Essential means essential
Authentication, CSRF protection, live crawl state and fraud prevention are limited to operating and securing requested features.
Your browser, your choice
This policy explains the cookies, local storage, scripts and similar technologies used by ScanMySEO. Essential technologies keep accounts, audits, reports and payments secure. Optional analytics are controlled through Cookie Settings.
At a glance
Rejecting optional analytics does not stop you from registering, signing in, running an authorised audit, viewing reports or managing billing. Security and user-requested technologies may still operate because those features cannot work safely without them.
Authentication, CSRF protection, live crawl state and fraud prevention are limited to operating and securing requested features.
Google Analytics 4 must remain inactive until you make an affirmative analytics choice.
ScanMySEO does not currently authorise behavioural advertising, retargeting or social-media tracking cookies.
Open Cookie Settings at any time. Withdrawing consent is intended to be as easy as giving it.
Controls and related information
1
ScanMySEO is operated by SCANMYSEO LTD, a company registered in England and Wales under company number 17166063. “ScanMySEO”, “we”, “us” and “our” refer to SCANMYSEO LTD.
This policy applies when you use scanmyseo.com, registration and sign-in pages, the audit interface, customer dashboards, findings and report pages, billing interfaces, AI Enhanced Audit, Ask Cozmo or Report AI, and other browser-based parts of the service that link to this policy.
It covers technologies placed or accessed directly by ScanMySEO, technologies operated by service providers on our pages, and relevant technologies encountered when you choose to leave ScanMySEO for a provider-hosted flow such as Google sign-in, LinkedIn sign-in, Stripe Checkout or the Stripe Customer Portal.
2
A cookie is a small text record a website asks a browser to store. This policy also uses “technology” to include local storage, session storage, server session identifiers, pixels, tags, scripts, software development kits, browser permissions, device or browser identifiers, URL parameters, embedded content and comparable methods of storing or accessing information on a device.
A technology can process personal data even where it does not reveal your name. Online identifiers, IP addresses, device information and combinations of usage events may still relate to an identifiable person. More information is in our Privacy Policy.
3
Under this version of the policy, ScanMySEO uses affirmative consent for optional analytics. We do not rely on the limited statistical-purpose exception as the basis for Google Analytics 4. The required production behaviour is:
Google Tag Manager, the Google Analytics library and any Google Analytics
noscript frame must be technically blocked before analytics consent. If a
release fails that test, it is a configuration defect to be corrected rather than a
basis for treating the visitor as having agreed.
Strictly necessary and security technologies do not depend on analytics consent. They are used only where reasonably needed to provide a feature you request, authenticate a user, prevent fraud or abuse, preserve session integrity, detect technical faults, or comply with applicable security obligations.
4
Used for login sessions, account security, CSRF protection, OAuth state, rate limiting, reCAPTCHA, secure checkout initiation and fraud prevention.
Used for live crawl progress, report-download authorisation, remembered preferences and avoiding repeated completion prompts.
Google Analytics 4 measures site and feature use only after an affirmative analytics choice.
Google, LinkedIn and Stripe may use their own technologies when you intentionally enter their sign-in or payment environments.
ScanMySEO does not currently use a marketing, cross-site behavioural advertising, retargeting, affiliate-conversion or social-media tracking category. We will not add one silently. A future introduction would require a revised inventory and an appropriate choice before the technology operates.
5
The table describes the approved production configuration as at the effective date. Exact provider names and expiry periods can vary by browser, account state, provider release and whether you already have a provider account. ScanMySEO reviews the inventory against live logged-out, logged-in, consent-rejected, consent-accepted, OAuth and Stripe journeys.
| Name or technology | Provider / party | Purpose and information | Typical duration | Choice |
|---|---|---|---|---|
session or configured equivalent |
ScanMySEO · first party | Maintains the signed-in session, security state, pending return destination and permitted temporary crawl state. The cookie holds a protected session identifier or signed session value, not your password. | Browser session and server-side expiry; under the current application configuration, an ordinary permanent session lasts for up to 12 hours and may end sooner after logout or a security event. | Necessary operates before consent. |
remember_token or configured equivalent |
ScanMySEO · first party | Keeps a user signed in only when “Remember me” is selected. It is protected with Secure, HttpOnly and SameSite controls in production. | Up to 14 days, or sooner on logout, password/security action or manual deletion. | User requested |
| CSRF token in form fields or page metadata | ScanMySEO · first party | Helps confirm that account, billing and form submissions came from the expected session. This is normally a token rather than a separate tracking cookie. | Current form or session. | Necessary |
| OAuth state, nonce and temporary return state | ScanMySEO · first party | Protects Google and LinkedIn sign-in against request forgery, preserves a safe return destination and can temporarily retain a pending crawl URL. | Current sign-in flow or session; removed or invalidated after completion or expiry. | Necessary when selected |
scanmyseo_cookie_preferences_v2 |
ScanMySEO · first party | Records whether optional analytics was accepted or rejected, the categories chosen, timestamp, consent-interface version and policy version. | Up to 6 months, then we ask again where appropriate; replaced sooner after a material change. | Preference record |
lastReportTimestamp in local storage |
ScanMySEO · first party | Remembers when the report-completion experience was last shown so the same completion prompt is not repeated unnecessarily. | Until overwritten or browser storage is cleared. It is used only to manage the report-completion interface and is not an advertising identifier. | Functionality |
| Socket.IO connection or transport identifiers | ScanMySEO · first party | Connects an authenticated browser to the correct user room for live audit progress, reconnection and billing or completion events. Identifiers are not used for advertising. | Current connection or browser session. | Functionality |
_GRECAPTCHA and relevant Google security cookies |
Google reCAPTCHA · third party | Assesses interaction, device, network and browser signals to distinguish legitimate users from automated abuse on protected forms and actions. Existing Google cookies may also be available to Google. | Provider-controlled. Google determines the exact duration under its security configuration and may retain the cookie for several months. | Security |
Google Tag Manager container GTM-MPDZZTHK |
Google Tag Manager · third party script | Manages approved optional analytics tags. The container does not need a dedicated advertising purpose and is not authorised to publish unclassified tags. | The script is loaded for the page after analytics consent; GTM itself does not ordinarily set a dedicated cookie. | Analytics consent |
_ga |
Google Analytics 4 · third party | Distinguishes browser instances for aggregate usage measurement. ScanMySEO must not send names, email addresses, full report identifiers or customer-entered website URLs as analytics parameters. | Up to 2 years, refreshed on qualifying activity unless removed sooner. | Analytics consent |
_ga_2EH3ZH5FGX or _ga_<container-id> |
Google Analytics 4 · third party | Maintains session state for the ScanMySEO GA4 property and measurement ID G-2EH3ZH5FGX. |
Up to 2 years, refreshed on qualifying activity unless removed sooner. | Analytics consent |
| Google account cookies during Google sign-in | Google · third party | Recognises an existing Google session, presents the authorisation screen and secures the OpenID Connect flow. ScanMySEO requests basic identity information such as verified email, name and provider user identifier. | Set and retained by Google under its own settings and policy. | Only when selected |
| LinkedIn account cookies during LinkedIn sign-in | LinkedIn · third party | Recognises an existing LinkedIn session, presents authorisation and secures the OpenID Connect flow. ScanMySEO requests basic identity information such as email, name and provider user identifier. | Set and retained by LinkedIn under its own settings and policy. | Only when selected |
__stripe_mid, __stripe_sid, m and related Stripe security cookies |
Stripe · third party | Fraud prevention, secure payment, checkout continuity, customer-portal authentication and payment-service reliability. Stripe receives device, browser, network, transaction and account-linkage information under its own notice. | Varies by cookie. __stripe_sid is typically short-lived; __stripe_mid may remain for about 1 year; some security records may persist longer. |
Payment/security |
A browser scan may also show provider load-balancing, content-delivery or bot-security identifiers that change without notice. We list a newly material purpose or persistent identifier in the next policy revision rather than disguising it under a catch-all.
6
These technologies support functions such as:
We assess necessity by asking whether the requested feature can be delivered safely and proportionately without the technology. A provider being convenient does not, by itself, make every technology “strictly necessary”.
Blocking these technologies can prevent sign-in, secure forms, live progress, downloads, payment or account protection from working. Analytics rejection does not have that effect.
7
ScanMySEO may remember a limited interface preference where doing so is necessary to
deliver a requested experience or avoid repeatedly interrupting you. Current examples
include the cookie-choice record and lastReportTimestamp. The browser can
also remember its own theme, reduced-motion, language, zoom and permission settings.
We do not use local storage as an undeclared substitute for advertising cookies. A new persistent key must be classified, documented and included in release testing before it is introduced.
Clearing site data in your browser removes local storage and most first-party cookies. This can sign you out, reset preferences and cause notices to be shown again. Clearing a browser record does not necessarily delete information already received by ScanMySEO or a provider; those records are handled under the Privacy Policy and the provider’s policy.
8
With your permission, ScanMySEO uses Google Analytics 4 (“GA4”) to understand aggregate
website and feature usage, diagnose journeys that are difficult to use, measure whether
product information is being found and improve service performance. Our GA4 measurement
ID is G-2EH3ZH5FGX.
The configuration governed by this policy is intended to:
After consent, Google may receive or derive a pseudonymous browser identifier, truncated or processed network information, page or screen details, device and browser properties, approximate location, referral source, event timestamps and configured product events. Pseudonymous does not mean anonymous.
Withdrawing analytics consent stops future optional analytics loading and should trigger deletion of ScanMySEO-domain GA cookies where technically possible. It does not guarantee deletion of information already lawfully received by Google or independently held in a Google account. You can also use Google’s browser opt-out tool.
Read Google’s Analytics privacy information and Google’s Analytics Opt-out Browser Add-on.
9
Google Tag Manager (“GTM”) is a tag-management system, not the analytics product itself.
The approved ScanMySEO container is GTM-MPDZZTHK. GTM can cause other scripts
to load, so the privacy impact depends on the tags published through it.
ScanMySEO’s production rule is that GTM must not load until the visitor permits analytics.
The container must use a default-denied state, and no noscript fallback may
bypass that choice. Only authorised personnel may publish changes. Each new tag must be
assigned a provider, purpose, category, data set, retention period and consent status
before release.
GTM is not authorised under this policy to load advertising pixels, social-media pixels, session-replay tools, fingerprinting or experimentation tags. Introducing any such purpose would require a new assessment and updated controls.
10
ScanMySEO uses Google reCAPTCHA on protected forms and actions to reduce automated account abuse, spam, credential attacks and fraudulent submissions. Depending on page design, reCAPTCHA may load when a protected page opens or immediately before submission.
Google can process interaction patterns, IP address, browser and device properties, cookies, page context and risk signals. Where you are already signed in to Google, Google may be able to associate activity with that Google environment under its own terms. We treat the limited security use as necessary because the protected operation would face a materially higher abuse risk without proportionate bot controls.
Blocking reCAPTCHA can prevent a protected registration, sign-in, newsletter or report action from being submitted. It does not permit ScanMySEO or Google to use the security integration as an undeclared analytics or advertising tag.
Google’s Privacy Policy and Terms apply to Google’s processing.
11
“Continue with Google” and “Continue with LinkedIn” are optional authentication routes. Selecting one redirects you to that provider or opens its authorisation environment. The provider can recognise whether your browser is already signed in and can use its own account, security and preference cookies.
ScanMySEO uses temporary state and nonce values to protect the callback. We request the minimum basic identity scopes needed for sign-in: OpenID identity, profile and email. We do not use those permissions to post to your provider account, read private social posts or access your contacts.
Rejecting ScanMySEO analytics does not remove Google or LinkedIn cookies that those providers already placed on their own domains. You can instead use password sign-in where available. Provider controls are described in Google’s Privacy Policy and LinkedIn’s Privacy Policy.
12
ScanMySEO redirects eligible customers to Stripe-hosted Checkout and the Stripe Customer Portal. Stripe uses cookies and related device signals to prevent fraud, secure payments, authenticate portal sessions, remember checkout progress and meet financial-services obligations.
Stripe controls the technologies on Stripe-hosted pages. ScanMySEO cannot delete every Stripe-domain cookie or override Stripe’s legal retention duties. Rejecting optional ScanMySEO analytics does not disable the strictly necessary Stripe technologies required when you choose to pay or manage a subscription.
ScanMySEO does not receive or store your complete card number or card security code. Details of Stripe’s technologies are in Stripe’s Cookie Policy and Privacy Policy.
13
The audit interface can open an authenticated Socket.IO connection so your browser can receive progress, page-count, completion and billing-confirmation events without constant page refreshes. Connection or transport identifiers can be created in browser memory, session state or network requests and are tied to the authenticated session.
The server verifies the signed-in user before joining a user-specific room. The identifiers are used for delivery, reconnection, fault diagnosis and preventing cross-user disclosure. They are not an advertising identity and are not intended to track you after the connection or session ends.
14
The audit experience may offer a browser notification when a report is ready. Permission is optional and is controlled by your browser or operating system. Refusing or later disabling notifications does not affect report access.
The browser stores the permission decision. A notification should contain only concise service information, such as that an audit has completed, and should not expose sensitive report content on a locked screen. You can revoke permission in your browser’s site settings.
15
Some pages request browser libraries, fonts, icons or styles from external delivery providers. A request can disclose IP address, browser and device headers, requested URL, timestamp and referrer even where no persistent cookie is set. Current examples may include Google Fonts, cdnjs or Cloudflare, jsDelivr, BootstrapCDN and DataTables CDN.
These requests are used to deliver interface resources, not to create a ScanMySEO advertising profile. We review whether self-hosting or privacy-preserving delivery is practical and restrict referrer information through browser security headers where appropriate.
Optional external videos, social widgets, review tools or similar embeds should use a click-to-load or consent-controlled design before they can set non-essential technology. A normal text link to an external website does not load that website’s cookies until you follow it.
16
You can:
Browsers let you view, delete or block cookies and site data. Blocking all cookies can prevent authentication, secure forms, Stripe flows or report downloads from working. Private browsing can also shorten storage duration. Browser controls supplement rather than replace our own optional-cookie controls.
Where a legally recognised browser signal such as Global Privacy Control applies to the relevant processing, ScanMySEO will treat it as an objection or opt-out signal to the extent required. Because the site already offers a direct reject control, you should use Cookie Settings for the clearest account-independent record of your choice.
Google, LinkedIn and Stripe provide their own account and cookie controls. ScanMySEO’s settings cannot remove a provider cookie placed independently on the provider’s domain or undo information collected before you withdrew consent.
17
Expiry periods are listed in the inventory. A cookie may disappear earlier because you logged out, changed a password, cleared storage, used private browsing, withdrew consent or the provider rotated its security state. Some technologies refresh their expiry when used again.
The ScanMySEO consent preference is normally kept for up to 6 months so we do not ask on every visit. We may ask sooner after a material change, when the stored version cannot be read, or where law or guidance calls for a renewed choice.
Withdrawing analytics consent stops future optional use. We attempt to remove first-party GA cookies available to our domain, but browser restrictions and provider-side retention mean this is not a promise that every historic copy is immediately erased. Personal data retention outside the browser is explained in the Privacy Policy.
18
Third-party technologies can result in information being processed outside the United Kingdom, including by globally operated Google, LinkedIn and Stripe services. Depending on the service and destination, transfers are protected through UK adequacy regulations, contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, transfer-risk assessments and supplementary security measures.
Provider locations, purposes and safeguards are described more fully in our Privacy Policy.
19
ScanMySEO accounts are intended for people aged 18 or over. We do not intentionally use optional analytics to profile children or serve targeted advertising. A parent or guardian who believes a child has created an account or that a child’s device information has been processed unexpectedly should contact us so we can investigate and take proportionate action.
20
We update this policy when a technology, provider, purpose, retention period, legal basis or consent design materially changes. The effective date and version change only after a genuine review; they are not automatically replaced with the current date on every page load.
Our release and review process should include:
A material new optional purpose will be brought to your attention before it begins. We do not treat continued browsing as consent to a new optional technology.
21
Questions about cookies, consent records or browser technologies can be sent to cozmo@scanmyseo.com with the subject “Cookie and privacy question”, or through the ScanMySEO contact form.
Include the browser, device type, page and approximate time of the issue where you are reporting an unexpected technology. Do not send passwords, card details, private keys or other secrets.
Contact ScanMySEO or reopen Cookie Settings without signing in.
Your privacy, clearly controlled
Essential cookies keep your account secure. With your permission, optional analytics and marketing cookies help us improve the product and understand what is useful. Read the cookie policy.
Cookie settings