Privacy Policy
Last updated: August 5, 2026
SearchLift is operated by Good Fellas Technology LLC, a Georgia limited liability company (“we”, “us”). SearchLift analyses websites you own or manage, drafts SEO improvements, and — only when you confirm each one — writes those improvements back to your CMS. This policy explains what data we collect, who we share it with, how long we keep it, and how to get it back or delete it. Questions: hello@getsearchlift.io.
This policy covers www.getsearchlift.io and the SearchLift application. It also covers the lead-capture widget and audit forms SearchLift customers embed on their own websites — see “Who is responsible for your data” for who answers for that data.
Who is responsible for your data
SearchLift is sold to businesses and to agencies who run it on behalf of their own clients. That means two different roles, and which one we are depends on whose data it is. In GDPR terms, “controller” means the party that decides why and how data is used; “processor” means the party that acts on the controller’s instructions.
We are the controller
For the data we hold because you are our customer:
- your account and organisation records, and the email addresses of your members;
- your subscription, plan, add-ons and credit balances;
- support correspondence with us;
- diagnostic and usage data generated by your use of the product;
- leads who request a free audit on our marketing site, at /free-audit;
- the record that your organisation registered interest in a feature we have not built, on the “tell me if it ships” waitlist inside the app;
- measurement of how our own marketing website is used, and the record of which campaign or link brought a visitor to it.
We are the processor, and you are the controller
For everything you connect, upload or collect through SearchLift about the sites you manage and the people you serve:
- Search Console and Analytics data for properties you connect, including properties belonging to your clients;
- the content we crawl from those websites, and the changes we write back;
- the recipient addresses you enter for client reports, and your clients’ own business context;
- leads captured by the SearchLift widget on your website. A visitor who submits their email address and site URL to your embedded widget is giving that information to you. We store it, run the audit, and send the report — under your name and, if you have verified one, your own sending domain — because you instructed us to.
When we are the processor, you are responsible for having a lawful basis to collect that data and for telling the people it concerns what you do with it. We process it only to provide SearchLift to you, and on your instructions. If a widget lead or a client contacts us directly about their data, we will pass the request to the customer whose account holds it, and tell the person we have done so — except where a law requires us to act ourselves. Every widget lead and client report also carries a one-click unsubscribe link that works without going through anyone.
If you need a data processing agreement, email hello@getsearchlift.io.
What we collect
Account data
Your email address, your organisation and site records, your role in that organisation, and anything you type into settings — site URLs, business context, report recipients, sender-domain configuration and an uploaded logo, if you add one.
Google Search Console and Analytics data
Read-only, via Google OAuth, for the properties you choose. Detailed in “Google user data we access” below, which also covers what we receive if you use Google to sign in.
Your website’s content
We fetch pages from the sites you connect — following your sitemap and the links between your pages — and read what is published there: titles, meta descriptions, headings, body copy, images and internal links. We read what any visitor could read. We do not attempt to reach anything behind a login unless you give us credentials for it.
Billing data
Payments run through Stripe. Your card details go from your browser to Stripe directly. We never see, receive or store your card number, CVC or expiry date. What we store is a Stripe customer identifier, your plan, subscription status, add-ons, credit balances and the events Stripe sends us about them.
Widget and free-audit leads
When someone submits the SearchLift widget on a customer’s website — or our own free-audit form — we store the email address they typed, the website URL they submitted, the IP address the request came from, and the audit we generated. The IP address is kept because it is the control that stops one visitor spending a customer’s whole daily allowance; it is used for abuse limits, not for profiling or advertising.
A widget submission also records the web address of the page the form was submitted from, so the customer can tell which of their pages produced the lead and so we can check the submission came from a site that customer registered. Afterwards, the customer can set a status on the lead (new, contacted, converted, dismissed) and write a free-text note about it. That note is written by the customer, is visible to their organisation, and is not something we generate or read as a matter of course.
The white-label waitlist
Full white-label report hosting is something we are considering rather than selling, and customers on the plan it would belong to can register their organisation’s interest from inside the app. If you do, we store the email address already on your account, the name of the list, your organisation, the plan it was on at the time, and the date — nothing else. There is no name, company or message field, and nothing for you to type. We also record a counter against your IP address so one person cannot flood the list; that counter is described under abuse controls below and is not stored against your email address.
This capture used to sit on our public pricing page and accept an address from anyone. It no longer does. Email addresses collected there before the change are still on the list and are still governed by everything below; they simply have no organisation attached to them.
Nothing sends from that list today. It is a record of interest, not a permission to mail you, and it deliberately has no confirmation email — an anonymous box that triggers a message is a way to make our domain email a stranger. If the feature ships and we decide to announce it, that announcement goes through the same suppression list as everything else we send, so an address that has ever unsubscribed, bounced or reported us is refused. You can ask us to remove you at any time.
How visitors use our marketing website
Our public marketing pages carry a Google Tag Manager container, and the tag configured inside it today is Google Analytics. It measures how the site is used — which pages people read, in what order, and which ones lead somewhere. It is not part of the application you sign in to. It is never sent your email address, your account or organisation identifier, the sites you manage, or anything about your clients or their data.
It stores nothing on your device until you answer the banner. Until you answer, and if you decline, all four of Google’s consent signals stay denied, which means no analytics or advertising identifier may be read from or written to your browser — so your visits cannot be joined together into a profile of you. What Google still receives in that state is the requests themselves: the address of the page you are on, the page that referred you there, your browser, operating system, device type and language, and your IP address, which Google uses to derive an approximate location. Google states it does not log or store IP addresses in Analytics. If you accept, Google additionally stores a randomly generated identifier on your device so that repeat visits are counted as one person rather than several.
We use this to understand our own website and nothing else. Google Signals is not enabled on our Analytics property, the property is not linked to Google Ads or any other advertising product, and we build no advertising audiences from it. Those three are settings in Google’s own consoles rather than in our code, so we state them as what is true today: if any of them is ever turned on, this page says so before it is. The cookies, the choice itself and how to change it are described under “Cookies, analytics and your choices” below.
How you found us
When you arrive at our website from a link carrying campaign parameters — the utm_source, utm_medium, utm_campaign, utm_term, utm_content family — we keep those values, the address of the page you landed on, the website that referred you (its host and path; we drop the query string) and the date. An arrival with no campaign parameters and no outside referrer still records the landing page, so that a purchase can be honestly called direct rather than guessed at. The first arrival wins: later visits never overwrite it. It is held in a first-party cookie named sl_attr in your own browser.
Nothing about a visit reaches our systems unless and until you start a checkout. There is no page-view beacon to our servers, no visits table and no landing log. If you browse our site and leave, we hold no record of you at all. If you do start a subscription, those campaign values travel with that checkout and are then stored against your subscription and your organisation.
This is our own first-party record and it describes a route, not a person: a campaign name, a referring site, a landing path. It answers one question — which of the things we do actually brings people here. It is not sold, not given to an advertising network, and not used to target you with advertising. Once it is attached to an account it is part of that account’s record and is deleted with it.
Usage, diagnostics and support
Job history and run status, per-page analysis results, API call counts and the cost of each run, rate-limit counters, security events (sign-ins, invites, suspensions, support access), and application errors. Plus whatever you send us in a support email.
How we use it
We use what we collect to:
- run the analysis you asked for and show you the results;
- generate title, meta, heading, excerpt and internal-link suggestions, and briefs, using an AI model;
- write approved changes to your CMS and keep the record needed to undo them;
- send you and your report recipients the emails described below;
- bill you, meter usage against your plan, and prevent abuse of paid features;
- diagnose faults, keep the service secure, and comply with the law;
- measure how our own marketing website performs, within the choice you make about analytics cookies, and record which campaign or link brought you to it.
We do not use your data, or your clients’ data, to train AI models. We do not sell it. We do not use it for advertising, ours or anyone else’s.
The last bullet is about visits to our own marketing website, not about the data you entrust to us. The two never meet: nothing you or your clients put into SearchLift is sent to our analytics, and our analytics is not consulted when we run your work.
Google user data we access
Signing in with Google
If you choose “Continue with Google” on the sign-in or sign-up page, Google asks you to share the standard sign-in scopes — openid, email and profile. We receive your Google account identifier, your email address and basic profile details such as your name and picture, and we use them for one thing: to create and authenticate your SearchLift login. This is the same Google OAuth client used for the connections below, so you may see these scopes listed alongside them. If you would rather not share them, sign in with an email address and password instead — the product works identically.
Connecting a property for analysis
When you connect your Google account, we request read-only access to:
- Google Search Console (
webmasters.readonly) — impressions, clicks, click-through rate, average position, and queries for the properties you choose. - Google Analytics 4 (
analytics.readonly) — engagement metrics used to prioritize which pages to improve.
We only ever read this data. We never post, modify, or delete anything in your Google account.
How we use Google user data
Google Search Console and Analytics data is used solely to generate SEO recommendations for your own websites and to show you the resulting analysis. We do not use it for any other purpose. The sign-in scopes are used solely to authenticate you.
Limited Use
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- sell your Google user data;
- use it for advertising;
- transfer or disclose it to third parties except as needed to provide the service, to comply with applicable law, or as part of a merger or acquisition;
- allow humans to read it, except with your explicit consent, for security or to comply with the law, or where the data is aggregated and anonymized.
We do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models.
Who else processes your data
We use the following companies to run SearchLift. Each one gets only what it needs to do its job, and each is bound by its own contract with us. This is the complete list as of the date above.
- Supabase — database, file storage and authentication. Receives: your account and site records, analysis results, your encrypted third-party credentials, and any logo you upload
- Vercel — hosting for the website and application. Receives: the requests your browser makes, including IP address and request metadata
- Render — hosting for the analysis engine and background workers. Receives: the job payloads that run your analyses and write-backs
- Anthropic (Claude) — the AI model that drafts SEO copy. Receives: page content, titles, headings, search queries and keywords, and the business context you enter — sent per request to generate suggestions. Under Anthropic's commercial terms this content is not used to train their models
- DataForSEO — search-results and competitor data. Receives: keywords, your domain, and competitor domains — not your visitors
- Google PageSpeed Insights and Chrome UX Report — page performance measurement. Receives: the public URLs of the pages being audited
- Google (Tag Manager and Google Analytics) — measurement of our own marketing website — Tag Manager delivers the tags, Analytics is the tag we run in it — and only where you allow it. Receives: the addresses of the pages you view on our site, the page that referred you, your browser, operating system, device type and language, and your IP address, which Google uses to derive an approximate location — plus, only if you accept analytics cookies, a randomly generated identifier that lets repeat visits be counted as one. It receives nothing about your account, your organisation, your clients, or your Search Console and Analytics data
- Stripe — payments and subscriptions. Receives: your name, email, billing address and card details, collected by Stripe directly. If you arrived from a campaign or referring link, the campaign, referrer and landing-page values described above travel with the checkout as metadata
- Resend — transactional and report email delivery. Receives: recipient addresses, subject lines and message content, plus the delivery, bounce and complaint events that come back
- Cloudflare (Turnstile) — bot check on the embeddable lead-capture widget. Receives: the IP address and challenge token of whoever submits the widget form. It is not used on our own free-audit form, which is protected by rate limits and a confirmation click instead
- Sentry — error monitoring and session replay. Receives: error messages and stack traces, and a sampled replay of browser sessions. Our server-side monitoring is explicitly configured not to send request bodies, cookies, user identifiers or server-side variable values; browser session replay masks page text and blocks media using the library's default masking
- Kit (formerly ConvertKit) — our own marketing email list. Receives: the email address of someone who both ticked the marketing box on our free-audit form and then clicked the confirmation link we emailed them, and — when you buy a plan — the name, email address and plan on that purchase. Your clients' data and the leads captured by your widget are not sent here
Google appears above for more than one reason, and they are not the same relationship. Your Search Console and Analytics data, described earlier, is your own data held in your own Google account, which we read on your behalf and only with the access you granted — Google is not our sub-processor for it, it is your provider. PageSpeed Insights receives the public web address of a page we are auditing. Google Analytics is the only one of the three where Google processes data about visitors to our website on our behalf, which is why it is the only one behind a consent banner.
If you configure an outgoing webhook, we send a notification to the URL you specify each time a widget lead’s report goes out — carrying that lead’s email address, the site URL they submitted, and a link to their report. That destination is your choice and your responsibility.
This list will change as the product does. When it does, we update this page and the “Last updated” date, and we email account owners before a new sub-processor starts handling customer data.
Changes we make to your website
SearchLift can write to WordPress, Webflow, Wix, Shopify, Ghost and Duda. It never does so on its own. Every change follows the same four steps:
- Preview — we show you the current value and the proposed value, side by side.
- Confirm — nothing is written until you approve that specific change.
- Write — we call your CMS with the credentials you supplied for it, and nothing else.
- Log — we store the old value, the new value and your CMS’s own revision reference, so the change can be identified and rolled back.
Some platforms have no write API. Those sites still get the full analysis and copy-and-paste suggestions; there is simply no Apply button, and we do not claim otherwise.
How we protect and store it
- Your Google authorization token and any other third-party credentials are encrypted at rest using application-level encryption. Decryption happens only on our own servers, and only to carry out something you have asked for. Most of it happens inside the background worker at the moment your analysis runs. The rest happens in the application itself, where you are waiting on an answer that has to come from Google — drawing your traffic chart, listing your Search Console or Analytics properties, checking whether your Analytics setup is complete, and revoking the token when you disconnect.
- Decrypted credentials are injected into a single job and are not shared between jobs or between customers.
- Credentials are never exposed to your browser and are never logged.
- Access is scoped per account by database row-level security, so one organisation’s queries cannot return another organisation’s rows. Members see only the organisations they belong to, and only what their role allows.
- A credential we hold for one of your sites is dropped rather than forwarded if a request is redirected to a different domain, so a hijacked redirect cannot carry it somewhere it does not belong.
- Our server-side error monitoring is configured not to capture request bodies, cookies, user identifiers or server-side variable values, because those are exactly where secrets would be. In the browser we rely on our monitoring provider’s default masking, which hides page text and blocks media in session replays.
These are safeguards, not guarantees. No method of transmitting or storing data is 100% secure, and we cannot warrant absolute security. If we become aware of a breach affecting your data, we will notify you and, where required, the relevant authority.
Support access to your account
To investigate a problem you report — or a fault we detect — authorized SearchLift staff may access your account. We keep this tightly bounded:
- Only platform administrators can do it, and only after recording a written reason.
- The default is read-only: staff view your account state without signing in as you. Signing in as you requires a separate, explicit confirmation and is used only when read-only access isn't enough to diagnose the problem.
- Every session is time-limited (30 minutes) and recorded — who accessed the account, when, and why.
- Actions that change money, credentials or account existence are blocked outright during a support session: staff cannot delete your account, change your billing, or connect or disconnect your data sources. Support access is for diagnosis, not for acting on your behalf.
- Your Google Search Console and Analytics data remains subject to the Limited Use terms above; support access does not change how that data may be used.
You can ask us for the record of support access to your account at any time. Email hello@getsearchlift.io from the address on the account and we will send you the log entries — who, when, which mode, and the reason given.
Cookies, analytics and your choices
We run no advertising pixels and carry no data-broker tags. Our marketing website does load a Google Tag Manager container — a piece of Google infrastructure that holds our measurement tags — and the tag configured in it today is Google Analytics. It is the only thing described on this page that asks your permission first.
The choice we ask you to make
On your first visit to our marketing site a banner asks whether you accept. Until you answer, the answer is no. We use Google’s Consent Mode, and all four of its signals — analytics storage, advertising storage, advertising user data and advertising personalisation — start denied, so nothing may read or write an identifier on your device before you have said it may. Declining is a complete answer: the site works identically, and we do not ask again for the life of the cookie that records your decision.
The banner is all-or-nothing, and we would rather say so than let “accept” look narrower than it is. Accepting grants all four signals; declining grants none. There is no per-category switch. Today the container runs no advertising tag, so the three advertising signals permit something nothing currently uses — but what you are agreeing to is the permission, not our current tag list, and the honest description is the permission.
Being honest about what declining does not do: in the denied state the container still loads and the analytics tag still contacts Google, so Google still receives the requests — the page address, the referring page, your browser and device, and your IP address. What it does not do is store or read an identifier on your device, so those requests cannot be tied to each other or to you across visits.
Changing your mind
Your answer is not final. The Cookie preferences link in the footer of every page reopens the banner, and you can accept or withdraw at any time. Withdrawing stops further storage from that moment. It does not by itself erase measurements Google has already recorded — for that, email hello@getsearchlift.io and we will action a deletion request against our Analytics property. You can also clear or block these cookies in your browser, which has the same effect from your side.
What is actually stored
sl_consent— a first-party cookie recording whether you accepted and when. It is the only way we can honour a “no” without asking again on every page. It says nothing about who you are. We keep it six months, then ask once more rather than treat one click as permanent.- Google Analytics (
_gaand_ga_<stream id>) — set only if you accept. They hold a randomly generated identifier so that repeat visits are counted as one person. Google’s standard lifetime for them is up to two years from your last visit. sl_attr— the campaign parameters, the referring website, the page you first landed on and the date, kept in your own browser for 90 days, so that a subscription started later can be attributed to the link that brought you. Described in full under “What we collect” above.- Session cookies (names beginning
sb-) — issued by our authentication provider to keep you signed in. Strictly necessary; clearing them signs you out. sl_oauth— a short-lived cookie set while you connect a Google account. It carries the anti-forgery state value and which site you are connecting, and it is discarded as soon as the connection completes.sl_imp/sl_admin_return— set only during a staff support session, on the staff member’s browser, not yours. Both are HTTP-only.- Cloudflare Turnstile — sets its own values on pages carrying a SearchLift customer’s embedded lead-capture widget, to distinguish people from bots. It is not used on our own free-audit form.
- Sentry session replay — uses browser storage to tie a sampled replay to the error it belongs to.
That list describes what is set today. Because our measurement tags live in a tag manager, the set can change without this website’s code changing, so we do not claim it is closed for all time. What we do commit to is the order of operations: a tag that sends data to a company not named in this policy is not added until this policy names it, in the sub-processor list above and in this section, with the “Last updated” date changed.
Email we send
Email to you
Sign-in links, invitations, billing notices, run results and service alerts are transactional: they are part of the service and are sent for as long as you have an account. Closing the account stops them.
Our own marketing list is separate and is double opt-in. Requesting a free audit does not put you on it. You go on it only if you tick the marketing box on the free-audit form and then click the link in the confirmation email we send to the address you typed — the click is the only evidence that has ever existed that the address is actually yours. Miss either step and nothing is added. Buying a plan also adds the purchaser. Every message on that list has an unsubscribe link.
Email to your clients and leads
Client reports and widget lead reports are sent on a customer’s behalf, from our sending infrastructure, and — where the customer has verified their own subdomain — under their name and branding. Every one of these messages carries a working one-click unsubscribe link. Following it stops that stream immediately and does not require an account, a login or a conversation with the agency.
The suppression list
When an address hard-bounces or reports a message as spam, we add it to a suppression list and stop sending to it — across the whole platform, not just the account that triggered it. That protects the deliverability every customer shares. Temporary failures such as a full mailbox do not suppress an address. If you believe your address was suppressed in error, email hello@getsearchlift.io and we will remove it. We keep suppression records for as long as we operate the service; deleting them would mean mailing people who have already told us to stop.
Retention and deletion
Disconnecting a source
You can disconnect a data source at any time, which revokes the stored token and stops further access. You may also revoke access directly from your Google Account permissions page.
Deleting your account
Account › Export or delete has a self-serve delete. It asks you to type DELETE to confirm, and what it removes depends on whether anyone else is in your organisation. We describe both outcomes because they are genuinely different:
- If you are the only member of your organisation — the whole organisation is deleted, and everything that hangs off it goes with it: its sites, business context, analyses and suggestions, per-page records and applied changes, snapshots and link maps, its widget leads, its subscription record, and every stored connection, including your encrypted Google, CMS and other third-party credentials. Your login is deleted too.
- If anyone else is a member — we remove you: your membership of that organisation and your login. The organisation itself is not deleted, and neither is anything in it — its sites, its widget leads and its encrypted credentials all survive, because other people still have accounts that depend on them. Deleting your own login does not delete data that other members are still using, even if you were the owner.
So if you want an organisation and everything in it gone, and it has more than one member, the self-serve button is not enough on its own. There is no way to remove another member from the product interface today: either every member deletes their own account (the last one to do so triggers the full deletion above), or you email hello@getsearchlift.io from the owner’s address and ask us to delete the organisation. We will do it within 30 days and confirm when it is done. We email you a confirmation in every case, and neither outcome can be undone.
Getting a copy of your data
There is no self-serve export button — the “Export or delete” panel currently offers only the delete. To get an export, email hello@getsearchlift.io from the address on the account and we will send you a machine-readable export of your account, site and analysis data within 30 days.
How long we keep things
- Account, site and analysis data — for as long as the organisation exists, then deleted when the organisation is deleted, as described above.
- Abuse-control counters — rate-limit records are cleared a day after the window they cover; single-use widget form tokens an hour after they expire. Both happen automatically.
- Suppression records — kept indefinitely, for the reason given above.
- Billing records — at least seven years, and longer where tax and accounting law requires it. That is longer than your account may live.
- Widget leads — held for the customer whose widget captured them and destroyed when that organisation is deleted. There is no age-based expiry running today, so our commitment is the ceiling: 24 months from capture. We will delete a lead sooner on request from the person it describes or the customer who captured it.
- Free-audit records (our own form) — 24 months. We keep the address and the site for that period because the record is the control that enforces one free audit per address per site; delete it and the limit stops existing. Ask us and we will remove yours sooner.
- Waitlist signups — 24 months, or until we decide not to build the feature, whichever comes first.
- Security and support-access logs — 24 months. These are the records of sign-ins, invitations, suspensions and staff access to accounts; they exist to answer “who did that, and when” and are not used for anything else.
- Website analytics — in Google’s systems we set event-level retention to no more than 14 months. The identifier in Google’s cookies expires up to two years after your last visit, and ends sooner if you withdraw consent or clear your cookies. Aggregate reports Google derives from the measurements outlive the underlying events and describe no individual.
- Attribution — held in your browser for no more than 90 days. If a subscription is started, the values attached to it are kept with your organisation’s record for as long as the organisation exists and are deleted with it; the copy that travelled with the checkout lives as long as that billing record does, above.
- Your cookie choice — the
sl_consentcookie that records it, six months, after which we ask again. - Encrypted database backups — a rolling window of no more than 30 days, held by our database provider. Deleted data can persist in a backup until that window passes, after which the backup is destroyed.
Your rights
If you are in the EU, EEA or UK
You have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- receive your data in a portable, machine-readable format;
- object to processing, or ask us to restrict it;
- withdraw consent where our processing relies on it; and
- complain to your national data protection supervisory authority.
If you are in California
Under the CCPA as amended by the CPRA you have the right to know what we collect and why, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined in the CPRA. We run no ad networks, no advertising pixels and no data-broker integrations.
We do run Google Analytics on our marketing website, and we would rather point at it than let a no-sale sentence do the work of hiding it. It is configured for measurement only: the property is not linked to Google Ads or any other advertising product, Google Signals is not enabled, and no advertising audience is built from it. It stores nothing on your device unless you accept the banner, and you can withdraw at any time from Cookie preferences in the footer — which is the opt-out, available to everyone, whether or not California law reaches you. If any of that ever changes, this page changes first.
How to exercise them
Delete your account yourself from Account › Export or delete — reading the two outcomes described above first, because which one applies to you depends on whether anyone else is in your organisation. For anything else, including an export or the deletion of an organisation with more than one member, email hello@getsearchlift.io. We respond within 30 days. We will ask you to verify that you control the address on the account before we act on a request.
If your data is in SearchLift because an agency put it there — you are their client, or you submitted their embedded form — they are the controller and your request goes to them. Send it to us anyway if you cannot reach them: we will forward it and tell you we have.
International transfers
We are based in the United States, and our infrastructure is configured to store and process data in the United States. Three of the providers named above run globally distributed networks — our web host, the widget’s bot check, and the tag container and analytics endpoint your browser talks to if you accept measurement — so a request from your browser may first reach a network location near you before it reaches our US infrastructure. If you are outside the US, using SearchLift means your data is transferred there. Where a transfer from the EEA or UK requires a legal mechanism, we rely on the European Commission’s Standard Contractual Clauses, which are part of our contracts with the sub-processors named above.
Children
SearchLift is a business tool. It is not directed to children. Our Terms of Service require account holders to be at least 18, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, email hello@getsearchlift.io and we will delete it.
Changes to this policy
We may update this policy. The “Last updated” date at the top always reflects the current version. For changes that materially affect how we handle your data — a new category of collection, a new sub-processor handling customer data, a new purpose — we email account owners before the change takes effect. Continuing to use SearchLift after that means you accept the updated policy.
Adding a measurement or marketing tag to our tag container counts as one of those changes, because it means a new company receives data about people who visit our site. This page is updated before such a tag goes live, not after.
Contact us
Good Fellas Technology LLC, a Georgia limited liability company, operating SearchLift at www.getsearchlift.io.
Email: hello@getsearchlift.io
This policy is governed by the laws of the State of Georgia, United States. Disputes about it follow the same route as disputes about our Terms of Service: write to us first at hello@getsearchlift.io and give us 30 days to resolve it informally, and if that fails, the state or federal courts sitting in Fulton County, Georgia. Nothing here limits a right you have under a data protection law that applies to you regardless of the governing law.