Privacy statement
Last updated: August 2026
This is an English translation of our Dutch document, provided for your convenience. The Dutch version is the binding one; in case of any discrepancy between the two, the Dutch text prevails. You can read it at geocrafter.nl/nl/terms and geocrafter.nl/nl/privacy.
1. Introduction
GEO-Crafter measures how visible your company is in the answers of AI assistants. The service is aimed exclusively at businesses; the data we process is essentially business contact and domain data. To deliver the service we also process a limited amount of personal data. In this statement we explain which data, why, with whom we share it and how long we keep it.
GEO-Crafter is an initiative of iPeople (Dutch Chamber of Commerce no. 52880303), established in Haarlem, the Netherlands. For these processing activities we are the controller within the meaning of the GDPR.
2. Which data we process
- Account data: your name and email address (plus a normalised variant of it for account management), an encrypted password (hashed with bcrypt) that we cannot read, whether your email address has been verified, which plan you have, any administrator status you may have and the date your account was created.
- Domain, scan and report data: the domain or brand you provide, the information we derive from that domain (a website profile), the questions generated for your scan, and the results: whether and how you are mentioned in AI answers, the sentiment, the source URLs and citations, the competitors that appear, the recommended action points and, if you use monitoring, your monitoring settings. We record your scan and quota usage in order to deliver the service to you. Please note: scan results reflect what AI assistants say about your market and may therefore also contain data about third parties, such as company names and, for example in the case of a sole trader or a named entrepreneur, individuals identifiable from them. That information comes from the answers of AI assistants and the sources they cite; such answers may contain inaccuracies. We process this data on the basis of our legitimate interest in delivering the service; our analysis focuses on organisations and brands and we do not build profiles of individuals. Are you named in a report as a third party and is it incorrect, or do you wish to object? Email [email protected]; see also point 8.
- Purchase and subscription data: if you take out a subscription, we process the business details you provide before checkout (company name and Chamber of Commerce or VAT number), your acceptance of the terms (with version and timestamp) and your business declaration, plus your plan and payment status and invoicing data. See point 6 for the role of our payment service provider.
- Email verification and invitations: for an access request or verification we process your email address, the domain provided and, if entered, your market, plus the status of the invitation and the associated (temporary) tokens. This allows us to grant you access and keep you informed.
- Technical logs: our servers temporarily record technical data (such as an IP address and error messages) in order to keep the service working and secure and to prevent abuse.
Administrator access for support, security and quality. Specifically designated administrators may temporarily gain access to your account environment for support, investigating malfunctions, security and checking and improving the quality of scans, reports and recommendations. During such a session they can access the same data and functions as the account user. We limit access to what is necessary for the specific purpose and, where possible, use aggregated or non-identifiable information for improving the service. Every session is logged, including the administrator involved, the reason and the time.
3. Legal bases
We process this data on the following bases (article 6 GDPR):
- Performance of the agreement: account data, domain and scan data, granting access, and in the case of a subscription the checkout and subscription administration.
- Legal obligation: the tax administration of invoices and purchases (kept for 7 years, see point 7).
- Legitimate interest: technical logs, security and abuse prevention (a working, secure service); retaining contract and acceptance evidence for purchases; the processing of third-party data in scan results (see point 2); and administrator access for support and quality assurance (see point 2). Where we use scan data for broader product analysis, we do so in aggregated, non-identifiable form wherever possible.
- Consent: in so far as you give it to us explicitly, for example when leaving voluntary feedback. You can withdraw that consent at any time via [email protected].
4. What we do not do
- We do not sell your data to third parties.
- We do not use your data for third-party advertising or profiling.
- The scans concern business domain and brand information; they are not intended to process special categories of personal data or otherwise sensitive personal data. Please do not put such data into your scans.
5. Cookies
GEO-Crafter does not use tracking or advertising cookies.
In essence one functional cookie is used:
- Session cookie (login): after you log in we store a secure session (an encrypted token) so that you stay logged in. It contains no data that is readable by third parties.
Under the cookie rules (article 11.7a of the Dutch Telecommunications Act) no consent banner is required for strictly necessary functional cookies, which is why we do not have one.
6. Service providers and transfers
We engage the following processors. Where applicable, data processing agreements in accordance with the GDPR have been concluded with them.
- Hetzner Online GmbH (hosting and database, Germany/EU): our application and database run on servers within the EU.
- Cloudflare, Inc. (CDN, DNS and security): cloudflare.com/privacypolicy.
- Umami (privacy-friendly web statistics, EU-hosted): measures aggregated page visits without cookies and without personal data traceable to you.
- Brevo (Sendinblue SAS) (transactional email such as verification and invitation messages, France/EU): brevo.com/legal/privacypolicy.
- Google Cloud / Vertex AI (AI analysis for the free scan and, depending on the configuration, for the Gemini measurements in the paid scan): the domain and question data you provide are processed in order to measure your visibility.
- AI providers and specialised data partners (for the scans): in order to measure your visibility, the questions generated for your scan are put to AI assistants (ChatGPT by OpenAI, Claude by Anthropic, Gemini and Google AI Overviews by Google, and Perplexity) either directly or through a specialised data partner established in the EU. The questions contain business domain and brand information, no account data. We also use external SERP and keyword data to help generate the scan questions.
Transfers outside the EEA: Hetzner (hosting/database) and Brevo (email) are located within the EU, as is our data partner for AI measurements. Cloudflare (US) and the AI providers that process scans (Google, OpenAI, Anthropic and Perplexity) are partly established outside the EEA. For those transfers we rely on the EU-US Data Privacy Framework (for certified parties) and/or the European standard contractual clauses (SCCs). Your account data stays on our EU infrastructure; only the business domain and question information from your scan goes to the AI providers.
Payments through Stripe. For subscriptions we use Stripe Payments Europe, Limited (Ireland/EU). In doing so, Stripe receives among other things your name, email address, company and invoicing details, tax number and transaction and payment data. Full card details are processed directly by Stripe and are not stored by us. Stripe acts as our processor for certain processing activities and as an independent controller for others, for example for fraud prevention, risk management and statutory financial obligations; see stripe.com/privacy. We ourselves keep and manage the subscription and payment administration needed to perform the agreement and for our statutory records, including your plan, the subscription status, Stripe references, invoices and tax data.
7. Retention periods
- Account and scan data: for as long as you have an account with us. You can delete scans yourself. If you delete your account (or ask us to), we erase the associated data within 30 days.
- Verification and invitation tokens: verification links (such as for password recovery or an email change) expire within 24 hours; an invitation link is valid for 14 days. Expired or used tokens are automatically deleted shortly afterwards.
- Access requests and invitations: up to a maximum of 12 months after they have been handled or have expired, after which we delete them.
- Administrator access log and cost records: we keep the log of administrator sessions (point 2) and our internal record of API usage for a maximum of 12 months.
- Technical logs: in our own systems for a maximum of 90 days, solely for security and troubleshooting. Service providers we engage (such as our hosting and payment service providers, see point 6) apply their own periods to their own logs.
- Invoice and purchase data: data required for our (tax) administration, such as invoices and the company details and declarations recorded at the time of a purchase, are kept for 7 years under the statutory retention obligation, even if your account has since been deleted.
Would you like your account or data deleted? Send a message to [email protected].
8. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, objection and data portability in respect of the personal data we process about you. You can submit a request via [email protected]. We respond within the statutory period.
Do you disagree with how we handle your data? You can lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in your own country.
9. Contact
GEO-Crafter is an initiative of iPeople.
- Chamber of Commerce: 52880303
- Place of business: Haarlem, the Netherlands
- Correspondence address: Box A0833, Keurenplein 41, 1069 CD Amsterdam
- VAT identification number: NL001434116B43
- Email: [email protected]
10. Changes
We may amend this privacy statement. The date at the top indicates when it was last updated. In the event of a material change that affects you as a registered user, we inform you appropriately (for example by email or a notification in the app) before the change takes effect for you.