statistics category, which is separate from the advertising one: you may accept either without the other. It tells us which pages are read, how visitors arrive and where they give up, and the data goes to Google Ireland Limited. For this processing Google acts as our processor under the Google Analytics Data Processing Terms — a different role from the advertising one above, where Google is an independent controller. Google truncates your IP address before storing it. Google’s own information is at policies.google.com/privacy. If you refuse, or later withdraw, the tag does not load and its cookies are deleted.
8. International transfers
Our infrastructure and databases are hosted in the European Union (Germany). Some sub-processors (e.g. Anthropic, Cloudflare) are located in or route through the United States; those transfers are covered by the European Commission's Standard Contractual Clauses and, for UK personal data, the UK International Data Transfer Addendum, together with supplementary measures. A copy of the relevant safeguards is available on request via [email protected].
If you have consented to advertising or statistical measurement, data also reaches Meta Platforms Ireland Limited and Google Ireland Limited and may be transferred to Meta Platforms, Inc. and Google LLC in the United States; both rely on the EU–US Data Privacy Framework and on Standard Contractual Clauses.
9. Retention
- Account data: deleted within 30 days after you close your account (or on a verified erasure request), unless longer retention is legally required.
- Billing & invoicing records: retained for 10 years, as required by Italian tax law.
- Operational and security logs: up to 12 months.
- Raw fetched HTML: purged within 48 hours; cleaned text and cached results expire within 24 hours.
- Analyses & reports: retained in your account until you delete them or close your account.
10. Automated decision-making & AI
We do not carry out automated decision-making that produces legal or similarly significant effects on you (Art. 22 GDPR). AI is used only to analyse public page content and generate your report; it makes no decision about you.
11. Cookies
We set strictly-necessary cookies, which require no consent, and — only if you allow them — the advertising-measurement cookies of the Meta pixel and of the Google Ads tag, and the statistics cookies of Google Analytics — which sit in a separate consent category, so you can allow one without the other. A consent banner appears on your first visit and nothing optional runs before you choose. You can change or withdraw your choice at any time through Cookie preferences at the bottom of every page. Our own audience measurement uses no cookies at all. See our Cookie Policy for the full list.
12. Your rights (GDPR / UK GDPR)
You have the right to access, rectification, erasure, restriction, data portability, and objection, and — where processing is based on consent — the right to withdraw it. To exercise any right, contact [email protected] or use our contact form. We may need to verify your identity and respond within one month (extendable by two further months for complex requests). You may lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or, for UK data subjects, the ICO (ico.org.uk).
13. Data you submit for analysis (our processor role)
For pages you submit and for which you are the controller, we process any personal data they contain only on your instructions and for the sole purpose of producing the analysis you request, under our DPA. We do not use it for our own purposes, do not sell or share it, and delete it as described in section 9.
14. California privacy rights (CCPA / CPRA)
If you are a California resident: we collect identifiers (email, IP), commercial information (billing and transactions) and internet activity (logs) for the business purposes in section 5. We do not sell your personal information for money, and we have not done so in the preceding 12 months. If — and only if — you turn on advertising measurement, the data described in section 3 is shared with Meta and Google for cross-context behavioral advertising within the meaning of the CPRA; the statistics category does not involve any such sharing. That sharing requires your opt-in and stops as soon as you withdraw it under "Cookie preferences"; if you never opt in, no such sharing takes place. You have the rights to know/access, delete, correct, to opt out of sharing, and to non-discrimination; submit a request via [email protected]. We verify identity before responding.
15. Other jurisdictions & children
Where other data-protection laws apply to you (e.g. Brazil's LGPD, Canada's PIPEDA), we honor the equivalent rights they grant. SerpTune is a business service, not directed to children; users must be at least 18, and we do not knowingly collect data from anyone under 16.
16. Security
We protect data with encryption in transit (TLS, HSTS), hashed passwords (Argon2id), CSRF protection, rate limiting and login lockout, bot protection, least-privilege access, and audit logging. No system is perfectly secure; we will notify you and the competent supervisory authority of a personal-data breach where and as legally required.
17. Changes & contact
We may update this policy; material changes will be notified by email and in-app notice before they take effect. Privacy questions and data-subject requests: [email protected] or our contact form. Postal: Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy.