1. Who We Are
OnlineCorners ("we", "us", "our") operates the website intelligence platform available at onlinecorners.com. We provide website scanning and analysis services including security checks, DNS analysis, SEO auditing, and technical health reports. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, and password when you register.
- Profile information: phone number (for two-factor verification), billing address.
- Payment information: processed securely by Stripe. We do not store card numbers.
- URLs you submit: domain names and URLs you scan through our platform.
- Communications: messages you send us via support or feedback forms.
2.2 Information Collected Automatically
- Usage data: pages visited, features used, scan history, and interaction timestamps.
- Device data: IP address, browser type and version, operating system.
- Cookies: session cookies for authentication, preference cookies for theme settings.
- Analytics: aggregated usage metrics via PostHog and Google Analytics 4.
2.3 Information from Third Parties
- Google OAuth: if you sign in with Google, we receive your name, email address, and profile picture from Google.
- Stripe: subscription status, plan tier, and billing events.
3. How We Use Your Information
- Provide, operate, and improve our website scanning and analysis services.
- Create and manage your account, authenticate your identity.
- Process payments and manage your subscription plan.
- Send transactional emails: account verification, scan alerts, scheduled report notifications.
- Enforce scan quotas and rate limits based on your subscription tier.
- Monitor platform security, detect abuse, and prevent fraud.
- Analyze usage patterns to improve features and fix bugs.
- Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your submitted URLs for any purpose other than running the scan you requested.
4. How We Share Your Information
We share information only in the following limited circumstances:
- Service providers: Stripe (payments), Resend (email), Plivo (SMS), Cloudflare (CDN and image hosting), PostHog (analytics), Sentry (error monitoring). These providers process data on our behalf under data processing agreements.
- Legal requirements: when required by law, court order, or to protect the rights and safety of our users or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before this occurs.
5. Cookies and Tracking
We use the following types of cookies:
- Essential cookies: required for authentication and session management. Cannot be disabled.
- Preference cookies: store your theme (light/dark) preference.
- Analytics cookies: PostHog and Google Analytics 4 help us understand how users interact with the platform. These can be blocked via your browser settings or a privacy extension.
6. Data Retention
- Account data is retained as long as your account is active.
- Scan results are retained for 90 days for free users and indefinitely for paid subscribers.
- Upon account deletion, personal data is purged within 30 days, except where retention is required by law.
- Aggregated, anonymised analytics data may be retained indefinitely.
7. Your Rights
Depending on your location, you may have the following rights:
- Access: request a copy of the personal data we hold about you.
- Correction: update inaccurate or incomplete information via your profile settings.
- Deletion: request deletion of your account and associated data.
- Portability: request an export of your scan history in CSV format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at privacy@onlinecorners.com.
8. Security
We implement industry-standard security measures including TLS encryption in transit, bcrypt password hashing, API key hashing, and regular security audits. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
9. Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.
10. International Transfers
Our servers are located in the European Union. If you access our service from outside the EU, your information may be transferred to and processed in the EU. By using our service, you consent to this transfer. We ensure appropriate safeguards are in place in accordance with applicable data protection law.
11. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will notify you by email or by displaying a notice on our platform. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us: