Legal
Privacy Policy
A readable summary of how AuthorityCat handles account, marketplace, payment, analytics, cookie, Google Search Console, Ahrefs, Moz, and support data.
On this page
Scope
This Privacy Policy explains how AuthorityCat handles information when someone visits the public website, creates an account, uses buyer, publisher, team, or admin workspaces, submits websites, manages projects or orders, connects integrations, or contacts support.
- Public website visits
- Authenticated platform workspaces
- Marketplace and project activity
- Support and contact requests
Account information and authentication
AuthorityCat may process account details such as name, email address, profile image, account type, workspace role, organization membership, sign-in provider identifiers, session state, and security logs needed to authenticate users and protect accounts.
- Clerk authentication where configured
- Google sign-in where selected
- Workspace role and access checks
- Security and abuse-prevention logs
Marketplace activity
Marketplace activity can include searches, publisher website records, submitted domains, verification state, categories, languages, prices, placement types, metrics, orders, messages, favorites, blocklists, and audit history needed to operate the buyer and publisher workflow.
- Website listings and moderation
- Buyer evaluation and orders
- Publisher delivery records
- Administrative review history
Payments and wallet
AuthorityCat may store wallet transactions, order amounts, payment status, payout state, provider references, and limited payment details returned by configured providers. Full card data is handled by the payment provider and should not be sent through support messages.
- Wallet credits and debits
- Order payment status
- Payout records
- Provider references
Analytics, cookies, and browser storage
Cookies and browser storage can be used for authentication, OAuth state, workspace selection, account-scoped dashboard state, fraud prevention, reliability, and analytics where configured. Essential storage is needed for sign-in and workspace continuity.
- Session cookies
- OAuth verification state
- Account-scoped UI state
- Service analytics where enabled
Third-party integrations
AuthorityCat may use third-party services for authentication, hosting, database storage, payments, email or support handling, analytics, Ahrefs metrics, Moz metrics, and Google Search Console features where those integrations are configured.
- Google Search Console read-only data when connected
- Ahrefs metric data where available
- Moz metric data where available
- Payment and infrastructure providers
Google and Search Console
If a user connects Google Search Console, AuthorityCat uses the granted read-only access to list accessible properties and show selected search-performance data inside the relevant project workflow. The connection is used to provide the requested feature and can be disconnected by the user where the product supports it.
- Read-only Search Console access
- Properties selected by the user
- Queries, pages, clicks, impressions, CTR, and position where available
- No modification of Google properties
Data security and user rights
AuthorityCat uses access controls, authenticated sessions, server-side credentials, encrypted tokens where configured, transport security, and operational safeguards. Users may request access, correction, deletion, or other privacy actions according to applicable law and product limitations.
- Role-based access
- Credential protection
- Data requests through Contact
- Retention for orders, payments, audit, and legal obligations where required
Contact
Privacy questions and data requests should be sent through the Contact page with the account email and enough detail to identify the affected workspace, project, listing, order, or integration.
- Use /contact
- Include account email
- Do not send passwords or full card numbers
Need to make a privacy request?
Include the account email and the workspace, project, listing, order, or integration related to the request.
