Privacy Policy
Privacy policy for Go Top SEO
Introduction
GO TOP MARKETING GRUO LTD (company number 517274346) (“we”, “our”, or “the company”) operates the Go Top SEO service at https://www.gotopseo.com (the “Service”). This privacy policy describes our practices regarding the collection, use, and disclosure of personal information when you use our Service.
Information We Collect
We collect different types of information, including:
- Authentication information: name, email address, password (encrypted)
- Profile information: plan details and subscription information
- Business information: company name, domain, keywords, ranking data
- Technical information: IP address, browser type, referring page
- Google account data: only if you choose to sign in with Google or to connect Google Search Console or Google Business Profile — see “Data We Receive from Google” below
- Information from your site: public pages, robots.txt, the sitemap and llms.txt read in the free site check and the onboarding scan, and the findings derived from them — see “Site Scanning” below
- WordPress connection: the site address, a username and Application Password and the plugin’s signing key (both stored encrypted), and the log of fixes on the site — see “WordPress Connection” below
- Shopify connection: the store address, the store identifier, the permissions you approved at installation, and the access token the store issues (stored encrypted) — see “Connecting a Site on Another Platform” below
- Wix or webhook connection: the site address or the endpoint you configured, and the Wix API key or the signing secret (stored encrypted and never shown again after saving) — see “Connecting a Site on Another Platform” below
- An address for local rank tracking: if you typed an exact address, it is stored together with the coordinates returned — see “Turning an Address into Coordinates” below
- Link network: your joining consent (who accepted, when, the wording and the link type) and the placement log — see “Link Network” below
- Results and content: AI visibility check results, and content generated for you: topics, questions and articles
- Email preferences: which messages you receive, and unsubscribes from reminders
- Payment information: we do not store your payment instrument. For accounts whose billing authority is Shopify — including merchants who installed the app through Shopify — payment is processed by Shopify under Shopify App Pricing, and we never direct them to PayPal. For customers who signed up directly on our website, whose billing authority is not Shopify, payment is processed through PayPal
How We Use Your Data
We use your information to:
- Provide the rank tracking service
- Run scans and AI visibility checks, generate content and apply the site fixes you approve
- Send reminders and progress reports, and answer your enquiries
- Authenticate users and manage accounts
- Process payments
- Send service updates and news
- Improve our service
- Comply with legal requirements
Information Sharing
We do not share your personal information with third parties, except:
- Shopify: for payment processing for accounts billed through Shopify App Pricing, and for publishing content to a connected store
- PayPal: for payment processing for website-billed customers only
- Supabase: for secure data storage
- Serper: for Google search queries and rank checks
- Resend: for sending email — see “Email Messages” below
- Vercel: for hosting the site and the Service
- Google (Gemini API, Search Console, Business Profile, Google Ads API): our AI provider for generating text and images, the connections you choose to make, and the Google Ads API, to which we send keywords to get search volumes and further keyword ideas. That interface is a Company account and not an advertising account of yours; we do not run campaigns for you — see “AI Providers” and “Data We Receive from Google” below
- Wix: only if you connected a Wix site — to read the site’s content and publish articles to its blog
- The endpoint you configured yourself (webhook): only if you connected a site on another platform — the article is sent to the address you gave, in a signed request
- PDFShift: to convert a report to PDF, and only when you asked to download one. We send the report’s content as displayed in order to get the PDF file back
- OpenStreetMap (Nominatim): to turn an address into coordinates, and only when you typed an exact address for local rank tracking. The address you typed and the country name are sent, never account details
- ScrapeLLM: for AI visibility tracking — see “AI Providers” below
- Other sites in the link network: only if you joined the network — see “Link Network” below
- Meta (Facebook / Instagram): for targeted advertising — see the Meta Advertising section below. Data we receive from Google APIs is never shared with Meta or used for advertising
- When required by law
Data We Receive from Google
Go Top SEO can connect to your Google account in three optional ways. Each one asks for its own permission on Google’s consent screen, and we request only the access described here.
Sign in with Google
If you choose “Continue with Google”, Google shares your name, email address and profile picture with us through Supabase Auth. We use them only to create your account and sign you in.
Google Search Console
Permission: read-only access to Search Console (webmasters.readonly). We never ask for permission to change anything in your Search Console account.
- What we read: the list of Search Console properties your Google account can access, so you can choose one for each project; and, for the property you choose, its search performance data: search queries and pages with their clicks, impressions, click-through rate and average position, and the property’s totals.
- What we store: the property assigned to each project and your permission level on it, and the performance data of each sync (the last 28 and 90 days). Data is synced when you press sync and automatically about once a week.
- How we use it: to show you your site’s search performance, to find content opportunities, to include search figures in your reports, and to suggest article topics. For topic suggestions, search queries from this data may be sent to Google’s Gemini model (see “AI Providers” below).
Google Business Profile (Posts on Google Maps)
Permission: business.manage, requested in a separate consent only when you connect this feature. Google offers no narrower permission that allows creating posts.
- What we read: the Business Profile accounts you manage and their business locations: business name, address, website and Google Maps link.
- What we store: the location you choose for a project (its Google identifiers, name, address, website and Maps link), and each post you create: its text, button, photo, scheduled time, and Google’s post identifier, link and review status.
- What we do with it: we create a post only when you press publish, or at the time you scheduled it, and then read that post back from Google to show you whether it is live. We do not change your business information and we do not read or reply to reviews.
- AI drafts: if you ask for a draft, the business name and the article or topic you chose are sent to Google’s Gemini model. A draft is never published until you review it and press publish.
Limited Use
Go Top SEO’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide the features described above, which you see and use in the app.
- We do not sell Google user data, and we do not use or transfer it for advertising, including retargeting and personalised or interest-based ads.
- We do not use Google user data to develop, improve or train generalised AI or machine-learning models. We send parts of it to an AI provider only to produce the result you asked for, as described in “AI Providers” below.
- We do not allow people to read this data, unless you give us permission (for example, when you ask for support), it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data is aggregated and anonymised for internal operations.
How We Protect Google Data
- The Google OAuth refresh tokens that let us access Search Console and Business Profile are encrypted with AES-256-GCM before we store them, and are decrypted only on our servers at the moment of use. We do not store access tokens.
- Google data is stored in our Supabase database, and the app shows it only to your own account.
Disconnecting, Retention and Deletion
- Search Console: “Disconnect property from project” removes the property from that project and stops syncing it. “Revoke Google access for the whole account” is available once no project uses the connection: it asks Google to revoke our access and deletes the stored token. In both cases, data already synced is kept.
- Business Profile: “Disconnect” asks Google to revoke our access and deletes the stored token and the saved business location. Your post history stays in the app, and published posts stay on Google until you remove them there.
- Retention: synced Search Console data and your post history are kept for as long as your account exists, unless you ask us to delete them.
- Deletion: to delete your account or the Google data stored with it, email us at oren@gotop.co.il.
- Revoking access at Google: you can also remove our access at any time at myaccount.google.com/permissions. After that we can no longer read from or post to your Google account. Data we already stored stays until you disconnect in the app or ask us to delete it.
Site Scanning (Free Check and Onboarding Scan)
In the free site check, which you can run before signing up, and in the onboarding scan after a project is created, we access the site address you entered and read public pages on it, and its robots.txt, sitemap and llms.txt files. Reading is done without signing in, without cookies and without access to protected areas, and the onboarding scan reads a page only if robots.txt allows it.
- What we store: the site address, the findings derived from the pages (such as titles, descriptions, site structure and SEO signals), and a business summary generated from them. The result of a free check is also stored so it can be shown again and to limit misuse of the check.
- How we use it: to show you the findings, to tailor the Service to your site and to suggest topics and fixes. Some of the text may be sent to Google’s Gemini model to produce the summary (see “AI Providers”).
- Deletion: you can email us to ask for stored results to be deleted.
WordPress Connection and the GO TOP SEO Bridge Plugin
When you connect a WordPress site, we store the site address, the username and Application Password you created, and the signing key that authenticates requests between us and the plugin. Both are stored encrypted and decrypted only on our servers at the moment of use. With your consent, and your approval of each fix or an automatic approval you turned on, the GO TOP SEO Bridge plugin applies to the site only fixes from a closed list (SEO title, meta description, canonical address, focus keyphrase, image alt text, an FAQ block, JSON-LD schema, internal links, repair of broken links, demotion of a duplicate H1 heading, and creating llms.txt). On a site without the plugin, the fixes WordPress’s REST interface allows are written with the application password we stored, under the same approvals and into the same log. Alt text for an image a page shows outside its own text is written on the image itself in the media library, so it applies on every page that shows it; we do not touch the image file, its name or its caption.
- Fix log: every fix is recorded in our log with who approved it, the time it was applied, the IP address the approval was given from, and the previous and the new value, so that it can be shown and undone and so that we have evidence that the write to the site was made with your approval. The log is kept as long as the project exists.
- Automatic approval of fixes: if you turned on automatic approval in a project, for the three types of fix described in the Terms of Use, we keep a separate record of that: who turned it on, when, the IP address it was turned on from, and after it is turned off also who turned it off and when. A fix applied under automatic approval is recorded in the fix log with the time it was applied, the person who turned the approval on and the IP address recorded when it was turned on, and is marked as an automatic fix. At the moment the fix itself is applied we do not read and do not store a new IP address, because no person acted then and we do not need it. A summary of the automatic fixes is shown on the Site health screen and we do not send an email about it. The records are kept as long as the project exists.
- Disconnecting and removal: “Disconnect” deletes the stored connection details and the signing key, after which we can no longer reach the site. You can also remove the plugin from your WordPress admin at any time. Fixes already applied stay on the site unless you undid them.
- What we do not do: we do not delete content, and we do not touch your site’s prices, products, theme, other plugins, settings or users.
Connecting a Site on Another Platform
Besides WordPress, you can connect a Shopify store, a Wix site, or a site on any other platform through an endpoint you configure. Each connection is optional and is made by you.
- Shopify: installing the app in your store lets us read the store’s content, products and pages, and publish articles to the store blog, within the permissions you approved at installation. With your approval of each fix, we also write site fixes to the store’s articles and pages. The approval itself is recorded in a log: who approved it, when, the IP address the approval was given from, and the previous and the new value — so that we can show you what was done, so that a fix can be undone, and so that we have evidence that the write to your store was made with your approval. The log is kept for as long as the project exists. The store’s access token is stored encrypted. Removing the app from the store revokes the access.
- Wix: the connection uses an API key you issue in your own account, and is used to read the site’s content and publish articles to its blog. We send Wix the article’s content and its publishing details, and no other account data. The key is stored encrypted, is never shown again after saving, and is deleted when you disconnect. You can revoke it on the Wix side at any time.
- Webhook: the Service sends the article to the endpoint you configured, in a signed request. The endpoint is yours, so what happens to the article once it arrives is under your control. The signing secret is stored encrypted, is never shown again after saving, and is deleted when you disconnect.
- Errors: if publishing fails we store an internal error code only. We do not store or display the provider’s or your server’s own error text.
Turning an Address into Coordinates
To track rankings from an exact point you can type an address instead of coordinates. When you do, we send the address you typed and the project’s country name to OpenStreetMap’s Nominatim service to get coordinates back. We do not send your name, your email address or any other account details. The address and the coordinates returned are stored with us as the tracking target’s definition, and you can change or delete them in the target’s settings. OpenStreetMap is operated by the OpenStreetMap Foundation, and the Nominatim service has its own usage and privacy policy.
Converting a Report to PDF
When you ask to download a report as a PDF, we send the report’s content as displayed to the PDFShift service, which returns the file to us. This happens only when you pressed to download a report, never on a regular or scheduled basis, and the content is sent for the conversion alone. Retention at PDFShift is governed by their own privacy policy and terms.
Link Network
Joining the link network is optional, is done for each project separately, and is off by default. Whoever joins agrees to both directions: that a link from their articles may point to another network member’s site, and that links to their site may be placed in other members’ articles. A connected Shopify store can join as well, and the links are placed only inside articles the Service writes and publishes to the store’s blog. For such a store, ownership of the domain is taken from the connection itself: the store’s myshopify address and its primary domain, as Shopify reported them at installation.
- What we store: who accepted the joining, when, the wording of the terms accepted and the link type, and each placement made, on both sides.
- What another member sees: the Company does not publish a member list. The receiving side sees the address of the site that links to it and, once published, the page where the link appeared. A published link is a public link on the site.
- Leaving: you can leave the network at any time. Leaving stops new placements; links already published stay unless you remove them from your site, and placements stay in the log.
Partner Program
The partner program is for people who recommend the Service and receive a commission for customers who join through them. Taking part is voluntary, every application is reviewed by a person, and none of this applies to you unless you apply.
- When you apply: we receive what you send us by email or WhatsApp — your name, your contact details, the site, channel or audience you intend to promote to and, after approval, the payout method you choose. We use them to decide on the application and to run the agreement with you.
- While you are a partner: we store your contact details, your referral code, the accounts that opened through it, the qualifying payments and the commission calculated on them, the payouts made to you, and the invoices and tax certificates the law requires us to keep.
- What a partner sees about the people they referred: nothing personal. A partner sees counts and amounts. A partner does not receive the email address, the website, the plan or the identity of any customer they referred.
- Paying commission: the provider the partner chooses — PayPal, Wise or a bank transfer — receives the details it needs in order to pay. Invoices and withholding certificates are kept for seven years, as Israeli bookkeeping rules require.
- Crediting a referral: the partner’s code travels in the link itself. We set no cookie for the program and store nothing on your device, so what you choose about cookies does not affect it in either direction. If we ever credit a visit that comes back later, which would mean storing something, this policy will say so and your consent will be asked first.
As of the date of this policy the program runs by application only: we receive applications and approve partners by hand, and no referral tracking, commission record or payout has been built yet. Each of them will be described here before it starts running. The terms themselves are in the Partner Program Agreement, which also requires a partner to say openly that they are paid.
AI Providers
Some features send data to the following AI services to produce the result you asked for:
- Google Gemini (Gemini API): generates article topic ideas, questions, articles, images, and Google Business Profile post drafts. We send the details a request needs, such as your business name, website, keywords and topics and, as described above, Search Console search queries and your Business Profile name.
- ScrapeLLM: for AI visibility tracking, sends questions built from your business name, location and tracked keywords to AI assistants (ChatGPT, Perplexity, Gemini, Microsoft Copilot, Grok and Google AI Mode) and returns their answers to us. It does not receive data from your Google account. In addition to checks you start yourself, an automatic monthly check runs for the project; it counts toward your plan’s allowance of checks and can be turned off on the “AI Visibility” screen, in the “Automatic monthly check” card.
Email Messages
We send email through the sending provider Resend, which receives your email address and the content of the message in order to deliver it.
- Account and service messages: sign-up, verification, billing and updates about using the Service.
- Reminders: when content is waiting for your approval, a reminder may be sent. Every reminder has a one-click unsubscribe link, with no sign-in needed, and unsubscribing stops these reminders. Your preference is stored with us.
- Monthly progress report: a monthly summary of the project, for projects where you turned it on in the settings.
How We May Contact You About a Free Check
If you ran a free check on a website, we may get in touch about it. By email, only to the address you gave us and only as far as the boxes you ticked allow: the report you asked for, and updates or marketing content only if you agreed to those on their own separate box.
We may also contact the business whose website was checked, using contact details that business publishes on its own site — a phone number or a general address. We do that on our legitimate interest in offering a service to a business that looks like a fit (GDPR Art. 6(1)(f)), not on your consent, and those details come from the site itself rather than from anything you gave us. When we call, we say who we are and where we got the number.
You can tell us to stop at any time and by any channel, and we stop — by email, by phone, in every language. For direct marketing that is an absolute right (GDPR Art. 21(2)), it costs you nothing, and we record it so a later list cannot undo it.
Data Security
We use SSL/TLS encryption for all communication. Your passwords are stored encrypted via Supabase Auth. We maintain high data security standards, but we cannot guarantee 100% security.
Your Rights
Under applicable privacy law, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account
- Object to certain processing
- Request data portability
To exercise these rights, contact us at:
Email: oren@gotop.co.il
Phone: 054-9489377
Cookies
We sort cookies into three categories, and we ask you about two of them before they load:
- Strictly necessary: signing in, remembering your interface language, security and abuse prevention. The service cannot run without them, so they need no consent.
- Measurement: how many people visited, which pages they read and what did not work. Loaded only if you allow it.
- Marketing: measuring how our ads perform and showing relevant ads on the Google and Meta networks. Loaded only if you allow it.
Before you choose, no measurement or marketing cookie is set and no request is made to Google’s servers. Accepting and refusing are two equal buttons on the notice, and each category can be allowed on its own.
Changing or withdrawing your consent: at any time, through the “Cookie settings” link at the bottom of every page. Withdrawing is exactly as easy as giving consent, and costs you nothing in the service.
The partner program: it sets no cookie at all. If you reach the site through a partner link, that partner’s code is carried in the link itself and nothing is written to your device, which is why the program does not appear among the categories above and why your choice on this notice neither helps nor hinders it. A cookie that keeps a partner’s code is not strictly necessary for the site to work, so we would have needed your consent for one; we chose not to need it.
If your browser sends a Global Privacy Control signal, we treat it as a refusal: no measurement or marketing cookies are loaded, and we do not show you the notice.
So that we can demonstrate what you chose, we record every decision: what you were shown, what you chose, when, in which language, on which page, and a one-way hash of your IP address. The IP address itself is not stored in that log. The log is append-only and cannot be edited or deleted from within the system.
Analytics & Marketing Services
Our measurement and marketing tools are managed through Google Tag Manager, which loads only after you have allowed measurement or marketing. The tools that may run through it:
- Google Analytics: traffic and acquisition analysis (subject to measurement consent)
- Google Ads: conversion measurement and personalised advertising (subject to marketing consent)
- Meta Pixel: conversion measurement and advertising on Facebook and Instagram (subject to marketing consent)
Which tools are active changes from time to time. What does not change: none of them loads before you have allowed its category, and withdrawing your consent stops the collection.
We declare your consent state to Google through the Consent Mode v2 protocol, so the tools are bound by your choice even if we add a new tag in the future.
Meta Advertising (Facebook / Instagram)
We use the Meta Pixel (Facebook Pixel) to run advertising campaigns on Facebook and Instagram. The Pixel allows us to measure conversion events (such as completing a signup), build custom audiences, and show relevant ads to people who have visited our site.
Information that may be collected and sent to Meta includes:
- Browsing data and pages visited on our site
- Conversion events (such as registering for the service)
- IP address and browser technical information
- Information collected via Meta cookies
This use is subject to the privacy policy of Meta Platforms, Inc., available at facebook.com/privacy/policy. You can opt out of personalised advertising through your Facebook account’s privacy settings.
Contacting Us via WhatsApp
Our site and services may offer an option to contact us via WhatsApp. When a user chooses to contact us through WhatsApp, we may receive and process the information provided as part of that contact, including name, phone number, the content of the messages, files or images sent to us at the user’s initiative, and any additional contact details shared during the conversation.
The information provided to us via WhatsApp will be used to respond to the inquiry, provide service and support, handle requests, document inquiries, improve the service, maintain information security and protect our rights, as well as to comply with legal requirements where necessary.
Use of WhatsApp is also subject to the terms of use and privacy policy of WhatsApp and/or Meta, and we recommend reviewing them before using this channel. Please do not send us, via WhatsApp, sensitive information that is not required to handle your inquiry, including passwords, full payment details, medical information, identification documents or other sensitive personal information, unless you have been expressly asked to do so for a defined purpose.
We may retain the correspondence records for as long as necessary for the purposes of providing the service, handling inquiries, documentation, monitoring, legal defense and compliance with the law. Users may contact us to request access to, correction of, or deletion of the personal information they provided, subject to applicable law and this privacy policy.
Legal Basis for Processing
We process personal data only where we have a legal basis for it. Each purpose has its own basis, which is why your options differ from one purpose to the next:
- Performance of a contract (GDPR Art. 6(1)(b)): opening an account, running the subscription, performing scans and checks, generating content and publishing it to the site you connected. Without this there is no service.
- Consent (Art. 6(1)(a) and the ePrivacy rules): measurement and marketing cookies, marketing email, and joining the link network. Each is separate, and each can be withdrawn at any time.
- Legitimate interests (Art. 6(1)(f)): securing the system, preventing abuse, operational reminders about your own account, and improving the service from aggregate data. You may object to processing on this basis.
- Legal obligation (Art. 6(1)(c)): keeping billing records and reporting to the tax authorities.
In Israel we are subject to the Protection of Privacy Law, 5741-1981, including Amendment 13, which took effect on 14 August 2025. We are not required to appoint a data protection officer under that amendment, and we are not a data broker: we do not sell personal data to anyone, for any consideration.
How Long We Keep Data
We keep data only as long as it is needed for the purpose it was collected for:
- Account and the content generated for you: for the life of the account, and up to 90 days after it is deleted so an accidental deletion can be undone. Then erased.
- Billing records and invoices: seven years, as Israeli tax law requires. We have no discretion here, even if you ask for erasure.
- Connection credentials (WordPress, Shopify, Search Console): until you disconnect or delete the account, and then erased immediately.
- Free site check: cached for up to 24 hours, then erased if no account was opened from it.
- Cookie decision log: up to three years from the decision, so that we can demonstrate what you chose. That is the legal basis for keeping it, which is why it is not erased together with the account.
- Security and server logs: up to 90 days.
International Transfers
The service runs on international cloud and infrastructure providers, so data may be stored or processed outside your country of residence. The main providers: Vercel (application hosting), Supabase (the database, in the Mumbai region in India), and every other provider listed under “Information Sharing” above, among them the AI and search providers, the PDF conversion provider and the address lookup service.
For data about residents of the European Economic Area, Switzerland or the United Kingdom: Israel has been recognised by the European Commission as providing an adequate level of protection, so a transfer to us requires no further instrument. For transfers to providers outside the EU in countries without an adequacy decision we rely on the European Commission’s Standard Contractual Clauses, within those providers’ own terms.
You may ask us which instrument we rely on for a particular transfer, and we will answer in writing.
Rights of Residents of the EEA, Switzerland and the UK
If you are in the European Economic Area, Switzerland or the United Kingdom, you also have the following rights under the GDPR and the UK GDPR:
- Access (Art. 15): a copy of the data we hold about you.
- Rectification (Art. 16) and erasure (Art. 17).
- Restriction of processing (Art. 18).
- Portability (Art. 20): your data in a structured, machine-readable format.
- Objection (Art. 21), including an absolute right to object to marketing.
- Withdrawal of consent (Art. 7(3)) at any time, without affecting the lawfulness of processing carried out before it.
We answer within 30 days. We will not charge you and will not degrade your service because you exercised a right.
Right to complain: if you are not satisfied with our answer, you may complain to the supervisory authority in your country of residence, or to the Israeli Privacy Protection Authority (Privacy Protection Authority). Contacting us first is not a condition of complaining, though we would welcome the chance to put it right.
Rights of United States Residents
If you are a resident of California, or of another state that has enacted a state privacy law, you have the right to know which categories of data were collected about you, to obtain a copy, to request deletion, to correct inaccurate data, and not to be discriminated against for exercising a right.
We do not sell personal information and we do not transfer it for consideration. We do share identifiers and usage events with the Google and Meta advertising networks for targeted advertising, which may count as “sharing” under California law. That sharing happens only if you allowed the marketing category, and it stops the moment you withdraw.
We honour the browser’s Global Privacy Control signal as a “do not sell or share my personal information” request, and we record it. No form is needed: the signal itself is enough.
Automated Decisions
The service produces recommendations and content with AI models, but it makes no automated decision with a legal or similarly significant effect on you: no credit scoring, no candidate screening, and no eligibility decision made without a person. Content is published to the site you connected according to the schedule and the approvals you set.
Minimum Age
The service is intended for businesses and site owners, not for children. We do not knowingly collect data from anyone under 18, and the service may not be used below that age. If such data has reached us, write to us and we will erase it.
Privacy Contact and Representatives
For any privacy matter, including exercising the rights above:
Email: oren@gotop.co.il
Phone: +972-54-948-9377
We are not required to appoint a data protection officer under Amendment 13 to the Israeli Protection of Privacy Law, and we have not appointed one. Requests are handled by the contact above.
Updates to This Policy
We may update this policy from time to time. Changes take effect immediately upon publication. We encourage you to review this policy regularly.
Contact
If you have questions about this privacy policy, please contact:
Email: oren@gotop.co.il
Phone: 054-9489377
This policy was last updated on October 6, 2026