Privacy Policy
Last updated: January 2025
1. Our Commitment to Your Privacy
Courtane Agency ("we," "our," or "us") is a digital marketing agency headquartered in Albuquerque, New Mexico, specializing in SEO optimization, media buying, and growth strategy services. Your privacy is fundamental to our business, and we are committed to protecting the confidentiality and security of your personal and business information.
This Privacy Policy explains in detail how we collect, use, process, disclose, and safeguard your information when you interact with our website, use our digital marketing services, access our SEO audit platform, utilize our AI-powered recommendation engine, or engage with our media buying and growth strategy services.
By using our services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
Effective Date: This Privacy Policy is effective as of January 2025 and applies to all information collected by Courtane Agency on or after this date.
2. Information We Collect
We collect information that helps us provide, maintain, and improve our digital marketing services. The types of information we collect depend on how you interact with our services.
2.1 Information You Provide Directly
Account Registration Information:
- Full name and business title
- Business email address (required for account creation)
- Phone number (for account verification and communication)
- Company name and business type
- Business address and mailing information
- Password and security questions (stored securely using industry-standard encryption)
Website and Domain Information:
- Website URLs for SEO audits and tracking
- Domain names and subdomain information
- Website structure, content, and metadata
- Historical performance data you choose to share
- Sitemap URLs and robots.txt files
Payment and Billing Information:
- Credit card number, expiration date, and CVV (processed securely through PCI-compliant payment processors)
- Billing address
- Payment history and subscription details
- Tax identification numbers (for Business plan customers, if required)
Note: We do not store complete credit card information on our servers. All payment processing is handled by secure, PCI-DSS compliant third-party payment processors.
Service-Specific Information:
- Google Analytics, Google Search Console, and Google Ads account connections (with your explicit authorization)
- Social media advertising account credentials (Facebook Ads, Instagram Ads, LinkedIn Ads)
- Marketing goals, KPIs, and performance targets
- Competitor website URLs (for competitive analysis)
- Target keywords and search terms
- Industry sector and business niche information
Communication Information:
- Email correspondence with our support and sales teams
- Support ticket history and chat transcripts
- Feedback, survey responses, and testimonials
- Preference settings for notifications and communications
2.2 Information We Collect Automatically
Technical and Device Information:
- IP address (Internet Protocol address)
- Browser type and version (Chrome, Firefox, Safari, Edge, etc.)
- Operating system and device type (Windows, macOS, iOS, Android)
- Screen resolution and display settings
- Language preferences
- Time zone information
- Device identifiers and unique device tokens
Usage and Behavioral Data:
- Pages visited on our website and duration of visits
- Features used within our platform (SEO audit tool, AI suggestions, reports, etc.)
- Time and date of service usage
- Click patterns and navigation paths
- Search queries within our platform
- Download and export activity (report downloads, data exports)
- Chrome extension usage and interactions
Performance and Analytics Data:
- Website loading times and performance metrics
- Error logs and debugging information
- Server logs and access records
- Platform usage statistics and feature adoption rates
2.3 Information Collected Through Third-Party Services
When you connect your accounts with third-party services (Google Analytics, Search Console, Google Ads, etc.), we collect data from these platforms with your explicit permission:
- Google Analytics Data: Website traffic metrics, user behavior, conversion data, demographic information
- Search Console Data: Search performance, click-through rates, keyword rankings, indexing status
- Google Ads Data: Campaign performance, ad spend, click data, conversion tracking
- Social Media Platform Data: Advertising campaign metrics from Facebook, Instagram, LinkedIn (when connected)
This data is collected in accordance with the privacy policies of these third-party platforms and is used solely to provide you with comprehensive SEO audits, media buying optimization, and growth strategy recommendations.
3. How We Use Your Information
We use the information we collect for various purposes, all aimed at providing you with exceptional digital marketing services and improving your experience with Courtane Agency.
3.1 Service Delivery and Operation
- SEO Audit Performance: To conduct comprehensive SEO audits analyzing 200+ ranking factors, identify technical issues, and generate actionable recommendations
- AI-Powered Recommendations: To train and improve our AI suggestion engine, providing personalized optimization recommendations based on your website's unique characteristics
- Media Buying Optimization: To analyze advertising campaign performance, optimize ad spend across Google Ads, Facebook, Instagram, and LinkedIn, and maximize ROI
- Growth Strategy Development: To create custom growth strategies tailored to your business goals, industry, and target audience
- Report Generation: To create professional, white-label reports you can share with stakeholders or clients
- Platform Access: To manage your account, authenticate your identity, and provide access to subscribed features
- Data Synchronization: To sync data from connected third-party accounts (Google Analytics, Search Console, etc.) for comprehensive analysis
3.2 Communication and Support
- To send you important account notifications, service updates, and security alerts
- To respond to your inquiries, support requests, and technical assistance needs
- To provide customer service via email, phone, or chat
- To send you service-related announcements and policy updates
- To notify you about new features, platform improvements, and product updates
- To conduct user satisfaction surveys and gather feedback for service improvement
3.3 Transaction Processing
- To process subscription payments and manage billing cycles
- To send invoices, payment confirmations, and receipts
- To prevent fraudulent transactions and verify payment information
- To manage subscription renewals and cancellations
- To handle refund requests in accordance with our Refund Policy
3.4 Marketing and Promotional Communications
With your consent, we may use your information to send marketing communications about:
- New features and platform enhancements
- SEO tips, best practices, and industry insights
- Webinars, educational content, and case studies
- Special offers, promotions, and pricing updates
- Industry reports and market analysis
You can opt out of marketing communications at any time by clicking the unsubscribe link in any email or by updating your communication preferences in your account settings. Opting out of marketing communications will not affect service-related communications.
3.5 Service Improvement and Analytics
- To analyze usage patterns and identify popular features
- To understand how users interact with our platform and improve user experience
- To identify technical issues, bugs, and areas for improvement
- To conduct A/B testing and feature experiments
- To develop new services and features based on user needs
- To generate anonymized, aggregated statistics about our services
3.6 Legal and Compliance
- To comply with applicable laws, regulations, and legal processes
- To respond to subpoenas, court orders, or government requests
- To protect our rights, privacy, safety, or property
- To enforce our Terms of Use and prevent violations
- To detect, prevent, and address fraud, security threats, or technical issues
- To fulfill tax and accounting obligations
4. Information Sharing and Disclosure
We respect your privacy and are committed to protecting your personal information. We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We may share your information only in the following limited circumstances:
4.1 Service Providers and Business Partners
We work with trusted third-party service providers who perform functions on our behalf. These providers are contractually obligated to protect your information and may only use it for the purposes we specify:
- Payment Processors: To securely process credit card payments (Stripe, PayPal, etc.)
- Cloud Hosting Providers: To host our platform and store data securely (AWS, Google Cloud)
- Email Service Providers: To send transactional and marketing emails (SendGrid, Mailchimp)
- Analytics Providers: To analyze website usage and improve our services (Google Analytics)
- Customer Support Tools: To provide customer support services (Zendesk, Intercom)
- Security Services: To protect against fraud and security threats
- Database Services: To securely store and manage data
4.2 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of the transaction. We will notify you via email and/or prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your information.
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, or government investigations). We may also disclose information to protect:
- Our rights, privacy, safety, or property
- Your safety or the safety of others
- The integrity of our services
- Compliance with legal obligations
4.4 With Your Explicit Consent
We will share your information with third parties when you explicitly authorize us to do so. For example:
- When you connect your Google Analytics or Search Console accounts (with OAuth authorization)
- When you authorize us to access your advertising accounts
- When you request us to share information with a business partner or consultant
4.5 Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you. This may include statistical data about industry trends, average SEO scores, or general usage patterns. This information helps improve our services and provides industry insights.
5. Data Security and Protection
At Courtane Agency, we take data security seriously. We implement a comprehensive, multi-layered security approach to protect your information from unauthorized access, alteration, disclosure, or destruction.
5.1 Technical Security Measures
- Encryption: All data in transit is protected using TLS 1.3 encryption. Sensitive data at rest is encrypted using AES-256 encryption
- Secure Authentication: Passwords are hashed using bcrypt with salt, and we support two-factor authentication (2FA) for enhanced account security
- Secure Infrastructure: Our servers are hosted on enterprise-grade cloud infrastructure with regular security updates and patches
- Access Controls: We employ role-based access controls and principle of least privilege to ensure only authorized personnel can access your data
- Regular Security Audits: We conduct regular security assessments, penetration testing, and vulnerability scanning
- Firewall Protection: Advanced firewall systems protect our network infrastructure
- Intrusion Detection: We monitor for suspicious activities and unauthorized access attempts 24/7
5.2 Organizational Security Measures
- All employees undergo background checks and sign confidentiality agreements
- Regular security training and awareness programs for all staff members
- Strict data access policies limiting employee access to only the information necessary for their role
- Regular review and updates of security policies and procedures
- Incident response plan for security breaches or data incidents
5.3 Payment Information Security
We never store complete credit card information on our servers. All payment processing is handled by PCI-DSS Level 1 compliant payment processors (Stripe, PayPal). We only store tokenized payment identifiers necessary for subscription management.
5.4 Third-Party Account Security
When you connect third-party accounts (Google Analytics, Search Console, etc.), we use OAuth 2.0 authorization, which means we never see or store your passwords. You can revoke access at any time through your account settings or directly from the third-party platform.
5.5 Security Breach Notification
In the unlikely event of a security breach that compromises your personal information, we will:
- Notify affected users within 72 hours of discovering the breach (where required by law)
- Provide clear information about what information was compromised
- Explain what steps we're taking to address the breach
- Offer guidance on steps you can take to protect yourself
- Report to relevant data protection authorities as required by applicable laws
Important: While we implement industry-standard security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your information to the best of our ability.
6. Cookies and Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies to enhance your experience, analyze usage patterns, and improve our services.
6.1 Types of Cookies We Use
Essential Cookies:
- Required for basic website functionality and cannot be disabled
- Enable secure login, maintain session state, and remember your preferences
- Examples: authentication tokens, session IDs, security cookies
Performance and Analytics Cookies:
- Help us understand how visitors interact with our website
- Collect information about page views, bounce rates, and user journeys
- We use Google Analytics (with IP anonymization enabled) for this purpose
- These cookies help us improve website performance and user experience
Functional Cookies:
- Remember your preferences and settings (language, region, display preferences)
- Enable enhanced functionality and personalization
- Remember login credentials (if you choose "Remember Me")
Marketing and Advertising Cookies:
- Used to track your browsing activity to show you relevant advertisements
- Help us measure the effectiveness of our marketing campaigns
- Used for remarketing purposes (showing ads to previous visitors)
- Only used with your consent
6.2 Third-Party Cookies
We may also use third-party cookies from trusted partners, including:
- Google Analytics: For website analytics and usage statistics
- Google Ads: For remarketing and conversion tracking
- Facebook Pixel: For advertising and analytics (if you consent)
- LinkedIn Insight Tag: For advertising and analytics (if you consent)
6.3 Managing Cookies
You have control over cookies. You can:
- Adjust your browser settings to refuse all cookies or alert you when cookies are being sent
- Use our cookie preference center (accessible via the cookie banner) to manage your cookie preferences
- Delete cookies already stored on your device through your browser settings
Note: Disabling certain cookies may limit your ability to use some features of our website and services. Essential cookies cannot be disabled as they are necessary for basic functionality.
7. Your Privacy Rights and Choices
Depending on your location (United States, European Union, California, etc.), you may have certain rights regarding your personal information. We are committed to honoring these rights.
7.1 Rights Under GDPR (European Union Users)
If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights:
- Right of Access: Request a copy of all personal information we hold about you, including what data we collect, how we use it, and with whom we share it
- Right to Rectification: Request correction of inaccurate or incomplete personal information
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal information under certain circumstances (e.g., when data is no longer necessary or you withdraw consent)
- Right to Restriction of Processing: Request that we limit how we process your personal information in certain situations
- Right to Data Portability: Receive your personal information in a structured, commonly used, and machine-readable format, and transmit it to another controller
- Right to Object: Object to processing of your personal information for direct marketing purposes or based on legitimate interests
- Right to Withdraw Consent: Withdraw previously given consent for data processing at any time
- Right to Lodge a Complaint: File a complaint with your local data protection authority if you believe we've violated your rights
7.2 Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request disclosure of categories and specific pieces of personal information we collect, use, disclose, or sell
- Right to Delete: Request deletion of personal information we've collected about you
- Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)
- Right to Non-Discrimination: Exercise your privacy rights without discrimination
- Right to Correct: Request correction of inaccurate personal information
7.3 General Rights (All Users)
Regardless of your location, you can:
- Update Your Information: Edit your account information, preferences, and settings at any time through your account dashboard
- Access Your Data: Download your SEO audit reports, analytics data, and account information
- Delete Your Account: Request permanent deletion of your account and associated data
- Manage Communications: Unsubscribe from marketing emails while continuing to receive service-related communications
- Revoke Third-Party Access: Disconnect third-party account integrations (Google Analytics, Search Console, etc.) at any time
7.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at contact@courtaneagency.com or call us at 1 (505) 483-0953. Include:
- Your full name and account email address
- A clear description of the right you wish to exercise
- Specific information about the data or action you're requesting
- Verification of your identity (to protect your privacy and prevent fraud)
We will respond to your request within 30 days (or as required by applicable law). In some cases, we may need additional time or information to process your request, which we'll communicate to you promptly.
8. Data Retention and Deletion
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
8.1 Retention Periods
Account Information:
- Active accounts: Retained for the duration of your subscription and 90 days after cancellation
- Free tier accounts: Retained indefinitely until you request deletion
- Inactive accounts: May be archived after 12 months of inactivity
SEO Audit Reports and Data:
- Retained for the duration of your account plus 90 days after account deletion
- You can download and export your reports at any time before deletion
- Aggregated, anonymized data may be retained longer for analytics purposes
Payment and Billing Information:
- Retained for 7 years after your last transaction (as required by tax and accounting laws)
- Credit card information is not stored on our servers (handled by payment processors)
Communication Records:
- Support tickets and email correspondence: Retained for 3 years
- Chat transcripts: Retained for 2 years
- Feedback and testimonials: May be retained indefinitely (with your consent)
8.2 Deletion Process
When you request account deletion or when retention periods expire:
- Your account will be deactivated immediately
- Personal information will be deleted from our active systems within 30 days
- Backup copies may be retained for up to 90 days for disaster recovery purposes
- We will notify you when deletion is complete
Important: Some information may be retained longer if required by law (e.g., tax records, legal disputes, or regulatory requirements). We will inform you if this applies to your data.
9. Children's Privacy
Courtane Agency's services are designed for businesses and professionals and are not intended for individuals under the age of 18 (or the age of majority in your jurisdiction).
We do not knowingly collect, use, or disclose personal information from children under 18. If we discover that we have collected personal information from a child under 18 without parental consent, we will take immediate steps to delete that information from our systems.
If you believe we have collected information from a child under 18, please contact us immediately at contact@courtaneagency.com and we will promptly investigate and take appropriate action.
10. International Data Transfers and Processing
Courtane Agency is based in the United States (Albuquerque, New Mexico). If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.
10.1 Data Transfer Safeguards
We ensure appropriate safeguards are in place to protect your information during international transfers:
- Standard Contractual Clauses: We use EU-approved standard contractual clauses when transferring data from the EEA
- Adequacy Decisions: We rely on adequacy decisions by the European Commission where applicable
- Certified Service Providers: Our service providers are certified under frameworks like Privacy Shield (where applicable)
- Encryption: All data transfers are encrypted using industry-standard protocols
10.2 Third-Party Data Processing
Some of our service providers may process your data outside your country of residence. We ensure all service providers meet our security and privacy standards through contractual obligations.
11. Do Not Track Signals
Some web browsers include a "Do Not Track" (DNT) feature that signals to websites you visit that you do not want to have your online activity tracked. Currently, there is no uniform standard for recognizing and implementing DNT signals. As a result, Courtane Agency does not currently respond to DNT browser signals or mechanisms.
However, we provide you with control over your data through the privacy settings in your account and our cookie preference center. You can manage your tracking preferences there.
12. Third-Party Links and Services
Our website and services may contain links to third-party websites, services, or applications that are not operated by Courtane Agency. This Privacy Policy does not apply to these third-party services.
Examples of third-party services you may encounter include:
- Google Analytics, Search Console, and Google Ads (when you connect these accounts)
- Social media platforms (Facebook, LinkedIn, Instagram) for advertising integration
- Payment processors (Stripe, PayPal)
- External resources and documentation links
We encourage you to review the privacy policies of any third-party services you access. We are not responsible for the privacy practices or content of these third-party services.
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, legal requirements, or for other operational, legal, or regulatory reasons.
13.1 How We Notify You of Changes
- Website Notification: We will post the updated Privacy Policy on this page with an updated "Last updated" date
- Email Notification: For material changes, we will notify active subscribers via email at least 30 days in advance
- In-Platform Notification: We may display a notice in your account dashboard for significant changes
- Continued Use: Your continued use of our services after changes become effective constitutes acceptance of the updated Privacy Policy
13.2 What Constitutes Material Changes
We consider the following to be material changes requiring advance notification:
- New purposes for data collection or use
- New categories of personal information collected
- Significant changes to data sharing practices
- Changes to your rights or how to exercise them
- Changes to our security practices
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. The "Last updated" date at the top of this page indicates when the Privacy Policy was last revised.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Email: contact@courtaneagency.com
Phone: 1 (505) 483-0953
Address: 2105 Vista Oeste NW, Suite E #3628, Albuquerque, NM 87120