Skip to content
ScanMySEO
ScanMySEO website navigation
  • Search intelligence
  • How it works
  • Pricing
  • Contact
Log in Start free
  1. Home
  2. Cookie Policy

Your browser, your choice

Cookie Policy

This policy explains the cookies, local storage, scripts and similar technologies used by ScanMySEO. Essential technologies keep accounts, audits, reports and payments secure. Optional analytics are controlled through Cookie Settings.

Effective date
12 July 2026
Last updated
12 July 2026
Version
2.0
Organisation
SCANMYSEO LTD · 17166063

At a glance

Clear controls without blocking the core service

Rejecting optional analytics does not stop you from registering, signing in, running an authorised audit, viewing reports or managing billing. Security and user-requested technologies may still operate because those features cannot work safely without them.

01

Essential means essential

Authentication, CSRF protection, live crawl state and fraud prevention are limited to operating and securing requested features.

02

Analytics are optional

Google Analytics 4 must remain inactive until you make an affirmative analytics choice.

03

No advertising category

ScanMySEO does not currently authorise behavioural advertising, retargeting or social-media tracking cookies.

04

Change your mind

Open Cookie Settings at any time. Withdrawing consent is intended to be as easy as giving it.

Controls and related information

Manage your preferences or learn more

Personal data Privacy Policy How account, crawl, report, AI and technical information is handled. Service rules Terms of Service Rules governing accounts, audits, reports, subscriptions and AI features.
Contents
  1. Who we are and scope
  2. What the technologies are
  3. Our consent approach
  4. Categories we use
  5. Technology inventory
  6. Essential and security
  7. Preferences and local storage
  8. Google Analytics
  9. Google Tag Manager
  10. Google reCAPTCHA
  11. Google and LinkedIn sign-in
  12. Stripe
  13. Live crawl updates
  14. Browser notifications
  15. External resources and embeds
  16. How to control technologies
  17. Expiry and deletion
  18. International processing
  19. Children
  20. Changes and governance
  21. Contact

On this page

  1. Who we are and scope
  2. What the technologies are
  3. Our consent approach
  4. Categories we use
  5. Technology inventory
  6. Essential and security
  7. Preferences and local storage
  8. Google Analytics
  9. Google Tag Manager
  10. Google reCAPTCHA
  11. External sign-in
  12. Stripe
  13. Live crawl updates
  14. Browser notifications
  15. External resources
  16. Your controls
  17. Expiry and deletion
  18. International processing
  19. Children
  20. Changes and governance
  21. Contact
Back to top

1

Who we are and what this policy covers

ScanMySEO is operated by SCANMYSEO LTD, a company registered in England and Wales under company number 17166063. “ScanMySEO”, “we”, “us” and “our” refer to SCANMYSEO LTD.

This policy applies when you use scanmyseo.com, registration and sign-in pages, the audit interface, customer dashboards, findings and report pages, billing interfaces, AI Enhanced Audit, Ask Cozmo or Report AI, and other browser-based parts of the service that link to this policy.

It covers technologies placed or accessed directly by ScanMySEO, technologies operated by service providers on our pages, and relevant technologies encountered when you choose to leave ScanMySEO for a provider-hosted flow such as Google sign-in, LinkedIn sign-in, Stripe Checkout or the Stripe Customer Portal.

2

What cookies and similar technologies are

A cookie is a small text record a website asks a browser to store. This policy also uses “technology” to include local storage, session storage, server session identifiers, pixels, tags, scripts, software development kits, browser permissions, device or browser identifiers, URL parameters, embedded content and comparable methods of storing or accessing information on a device.

First-party technology
Set or read for the ScanMySEO domain and controlled by ScanMySEO or a provider acting for us.
Third-party technology
Set or read by another organisation, including Google, LinkedIn or Stripe, under that organisation’s own controls.
Session technology
Normally removed when the browser session ends, although server-side session expiry may occur sooner or later.
Persistent technology
Can remain after the browser closes until its expiry date, replacement or manual deletion.

A technology can process personal data even where it does not reveal your name. Online identifiers, IP addresses, device information and combinations of usage events may still relate to an identifiable person. More information is in our Privacy Policy.

3

Our consent approach

Under this version of the policy, ScanMySEO uses affirmative consent for optional analytics. We do not rely on the limited statistical-purpose exception as the basis for Google Analytics 4. The required production behaviour is:

  • optional analytics and Google Analytics storage remain off by default;
  • no analytics tag or measurement event is sent until you select an analytics choice;
  • rejecting analytics leaves the core service available;
  • closing or ignoring the banner is not treated as consent;
  • optional choices are not pre-selected;
  • withdrawal is available through the same Cookie Settings control used to give consent; and
  • a new purpose or materially different provider triggers an updated notice and, where required, a fresh choice.
Our deployment rule

Google Tag Manager, the Google Analytics library and any Google Analytics noscript frame must be technically blocked before analytics consent. If a release fails that test, it is a configuration defect to be corrected rather than a basis for treating the visitor as having agreed.

Strictly necessary and security technologies do not depend on analytics consent. They are used only where reasonably needed to provide a feature you request, authenticate a user, prevent fraud or abuse, preserve session integrity, detect technical faults, or comply with applicable security obligations.

4

Technology categories used by ScanMySEO

Strictly necessary, authentication and security

Used for login sessions, account security, CSRF protection, OAuth state, rate limiting, reCAPTCHA, secure checkout initiation and fraud prevention.

User-requested functionality

Used for live crawl progress, report-download authorisation, remembered preferences and avoiding repeated completion prompts.

Analytics and service improvement

Google Analytics 4 measures site and feature use only after an affirmative analytics choice.

External provider flows

Google, LinkedIn and Stripe may use their own technologies when you intentionally enter their sign-in or payment environments.

Categories not currently authorised

ScanMySEO does not currently use a marketing, cross-site behavioural advertising, retargeting, affiliate-conversion or social-media tracking category. We will not add one silently. A future introduction would require a revised inventory and an appropriate choice before the technology operates.

5

Current technology inventory

The table describes the approved production configuration as at the effective date. Exact provider names and expiry periods can vary by browser, account state, provider release and whether you already have a provider account. ScanMySEO reviews the inventory against live logged-out, logged-in, consent-rejected, consent-accepted, OAuth and Stripe journeys.

Cookies and related technologies used by ScanMySEO
Name or technology Provider / party Purpose and information Typical duration Choice
session or configured equivalent ScanMySEO · first party Maintains the signed-in session, security state, pending return destination and permitted temporary crawl state. The cookie holds a protected session identifier or signed session value, not your password. Browser session and server-side expiry; under the current application configuration, an ordinary permanent session lasts for up to 12 hours and may end sooner after logout or a security event. Necessary operates before consent.
remember_token or configured equivalent ScanMySEO · first party Keeps a user signed in only when “Remember me” is selected. It is protected with Secure, HttpOnly and SameSite controls in production. Up to 14 days, or sooner on logout, password/security action or manual deletion. User requested
CSRF token in form fields or page metadata ScanMySEO · first party Helps confirm that account, billing and form submissions came from the expected session. This is normally a token rather than a separate tracking cookie. Current form or session. Necessary
OAuth state, nonce and temporary return state ScanMySEO · first party Protects Google and LinkedIn sign-in against request forgery, preserves a safe return destination and can temporarily retain a pending crawl URL. Current sign-in flow or session; removed or invalidated after completion or expiry. Necessary when selected
scanmyseo_cookie_preferences_v2 ScanMySEO · first party Records whether optional analytics was accepted or rejected, the categories chosen, timestamp, consent-interface version and policy version. Up to 6 months, then we ask again where appropriate; replaced sooner after a material change. Preference record
lastReportTimestamp in local storage ScanMySEO · first party Remembers when the report-completion experience was last shown so the same completion prompt is not repeated unnecessarily. Until overwritten or browser storage is cleared. It is used only to manage the report-completion interface and is not an advertising identifier. Functionality
Socket.IO connection or transport identifiers ScanMySEO · first party Connects an authenticated browser to the correct user room for live audit progress, reconnection and billing or completion events. Identifiers are not used for advertising. Current connection or browser session. Functionality
_GRECAPTCHA and relevant Google security cookies Google reCAPTCHA · third party Assesses interaction, device, network and browser signals to distinguish legitimate users from automated abuse on protected forms and actions. Existing Google cookies may also be available to Google. Provider-controlled. Google determines the exact duration under its security configuration and may retain the cookie for several months. Security
Google Tag Manager container GTM-MPDZZTHK Google Tag Manager · third party script Manages approved optional analytics tags. The container does not need a dedicated advertising purpose and is not authorised to publish unclassified tags. The script is loaded for the page after analytics consent; GTM itself does not ordinarily set a dedicated cookie. Analytics consent
_ga Google Analytics 4 · third party Distinguishes browser instances for aggregate usage measurement. ScanMySEO must not send names, email addresses, full report identifiers or customer-entered website URLs as analytics parameters. Up to 2 years, refreshed on qualifying activity unless removed sooner. Analytics consent
_ga_2EH3ZH5FGX or _ga_<container-id> Google Analytics 4 · third party Maintains session state for the ScanMySEO GA4 property and measurement ID G-2EH3ZH5FGX. Up to 2 years, refreshed on qualifying activity unless removed sooner. Analytics consent
Google account cookies during Google sign-in Google · third party Recognises an existing Google session, presents the authorisation screen and secures the OpenID Connect flow. ScanMySEO requests basic identity information such as verified email, name and provider user identifier. Set and retained by Google under its own settings and policy. Only when selected
LinkedIn account cookies during LinkedIn sign-in LinkedIn · third party Recognises an existing LinkedIn session, presents authorisation and secures the OpenID Connect flow. ScanMySEO requests basic identity information such as email, name and provider user identifier. Set and retained by LinkedIn under its own settings and policy. Only when selected
__stripe_mid, __stripe_sid, m and related Stripe security cookies Stripe · third party Fraud prevention, secure payment, checkout continuity, customer-portal authentication and payment-service reliability. Stripe receives device, browser, network, transaction and account-linkage information under its own notice. Varies by cookie. __stripe_sid is typically short-lived; __stripe_mid may remain for about 1 year; some security records may persist longer. Payment/security

A browser scan may also show provider load-balancing, content-delivery or bot-security identifiers that change without notice. We list a newly material purpose or persistent identifier in the next policy revision rather than disguising it under a catch-all.

6

Strictly necessary, authentication and security technologies

These technologies support functions such as:

  • creating, rotating, maintaining and ending authenticated sessions;
  • implementing “Remember me” when requested;
  • protecting registration, login, password reset, account deletion and billing forms;
  • maintaining OAuth state and validating safe sign-in callbacks;
  • authorising access to private dashboards, reports and downloads;
  • preventing one user from receiving another user’s live crawl events;
  • rate limiting, bot detection, fraud prevention and suspicious-session investigation;
  • avoiding duplicate orders or submissions; and
  • detecting faults that affect delivery or security.

We assess necessity by asking whether the requested feature can be delivered safely and proportionately without the technology. A provider being convenient does not, by itself, make every technology “strictly necessary”.

Blocking these technologies can prevent sign-in, secure forms, live progress, downloads, payment or account protection from working. Analytics rejection does not have that effect.

7

Preferences, local storage and browser-held state

ScanMySEO may remember a limited interface preference where doing so is necessary to deliver a requested experience or avoid repeatedly interrupting you. Current examples include the cookie-choice record and lastReportTimestamp. The browser can also remember its own theme, reduced-motion, language, zoom and permission settings.

We do not use local storage as an undeclared substitute for advertising cookies. A new persistent key must be classified, documented and included in release testing before it is introduced.

Clearing site data in your browser removes local storage and most first-party cookies. This can sign you out, reset preferences and cause notices to be shown again. Clearing a browser record does not necessarily delete information already received by ScanMySEO or a provider; those records are handled under the Privacy Policy and the provider’s policy.

8

Google Analytics 4

With your permission, ScanMySEO uses Google Analytics 4 (“GA4”) to understand aggregate website and feature usage, diagnose journeys that are difficult to use, measure whether product information is being found and improve service performance. Our GA4 measurement ID is G-2EH3ZH5FGX.

8.1 Approved configuration

The configuration governed by this policy is intended to:

  • keep analytics storage and tag loading denied until consent;
  • use basic consent behaviour rather than advanced cookieless analytics pings before consent;
  • retain event-level GA4 user data for no longer than 14 months;
  • avoid sending email addresses, names, payment details, report contents, private dashboard data or customer-entered target URLs;
  • keep Google Signals, advertising personalisation, demographic reporting and User-ID disabled unless a future policy and consent interface expressly say otherwise; and
  • use collected information for ScanMySEO’s own aggregate product and website analysis, not cross-site advertising.

8.2 Information Google may receive

After consent, Google may receive or derive a pseudonymous browser identifier, truncated or processed network information, page or screen details, device and browser properties, approximate location, referral source, event timestamps and configured product events. Pseudonymous does not mean anonymous.

8.3 Withdrawal

Withdrawing analytics consent stops future optional analytics loading and should trigger deletion of ScanMySEO-domain GA cookies where technically possible. It does not guarantee deletion of information already lawfully received by Google or independently held in a Google account. You can also use Google’s browser opt-out tool.

Read Google’s Analytics privacy information and Google’s Analytics Opt-out Browser Add-on.

9

Google Tag Manager

Google Tag Manager (“GTM”) is a tag-management system, not the analytics product itself. The approved ScanMySEO container is GTM-MPDZZTHK. GTM can cause other scripts to load, so the privacy impact depends on the tags published through it.

ScanMySEO’s production rule is that GTM must not load until the visitor permits analytics. The container must use a default-denied state, and no noscript fallback may bypass that choice. Only authorised personnel may publish changes. Each new tag must be assigned a provider, purpose, category, data set, retention period and consent status before release.

GTM is not authorised under this policy to load advertising pixels, social-media pixels, session-replay tools, fingerprinting or experimentation tags. Introducing any such purpose would require a new assessment and updated controls.

10

Google reCAPTCHA

ScanMySEO uses Google reCAPTCHA on protected forms and actions to reduce automated account abuse, spam, credential attacks and fraudulent submissions. Depending on page design, reCAPTCHA may load when a protected page opens or immediately before submission.

Google can process interaction patterns, IP address, browser and device properties, cookies, page context and risk signals. Where you are already signed in to Google, Google may be able to associate activity with that Google environment under its own terms. We treat the limited security use as necessary because the protected operation would face a materially higher abuse risk without proportionate bot controls.

Blocking reCAPTCHA can prevent a protected registration, sign-in, newsletter or report action from being submitted. It does not permit ScanMySEO or Google to use the security integration as an undeclared analytics or advertising tag.

Google’s Privacy Policy and Terms apply to Google’s processing.

11

Google and LinkedIn sign-in

“Continue with Google” and “Continue with LinkedIn” are optional authentication routes. Selecting one redirects you to that provider or opens its authorisation environment. The provider can recognise whether your browser is already signed in and can use its own account, security and preference cookies.

ScanMySEO uses temporary state and nonce values to protect the callback. We request the minimum basic identity scopes needed for sign-in: OpenID identity, profile and email. We do not use those permissions to post to your provider account, read private social posts or access your contacts.

Rejecting ScanMySEO analytics does not remove Google or LinkedIn cookies that those providers already placed on their own domains. You can instead use password sign-in where available. Provider controls are described in Google’s Privacy Policy and LinkedIn’s Privacy Policy.

12

Stripe Checkout and Customer Portal

ScanMySEO redirects eligible customers to Stripe-hosted Checkout and the Stripe Customer Portal. Stripe uses cookies and related device signals to prevent fraud, secure payments, authenticate portal sessions, remember checkout progress and meet financial-services obligations.

Stripe controls the technologies on Stripe-hosted pages. ScanMySEO cannot delete every Stripe-domain cookie or override Stripe’s legal retention duties. Rejecting optional ScanMySEO analytics does not disable the strictly necessary Stripe technologies required when you choose to pay or manage a subscription.

ScanMySEO does not receive or store your complete card number or card security code. Details of Stripe’s technologies are in Stripe’s Cookie Policy and Privacy Policy.

13

Socket.IO and live audit progress

The audit interface can open an authenticated Socket.IO connection so your browser can receive progress, page-count, completion and billing-confirmation events without constant page refreshes. Connection or transport identifiers can be created in browser memory, session state or network requests and are tied to the authenticated session.

The server verifies the signed-in user before joining a user-specific room. The identifiers are used for delivery, reconnection, fault diagnosis and preventing cross-user disclosure. They are not an advertising identity and are not intended to track you after the connection or session ends.

14

Browser notifications

The audit experience may offer a browser notification when a report is ready. Permission is optional and is controlled by your browser or operating system. Refusing or later disabling notifications does not affect report access.

The browser stores the permission decision. A notification should contain only concise service information, such as that an audit has completed, and should not expose sensitive report content on a locked screen. You can revoke permission in your browser’s site settings.

15

External resources, content-delivery networks and embeds

Some pages request browser libraries, fonts, icons or styles from external delivery providers. A request can disclose IP address, browser and device headers, requested URL, timestamp and referrer even where no persistent cookie is set. Current examples may include Google Fonts, cdnjs or Cloudflare, jsDelivr, BootstrapCDN and DataTables CDN.

These requests are used to deliver interface resources, not to create a ScanMySEO advertising profile. We review whether self-hosting or privacy-preserving delivery is practical and restrict referrer information through browser security headers where appropriate.

Optional external videos, social widgets, review tools or similar embeds should use a click-to-load or consent-controlled design before they can set non-essential technology. A normal text link to an external website does not load that website’s cookies until you follow it.

16

How to control cookies and related technologies

16.1 ScanMySEO Cookie Settings

You can:

  • accept optional analytics;
  • reject optional analytics;
  • save a customised choice where more than one optional category is introduced;
  • reopen settings from the footer without signing in; and
  • withdraw consent without losing ordinary access to the core service.

16.2 Browser controls

Browsers let you view, delete or block cookies and site data. Blocking all cookies can prevent authentication, secure forms, Stripe flows or report downloads from working. Private browsing can also shorten storage duration. Browser controls supplement rather than replace our own optional-cookie controls.

16.3 Global Privacy Control and browser signals

Where a legally recognised browser signal such as Global Privacy Control applies to the relevant processing, ScanMySEO will treat it as an objection or opt-out signal to the extent required. Because the site already offers a direct reject control, you should use Cookie Settings for the clearest account-independent record of your choice.

16.4 Provider controls

Google, LinkedIn and Stripe provide their own account and cookie controls. ScanMySEO’s settings cannot remove a provider cookie placed independently on the provider’s domain or undo information collected before you withdrew consent.

17

Expiry, renewal and deletion

Expiry periods are listed in the inventory. A cookie may disappear earlier because you logged out, changed a password, cleared storage, used private browsing, withdrew consent or the provider rotated its security state. Some technologies refresh their expiry when used again.

The ScanMySEO consent preference is normally kept for up to 6 months so we do not ask on every visit. We may ask sooner after a material change, when the stored version cannot be read, or where law or guidance calls for a renewed choice.

Withdrawing analytics consent stops future optional use. We attempt to remove first-party GA cookies available to our domain, but browser restrictions and provider-side retention mean this is not a promise that every historic copy is immediately erased. Personal data retention outside the browser is explained in the Privacy Policy.

18

International processing

Third-party technologies can result in information being processed outside the United Kingdom, including by globally operated Google, LinkedIn and Stripe services. Depending on the service and destination, transfers are protected through UK adequacy regulations, contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, transfer-risk assessments and supplementary security measures.

Provider locations, purposes and safeguards are described more fully in our Privacy Policy.

19

Children

ScanMySEO accounts are intended for people aged 18 or over. We do not intentionally use optional analytics to profile children or serve targeted advertising. A parent or guardian who believes a child has created an account or that a child’s device information has been processed unexpectedly should contact us so we can investigate and take proportionate action.

20

Changes, audits and governance

We update this policy when a technology, provider, purpose, retention period, legal basis or consent design materially changes. The effective date and version change only after a genuine review; they are not automatically replaced with the current date on every page load.

Our release and review process should include:

  • logged-out and logged-in browser scans on desktop and mobile;
  • tests before a choice, after rejection, after acceptance and after withdrawal;
  • registration, password, OAuth, report, AI, Stripe Checkout and Customer Portal journeys;
  • inspection of cookies, local storage, session storage, IndexedDB, network requests, tags and embeds;
  • review of the GTM container before and after publication;
  • verification that optional tags do not load on this Cookie Policy itself before consent; and
  • a versioned record of the inventory and test result.

A material new optional purpose will be brought to your attention before it begins. We do not treat continued browsing as consent to a new optional technology.

21

Contact us

Questions about cookies, consent records or browser technologies can be sent to cozmo@scanmyseo.com with the subject “Cookie and privacy question”, or through the ScanMySEO contact form.

Include the browser, device type, page and approximate time of the issue where you are reporting an unexpected technology. Do not send passwords, card details, private keys or other secrets.

Need help with a preference or unexpected cookie?

Contact ScanMySEO or reopen Cookie Settings without signing in.

Contact ScanMySEO
Back to top Privacy Policy Terms of Service

Your privacy, clearly controlled

A few cookies make ScanMySEO work better.

Essential cookies keep your account secure. With your permission, optional analytics and marketing cookies help us improve the product and understand what is useful. Read the cookie policy.

Cookie settings

Choose what ScanMySEO may use.

Policy details
ScanMySEO Technical SEO and website intelligence

Built for founders, marketers, developers and agencies who need clear priorities without losing the underlying evidence.

Public-site analysis Human implementation remains final

Platform

  • Search intelligence
  • How it works
  • Full audit checks
  • Plans and pricing

Resources

  • Articles and fix guides
  • Product feedback
  • Contact and support
  • About ScanMySEO

Trust and control

  • Terms of Service
  • Privacy Policy
  • Cookie Policy

Signals worth acting on

Join the ScanMySEO intelligence briefing.

Product updates, practical SEO guidance and evidence-led website intelligence. No purchased lists.

Protected by reCAPTCHA.

© SCANMYSEO LTD · Registered in England and Wales · Company 17166063

LinkedIn Feedback