Privacy Policy
Last updated:
This policy explains what personal data BoostMaster processes when you use the service, why and for how long it is kept, who it is shared with, and how you can exercise your rights.
In short: We process your data only to provide the service to you. We do not use your Google Search Console data for advertising, sell it to third parties, or use it to train AI models. When you disconnect, the related data is deleted.
1. Data controller
The data controller is BoostMaster. Contact: [email protected]
2. Data we process
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email address and Google account ID from your Google account | Account creation, sign-in, notifications | Performance of contract |
| IP address, browser info, login records | Security, abuse detection | Legitimate interest |
| Sites and URLs you add | Diagnostics and reporting | Performance of contract |
| Crawl results and index state history | Reporting, trends, alerts | Performance of contract |
| Billing details | Invoicing, statutory retention | Legal obligation |
| Google Search Console access and refresh tokens | Reading index status | Explicit consent |
| Support correspondence and contact form messages (name, email, message, IP address) | Providing support, answering your questions, preventing abuse | Performance of contract / legitimate interest |
| Telegram chat ID (only if you turn on Telegram notifications) | Alert notifications | Explicit consent |
We do not store passwords. Sign-up and sign-in happen only with your Google account; Google verifies your identity. We never see or store your payment card details; payments are handled by licensed payment institutions.
3. Google user data
Sign in with Google. At sign-in and sign-up we request only the openid,
email and profile scopes, which give us your name, email address and stable Google
account ID. We do not request Search Console access at this stage.
Search Console connection. When you connect a project, we separately request, at that moment only, the following scopes for these specific purposes:
webmasters.readonly— To read the index status, coverage state, last crawl time and Google-selected canonical for pages in your verified property. Without this data the product's evidence layer cannot function.webmasters— Only upon your explicit action, to submit or update your sitemap in Search Console.openid,email— To show you which Google account Search Console was connected with.
Limited Use commitment
BoostMaster's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google data solely to provide user-facing features to you.
- We do not use it for advertising; we operate no advertising products.
- We do not use it to train AI or machine learning models.
- We do not sell or transfer it to third parties.
- Human access occurs only with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised. Our support staff can never view your Google tokens; tokens are stored encrypted.
You may disconnect at any time from the dashboard. On disconnection, access and refresh tokens are deleted immediately and no further data is retrieved from that property.
4. Cookies
We use only cookies strictly necessary for the service: a session cookie, a CSRF security cookie and a cookie that keeps you signed in. All are sent over HTTPS only. Our infrastructure provider Cloudflare may set strictly necessary security cookies for attack protection. We use no advertising, third-party tracking, analytics or profiling cookies. Fonts and scripts load from our own domain; our pages run no third-party scripts, and this is enforced in the browser by a Content Security Policy.
5. Retention
| Data | Retention |
|---|---|
| Account details | While the account is open |
| Crawl and index state history | 90 days after account closure |
| Google tokens | Deleted immediately on disconnection |
| Login and security records | 12 months |
| Invoicing and accounting records | 10 years (statutory requirement) |
| Support correspondence and contact form messages | 24 months |
6. Sharing and transfers
We do not share your data with anyone for marketing purposes. Providers used to operate the service access only the data necessary for their function and act as data processors:
| Provider | Function | Data accessed | Location |
|---|---|---|---|
| Cloudflare, Inc. | Content delivery, attack and abuse protection, TLS | IP address, browser info, request content (in transit) | Global network, outside Türkiye |
| Telegram (only if you turn on these notifications) | Alert notifications | Your Telegram chat ID; project name, page address and alert text in the message | Outside Türkiye |
| Google LLC | Sign in with Google; Search Console data (if you connect) | Google account identity; Search Console property data | Outside Türkiye |
| Hostinger (server hosting) | Hosting the application and database | All data processed in the service (at infrastructure level) | Lithuania (European Union) |
| Payment institutions (iyzico, Stripe) | Taking payments | Information required for the payment | Türkiye / abroad |
The service's servers are located in the European Union (Lithuania); in addition, because of Cloudflare and Google services (and Telegram, if you turn on Telegram notifications), your personal data is transferred outside Türkiye. You can remove the Telegram connection at any time under Settings → Account; your chat ID is then deleted. These transfers are limited to what is necessary to provide the service and to the purposes above.
7. Security
- All traffic is encrypted with TLS.
- No passwords are stored; authentication is performed by Google. Sign-in is protected with state validation, a one-time nonce and PKCE.
- Google tokens and API keys are stored encrypted; the full value of an API key is never stored, only a hash.
- Privileged access is role-based and every administrative action is written to an immutable audit log.
- Database backups are held in storage accessible only to an authorised system account.
- Scripts running in the browser are restricted to our own domain by a Content Security Policy.
8. Your rights
Under the Turkish Personal Data Protection Law (KVKK) Article 11 and, where applicable, the GDPR, you have the right to access your data, request correction or erasure, restrict or object to processing, request data portability, and be informed about transfers to third parties.
Send requests to [email protected] or, if you have an account, through the Support section of the dashboard; we respond within 30 days at the latest.
9. Changes
Material changes to this policy are announced by email before they take effect. The date at the top of this page shows when it was last updated.