Privacy Policy
Last updated: 9 June 2026
This Privacy Policy explains how GEOSCORES ("we", "us") collects and processes personal data when you use our website and platform (the "Service"). We act as a data controller under the UK GDPR and the EU GDPR for the personal data described below.
1. Who we are
GEOSCORES is the trading name of the entity operating geoscores.tech. For privacy questions or to exercise your rights, contact privacy@geoscores.tech.
2. What data we collect
- Account data — email address, hashed password (if applicable), name if provided, authentication metadata.
- Business data you submit — business name, website, description, category, location, and other inputs used to generate reports.
- Reports and audit history — generated scores, AI engine outputs, competitor analyses, and snapshots tied to your account.
- Billing data — subscription status, plan, billing period dates. Card details are handled by Stripe; we never see or store them.
- Communications — emails you send us and email-delivery metadata (opens, bounces, unsubscribes).
- Technical data — IP address, device and browser information, log data, and limited usage analytics. See cookies below.
3. How we use it and our legal bases
- Provide the Service — running audits, generating reports, sending transactional emails. Legal basis: contract.
- Billing and fraud prevention — processing payments via Stripe. Legal basis: contract and legitimate interests.
- Security and platform integrity — abuse prevention, rate limiting, audit logs. Legal basis: legitimate interests.
- Product improvement — aggregated, de-identified analytics. Legal basis: legitimate interests.
- Marketing emails — only with consent or to existing customers about similar services, with an easy unsubscribe.
- Legal compliance — to meet tax, accounting and regulatory obligations. Legal basis: legal obligation.
4. AI processing
To produce reports we send the business inputs you provide (e.g. name, website, category, location) to third-party AI providers such as OpenAI, Anthropic, Google and Perplexity. We do not knowingly send special category personal data. AI providers process this data as our processors or as independent controllers depending on their terms; their use of inputs for model training is disabled where their API contracts allow.
5. Cookies and similar technologies
We use a small number of cookies and similar technologies that fall into two categories:
- Strictly necessary — session, authentication, security and consent-preference cookies. These are required and do not need consent.
- Analytics — only set if you accept via the cookie banner. Used to understand usage and improve the product. You can change your preference at any time by clicking "Cookie preferences" in the footer.
6. Sharing
We share personal data with carefully selected processors that help us run the Service:
- Cloud hosting and database providers (EU/UK or equivalent safeguards).
- Stripe (payments).
- Email delivery providers (transactional and notification emails).
- AI model providers (as described above).
- Customer-support and analytics tooling we may add, listed in this policy as they're introduced.
We do not sell personal data. We may disclose data when required by law or to protect our rights and users.
7. International transfers
Some providers (including AI providers) are located outside the UK/EEA. Where they are, transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or an applicable adequacy decision.
8. Retention
We keep account and business data while your account is active, plus a reasonable period afterwards for legal, accounting and dispute-resolution purposes (typically up to 7 years for billing records). When you delete your account we erase or anonymise personal data within 30 days, except where retention is required by law.
9. Your rights
Under UK and EU GDPR you have the right to:
- access your personal data;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to certain processing;
- data portability — receive your data in a machine-readable format;
- withdraw consent at any time where processing is based on consent;
- complain to a supervisory authority (in the UK, the Information Commissioner's Office, ico.org.uk).
You can exercise the most common rights directly from your account settings: export your data as JSON, or permanently delete your account. For any other request, email privacy@geoscores.tech and we will respond within one month.
10. Security
We use encryption in transit, access controls, audit logs, principle-of-least-privilege access, and reputable infrastructure providers. No system is perfectly secure; we will notify affected users and regulators of any qualifying breach as required by law.
11. Changes
We may update this policy. Material changes will be notified by email or in-product before they take effect.
This document is a template and should be reviewed by a qualified lawyer or DPO before being relied on for compliance.