Privacy Policy

Last updated: 1 June 2026

This policy explains what data SEO First Web collects when you use this site, why we collect it, who we share it with, and how to ask for a copy or have it deleted. We try to keep it short and plain-English. If anything is unclear, email us at info@seofirstweb.co.uk and we'll explain.

Who we are

SEO First Web is a London-based digital consultancy. For UK GDPR / Data Protection Act 2018 purposes, we are the data controller for personal data submitted through this site. Contact: info@seofirstweb.co.uk.

What data we collect

We collect personal data in four situations only:

  • Consultation enquiries. When you submit the contact form or click "Book a Free Consultation", we collect the name, email and message you provide so we can reply.
  • Orders and payments. When you buy a service through our Pricing page, the payment is processed by Stripe. Stripe collects the details it needs to take the payment and prevent fraud (such as your name, email, billing address and card information). We never see or store your full card number: we receive a confirmation of the order with your name and email, so we can deliver the service and meet our tax and accounting obligations.
  • Tool email reports. A few of our free tools (SEO Audit, Online Business Starter Audit, Business Idea Validator) optionally send you a copy of your results by email. If you tick the box and enter your email, we store it long enough to send the report and follow up with relevant SEO advice.
  • Site analytics. Anonymous, aggregated traffic data via Vercel Analytics: pages viewed, country, device class, referrer. No cookies set for analytics. No personal identifiers stored.

We never receive uploaded files. Every PDF, image and link-audit tool on this site runs entirely in your browser. Files are not transmitted to us. You can verify in DevTools → Network while using any tool.

Why we collect it

Three lawful bases under UK GDPR:

  • Consent: for the optional email reports and the consultation enquiry.
  • Legitimate interest: for the anonymous analytics, used to improve the site.
  • Contractual necessity: to process and fulfil any order you place, and to deliver the services you've engaged us for.
  • Legal obligation: to keep order and payment records for the period HMRC requires.

Who we share it with

We use a handful of trusted third parties to actually deliver this site and our tools. None of them sell your data. Each handles only the slice of data they need:

  • Stripe (United States and Ireland, GDPR-compliant, PCI-DSS certified payment processor), online payments. Sees: the payment and billing details you enter at checkout, plus your name and email. Stripe is the only party that handles your card details; we never receive them. Stripe's own privacy policy explains how it processes payment data.
  • Vercel (United States, GDPR-compliant data processor), hosting and analytics. Sees: requests to the site, IP for rate-limiting.
  • Resend (United States, GDPR-compliant), transactional email. Sees: your email and report contents when you opt into an email report.
  • Upstash Redis (Ireland EU region), per-IP rate limiting for SERP-backed tools. Sees: hashed IP addresses, count, no personal data.
  • Serper.dev (United States, GDPR-compliant), Google SERP data for the SERP Checker, KD Estimator and Index Checker tools. Sees: the keywords or URLs you submit, no personal data.
  • Google Suggest (United States, Google's standard privacy terms apply), keyword suggestions for People Also Ask Finder and Keyword Suggestion Tool. Sees: the keywords you submit.
  • Google Gemini / Anthropic Claude (United States, GDPR-compliant when used via API). Powers the Title & Meta Generator, Content Brief Generator and Social Preview AI suggestions. Sees: the text you submit for processing.
  • Google PageSpeed Insights (United States), Lighthouse scores for the SEO Audit. Sees: the URL you submit.

We never share enquiry data with anyone for marketing, advertising or any purpose unrelated to fulfilling your request.

How long we keep it

  • Consultation enquiries: kept for up to 24 months after our last contact, then deleted. Active client correspondence is kept for 6 years after the engagement ends (HMRC requirement).
  • Order and payment records: kept for 6 years after the transaction, as required by HMRC for tax and accounting. Card details are held by Stripe, never by us.
  • Tool email opt-ins: kept until you unsubscribe. Every email we send has an unsubscribe link.
  • Analytics: anonymous, retained for 12 months by Vercel, then aggregated.

Your rights

Under UK GDPR you have the right to:

  • Request a copy of the personal data we hold about you
  • Ask us to correct anything inaccurate
  • Ask us to delete your data (the "right to be forgotten")
  • Withdraw consent for any of our processing
  • Object to legitimate-interest processing (analytics)
  • Lodge a complaint with the UK Information Commissioner's Office at ico.org.uk

To exercise any of these rights, email info@seofirstweb.co.uk. We respond within 30 days (usually within 48 hours).

Cookies

This site does not set tracking cookies. The only browser storage we use is localStorage for tool preferences you explicitly set: your starred keyword suggestions, quiz results-in-progress, the broken-link-checker's "known-issue" markers. This data never leaves your device.

Children

This site and its services are intended for business owners, marketers and consultants, all adults working professionally. We don't knowingly collect data from anyone under 16. If you believe we hold data about a child, email us and we'll delete it.

Changes to this policy

If we change anything material, we'll update the "Last updated" date at the top of this page. Significant changes affecting how we use existing data will be notified to anyone we hold an email address for.

Contact

Any questions, requests or complaints: info@seofirstweb.co.uk.