Legal
Privacy Policy
How ReachPlane processes account, site, scan, integration, billing, support and operational data.
Last updated: 8 August 2026
Controller
[Legal entity required], [Legal form required], at [Registered address required], is the controller for the ReachPlane service. Contact: legal@reachplane.com.
Data we process
We process only the data needed to provide, secure and improve the service.
- Account identity and authentication events.
- Website URLs, crawl responses, findings, generated assets and verification evidence.
- Encrypted integration credentials and provider identifiers.
- Subscription, invoice and payment status received from payment providers.
- Support requests, audit records and bounded operational telemetry.
Purposes and legal bases
We use data to perform the service contract, protect the platform and customers, comply with legal obligations, and pursue legitimate interests such as reliability and abuse prevention. Optional analytics or model-improvement use requires a separate explicit opt-in.
Retention
Account and site data remains available while the service is active. After termination, operational scan data is scheduled for deletion within 180 days unless a shorter self-service deletion is requested. Security logs are normally retained for 30 days. One-time verification links expire after 24 hours and password reset links after 60 minutes. Billing records are retained only for the period required by applicable accounting and tax law.
Your controls
Authorized users can export or delete account data from the product. You may also request access, correction, restriction, portability or objection by contacting the legal address above. Identity verification may be required before a request is completed.
Security and transfers
ReachPlane uses access controls, encryption, tenant isolation, audit trails, secret management and reversible deployment controls. Providers may process data outside your country under their applicable transfer safeguards; see the Subprocessors page.
Model training
Customer content is not used to train shared models by default. Any future training or fine-tuning use requires a specific, revocable opt-in and a documented data scope.