Privacy Policy
Effective
1. Who we are
Maveriko is a product of Brand Vibe Consulting (“we”, “us”), of 4th Floor, Times Square Building, Andheri (E), Mumbai, Maharashtra 400059, India. Brand Vibe Consulting is the data controller for personal data processed through maveriko.com, and the Data Fiduciary in respect of that data for the purposes of India’s DPDP Act 2023. Full contact details are on the Contact page.
2. What we collect
When you run an audit — signed in or not
- The URL you submitted, the final URL after redirects, and the hostname.
- The report itself — the SEO and GEO scores, every individual check result, and the evidence extracted from the page (such as its title tag, meta description and heading structure).
- A one-way hash of your IP address, not the address itself. We combine your IP with a secret salt and store a truncated SHA-256 digest. It exists so we can enforce the daily free limit and attach an anonymous report to your account if you sign in afterwards. The original IP address is never written to our database.
- A daily counter keyed to that hash (or to your account ID when signed in), holding a number and a date — how many scans have been used today.
When you sign in
Sign-in is via Google only. Google returns, and we store, your email address, name and profile picture URL, plus the OAuth tokens that prove the sign-in. We also store your plan status and its expiry date. We never receive your Google password.
When you subscribe
Payments are processed by Razorpay. Razorpay sends us a record containing the payment and subscription identifiers, the email address and phone number you gave at checkout, and the amount and currency. Card numbers, UPI IDs, CVVs, bank credentials and one-time passwords are entered on Razorpay’s systems and are never transmitted to, or stored by, us.
If you fill in the billing details on your account page, we also store what you enter there — a contact phone number, a billing name and address, an optional company name and an optional GSTIN — so we can issue proper invoices and reach you about your subscription. Every one of these fields is optional, you can edit or clear them at any time from the billing page, and they are deleted along with your account.
If you set a report branding name (and optional website) on the same page, we store those two fields and print them on the letterhead of reports you download — that is their only use. Both are optional, editable, clearable, and deleted along with your account.
If you save tracked competitors on the same page, we store your own site’s hostname and up to three competitor hostnames, used only to build the comparison section of your dashboard. All are optional, editable, clearable, and deleted along with your account.
How we count visits
We keep a few daily totals for the public site, and nothing else: how many browser sessions opened it, how many pages were viewed, the average time a visit lasts, and — for each visit — the domain of the site it came from, the domain only. Those totals are the entire dataset: there is no cookie, no identifier, no profile and no row about you.
Two details matter more than the list. Your browser reduces the referring address to its domain before anything is sent, so the full link, and anything after the ? in it, never leaves your device; we then file that domain into a fixed set of buckets, and anything we don’t recognise is counted simply as “other”. And the time a visit lasted is added into a running average and the individual value discarded the moment it arrives. Your browser also remembers, for the length of the tab session only, that it has already been counted — which is why our servers never need anything that could identify you. Every one of these figures is stored per day and deleted after 90 days.
What we do not collect
- No Meta pixel, no session recorder and no heatmap script. Nothing on this site records your screen, your mouse or your keystrokes.
- No advertising or cross-site tracking cookies, and no data sold, rented or shared with data brokers.
- No third-party script on your report, comparison or dashboard pages. Google Analytics runs on the public marketing pages only, so the address of any site you audit is never sent to it — see the section below.
- No fonts or stylesheets loaded from third-party CDNs — typefaces are served from our own domain.
- No card, bank or government identity details.
Google Analytics, and how it is configured
We use Google Analytics 4 to understand which pages people arrive on and which searches and links bring them here. It runs on our public marketing pages only — never on a report, a comparison, your dashboard or the billing pages — so the address of a site you audit is never sent to Google.
What it stores on your device depends on where you are. In the European Economic Area, the United Kingdom and Switzerland, Google’s consent settings are set to denied before the tag loads, so it writes no cookie and no identifier, and Google cannot tell a returning visitor from a new one. Everywhere else, it sets two first-party cookies, _ga and _ga_W8XCVLXPMC, which let Google count a returning visitor once rather than twice; each lasts up to two years unless you clear it. In every region its advertising features and Google signals are switched off, and Google receives the page you viewed, its title, the referring site, your approximate location from your IP address, and your browser and device type.
3. Cookies
We set cookies for two reasons. The first is signing in: a session cookie that keeps you logged in, a CSRF-token cookie that prevents forged requests, and a short-lived callback-URL cookie used during the sign-in redirect. All three are strictly necessary. The second is analytics: outside the European Economic Area, the United Kingdom and Switzerland, Google Analytics sets the two cookies described above on our public pages. Inside those regions it sets none, so if you are there and never sign in, we set no cookies at all — which is why we show no consent banner. Clearing our cookies signs you out and makes Google Analytics treat your next visit as a first one; it has no other effect.
4. Why we process it, and on what legal basis
- To run the audit you asked for and show you the report — performance of a contract (UK/EU GDPR Art. 6(1)(b)); necessary for providing a requested service under India’s DPDP Act 2023.
- To save your report history and manage your account and plan — performance of a contract.
- To enforce daily limits and prevent abuse of the scanner — legitimate interests (Art. 6(1)(f)). Hashing the IP is how we keep this proportionate: the counter works without us ever holding the address.
- To take payment and keep the accounting records tax law requires — performance of a contract, and compliance with a legal obligation.
- To answer your emails — legitimate interests.
- To understand how people find and use the public site — the visit totals and Google Analytics described in section 2; legitimate interests.
5. Who else processes it
We use five service providers, each bound to process data only on our instructions. We add none beyond this list without updating this page.
- Vercel — hosting and content delivery for the website itself.
- Neon — the managed PostgreSQL database where accounts, reports and payment records are stored.
- Google — sign-in, only if you choose to sign in; and Google Analytics on our public marketing pages, configured as described in section 2. Analytics data is processed by Google on servers that may be outside your country.
- Razorpay — payment processing, only if you subscribe. Razorpay is an independent controller of the payment data it collects; see Razorpay’s own privacy policy for how they handle it.
Beyond these, we disclose personal data only where we are legally compelled to, or where it is necessary to establish or defend a legal claim.
6. Where your data is processed
Our providers operate global infrastructure, so data may be processed in the United States, the European Union or India depending on which region a given service runs in. Where data leaves the UK or EEA, our providers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved transfer mechanism.
7. How long we keep it
- Audit reports — 24 months from the scan, then deleted. Reports attached to an account are deleted when the account is.
- Daily-limit counters and daily visit totals — 90 days.
- Account data — until you ask us to delete it. We do not expire accounts automatically.
- Payment records — 8 years, because Indian tax law requires it. This is the one category we cannot delete on request while the retention period runs.
8. Report links are shareable — please read this one
Every report has its own URL, and anyone who has that URL can open the report. This is deliberate: it is how you send a report to a client or a colleague without them needing an account. We ask search engines not to index report pages, and they are not linked from anywhere public — but the link is the only thing protecting the report. Treat a report URL as unlisted, not private, and do not post one somewhere you would not post its contents.
9. The pages you audit
When you submit a URL, our crawler MaverikoBot/1.0 fetches that page once, along with its robots.txt and sitemap. We only ever fetch pages that are publicly reachable — private, loopback and internal network addresses are refused — so we do not collect data from anything behind a login. If the page you audit contains someone else’s personal data, that data may appear in the stored report, and you are responsible for having the right to submit that URL. Site owners can block the crawler; the About page explains how.
10. Your rights
Wherever you live, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete your account and its reports;
- restrict or object to processing based on legitimate interests;
- export your data in a portable format.
Under the UK and EU GDPR these are statutory rights, and you may also complain to your national supervisory authority — in the UK, the Information Commissioner’s Office. Under India’s DPDP Act 2023 you additionally have the right to nominate another person to exercise your rights, and the right to escalate an unresolved grievance to the Data Protection Board of India. California residents may exercise the equivalent CCPA rights; note that we do not sell or share personal information as those terms are defined there.
To exercise any of these, email hello@maveriko.com from the address on your account. We reply within 2 working days and complete the request within 30 days. There is no charge.
11. How we protect it
The site is served over HTTPS only, with HSTS, a strict Content-Security-Policy and clickjacking, MIME-sniffing and referrer protections enforced at the edge. The database is reachable only over TLS with credentials that are never present in our source code. Payment webhooks are verified by HMAC signature before we act on them, so a forged “payment received” message cannot grant access. IP addresses are hashed with a secret salt rather than stored. No system is perfectly secure, but we will notify you and the relevant authority without undue delay if a breach affects your data.
12. Children
Maveriko is a business tool and is not intended for children. Do not use it, or give us personal data, if you are under 18. If we learn that we hold a child’s data, we delete it.
13. Changes to this policy
If we change how we handle your data, we update this page and move the effective date at the top. Material changes are also emailed to account holders. The effective date is the version marker — a policy that reprinted today’s date on every visit would tell you nothing about what you agreed to.
14. Contact and grievances
Privacy questions, data requests and grievances all go to hello@maveriko.com, which reaches the person responsible for data protection at Brand Vibe Consulting. The postal address is on the Contact page. If you are not satisfied with our response, you may complain to your data protection authority.
