Privacy Policy

Last updated: 26 August 2026

Version 2026-08-26

This Privacy Policy explains what personal data Recometric collects, why, how long it is kept, who it is shared with, and what you can do about it. It covers both the public website and the Recometric application.

Who is responsible for your data

The data controller - the company that decides why and how your personal data is processed, and the one to contact about it - is:

  • SEOKLIKK Kft.
  • Company registry number: 07-09-034983
  • Tax number: 32350720-2-07
  • Registered seat: Szabadság út 22. 2. em. 2. ajtó, Dunaújváros, Hungary
  • Managing director: Balog Botond
  • Email: info@seoklikk.hu, phone: +36 70 153 8275

The same company, SEOKLIKK Kft., is also the seller of the Recometric service under the Terms of Service. Controller and seller are two roles of one legal entity here, not two businesses.

One other company is involved: Paddle.com Market Ltd. is the Merchant of Record for every payment. It is the party you actually buy from, and it handles billing, tax and refunds.

Paddle is not the controller of your Recometric account, business profile or scan data - SEOKLIKK Kft. is, as set out above. For the payment data Paddle collects at checkout (card details, billing address, invoice records) Paddle is a data controller in its own right, not our processor, and it processes that data under its own privacy policy.

So: address anything about your Recometric account, business data or scans to the controller above. Address anything about a payment, an invoice or your card details to Paddle, at paddle.net.

What we collect

Account data. Your email address, your name if you give one, and an encrypted password (or the fact that you signed in with Google). We never see your Google password.

Business data you enter. Your business name, website, location, industry, category, services, service areas, target customers, differentiators and the competitors you choose to track. This is the input to your scans.

Google Business Profile data. When you provide a Google Business Profile link or we look your business up by name and location, we retrieve and store publicly available listing details: the business name, address, category, rating, review count, opening hours and Google's own place identifier. This is public business information, not personal data about your customers.

Website content we fetch. When you enter a website address - your own, or a competitor's - we request that page over HTTP and read its publicly available content: the title, meta description, headings and the visible body text. That text is stored with the scan and, as described below, is placed verbatim into the prompts sent to the AI providers. We only request pages that are reachable without signing in.

Scan results. The prompts we send to AI assistants on your behalf, their answers, whether your business was mentioned, its position, sentiment, cited sources, competitors named alongside you, and the resulting score and history.

A hashed IP address. Irreversible, never the address itself, used only to stop one person from consuming unlimited free scans and to protect forms from abuse.

Consent records. Which legal documents you accepted, which version, and when - with a hashed IP address, so the acceptance is provable.

Support and contact messages. When you write to us - through the in-app support thread or the public contact form - we keep what you send: the message text, the email address to answer at, and, on the contact form, your name and business if you fill them in. Contact form submissions also record the hashed IP address described above, used to limit how many messages one network can send per day.

Cancellation feedback. If you cancel a subscription and choose to answer the optional questions about why, we store the reason you select and anything you type into the free-text fields. Answering is voluntary and has no effect on the cancellation itself.

Two-factor authentication. If you switch on two-factor authentication, we store the enrolled authenticator (TOTP) factor and your recovery codes - the codes only as salted hashes that cannot be turned back into the codes themselves. If you never enable it, none of this data exists.

Newsletter opt-in. Whether you subscribed to our product newsletter, and the moment you did: the timestamp is the record of your consent. Unsubscribing removes it.

Your name on the Founding Members page. If you buy the Founder Lifetime Deal, we publish the name and waitlist position from your waitlist signup on the public Founding Members page only if you explicitly agree - through the unticked-by-default checkbox when you claim the offer, or the switch in Settings. You can withdraw that consent in Settings at any time, which takes your name off the page; giving or withdrawing it never affects your membership.

Billing data. Handled by Paddle.com Market Ltd.. We store only your subscription's identifiers, plan, status and period dates. We never receive or store your card number.

Why we use it, and our legal basis

  • To run the service you asked for - scanning, scoring, reporting and showing your dashboard: performance of our contract with you.
  • To bill you and keep the records tax law requires: performance of the contract, and our legal obligations.
  • To send product notification emails (scan results, score-drop alerts, competitor reminders, the weekly summary): your consent, which you can withdraw at any time, per email type, in Settings or through the link in any of them.
  • To send account, security and billing notices: performance of the contract. These are not marketing and cannot be switched off while the account exists.
  • To prevent abuse of free scans and forms (hashed IP, bot protection): our legitimate interest in not having the service drained by automated abuse.
  • To answer your support and contact messages: performance of our contract with you where you have an account, and otherwise our legitimate interest in replying to people who write to us.
  • To send the product newsletter: your consent, given through the optional checkbox at signup or the switch in Settings, and withdrawable there at any time. The newsletter is the only marketing email we send.
  • To secure your account with two-factor authentication (the authenticator factor and hashed recovery codes): performance of the contract - it is a protection you switch on yourself - and our legitimate interest in keeping accounts secure.
  • To show your name on the public Founding Members page: your consent, and nothing else. Agreeing is never a condition of the founder offer, and you can withdraw the consent in Settings at any time.
  • To understand why subscriptions are cancelled (the optional cancellation feedback): our legitimate interest in improving the service, based only on what you choose to tell us.

We do not sell your data, and we do not use it for unrelated marketing.

Who we share it with (subprocessor list)

The parties below process data on our behalf, only as needed to deliver the service. This is our subprocessor list; it is part of this document, so it carries the same version and the same change history. Where a row says consent is required, nothing is sent at all until you have agreed.

SubprocessorWhat it does for usWhat we send itEstablished inNeeds your consent?
OpenAI (ChatGPT)AI visibility measurementYour business details and the fetched page text of the websites in the scan (yours and any competitor you name)United StatesNo
Anthropic (Claude)AI visibility measurementAs aboveUnited StatesNo
Google (Gemini)AI visibility measurementAs aboveIreland and the United StatesNo
PerplexityAI visibility measurementAs aboveUnited StatesNo
Google (Places API)Looking up your public Google Business Profile listing during onboardingThe business name, address or Google listing link you enteredIreland and the United StatesNo - this lookup is part of the service, not analytics, and it runs whatever you chose about cookies
SupabaseDatabase, authentication and file storageEverything listed under "What we collect"United StatesNo
VercelApplication hostingRequest data, including the hashed IP addressUnited StatesNo
ResendDelivery of the emails we send youYour email address and the content of that emailUnited StatesNo
Cloudflare (Turnstile)Bot and abuse protection on public formsForm-submission signals from your browserUnited StatesNo
Google (Google Analytics 4)Website analyticsPage views and device data. See Cookies below for exactly what it receivesIreland and the United StatesYes - if you decline, or have not answered yet, the Google script is never loaded and nothing is sent

About the page text we send the AI providers. A visibility measurement works by asking AI assistants the kind of question your customers ask, and by reading the site being measured. So the prompts contain your business details and the text we fetched from the website addresses in that scan - your own, and any competitor address you entered. We do not send the AI providers your email address, your password or your billing data. What we fetch and why is set out in section 5 of the Terms, together with how a site owner can turn our crawler away: recometric.ai/bot.

Paddle.com Market Ltd. is separate from that list. As Merchant of Record it handles payments, invoicing and tax, and it does so as its own data controller rather than on our instructions - see the section above. Your card details go to Paddle and never to us. What comes back to us is only your subscription's identifiers, plan, status and period dates.

Some of these process data outside the European Economic Area, including in the United States; where they do, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses. We do not share your data with third parties for their own marketing.

How long we keep it

  • Account, business and scan data: for as long as your account exists. Delete your account and it is removed, along with your business profile, scan history, results and alerts.
  • Billing records: kept as long as tax and accounting law requires, even after the account is deleted. This is a legal obligation we cannot waive.
  • Consent records: kept while the account exists and for as long afterwards as is needed to prove the consent was given.
  • Support threads and cancellation feedback: kept while your account exists; both are deleted with the account.
  • Contact form messages: kept for as long as they are needed to answer and follow up on your enquiry, or until you ask us to remove them.
  • Two-factor authentication data: the authenticator factor is removed when you switch two-factor authentication off; the hashed recovery codes, including retired and used ones, are kept as part of the account's security history. All of it is deleted with the account.
  • Newsletter consent: the opt-in timestamp is kept until you unsubscribe or delete the account.
  • Founding-member public listing: your name stays on the page only while your consent stands and you hold the membership; withdraw the consent and it is removed.
  • Hashed IP records used for abuse prevention: kept only as long as they are useful for that purpose, then deleted.
  • Waitlist entries: until launch and we have contacted you, or until you ask us to remove them, whichever is first.
  • Analytics (only if you accepted): up to 14 months at Google, then deleted by them. Your cookie choice itself is kept for 12 months, after which we ask again. See Cookies.

Your rights

Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent at any time without affecting processing already carried out. You can delete your account yourself in Settings, and change or switch off any notification email there too.

To exercise any of these rights, contact the controller at info@seoklikk.hu. You also have the right to complain to a supervisory authority - in Hungary, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) - or to the authority where you live.

Automated decision-making

Your Recometric Score™ is produced automatically from AI assistants' answers about your business. It measures a business's visibility, not a person, and it has no legal or similarly significant effect on any individual. No automated decisions are made about you personally.

Cookies

Two kinds, and the difference matters: the first kind is required for the site to work at all, the second only exists if you say yes.

Strictly necessary - always on

  • Sign-in and session (Supabase) - keeps you logged in. Without it you could not use an account. Lasts for the session and its refresh window.
  • Your cookie choice (rc_analytics_consent) - records whether you accepted or declined analytics, so we stop asking. 12 months. It holds one word, granted or denied, and nothing that identifies you.
  • Bot protection (Cloudflare Turnstile) - verifies a human is filling in a public form. May set limited technical cookies or read device signals for security.

These do not require consent because the service cannot be delivered without them - and in the case of the choice cookie, because storing “no” is the only way to honour it.

Analytics - only after you accept

Google Analytics 4 (property G-GPREJ9BN0L), operated by Google Ireland Limited with processing also in the United States. It tells us which pages and campaigns bring people to Recometric.

  • Nothing loads before you agree. This is not a switch we turn off inside Google's script - the script itself is never fetched, so no request reaches Google and no cookie is set, unless and until you accept.
  • Cookies set if you accept: _ga and _ga_GPREJ9BN0L, which distinguish one browser from another. Google sets these for up to 2 years; we ask again after 12 months regardless. If you decline later, we delete them.
  • What Google receives: the page address, the referring page, rough location derived from your IP, and general device and browser information. Google Analytics 4 does not log or store IP addresses.
  • What Google never receives: your email address, your name, your account or user ID, your business name or website, your competitors, any scan result or Recometric Score™, and any subscription or payment identifier. Page addresses are stripped before they are sent: only a short list of non-personal parameters (campaign tags, plan slug) survives, and anything else - including search terms and one-time links from our emails - is removed.
  • No advertising. We do not run ads and do not build advertising audiences. Google's advertising features, ad personalisation and Google Signals are switched off, and the advertising consent signals stay refused even when you accept analytics.
  • Transfers outside the EEA: Google processes some of this data in the United States, under the EU-US Data Privacy Framework and the European Commission 's standard contractual clauses.
  • Retention: Google keeps the event-level data for the period set on the property, up to 14 months, then deletes it.

Changing your mind. Your answer is stored for 12 months and you can change it at any time - use here or in the footer of any page. Declining after having accepted also deletes the Google cookies described above.

We do not use advertising or cross-site tracking cookies.

Children

Recometric is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy. Each version carries a version number and date, shown at the top of this page. If a change affects your rights or obligations, we will ask you to accept the new version before you keep using the service.

Contact

SEOKLIKK Kft., Szabadság út 22. 2. em. 2. ajtó, Dunaújváros, Hungary. Email: info@seoklikk.hu. For questions about the product itself, you can also reach us at hello@recometric.ai.