Privacy Policy
Last updated 3 September 2026
This policy explains what SupaTraffic collects, why we collect it, who we share it with, and what you can do about it. It covers both the website and the product.
1. What we collect
Your account. Your name, email address and profile picture, from Google when you sign in with it, or just your email address if you use a sign-in link. We never see or store a password.
The websites you connect. Which site it is, its address, the titles and addresses of its pages, and the readable text of a handful of them. How we get that depends entirely on how you connected the site, and the two paths are genuinely different:
- Connected through Webflow. You never give us an address. You approve SupaTraffic on Webflow, Webflow tells us which sites you granted, you pick one, and everything we learn about that site — its name, its address, its pages — comes from Webflow’s own API using the permissions you approved. We do not fetch your published website.
- Connected by address — WordPress, Ghost, Framer, or any other site. You type the address, and our server fetches the readable text of a handful of that site’s public pages, the same way any visitor’s browser would. We only ever read pages that are publicly reachable.
Credentials for the sites you connect. Approving SupaTraffic on Webflow, Shopify, Notion or GitHub makes that platform issue us an access token. On WordPress, Ghost, Framer and HubSpot you paste in a key the platform issued to you. Either way we store it encrypted, on our servers only. It is never sent to your browser, never shown in a page, never written to a log and never shared. We use it to publish the articles you asked for and — on Webflow and GitHub, where the platform is also how we read your site — to read the site or repository you picked. Nothing else.
What the product produces. The brand profile written from what we read, your keyword library, your calendar, and the articles themselves, including any edits you make.
Billing. Your subscription status and credit balance. Card details go directly to Stripe and never touch our servers.
Basic technical logs. IP address, browser and timestamps, kept for security and debugging.
2. Why we collect it
- To run the product you signed up for, which is the bulk of it.
- To bill you correctly and stop credits being spent twice.
- To keep the service up and to investigate abuse — someone giving us the address of a website that is not theirs, for instance.
- To send you service email. We do not sell your data to anyone, ever.
3. Who else sees it
We use a small number of processors, and only where the work genuinely requires it:
- Our model provider — the text of your connected website, however we read it, and your brand profile are sent to a language model to produce keywords and articles. This is the core of the product and cannot be opted out of while using it.
- The platform you connected — Webflow, WordPress, Ghost, Framer, Shopify, HubSpot, Notion or GitHub. We read the site you picked from it, and we send it the articles you publish. Only the one you connected, and only the site or collection you chose within it.
- Stripe — payments and subscriptions.
- Google — only if you choose to sign in with a Google account.
- Our email provider — sign-in links and service notices.
- Our hosting and database provider — where the application runs and your data is stored.
We also disclose data where the law requires it, and we will tell you when we are permitted to.
4. How long we keep it
Your account and its content stay until they are deleted, and both deletions are in your hands: you can delete a project from Settings, and close your whole account either from Settings or from your account page, which opens whether or not you have a website connected. Deleting a project deletes its brand profile, keywords, articles and the page text we read from the site. Deleting your account removes your personal data; we keep the minimum billing records that tax law requires, and anonymised aggregates that cannot be traced back to you. If you would rather we did it, ask — see section 5.
Connection credentials. We keep a platform’s access token only while the connection is live. Disconnect it in SupaTraffic and we delete our copy, and ask the platform to revoke it as well. Revoke it on the platform instead and we can no longer use it; we delete our stored copy as soon as we find that it has stopped working. A token left behind by a connection you started and never finished is deleted the same way.
5. Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to how we are using it. Email us and we will action it — normally within a few days, and always within a month. If you are in the UK or EU you also have the right to complain to your data protection authority.
6. Cookies
We set a cookie to keep you signed in, and Stripe sets its own on the checkout flow to prevent fraud. Both are strictly necessary to operate the service. We do not run advertising or cross-site tracking cookies.
7. Security
Data is encrypted in transit and at rest, access is limited to the people who need it, and each customer’s content is isolated at the database level. No system is perfect; if a breach affects you we will tell you promptly.
8. Changes
If we change this policy materially we will email you before it takes effect. The date at the top always reflects the current version.
9. Contact
Questions about any of this: [email protected].