Privacy Policy
Effective
1. Who we are
Maveriko is a product of Brand Vibe Consulting (“we”, “us”), of 4th Floor, Times Square Building, Andheri (E), Mumbai, Maharashtra 400059, India. Brand Vibe Consulting is the data controller for personal data processed through maveriko.com, and the Data Fiduciary in respect of that data for the purposes of India’s DPDP Act 2023. Full contact details are on the Contact page.
2. What we collect
When you run an audit — signed in or not
- The URL you submitted, the final URL after redirects, and the hostname.
- The report itself — the SEO and GEO scores, every individual check result, and the evidence extracted from the page (such as its title tag, meta description and heading structure).
- A one-way hash of your IP address, not the address itself. We combine your IP with a secret salt and store a truncated SHA-256 digest. It exists so we can enforce the daily free limit and attach an anonymous report to your account if you sign in afterwards. The original IP address is never written to our database.
- A daily counter keyed to that hash (or to your account ID when signed in), holding a number and a date — how many scans have been used today.
When you sign in
Sign-in is via Google only. Google returns, and we store, your email address, name and profile picture URL, plus the OAuth tokens that prove the sign-in. We also store your plan status and its expiry date. We never receive your Google password.
When you subscribe
Payments are processed by Razorpay. Razorpay sends us a record containing the payment and subscription identifiers, the email address and phone number you gave at checkout, and the amount and currency. That is the whole of it — card numbers, UPI IDs, CVVs, bank credentials and one-time passwords are entered on Razorpay’s systems and are never transmitted to, or stored by, us.
What we do not collect
- No analytics or product-telemetry service. There is no Google Analytics tag, no Meta pixel, no session recorder and no heatmap script on this site.
- No advertising or cross-site tracking cookies, and no data sold, rented or shared with data brokers.
- No fonts, scripts or stylesheets loaded from third-party CDNs — typefaces are served from our own domain, so no external host sees your visit.
- No card, bank or government identity details.
3. Cookies
We set cookies only to make signing in work: a session cookie that keeps you logged in, a CSRF-token cookie that prevents forged requests, and a short-lived callback-URL cookie used during the sign-in redirect. All three are strictly necessary, so no consent banner is required. If you never sign in, we set no cookies at all. Clearing them signs you out and has no other effect.
4. Why we process it, and on what legal basis
- To run the audit you asked for and show you the report — performance of a contract (UK/EU GDPR Art. 6(1)(b)); necessary for providing a requested service under India’s DPDP Act 2023.
- To save your report history and manage your account and plan — performance of a contract.
- To enforce daily limits and prevent abuse of the scanner — legitimate interests (Art. 6(1)(f)). Hashing the IP is how we keep this proportionate: the counter works without us ever holding the address.
- To take payment and keep the accounting records tax law requires — performance of a contract, and compliance with a legal obligation.
- To answer your emails — legitimate interests.
5. Who else processes it
We use four service providers, each bound to process data only on our instructions. We add none beyond this list without updating this page.
- Vercel — hosting and content delivery for the website itself.
- Neon — the managed PostgreSQL database where accounts, reports and payment records are stored.
- Google — sign-in, only if you choose to sign in.
- Razorpay — payment processing, only if you subscribe. Razorpay is an independent controller of the payment data it collects; see Razorpay’s own privacy policy for how they handle it.
Beyond these, we disclose personal data only where we are legally compelled to, or where it is necessary to establish or defend a legal claim.
6. Where your data is processed
Our providers operate global infrastructure, so data may be processed in the United States, the European Union or India depending on which region a given service runs in. Where data leaves the UK or EEA, our providers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved transfer mechanism.
7. How long we keep it
- Audit reports — 24 months from the scan, then deleted. Reports attached to an account are deleted when the account is.
- Daily-limit counters — 90 days.
- Account data — until you ask us to delete it. We do not expire accounts automatically.
- Payment records — 8 years, because Indian tax law requires it. This is the one category we cannot delete on request while the retention period runs.
8. Report links are shareable — please read this one
Every report has its own URL, and anyone who has that URL can open the report. This is deliberate: it is how you send a report to a client or a colleague without them needing an account. We ask search engines not to index report pages, and they are not linked from anywhere public — but the link is the only thing protecting the report. Treat a report URL as unlisted, not private, and do not post one somewhere you would not post its contents.
9. The pages you audit
When you submit a URL, our crawler MaverikoBot/1.0 fetches that page once, along with its robots.txt and sitemap. We only ever fetch pages that are publicly reachable — private, loopback and internal network addresses are refused — so we do not collect data from anything behind a login. If the page you audit contains someone else’s personal data, that data may appear in the stored report, and you are responsible for having the right to submit that URL. Site owners can block the crawler; the About page explains how.
10. Your rights
Wherever you live, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete your account and its reports;
- restrict or object to processing based on legitimate interests;
- export your data in a portable format.
Under the UK and EU GDPR these are statutory rights, and you may also complain to your national supervisory authority — in the UK, the Information Commissioner’s Office. Under India’s DPDP Act 2023 you additionally have the right to nominate another person to exercise your rights, and the right to escalate an unresolved grievance to the Data Protection Board of India. California residents may exercise the equivalent CCPA rights; note that we do not sell or share personal information as those terms are defined there.
To exercise any of these, email hello@maveriko.com from the address on your account. We reply within 2 working days and complete the request within 30 days. There is no charge.
11. How we protect it
The site is served over HTTPS only, with HSTS, a strict Content-Security-Policy and clickjacking, MIME-sniffing and referrer protections enforced at the edge. The database is reachable only over TLS with credentials that are never present in our source code. Payment webhooks are verified by HMAC signature before we act on them, so a forged “payment received” message cannot grant access. IP addresses are hashed with a secret salt rather than stored. No system is perfectly secure, but we will notify you and the relevant authority without undue delay if a breach affects your data.
12. Children
Maveriko is a business tool and is not intended for children. Do not use it, or give us personal data, if you are under 18. If we learn that we hold a child’s data, we delete it.
13. Changes to this policy
If we change how we handle your data, we update this page and move the effective date at the top. Material changes are also emailed to account holders. The effective date is the version marker — a policy that reprinted today’s date on every visit would tell you nothing about what you agreed to.
14. Contact and grievances
Privacy questions, data requests and grievances all go to hello@maveriko.com, which reaches the person responsible for data protection at Brand Vibe Consulting. The postal address is on the Contact page. If you are not satisfied with our response, you may complain to your data protection authority.
