Privacy Policy
Version 1.0 · Effective August 2026 · GeoScript, Inc.
GeoScript, Inc. ("GeoScript," "we," "our," or "us") respects your privacy and is committed to protecting the personal data we collect from or about you. This Privacy Policy describes:
- What personal data we collect and why;
- How we use, store, and share it;
- Your rights and choices regarding your data;
- How to contact us with questions or requests.
This Policy applies to data collected through geoscript.ai and the GeoScript platform (the "Services"). It does not apply to data that GeoScript processes on behalf of customers acting as data controllers — that processing is governed by the customer's subscription agreement and, where applicable, a Data Processing Agreement (DPA).
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
For personal data collected directly through geoscript.ai and the GeoScript platform (account data, contact data, marketing communications), GeoScript, Inc. is the data controller. For purposes of GDPR, GeoScript, Inc. is a Delaware corporation operating in the United States.
Contact for privacy matters: hello@geoscript.ai
GeoScript does not currently have a designated Data Protection Officer (DPO). Privacy inquiries should be directed to the email above.
2. Information We Collect
We collect three categories of information:
2.1 Information You Provide Directly
- Account data: name, email address, company name, job title, password when you register for a GeoScript account.
- Billing data: payment method details, billing address, and transaction history. Payment card data is handled directly by Stripe and is not stored on GeoScript servers.
- Communications: the content of messages you send us through contact forms, support requests, email, or chat — including your name and email address.
- Checker and waitlist data: if you use the free AI visibility checker, we may collect the business name and city you search, and if you submit the email capture form, your name, agency name, email address, seat count interest, feedback responses, and waitlist opt-in status.
- Partner and rep applications: if you apply to become an agency partner, affiliate, or sales rep, we collect the information submitted in those forms.
2.2 Information Collected Automatically
- Log data: IP address, browser type and version, device type, operating system, referring URLs, pages visited, time and date of visits, and session duration.
- Usage data: features accessed, actions taken within the platform, dashboard interactions, report generation activity, and API usage patterns.
- Cookies and similar technologies: we use essential cookies for authentication and session management. We may use analytics cookies (e.g., to understand aggregate usage patterns). See Section 8 for details.
2.3 Signal Data Collected via the GeoScript Script (Customer Data)
When customers install the GeoScript JavaScript tracking script on their websites (or their clients' websites), the Script collects Signal Data — including: AI engine crawler activity, AI referral session events, citation events, AI-attributed traffic signals, and related behavioral data from monitored websites.
Signal Data relates to website visitors and is collected on behalf of the customer (who is the data controller with respect to their website visitors). GeoScript acts as a data processor for this purpose under the customer's subscription agreement. Signal Data does not typically include directly identifiable personal information (such as names or email addresses of website visitors) unless the customer's website passes such data to the Script.
As described in the Terms of Service, all Signal Data is assigned to and owned by GeoScript. GeoScript uses Signal Data — in aggregate and anonymized form — to build and improve its AI search behavior dataset, power benchmark comparisons, develop new features, and publish research.
Customers are responsible for ensuring their use of the Script complies with applicable privacy laws, including providing required privacy notices to their website visitors and obtaining any required consents.
3. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Providing and operating the Services | Account data, billing data, usage data | Performance of contract (Art. 6(1)(b)) |
| Processing payments and managing subscriptions | Billing data, account data | Performance of contract (Art. 6(1)(b)) |
| Responding to support and sales inquiries | Communications, account data | Performance of contract / Legitimate interests (Art. 6(1)(b)/(f)) |
| Sending transactional emails (receipts, account notices, usage alerts) | Account data, billing data | Performance of contract (Art. 6(1)(b)) |
| Sending product updates, feature announcements, and marketing communications | Account data, email address | Consent (Art. 6(1)(a)) or Legitimate interests (Art. 6(1)(f)) — with opt-out |
| Improving and developing the Services | Usage data, log data, Signal Data (aggregated) | Legitimate interests (Art. 6(1)(f)) |
| Building and maintaining the AI search behavior dataset | Signal Data (aggregated/anonymized) | Legitimate interests (Art. 6(1)(f)) |
| Security, fraud prevention, and abuse detection | Log data, usage data, account data | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations | As required by applicable law | Legal obligation (Art. 6(1)(c)) |
| Waitlist management and founding partner communications | Checker/waitlist data | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests as our legal basis, we have assessed that our interests do not override the privacy rights of data subjects. You have the right to object to processing based on legitimate interests (see Section 9).
4. How We Share Your Information
We do not sell your personal data. We share personal data only in the following circumstances:
4.1 Service Providers (Subprocessors)
We share personal data with trusted third-party vendors who process data on our behalf to provide the Services. These include:
- Supabase — database, authentication, and storage (US)
- Stripe — payment processing (US). Stripe has its own privacy policy; GeoScript does not store full card numbers.
- Pinecone — vector database for AI search indexing (US)
- OpenAI / Anthropic / Perplexity / Google — AI engine query processing for the visibility monitoring service (US)
- Upstash — caching and rate limiting (US)
- Vercel — hosting and deployment infrastructure (US)
- Email delivery provider (TBD) — transactional and marketing email delivery
All subprocessors are contractually bound to process data only on GeoScript's instructions and to implement appropriate security measures. A full and up-to-date subprocessor list is available at geoscript.ai/data-policy.
4.2 Legal Requirements
We may disclose personal data when required to do so by law, court order, subpoena, or other legal process, or when we believe in good faith that disclosure is necessary to: protect our rights or property; prevent fraud or illegal activity; protect the safety of our users or the public; or comply with a governmental request.
4.3 Business Transfers
If GeoScript is involved in a merger, acquisition, asset sale, or other corporate transaction, personal data may be transferred to the acquirer or successor entity. We will provide notice before personal data is transferred and becomes subject to a different privacy policy.
4.4 Aggregated / Anonymized Data
We may share aggregated, anonymized data (including industry benchmarks, market-level AI search behavior statistics, and research publications) with the public, partners, or investors. This data does not identify individual customers or their clients.
4.5 With Your Consent
We may share data with third parties when you have given us explicit consent to do so.
5. Data Retention
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:
| Data Type | Retention Period |
|---|---|
| Account data (active customers) | Duration of subscription + 60 days after termination |
| Account data (deleted accounts) | Deleted within 60 days of account deletion request |
| Billing records and transaction history | 7 years (tax and accounting compliance) |
| Support and communications | 3 years from last interaction |
| Waitlist / checker submissions | Until launch or 24 months, whichever is first — or until you request deletion |
| Log and usage data | 13 months rolling |
| Signal Data (collected via Script) | Retained by GeoScript indefinitely as part of the AI search dataset; not subject to customer deletion requests (see Terms of Service §6.1) |
| Aggregated/anonymized data | Retained indefinitely; cannot be linked back to individuals |
6. International Data Transfers
GeoScript is based in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data will be transferred to and processed in the United States, which may not provide the same level of data protection as your home country.
We rely on the following transfer mechanisms for EU/EEA to US transfers:
- Standard Contractual Clauses (SCCs) — we incorporate the European Commission's approved SCCs (Module 2: controller to processor) into our agreements with subprocessors. Copies are available upon request.
- EU-U.S. Data Privacy Framework (DPF) — where applicable subprocessors are certified under the DPF, we rely on that certification as an additional transfer mechanism.
For questions about cross-border data transfers or to obtain a copy of applicable SCCs, contact hello@geoscript.ai.
7. Security
We implement technical and organizational measures designed to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit via TLS 1.2 or higher;
- Encryption of data at rest;
- Role-based access controls limiting data access to authorized personnel;
- Multi-factor authentication for administrative access;
- Regular security reviews of our infrastructure and subprocessors.
No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable security measures, we cannot guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you and, where required, the relevant supervisory authority within the timeframes required by applicable law (72 hours under GDPR).
8. Cookies and Tracking Technologies
We use cookies and similar technologies on geoscript.ai. Here is what we use and why:
| Category | Purpose | Can be declined? |
|---|---|---|
| Strictly necessary | Authentication, session management, security tokens, password-gating. Required for the site to function. | No — required for core function |
| Analytics | Aggregate usage analytics to understand how visitors use the site (e.g., page views, feature usage). Data is anonymized or pseudonymized. | Yes — via cookie preferences |
| Marketing / retargeting | Retargeting pixels (e.g., Meta Pixel, Google Tag) placed once you sign up or opt in, to reach you on other platforms with relevant content. | Yes — via cookie preferences |
A full Cookie Policy listing individual cookie names, providers, durations, and opt-out instructions will be published at geoscript.ai/cookie-policy prior to deploying non-essential cookies. Non-essential cookies will not be set before a consent banner is active.
9. Your Privacy Rights
Depending on where you are located, you may have the following rights regarding your personal data:
9.1 Rights Under GDPR (EEA, UK, Switzerland Residents)
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): Request deletion of your personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful. Note: Signal Data is not subject to erasure requests (see §2.3).
- Right to restriction (Art. 18): Request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20): Receive your personal data in a structured, machine-readable format where processing is based on consent or contract.
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: File a complaint with your local data protection supervisory authority. For EU residents, find your authority at edpb.europa.eu.
9.2 Rights Under CCPA (California Residents)
California residents have the following rights under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):
- Right to know: request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to delete: request deletion of personal information we have collected (subject to certain exceptions).
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale or sharing: GeoScript does not sell or share personal information for cross-context behavioral advertising.
- Right to non-discrimination: we will not discriminate against you for exercising your CCPA rights.
- Right to limit use of sensitive personal information: we do not collect sensitive personal information as defined under CPRA.
Categories of personal information collected (CCPA disclosure): identifiers (name, email, IP address); commercial information (purchase history); internet / electronic network activity (usage data, log data); geolocation (approximate, from IP). We do not collect sensitive personal information.
Sources: directly from you; automatically from your device; from our analytics and infrastructure providers.
Business purpose for collection: providing the Services, security, product improvement, communications.
9.3 How to Exercise Your Rights
To submit a privacy request (access, deletion, correction, portability, objection):
- Email hello@geoscript.ai with the subject line "Privacy Request"
- Include your full name, email address associated with your account, and a description of your request
- We will verify your identity before processing the request and respond within 30 days (or 45 days if an extension is needed, with notice)
We may need to retain certain data for legal compliance, security, or legitimate business reasons even after a deletion request.
10. Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child under 18, please contact us at hello@geoscript.ai and we will promptly delete it.
11. Third-Party Links and Services
The Services may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through the GeoScript platform.
12. Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. GeoScript does not currently respond to DNT signals because no industry-wide standard for DNT compliance has been adopted. We will revisit this position if such a standard is established.
13. Marketing Communications
If you opt in to receive marketing communications from GeoScript (including via our waitlist or founding partner form), we will send you product updates, announcements, and relevant content.
You can opt out at any time by:
- Clicking "unsubscribe" in any marketing email;
- Emailing hello@geoscript.ai with the subject line "Unsubscribe."
Opting out of marketing communications does not affect transactional emails related to your account (receipts, security alerts, service notices).
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address on your account) or by posting a prominent notice on geoscript.ai, at least 30 days before the change takes effect.
The "Effective" date at the top of this page indicates when the current version took effect. We encourage you to review this page periodically. Prior versions are available upon request.
15. Contact Us
For privacy questions, requests, or complaints:
GeoScript, Inc.
Privacy Inquiries
hello@geoscript.ai
If you are located in the EEA and believe your GDPR rights have not been adequately addressed, you have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.
This Privacy Policy was last updated in August 2026. Prior versions are available upon request.