The Data Controller for personal data collected through Search Console ADV ("the Service") is:
1. Account registration data
When creating an account: email address, password (stored as an irreversible hash, never in plain text), name, preferred language. Purpose: service delivery, authentication.
2. Google account data (OAuth 2.0)
If you connect a Google Search Console account: your Google name, email address and profile picture; OAuth access token and refresh token, the latter encrypted with AES-256 before being stored. Purpose: authenticating to the Google Search Console API on your behalf.
3. Google Search Console data and metrics
For sites with Insight SEO active, the Service retrieves and stores in a historical database (data warehouse): clicks, impressions, CTR, average position, search queries, page URLs, and data aggregated by country and device. This data relates to your web properties, not to individuals identified through Search Console itself, and is processed to power the Service's historical analysis features (Content Decay, Striking Distance, Alerts, Cannibalization and similar).
4. Billing data
When purchasing a paid package: name/company name, address, city, ZIP code, province, country, VAT number or tax code, PEC and SDI code (where applicable). Purpose: order management and accounting/administrative obligations.
5. Payment data
PayPal payments are handled entirely by PayPal: the Service only receives confirmation of the transaction outcome, not card or account details. For bank transfers, the Service stores the transfer reference details provided by the user (reference code, amount) for manual payment reconciliation.
6. Technical and security data
IP address and timestamp of login attempts, retained for security purposes (preventing unauthorized access and brute-force attacks).
7. Data extracted from the analyzed website
For cannibalization analysis, the Service runs a lightweight crawler against pages with existing traffic on the connected site, extracting title, meta robots, canonical link and H1 — public data about the analyzed website, not personal data about the user.
Data is not sold or transferred for third-party commercial purposes. It is shared, to the extent strictly necessary, with:
Passwords are stored as an irreversible hash (never in plain text). Google refresh tokens are encrypted with AES-256 before storage. Access to the Service is protected by rate-limiting on login attempts. HTTPS connections are used by default across the Service.
Under Articles 15-22 GDPR, you have the right to request at any time: access to your data, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. To exercise these rights: privacy@advsms.com. You can also revoke OAuth authorization at any time from myaccount.google.com/permissions.
If you have a complaint, you may contact the Italian Data Protection Authority (Garante Privacy) or your local supervisory authority.
The Service is not intended for individuals under 18 years of age. We do not knowingly collect data from minors; should we become aware of any, it will be deleted promptly.
This policy may be updated from time to time. Substantial changes will be communicated via a notice within the Service or by email to registered users.
For any question regarding the processing of personal data: privacy@advsms.com or by mail to Vicentia Srl, SS Padana verso Padova 170/D, 36100 Vicenza (VI), Italy.