Skip to content

Privacy Policy

Last updated: 2026-07-07

This policy has been prepared in three languages: English, Turkish and Portuguese. In case of any inconsistency between versions, the English version prevails. en tr pt

This Privacy Policy explains what personal data MessGEO ("we") collects, why we collect it and your rights under the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK). Data controller: Serkan Sayar, a sole trader operating under the trade name MessGEO, Tv. Conde Silva Monteiro 33, 4430-361 Vila Nova de Gaia, Portugal. NIF 322144817. Contact: [email protected].

1. Activity records

To keep the Service secure, prevent misuse and support you better, certain account actions (such as sign-in, panel setup and deletion, starting measurements, orders and purchases) are recorded with a timestamp and IP address for a limited time. These records are used only for these purposes, are not shared with third parties, and older entries are deleted regularly.

2. Data we collect

Account data: name, email, company, language preference and a one-way password hash (never the password itself). Service data: orders, reports, support messages, credit history and the tool queries you run (including target URLs and scores). Technical data: IP address used for rate limiting and abuse prevention, and strictly necessary cookies.

3. Why we process it

To provide the Service (performance of contract), to secure the Service against abuse (legitimate interest), to send service notifications such as order and account emails (performance of contract) and to comply with legal obligations. We do not sell personal data and we do not use it for third-party advertising.

4. Emails

To our account holders we send transactional emails only: welcome, password reset, order and support notifications. We also send emails introducing our service to businesses; those are described in the section 'Outreach emails we send to businesses' below. Delivery is handled by Resend (resend.com) acting as our processor. Emails are sent in the language you chose in your panel settings.

5. Outreach emails we send to businesses

We send emails introducing our service to businesses. We do not obtain the contact details used in those emails from you: we compile them from publicly available sources, mainly Google Maps business listings and the business's own website (source disclosure under GDPR Article 14). The data we process is the business name, public contact email, phone, address and website. Our legal basis is legitimate interest (GDPR Article 6(1)(f)): direct marketing addressed to businesses. We keep this data for 24 months after the last contact. If you object, we delete your record immediately and keep only an irreversible hash of your email address, solely to make sure we never email you again. To opt out, reply 'remove' to any email we send or write to [email protected]. You can exercise your rights of access, rectification, erasure and objection via [email protected], and you may also lodge a complaint with the Portuguese data protection authority CNPD or, in Türkiye, with the Personal Data Protection Board.

6. Cookies

We use strictly necessary cookies only. Details are in the Cookie Policy.

7. Data retention

Account data is kept while your account exists. If you delete your account, personal data (profile, orders, reports, tickets, credit history and email logs) is deleted immediately; tool query logs are anonymized and kept only as abuse prevention statistics.

8. Your rights

You can access and export all your data as a JSON file from your panel settings, correct your data, delete your account yourself at any time, and object to or restrict processing by contacting us. You may also lodge a complaint with your local supervisory authority.

9. Data sharing and transfers

Data is shared only with the infrastructure providers necessary to run the Service (hosting and email delivery), acting under data processing terms. Data may be processed in data centers outside your country with appropriate safeguards.

10. Security

Passwords are stored as strong one-way hashes, panel actions are protected against cross-site request forgery, access is role-based and internal data files are not reachable from the web. No method of transmission is 100% secure; we protect your data using industry practices.

11. Changes

We may update this policy; the date above reflects the latest version.

Privacy questions and data requests: [email protected]