Privacy Policy
VettedPublishers is in waitlist-validation phase. This policy explains exactly what we collect from you, why, how long we keep it, and how to get it back or delete it. Plain language. No dark patterns.
Data we collect
VettedPublishers now has three data-collecting surfaces: the waitlist form, the free TrustCheck tool, and paid Vetted List orders. This section covers the waitlist form; TrustCheck and Vetted List orders each have a dedicated section below (§04 and §05) because what they collect and why is different enough to deserve its own explanation.
When you submit the waitlist form, we store the following fields:
- Email address (required) - so we can confirm the submission and reach you with the validation outcome.
- Role (required) - one of: Agency, In-house SEO, Freelancer, or Other.
- Company URL (optional).
- Monthly placement volume (required) - a bucket: <5, 5-15, 15-50, or 50+.
- Biggest vetting headache (optional, free text, 500-character cap) - used to shape positioning and roadmap.
- Interview opt-in (optional checkbox) - if checked, we may reach out to schedule a 30-minute conversation about your vetting workflow.
We also use Plausible Analytics for traffic insight. Plausible is cookieless and does not store personally identifiable information. It records anonymous pageviews, referrer, country (not IP), and a single custom event when the waitlist form is submitted successfully.
Why we collect it
- Confirmation email - to acknowledge your waitlist submission.
- Validation outcome update - at roughly the 60-day mark, we email everyone on the list with whether the thesis validated and what comes next (founding-member access, public launch timing, or a clean shutdown).
- Interview reach-out - only if you opted in. Five-to-fifteen-minute scheduling exchange, no marketing follow-up.
- Positioning & roadmap improvement - the role, volume, and headache fields tell us which segments respond, what they struggle with, and what to build first. This is the entire reason the waitlist exists.
- TrustCheck & Vetted List fulfillment - to run the verdict pipeline you asked for and, for paid orders, to vet the domains you submitted and deliver an evidence dossier. See §04 and §05.
Plausible data is used in aggregate to understand which pages and traffic sources convert. It is never linked to a specific individual.
How long we keep it
Your waitlist submission is retained for the duration of the validation window (60-90 days from sign-up), then one of two things happens:
- If we proceed to product - your record migrates to account-context for the live VettedPublishers product. You can export every byte we hold or request full deletion at any time, no questions asked.
- If we kill the thesis - you receive a clean shutdown email explaining why, and all waitlist records are purged within 30 days of that email.
TrustCheck results and Vetted List order data follow different retention windows, described in §04 and §05 - they are separate flows from the waitlist and are not folded into this 60-90 day window.
TrustCheck data capture
TrustCheck is the free, single-domain tool on the homepage. When you run a check, we store the following in Supabase (hosted in the EU, eu-central-1):
- The domain you checked, the signals we pulled for it (Ahrefs-derived metrics such as domain rating, traffic, and keyword-profile shape), and the verdict our engine generated from those signals.
- Your email address (optional) - only requested if you run a second check or hit a rate limit, so we can send you the result instead. We never require an email for a first, single check.
- A hashed IP address - we never store your raw IP. It is run through SHA-256 with a static server-side salt before it touches the database, solely to enforce per-IP daily usage caps and stop abuse. The hash cannot be reversed back to your IP address.
Results are cached for 30 days, so a repeat check on the same domain (by you or anyone else) is served from that cached record instead of re-running the pipeline. This is also how the same evidence is shown consistently to anyone checking that domain within the window.
Uploaded vendor lists (Vetted List orders)
If you purchase a Vetted List, the domain list you upload after checkout is customer confidential. It is stored in a private Supabase Storage bucket (vendor-lists) that is never publicly readable - access is only possible through short-lived signed URLs, used solely by us during fulfillment.
We never share or resell your list. It is used for exactly one purpose: vetting the domains you submitted and producing your dossier. It is never handed to a third party, never used to build a competing product, and never used for anything beyond your order.
The one exception: where our vetting process confirms a domain belongs to a known link farm network, we may retain an anonymized brand-token in our cross-network watchlist - a normalized fragment of the domain name or a repeated branded keyword, not your company’s identity, your full list, or the full domain itself. This is how the same farm signal protects every future customer, not just you. Your identity, your order details, and your uploaded file are never added to the watchlist.
Uploaded files are accessed only via signed URLs with a limited window (90 days from upload) to support delivery and any follow-up under our 6-month guarantee. Order and verdict records themselves are retained longer, so the guarantee remains honorable for its full term.
AI model processing disclosure
During fulfillment of a Vetted List order, we use the Anthropic Claude API to assist with one step of our internal review pipeline: reading an exported keyword profile for a single candidate domain and producing a structured read - an estimated garbage-keyword share, brand-token candidates, and anomaly notes.
This is AI-assisted, operator-confirmed: the model never makes an accept/reject decision on a domain, and every output is reviewed by a human operator before anything reaches your dossier. Only the keyword export needed for that specific triage step is sent to the model - not your identity, payment details, uploaded file, or any part of your list unrelated to the domain being triaged. No other model provider is used anywhere in the pipeline.
Payment processing - Stripe
Vetted List orders are paid through Stripe Checkout, a hosted payment page operated by Stripe. We never see, collect, or store your card number, expiry date, or CVC - Stripe handles that entirely on infrastructure built for PCI-DSS compliance. All we receive back is the payment status, the amount charged, and the email address you provide at checkout.
Third parties we use
We use six vendors. All six are listed for transparency:
- Netlify - hosts the site and handles the waitlist form submission storage. US-based. GDPR-compliant DPA available on request.
- Resend - sends transactional email (waitlist confirmation, validation-outcome update, order and delivery emails). Email content and recipient address only; no marketing-platform integration.
- Plausible Analytics - EU-hosted, cookieless. No personal identifiers.
- Supabase - EU-hosted (eu-central-1) database and private file storage for TrustCheck results and uploaded vendor lists. Accessed only with a server-side service-role key; never exposed to the browser.
- Stripe - processes payment for Vetted List orders. See §07 - we never see your card details.
- Anthropic - powers the Claude API used for AI-assisted keyword triage during fulfillment (internal ops tooling only; not used by the live site or by TrustCheck). See §06.
We do not sell your data. We do not share it with marketing platforms, ad networks, or data brokers. The vendor list above is the complete list - no silent processors behind it.
Your rights (GDPR + CCPA)
Whether or not you live in a GDPR or CCPA jurisdiction, you have the following rights with us:
- Request a copy of every byte of data we hold on you.
- Request deletion of your record at any time.
- Request correction of any field (e.g., updating your email or company URL).
- Withdraw consent at any time. Withdrawing consent results in deletion of your record within 30 days.
To exercise any of these rights, email ontheroadseo@gmail.com with the subject line “Privacy request” and a one-line description of what you want done. We respond within 7 business days.
Contact
For any policy or data question, email ontheroadseo@gmail.com. Same address handles privacy requests, security reports, and general questions about VettedPublishers.
Note · policy will update at product graduation
This policy reflects the waitlist-validation phase. When VettedPublishers graduates from waitlist to live product, the policy will be updated to reflect the new data flows (account context, domain submissions, billing, etc). We will email every person on the waitlist before the new policy takes effect, with a clear summary of what changed and the option to delete your record before continuing.