Privacy Policy
This policy describes how Miraqo processes the personal data of users who use the service available at app.miraqo.io and the marketing site miraqo.io, in accordance with EU Regulation 2016/679 (GDPR) and — with respect to Google API integrations — the Google API Services User Data Policy, including the Limited Use requirements.
1. Data controller
Delete di Terni Davide
VAT: IT02657410185
Email: [email protected]
Registered address: Viale della Libertà 14, Pavia, Italy
2. Personal data collected
2.1 Data provided by the user
- Account: email, password (hashed), first and last name, organisation name.
- Billing: company name, VAT/tax ID, address, payment method (handled by Stripe — Miraqo does not store card details).
- SEO projects: domains, keywords, URLs and configurations entered by the user.
2.2 Data collected via Google integrations (OAuth)
If the user voluntarily chooses to connect their Google account to a Miraqo project, we access the following data in read-only mode via OAuth 2.0:
- Google Search Console (scope
webmasters.readonly): list of properties the user has access to, search queries, indexed pages, clicks, impressions, CTR and average position — limited to the properties selected by the user. - Google Analytics 4 (scope
analytics.readonly): list of accessible GA4 properties, daily aggregate metrics (sessions, users, engagement, conversions) broken down by landing page — limited to the property selected by the user.
OAuth tokens (access and refresh) are encrypted at rest with AES-128 (Fernet, django-cryptography library) before being saved to the database.
2.3 Automatically collected data
- Technical access logs (IP address, user agent, date and time) retained for 30 days.
- Technical session cookies (required for authentication).
- Error telemetry via Sentry, with
send_default_pii=False. - A count of the application sections each user opens (section name, day, number of views), retained for 90 days, to understand which features are used and improve the product (legitimate interest, Art. 6(1)(f) GDPR). No IP address, no browsing data outside the application, no third-party tools.
2.4 Data collected via the site chatbot
The site provides a virtual assistant (chatbot) to answer questions about features, pricing and the free trial, and to allow users who wish to be contacted. When used, we process:
- Message content exchanged with the assistant.
- Email, only if the user voluntarily provides it to be contacted (commercial contact request).
- Pseudonymised IP address (hash) and referring page, for security and abuse-prevention purposes.
Messages are processed by AI service providers (listed in §6). We advise against entering personal or sensitive data in the chat. Before the first message, explicit consent to this privacy policy is required: we record the date, time and version of the policy accepted.
Website usage statistics. We measure visits to this website with Matomo, a statistics software installed on our own infrastructure (self-hosted): no browsing data is sent to external analytics providers. Measurement uses no cookies and the IP address is anonymised before being stored; the collected data is aggregated and does not allow visitors to be identified.
3. Purposes of processing
- Providing the SaaS service (creating and managing SEO projects, ranking, audit, reports).
- Importing and displaying Google Search Console and Google Analytics 4 data in the user’s dashboard, with their explicit authorisation.
- Billing, subscription management and tax compliance.
- Service communications (notifications on significant changes, periodic reports, sync errors).
- Pre-sales assistance via chatbot and handling commercial contact requests, at the user’s initiative.
- Infrastructure security and abuse prevention.
4. Legal basis
- Performance of a contract (Art. 6.1.b GDPR) for providing the service.
- Explicit consent (Art. 6.1.a GDPR) for connecting Google integrations and for non-essential communications.
- Legal obligation (Art. 6.1.c GDPR) for billing and document retention.
- Legitimate interest (Art. 6.1.f GDPR) for security and abuse prevention.
- Explicit consent (Art. 6.1.a GDPR) for using the chatbot and any contact requests.
5. Limited use of Google data (Limited Use Disclosure)
Miraqo fully complies with the Google API Services User Data Policy — Limited Use Disclosure.
Specifically, we declare that data received from Google Search Console and Google Analytics 4 is used exclusively to:
- Show the user their own ranking and organic traffic metrics in the Miraqo dashboard.
- Correlate GA4 traffic metrics with the user’s tracked keywords to enable richer analysis.
- Export data in PDF reports or shareable links created by the user.
We do NOT use Google data for:
- Transfer, sale or sharing with third parties for profiling, marketing, advertising or data brokering.
- Training AI models, whether internal or third-party.
- Human access, except (i) with the user’s explicit consent, (ii) for technical assistance with consent, (iii) legal obligations, or (iv) internal security purposes in aggregate, de-identified form.
6. Third parties that process data
The following parties, acting as processors under Art. 28 GDPR, may process personal data in the course of the services they provide:
- NameHero LLC (United States) — infrastructure hosting; the servers delivering the service are located in the United Kingdom (Erith data centre, OVH infrastructure). Off-site backups are stored in the United States (California). NameHero support staff, bound by confidentiality obligations, may access the servers from the United States and India solely as required for technical support. Transfers to the United States and India are governed by Standard Contractual Clauses (Modules 2 and 3) signed on 18 August 2026.
- Cloudflare, Inc. (United States) — CDN, DDoS protection and TLS certificate management for the website and the application. All traffic passes through its servers: it processes IP addresses, request headers and browsing metadata. It does not retain application content.
- Stripe Payments Europe Ltd. — payment processing and billing data.
- TeamSystem S.p.A. (Fatture in Cloud) — invoice issuance and transmission to the Italian Interchange System (SdI): receives company name, VAT/tax number, address, recipient code/PEC and amounts.
- Google Ireland Ltd. — limited to data requested by the user via OAuth (GSC, GA4).
- Google LLC (Google Fonts) — the site loads web fonts via the
fonts.googleapis.comandfonts.gstatic.comCDNs; when pages load, the browser’s IP address is transmitted to Google’s servers to serve the fonts. - Anthropic PBC (United States) — language models that process the requests of the AI features the user activates (assistant, content generation, review replies, brand analysis): receives the prompts, which contain no identifying data; the content is not used to train models, as provided by the provider’s Commercial Terms.
- OpenRouter Inc. (United States) — routing of image-generation requests only, to OpenAI’s image model (Content Generator add-on only): receives the description of the image to be generated.
- Indigo Stream Technologies Ltd. (Copyscape) (United States) — plagiarism check on texts produced by the Content Generator: receives the generated text. Active only for users who purchased the corresponding add-on.
- Functional Software Inc. (Sentry) (United States; data stored in the European region, Frankfurt) — application error telemetry, configured without PII.
- AhaSend B.V. (Netherlands) — delivery of the application’s transactional emails (sign-up, password reset, invitations, notifications and reports): processes the recipient and the content of the message. It does not record opens or link clicks, and links are not rewritten.
- DNSExit (United States) — SMTP smart host of the mail server: it relays outbound messages sent from our mailboxes (for example info@ and privacy@), processing recipient and content in transit. The mailboxes reside on NameHero’s servers.
All providers located outside the European Union operate under the safeguards set out in Chapter V of the GDPR (adequacy decisions, Standard Contractual Clauses and/or the EU-US Data Privacy Framework, depending on the provider).
7. Retention period
- Account and project data: for as long as the organisation exists, even with an expired subscription. Closing the organisation from the settings deletes them immediately and irreversibly; only backup copies remain, overwritten by normal rotation. Organisations expired for more than 24 months may be closed by us, with 30 days’ notice by email.
- Billing data: 10 years as required by Italian tax regulations.
- Google OAuth tokens (GSC, GA4): while the integration remains active; deleted within 24 hours of manual disconnection or account deletion.
- Synced GSC/GA4 data: up to 16 months (rolling window aligned with Google API limits), deleted on revocation or account deletion.
- Access logs: 30 days.
- Sentry errors: 30 days.
- Site chat transcripts: maximum 30 days from the conversation, then automatically deleted.
- Contact requests (leads) from the chatbot: up to 24 months from last contact, unless an earlier deletion request is made; proof of consent (date and policy version) is retained alongside the lead.
8. Security measures
- HTTPS mandatory on all endpoints (TLS 1.2+).
- OAuth tokens and other credentials encrypted at rest (AES-128 Fernet).
- User passwords stored only as hashes using Argon2/PBKDF2.
- Login rate limiting, optional two-factor authentication.
- Daily backups of the database, filesystem and mailboxes to an external destination, with at least 10-day retention.
- Limited and audited administrative access.
9. Data subject rights
Users may exercise at any time the rights provided by Articles 15–22 GDPR:
- Access to their data.
- Rectification of inaccurate data.
- Erasure (right to be forgotten).
- Restriction of and objection to processing.
- Data portability (CSV/JSON export).
- Withdrawal of consent, in particular for Google integrations: available from the project “Integrations” page with immediate deletion of tokens and associated data, or directly from myaccount.google.com/permissions.
- Complaint to the supervisory authority. In Italy: www.garanteprivacy.it.
To exercise your rights, write to [email protected]. We respond within 30 days.
10. Cookies
The site uses only technical session cookies, necessary for the app to function and not used for profiling. The virtual assistant (chatbot) does not use cookies or store data on the user’s device. For details, see the Cookie Policy.
11. Changes to this policy
Significant changes will be notified by email to registered users and published on this page with at least 30 days’ notice before taking effect, except for changes required by legal obligations.
12. Contact
For any question about the use of your data, contact us at [email protected].