Privacy Policy
How we handle your information.
The short version. We collect what is needed to verify, research, and deliver the Scorecard, schedule a call, and perform work you accept. We do not sell personal information or share it for cross-context behavioral advertising. You may request access, correction, export, or deletion, subject to legal, contractual, and suppression retention.
1. Information we collect
Scorecard intake: website URL, contact name, email, optional phone, language, consent, verification state, and request source. Private invitations may also include business identity and public context already associated with the invitation. Public evidence: pages, visible text, metadata, navigation, forms, technical signals, screenshots, and relevant public competitor sources. Booking: requested time, timezone, Google Calendar status, event identifiers, and information needed for the invitation. We also retain communications, accepted documents, payments, access records, support requests, and necessary security logs.
2. Verification and use
Scorecard research does not begin until you complete the deliberate POST confirmation on the verification page. We use information to analyze public evidence, apply deterministic scoring criteria, explain findings, deliver the report, send the two authorized reminders, prevent abuse, schedule or manage calls, prepare proposals, and perform accepted solutions.
3. AI and public sources
Our AI provider may receive public website content, non-sensitive business context, and public sources to explain evidence and prepare observations. The contact's personal name, email, and phone are excluded from the research prompt. AI does not set scores and must not treat website content as instructions. We do not authorize claims about private analytics, exact ranking, or revenue impact without business-supplied data.
4. Private reports and security
Results use opaque tokens and require no account. These are private capability links: anyone holding one may open the report, so do not publish it. Private pages use no-index and no-store controls. We apply URL validation, internal-network protections, request limits, business isolation, and provider controls, but no system is perfectly secure.
5. Email, follow-up, and suppression
The normal Scorecard sequence contains three total messages: delivery on day 0, a useful reminder on day 3, and a final reminder on day 10. Opening the verification email alone never starts research. Follow-up stops on booking, reply, opt-out, bounce, complaint, suppression, or conversion. We retain the minimum information needed to honor an opt-out or complaint and prevent future contact.
Text messages. If you text the SwrlSite number or agree on a call or form to a text follow-up, we keep your mobile number, the consent record (what you sent or agreed to, when, and from which number), and the message thread so we can reply and honor STOP. Text consent is used only for SwrlSite's own conversation with you about your request; it is not sold, shared with third parties for their marketing, or used to text on behalf of other businesses. Reply STOP to opt out at any time; we then keep only what is needed to prevent future texts.
6. Calendar and video calls
We check Google Calendar availability and create, reschedule, or cancel reservations after a confirmed action. Google may process names, email addresses, times, and business details. For Zoom calls, the Google reservation is private and SwrlSite sends the invitation; Zoom processes the schedule, a booking reference, and information you provide when joining. Earlier appointments may use Google Meet. Each provider applies its own terms. Checking times does not create an appointment. A meeting-link or email failure does not cancel an already-confirmed reservation.
7. Retention
Raw Scorecard scan artifacts are scheduled for deletion after 30 days. The delivered report snapshot is normally retained for 12 months. Deletion requests may shorten those periods except where consent, suppression, security, contract, payment, or legal-defense records must be retained. Paid-client data is retained during the service and for a reasonable period afterward under the agreement and applicable obligations.
8. Providers and disclosure
We may use Railway and database or object-storage providers for hosting, OpenAI for approved processing, Resend for email, Google for calendar and meetings, Stripe for payments, and domain, analytics, telephony, or support providers included in an accepted scope. We share only what is needed to operate, comply with law, protect security, or perform the agreement. Websites we host for clients on their own domains run on the same hosting providers, and a visitor's inquiry on such a site is delivered to that client. We do not sell personal information.
9. Selective outbound
For selective invitations, we may retain public business contact data, its source, one verifiable observation, approval and delivery state, and reply, bounce, complaint, or opt-out records. We do not run the full report before the recipient claims and verifies it. A claim enters the same Scorecard lifecycle and stops incompatible invitation follow-up.
Founder outbound calls. Calls our founder places from the business number are recorded for private internal review. SignalWire stores the audio and OpenAI processes it to create a transcript and summary. Recordings, transcripts, summaries and notes are accessible only to authorized staff, are not shared, and never appear in public website audit reports. They follow our lead/contact retention and deletion policy below.
10. Your rights and contact
You may request access, correction, export, or deletion, withdraw future consent, or exercise applicable U.S. state rights by emailing contact@swrlsite.com. We will verify the request and may retain limited records where law or a legitimate obligation requires it. The service is not directed to anyone under 18.