GeoCurves Privacy Center

Privacy Policy

A practical explanation of the information behind your account, your analyses and your privacy choices.

Last updated: 2026-09-03

1. Who is responsible

GeoCurves is operated by ONETAP HOLDINGS LIMITED, Central District, Hong Kong (in this policy, “GeoCurves”, “we” or “us”). This policy covers geocurves.com, its account workspace and the analyses we provide.

Contact us at info@onetapseo.com, or submit a request through our Privacy Center. This is our current privacy contact while the dedicated GeoCurves mailbox is being prepared. For account and service administration, we determine why and how information is processed. Where we process information solely on a business customer’s instructions, the customer is responsible for its own collection and use, subject to the applicable arrangements.

2. What we collect and why

  • Account information: your name, email, a hashed password, invitation-code record, membership tier and account dates. These are used to create and secure accounts, manage access and apply usage limits. All fields shown on the registration form are required; without them we cannot create an account.
  • Project information: domains, brand and product names, aliases, competitors, target markets, keywords and monitoring settings you provide. We use these to run the analyses you request and organize results.
  • Analysis records: public-page URLs and extracted evidence, technical audit findings, AI-answer and citation observations, search rankings, scores, task status and history. These support your reports and comparisons. Public information can contain personal information; please avoid submitting private or sensitive content.
  • Security and operational information: IP/network information, request and authentication events, timestamps, status/error codes and usage counters. These help deliver the site, prevent abuse and diagnose failures. Our hosting and network providers also process connection information.
  • Privacy and support requests: the contact email, request type, details, reference, status and relevant dates you submit. If signed in, we associate the request with your account. We use this information to review, verify and respond to requests, not to advertise to you.
  • Privacy preferences: an opt-out preference and, when applicable, a Global Privacy Control signal. A browser cookie stores the choice without a unique tracking ID; signed-in choices can also be stored with your account.

We do not currently operate a payment checkout or collect payment-card details on this site. Displayed plan prices do not mean an automatic subscription charge is active.

3. Sources, website crawling and AI-related data

Information comes from you, your use of the service, pages we fetch for a requested website analysis, and configured search/AI-data services such as Ahrefs. Our favicon service requests site icons from our server and serves them through GeoCurves; it does not embed a third-party icon tracker in your browser.

Site Audit reads publicly accessible material and records sampled evidence. Read our crawler explanation and robots.txt controls. A report is an observation or inference, not a verified statement about an individual. You can ask us to review inaccurate personal information using the Privacy Center.

Reddit discussion collection requires an approved commercial data connection. Until configured, discussion fields remain unavailable; existing search and AI citation records can still be analyzed. We do not automatically post or reply on Reddit, and do not use Reddit content to train or fine-tune models. Optional external content classification requires a separately permitted configuration.

4. Who receives information

  • Huawei Cloud: hosts the application and database on our Hong Kong server.
  • Cloudflare: provides network delivery, proxy/CDN and security functions, processing connection and request information necessary for those services.
  • Ahrefs: receives analysis inputs such as domains, brands, competitors, keywords and countries through server-side requests to provide search and AI visibility results. We do not send your account password to Ahrefs.
  • Requested websites and configured data providers: receive server requests necessary to retrieve public pages, icons or licensed results. If a licensed Reddit or permitted enrichment provider is enabled, relevant query or bounded discussion information is sent to that provider for the requested processing.
  • Authorized operators and professional service providers: may access information where needed to support the service, handle requests, protect rights or meet legal obligations. We may disclose information where legally required, or in a business transfer subject to appropriate notice and protections.

Service-provider processing is different from selling information or sharing it for cross-context behavioral advertising. We do not currently carry out those sale/advertising-sharing activities, and do not install advertising or optional web-analytics trackers.

5. Cookies and privacy signals

We use necessary login and security cookies, limited authentication-related browser storage, and a cookie to remember an opt-out you request. Security cookies may also be set by Cloudflare when its relevant protections are used. See the Cookie Policy for the inventory and controls.

Our Do Not Sell or Share control is available without an account. We recognize Global Privacy Control (GPC) as an opt-out signal; a later visit without that signal does not erase a saved choice. We do not treat silence, continued browsing or registration as permission for advertising. Older “Do Not Track” signals are not used as an additional consent mechanism; no cross-site advertising tracking is enabled regardless.

6. Where processing takes place and how we protect it

Our primary application and database are hosted in Hong Kong. Cloudflare and other providers may process information in other locations. Hosting in Hong Kong does not mean every processing operation stays there. Contact the Privacy Center for details of the locations and any transfer safeguards applicable to your information; we do not claim that a particular transfer certification or contractual mechanism applies to every provider.

We use HTTPS, hashed passwords, server-side access controls, restricted credentials and operational backups. Access is limited by role and purpose. No service or security measure can guarantee absolute protection. Do not submit passwords, API secrets, identity documents or unnecessary sensitive information in project fields or support requests.

7. How long information is kept

  • Accounts, project configuration and GEO/Site Audit reports: retained while needed to provide the workspace and its history, until deletion or an applicable retention requirement. There is no automatic fixed expiry for all reports. You can delete a project in the workspace or request account deletion.
  • Reddit discussion content: content freshness is limited to at most 24 hours. Expired content is hidden and maintenance removes content and dependent results. Confirmed source deletions are synchronized; a content-free object ID may remain to prevent re-import. Monitoring configuration and independent search/AI records have separate operational lifecycles.
  • Backups: routine database backups rotate on a roughly 14-day schedule. New routine backups exclude Reddit discussion and derivative-result tables; monitor settings remain included. An earlier backup can remain until its existing rotation period ends. Restricted release/rollback backups may be kept separately while needed for recovery. Deleting active records does not instantly remove every backup copy; deletion requirements must be reapplied if a backup is restored.
  • Privacy choices: the browser preference lasts 180 days; an account preference remains until the account is deleted or the applicable choice changes. Authentication cookie periods are listed separately.
  • Privacy requests: kept while being handled and for up to 24 months after closure to document the response, subject to applicable legal requirements. Closed requests are then removed by automated maintenance; backup rotation can leave restricted copies for an additional period.
  • Shared provider caches and operational/security logs: can outlive an individual project, and cache read-expiry does not itself erase the stored record. They are reviewed for operational, security and legal needs. A verified deletion request includes reviewing these records where relevant; we do not promise that every shared record disappears immediately with a project.

8. Your rights and how to make a request

Depending on where you live and which laws apply, you may have rights to access or obtain a copy, correct, delete, restrict or object to processing, withdraw consent, or complain to a regulator. Some information must be retained or may be exempt from a request. We do not penalize you for exercising applicable privacy rights.

Use the Privacy Center or email info@onetapseo.com. We may verify identity and an authorized agent’s authority before disclosing or deleting records. Opting out of sale/advertising sharing does not require that verification. We handle requests within the applicable legal time limits and explain any permitted extension or refusal. You may use the same channel to appeal or ask for reconsideration.

Where EEA/UK data-protection law applies, account administration and requested services rely on contractual necessity where relevant; security, abuse prevention and proportionate service operation rely on legitimate interests; statutory rights and record-keeping rely on applicable legal obligations; and uses requiring consent rely on a separate affirmative choice. Public-content analytics require a case-specific basis and balancing assessment rather than assuming public data is unrestricted. We do not use consent as a blanket basis for all processing. You may object to legitimate-interest processing and contact your competent supervisory authority. Hong Kong users can also raise concerns with the Office of the Privacy Commissioner for Personal Data.

For California residents, applicable rights can include knowing categories, sources and purposes of information, access, correction, deletion, opt-out of sale/sharing, and limits on certain uses of sensitive information. We do not use sensitive information to infer personal characteristics for advertising. These notices and controls do not imply that every jurisdiction’s law or every statutory threshold applies to GeoCurves.

9. Children and changes to this policy

GeoCurves is a business analytics service and is not directed to children under 16. If you believe a child has supplied personal information, contact us so we can review and take appropriate action.

We update this policy when our practices change and show the revision date above. Material changes will be communicated where required. Adding a new provider or a new advertising/analytics purpose requires a fresh review of notices, permissions and safeguards; this policy is not advance consent to such changes.