Privacy Policy
Effective October 1, 2026
This policy explains what personal information we collect when you use localbusinessaudit.com, why we collect it, who we share it with, and the choices you have.
1. Who we are
LocalBusinessAudit (“we”, “us”) operates the website localbusinessaudit.com and the audit service offered on it (the “Service”). We are the controller of the personal information described in this policy. [To be completed: registered company name, entity type and registered address]
When agencies and other business customers use the Service to handle information about their own clients, we act on their behalf as a processor. That is covered by our Data Processing Agreement, not by this policy.
2. Information we collect
Information you give us
- Audit details: the business name, website address, city and business category you enter to run an audit.
- Email address: if you enter one on the audit form or to unlock a full report.
- Account details: your name, email address and password when you register. Passwords are stored only as a one-way hash; we cannot read them.
- Team and client information: email addresses of people you invite to your team, businesses you add as clients or in batches, addresses you email reports to, and any branding (name, logo, contact line) you upload.
- Messages: anything you send us by email.
Information collected automatically
- IP address: our servers receive your IP address with every request and it appears in our server logs. For visitors without an account we also store a one-way keyed hash of the IP address with each audit, to apply the monthly limit on free audits. We do not store the address itself in our database.
- One cookie: when you log in we set a single cookie,
lba_session, that keeps you signed in for up to 30 days. It is strictly necessary for accounts to work. We do not use advertising or analytics cookies. - Usage records: which audits were run under your account, when, and their status, along with the search phrases, schedules and API keys you set up. API keys are stored only as a one-way hash.
Information from other sources
- The audited website: our crawler reads the publicly available homepage of the website being audited, its robots.txt and sitemap, and checks a sample of its links.
- Google: we request a mobile speed test for the website from Google PageSpeed Insights, and public Google Business Profile information (such as name, category, rating, review count, phone number and website) for the business and its local competitors from the Google Places API.
- Stripe: if you subscribe, Stripe tells us your subscription status, plan and renewal date. We never receive or store your full card details.
3. How we use information
| Purpose | Legal basis (where GDPR or UK GDPR applies) |
|---|---|
| Running audits and showing you reports | Performing our contract with you, or steps you ask for before entering one |
| Creating and securing your account, confirming your email, resetting passwords | Performing our contract with you |
| Taking payment and managing subscriptions | Performing our contract with you; legal obligations for tax and accounting records |
| Applying usage limits and preventing abuse (including the hashed IP address) | Our legitimate interest in keeping the Service fair and secure |
| Contacting you about your audit and about our related services | Our legitimate interest in following up with people who asked for an audit, or your consent where the law requires it. You can opt out at any time |
| Fixing problems and improving the Service | Our legitimate interest in running a reliable service |
| Meeting legal requirements and enforcing our terms | Legal obligation; our legitimate interests |
We do not sell personal information, and we do not use it to make decisions with legal or similarly significant effects by automated means.
4. Report links
Each audit report has its own web address containing a long random identifier. Anyone who has that address can view the report, so share it only with people you want to see it. Reports are marked so that search engines do not list them.
Reports describe a business and its website. They do not show the email address or account of the person who ran the audit.
6. How long we keep information
- Account information and audits saved to an account: for as long as the account exists, then deleted on request.
- Audits run without an account, and emails entered to unlock them: until you ask us to delete them or we no longer need them for the purposes above.
- Login sessions: up to 30 days. Password-reset links expire after 60 minutes, email-confirmation links after 3 days, and team invitations after 7 days.
- Operational event records: 30 days.
- Billing records: as long as tax and accounting law requires.
7. Your choices and rights
You can update your name and password in Settings. To delete your account, obtain a copy of your information, correct it, or stop receiving messages from us, email [email protected] from the address the request relates to.
Depending on where you live, you may also have the right to access, correct, delete or restrict the use of your personal information, to object to our use of it, to receive it in a portable format, and to withdraw consent. People in the EEA, UK and Switzerland can complain to their data protection authority. California residents have the right to know, delete and correct their personal information and not to be discriminated against for exercising those rights; we do not sell or share personal information as those terms are defined in California law.
We respond to requests within 30 days. We may need to confirm your identity first.
8. If your website or business was audited
Anyone can ask the Service to audit a public business website. The audit reads only publicly available pages and public listing information, including contact details the business publishes on its homepage, such as a phone number or email address. Our crawler identifies itself as LocalBusinessAuditBot, and website owners can stop it as described on our bot page. If you have a concern about an audit of your business, contact [email protected].
9. Security
We protect information with encrypted connections (HTTPS), hashed passwords, hashed login and reset tokens, and access controls that limit our staff's access to what their role requires. No system is perfectly secure; if a breach affects your personal information we will notify you and the relevant authorities as the law requires.
10. International transfers
Our providers may process information in the United States and other countries. Where information is transferred out of the EEA, UK or Switzerland, we rely on safeguards recognised by law, such as the European Commission's standard contractual clauses.
11. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect personal information from children.
12. Changes to this policy
If we change this policy we will update the effective date above, and for significant changes we will notify account holders by email before the change takes effect.
13. Contact
Questions about privacy: [email protected]. [To be completed: registered company name, entity type and registered address]
Related documents: Terms of Service · Refund Policy · Master Service Agreement · Data Processing Agreement