Privacy policy
Last updated: 6 October 2026
On this page
1. Data controller
The controller of the personal data processed in SmoothSeen is its owner:
- Owner
- Manuel Sisto Fontáns
- Tax ID (NIF)
- 46291823E
- Address
- Lugar Xesta nº 38, 15866 Teo (A Coruña), Spain
You can write to that address about anything related to your data or to exercise your rights (section 8).
2. What data we process
Only what is needed to provide the service:
- Account data: name, email address, password (stored only as a hash, never in plain text), language, plan and sign-up date. If you sign in with Google, Google gives us your name, your email and your Google account identifier; we do not receive your password or any other permission.
- Consents: the date and version of the terms you accepted, whether you want to receive news by email and, if you purchase a paid plan, the date on which you asked for the service to start straight away and accepted losing the right of withdrawal, with the plan and the version of the terms.
- Billing data: name or company name, company, tax ID (NIF, CIF, NIE or VAT number) and billing address. Card details are collected and stored by Stripe; we neither see nor store them.
- What you enter in the service: the web addresses and domains you analyse, your projects, competitors, the searches and questions you track, the results and screenshots of the analyses, your agency white label (name, logo, colour, website and email) and the number of visits to the reports you share.
- Public data from the websites and businesses analysed: the public content of the website and, for local businesses, their listing and public reviews, which may include the public name of a review author.
- Contact form: your name, your email, the subject and the message.
- Technical data: your IP address, to limit login and sign-up attempts; technical session cookies; and server logs and error reports, without your IP address or your email, to diagnose faults. With your consent, browsing data from Google Analytics (section 10).
3. What we use it for and on what legal basis
Each use has its basis in the General Data Protection Regulation (GDPR):
- Creating and managing your account and providing the service: analyses, reports, monitoring and the email alerts that are part of it. Basis: performance of the contract (art. 6(1)(b) GDPR).
- Managing your subscription (which plan you have and its changes) and being able to prove that you asked for the service to start straight away (section 7 of the terms). Charging, taxes and invoices are handled by Stripe as the seller (section 4). Basis: performance of the contract and compliance with tax, accounting and consumer-protection obligations (art. 6(1)(b) and 6(1)(c) GDPR).
- Sending you news and offers by email, only if you ticked the box when signing up. Basis: your consent (art. 6(1)(a) GDPR), which you can withdraw at any time.
- Measuring use of the website with Google Analytics, only if you accept it in the cookie notice. Basis: your consent (art. 6(1)(a) GDPR).
- Protecting the service: limiting login attempts, preventing abuse and preventing the free trial from being repeated with the same email. Basis: our legitimate interest in the security of the service and in the trial being one per person (art. 6(1)(f) GDPR).
- Replying to what you send us through the contact form or by email. Basis: your request (art. 6(1)(b) GDPR) and our legitimate interest in handling it (art. 6(1)(f) GDPR).
- Detecting and fixing technical faults in the website and the server, using technical logs and error reports. Basis: our legitimate interest in the service working properly (art. 6(1)(f) GDPR).
We do not make automated decisions with legal effects on you and we do not profile you with your data.
4. Who it is shared with
We do not sell or hand over your data. To provide the service we use these providers, who act as processors on our behalf and only for what is stated, except Stripe at checkout, which acts as a controller (explained in its item):
- Stripe: payments, subscriptions and invoices. When you buy a plan, Stripe sells it as merchant of record through its subsidiary Sold through Link, LLC (Managed Payments): it collects your payment details, your name, your billing address and, if you buy as a business, your VAT number directly, and processes them as an independent controller, under Link’s privacy policy (link.com/privacy) and Stripe’s (stripe.com/privacy), to charge you, calculate and pay the taxes, issue receipts and invoices, prevent fraud and handle payment issues. We pass it your email and, if you filled them in, your name or company name and your billing address, and Stripe tells us the status of your subscription. Your card details never reach us.
- Google: sign-in with Google and, if you accept it, Google Analytics. In addition, to run the analyses we send it web addresses, domains, business names and the questions you track (PageSpeed Insights, Places, Web Risk and Gemini), not your account data.
- OpenAI: the questions you track in AI assistant monitoring, to check whether the answers cite your brand.
- Outscraper: searches and public reviews of local businesses.
- Open PageRank: the domains analysed, to measure their authority.
- Server and database hosting: [PENDING: provider and country].
- Email: Brevo (Sendinblue SAS, France), which sends the app’s emails (email confirmation, password recovery, alerts and end of trial) and receives your email address and the content of the message for that purpose; and DonDominio (Soluciones Corporativas IP, S.L., Spain), which hosts the domain’s mailboxes, including the support mailbox where the messages you send us arrive. Brevo inserts in the emails it sends a technical element that records whether the email has been opened; we do not use that data to profile you or for marketing purposes.
- Encrypted backups: [PENDING: provider and country].
- Sentry (Functional Software, Inc., United States): receives reports of technical errors in the website and the server so that we can fix them. They are configured not to include your IP address, your cookies, your email or what you type in forms; at most they carry your account’s numeric identifier and your plan type. It does not use cookies. The reports are stored in its European Union region (Frankfurt, Germany).
What you write in project names and in the questions you track is sent to those providers as is: do not include personal data in them.
Beyond this, we will only disclose data to the authorities when the law requires it.
5. International transfers
Stripe, Google, OpenAI, Outscraper and Sentry are United States companies or may process data there. Where there is a transfer outside the European Economic Area, it is covered by the EU-US Data Privacy Framework, if the provider has joined it, or by the standard contractual clauses approved by the European Commission (arts. 45 and 46 GDPR).
6. How long we keep it
Only as long as each purpose requires:
- Account and content: for as long as you have the account. If you delete it from your profile, your Stripe subscription is cancelled and the account, analyses, projects, white label and related files are deleted immediately.
- Free trial: if you have used it, we keep a cryptographic fingerprint (SHA-256) of your email, without the email itself, so that the trial cannot be repeated with it. It is kept even if you delete your account, for 24 months from the day you started the trial; after that it is deleted automatically.
- Invoices and payment data: kept by Stripe, which collects them and issues the invoices as the seller, for the periods required by tax and commercial law, even if you delete your account.
- Backups: made daily, encrypted and rotated automatically. Deleted data may remain in them, unused, for up to six months, until the backup expires.
- Technical records: payment notifications received from Stripe, 90 days; attempt counters with your IP, one hour at most; an unconfirmed email change, until its link expires; error reports in Sentry, 30 days.
- Contact messages: they are not stored in the database; they reach the support mailbox and are kept there [PENDING: period].
- Google Analytics: [PENDING: retention period set in Google Analytics].
7. Security
We apply technical and organisational measures appropriate to the risk: encrypted communications (HTTPS), passwords stored only as a hash, encrypted backups, restricted access to systems and limits against mass login attempts. If a security breach affected your data, we would notify the Spanish Data Protection Agency and, where appropriate, you, within the deadlines set by the GDPR.
8. Your rights
You can exercise these rights at any time:
- Access: knowing what data of yours we process.
- Rectification: correcting data that is inaccurate. Most of it can be changed from your profile.
- Erasure: deleting your data. You can delete your account from your profile.
- Portability: receiving your data in a machine-readable format. You can download it as JSON from your profile.
- Objection and restriction of processing.
- Withdrawing your consent at any time, without affecting what was done before: for news by email, by writing to us; for analytics, in «Cookie preferences» at the bottom of every page.
To exercise them, write to us from your account email to soporte@smoothseen.com. We will reply within one month. If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
9. Minors
SmoothSeen is not aimed at minors and does not allow anyone under 18 to sign up.
11. Data of agencies’ clients
When an agency uses SmoothSeen to analyse its clients’ websites or businesses, the agency is the controller of the data about those clients that it enters, and SmoothSeen processes it on the agency’s behalf, as a processor, under the conditions of the terms and conditions. Those clients can exercise their rights with the agency.
12. Changes to this policy
If we change this policy in a meaningful way, we will let you know by email or in the app before the change applies. The date of the latest version is at the top of this page.