Scope and who we are
This Privacy Policy explains how AuthorityCat collects, uses, stores, and shares information when you visit authoritycat.com, create an account, use a buyer, publisher, team, or administrator workspace, connect a third-party service, or contact us.
AuthorityCat is a marketplace and workspace for discovering publishers, managing websites and projects, purchasing or fulfilling content and link placements, tracking orders, and reviewing performance information.
Information we collect
The information we process depends on how you use AuthorityCat.
- Account and identity information: name, email address, username, profile image, account type, authentication provider identifiers, workspace membership, role, sign-in history, and security settings.
- Marketplace and workspace information: projects, publisher websites, domain-verification records, categories, prices, SEO metrics, orders, placement requirements, target URLs, anchor text, messages, team invitations, permissions, support requests, and audit activity.
- Website scan information: a domain or URL you submit and publicly available homepage content such as its title, metadata, headings, and text. The resulting marketplace shortlist may be kept in your browser session so it survives a refresh.
- Payment information: wallet activity, purchase amount, currency, payment status, provider references, and limited payment-method details such as card brand and last four digits when available. Full card numbers are handled by the payment provider and are not stored by AuthorityCat.
- Technical information: IP address, browser and device information, request and security logs, cookie or session identifiers, referral information, and interactions needed to operate, secure, and improve the service.
- Communications: information you send in support messages, emails, forms, team invitations, and other communications with us.
How we use information
- Provide, authenticate, maintain, and secure AuthorityCat accounts and workspaces.
- Display relevant marketplace inventory, process website scans, manage projects, orders, permissions, notifications, and placement records.
- Process wallet transactions and coordinate payments through configured payment providers.
- Connect optional third-party services requested by you, including Google Search Console.
- Prevent fraud, abuse, unauthorized access, and violations of our Terms of Service.
- Respond to support requests, send service communications, and comply with legal obligations.
- Measure reliability and improve product functionality using aggregated or appropriately protected information.
Google user data and APIs
AuthorityCat offers Google sign-in through its authentication provider and an optional Google Search Console connection for an AuthorityCat project. Google sign-in can provide basic account information such as your name, email address, profile image, and Google account identifier so that your AuthorityCat account can be authenticated.
For Google Search Console, AuthorityCat requests only the read-only Search Console scope (webmasters.readonly). If you grant access, we use it to list Search Console properties you can access and, after you select a matching property, retrieve search-performance information such as dates, queries, pages, clicks, impressions, click-through rate, and average position. This data is displayed in your project workspace and is not used to modify your Google property.
OAuth access and refresh tokens used for the Search Console connection are encrypted at rest. We use Google user data only to provide and maintain the user-facing features you request. We do not sell Google user data, use it for advertising, or transfer it for unrelated purposes. We may disclose it only to service providers acting for us where necessary to operate or secure the feature, when required by law, or with your explicit direction.
How information is shared
We do not sell personal information. We share information only as needed for the purposes described in this policy, including with:
- Authentication and account providers such as Clerk and Google.
- Database, hosting, infrastructure, monitoring, and security providers, including Supabase where configured.
- Payment processors such as Stripe or PayPal when you choose an available payment method.
- Other workspace members or marketplace participants when the service and your actions require it. Private account and authentication information is not made public as marketplace listing data.
- Professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a business reorganization subject to appropriate safeguards.
Cookies and browser storage
AuthorityCat uses cookies and similar browser storage for secure authentication, OAuth state verification, workspace selection, fraud prevention, account-scoped settings, and continuity of user-requested features. Some browser storage is necessary to keep interface state or a website-scan shortlist through a refresh.
Blocking essential cookies may prevent sign-in, workspace access, or connected-service flows from working correctly.
Retention, disconnection, and deletion
We retain account and workspace information for as long as needed to provide AuthorityCat, maintain transaction and audit records, resolve disputes, meet legal obligations, and protect the service. Retention periods vary according to the type of information and why it is processed.
A Google Search Console connection is retained until you disconnect it, remove the related project or account, or it is otherwise no longer needed. Disconnecting through AuthorityCat revokes the active Google authorization where available and removes the stored connection from AuthorityCat. You can also remove AuthorityCat access from your Google Account security settings.
To request account or personal-data deletion, email aamirmursleen@gmail.com from the address associated with your account. We may need to verify your identity and may retain limited information where required for security, financial records, legal compliance, or the establishment and defence of claims.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including authenticated and account-scoped access, server-side credentials, encrypted Google OAuth tokens, transport encryption, request validation, and access controls. No internet service can guarantee absolute security, so you should use a strong password, protect your account, and notify us of suspected unauthorized access.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. You may update available profile or workspace information in the service, disconnect Google Search Console from the relevant project, revoke Google access in your Google Account, or contact us to make a privacy request.
We will respond in accordance with applicable law and may ask for information needed to verify your identity and authority over the account or workspace.
Children
AuthorityCat is a business marketplace and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us so we can review and remove it where appropriate.
International processing
AuthorityCat and its service providers may process information in countries other than the country where you live. Where required, we use appropriate safeguards for international transfers and apply the protections described in this policy.
Changes to this policy
We may update this Privacy Policy as AuthorityCat, applicable law, or our data practices change. We will publish the revised policy at this URL and update the effective date. If a change materially affects your rights, we will provide additional notice where appropriate.
Contact us
Questions, privacy requests, and Google user-data requests can be sent to aamirmursleen@gmail.com. Please include enough information for us to identify the relevant AuthorityCat account and request.
