Version 2026-07-02
This Privacy Policy describes how NorfBay LLC, doing business as SerpCalls ("SerpCalls," "we," "us") collects, uses, shares, and protects information when you use serpcalls.com and related services (the "Service"). By using the Service, you agree to this Policy.
SerpCalls is a software-as-a-service for tracking local-search rankings for service businesses. For EU/UK GDPR purposes we are the data controller of account data and a data processor of data you submit about your own customers or businesses.
Our public free rank-check tool and our access-request form collect the business domain, city, and keyword you enter, and — if you request full results — your name, email, and business name. We use this to run the check you asked for and to follow up with you about SerpCalls. It is stored as a lead/signup record; you can ask us to delete it at privacy@serpcalls.com.
When you configure a workspace, the Service queries public search and business-data sources and stores the results for trend analysis:
If you connect a Google account, SerpCalls accesses the following through Google OAuth, using refresh tokens you grant and can revoke at any time (in-app or from your Google account):
Google API Services — Limited Use.SerpCalls's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing features described above. We do not sell it, do not use it for advertising, and do not use it to train generalized artificial-intelligence or machine-learning models. Humans do not read your Google user data except with your explicit consent, for security or abuse investigation, or where required by law.
We do not collect Social Security numbers, government IDs, biometric, financial-account, or health data. We do not knowingly collect data from children under 13.
We do not sell your data. We do not share it for cross-context behavioral advertising. We do not use it to train third-party AI models.
Legal bases under GDPR: contract performance, legitimate interests (security and product improvement), consent where required, and legal obligation.
We use the following processors to operate the Service. Each is bound by contract to protect your data and use it only for the purpose we specify.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Neon (PostgreSQL) | Primary database | All account, workspace, and ranking data | US |
| Cloudflare | Edge compute, routing, email delivery | Request metadata, session tokens, email content | Global |
| Stripe | Subscription billing | Billing contact, card data (held by Stripe) | US / EU |
| Oxylabs | Google SERP retrieval | Queried keywords and locations | Global |
| Google (Places API + connected Google APIs) | Business-profile/review data + your authorized Search Console, Analytics, Ads & Business Profile data | Place IDs, business metadata, and OAuth-connected Google data you authorize | US |
| Cloudflare Workers AI | AI insights & review-reply/post drafts | Ranking records; public review text & reviewer display names when drafting replies | Global |
| Sentry (Functional Software, Inc.) | Error & reliability monitoring | Exception details, stack traces, request path/method | US |
We also disclose information to comply with law, valid legal process, or government requests; to enforce our Terms; and to protect rights, property, and safety. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
Insights, recommendations, and draft review replies and posts are generated by Cloudflare Workers AImodels running on Cloudflare's infrastructure. Prompts are built from your workspace configuration, public SERP data, and — when drafting a reply to a review — the public review text and reviewer display name shown on the Google Business Profile you track. We do not include your account, password, or billing details in prompts, and prompt data is not used to train generalized AI models.
We use administrative, technical, and physical safeguards, including TLS in transit, encryption at rest, password hashing with HIBP screening, support for TOTP 2FA and WebAuthn passkeys, PostgreSQL row-level security scoped by workspace, least-privilege staff access, and audit logging for administrative actions. No system is perfectly secure. If you suspect your account is compromised, contact security@serpcalls.com immediately.
Depending on where you live, you may have the right to:
You can view and update most account and workspace data directly in the app. To delete your account and its associated data, to disconnect and revoke a connected Google account, or to exercise any other right, email privacy@serpcalls.com and we will action the request — account and workspace data are deleted within 30 days of a verified request. We respond within 30 days (CCPA: 45 days, with one 45-day extension if necessary).
California residents (CCPA/CPRA): we do not sell or share personal information for cross-context behavioral advertising. EU/UK residents (GDPR): we do not make automated decisions with legal or similarly significant effects.
Personal data may be processed in the United States and other countries where our sub-processors operate. Where required, we rely on Standard Contractual Clauses or other approved transfer mechanisms.
We may update this Policy. Material changes will be announced by email or in-app notice at least 15 days before they take effect. The version date at the top indicates the current version.
Privacy questions: privacy@serpcalls.com
Security: security@serpcalls.com
Data subject requests: privacy@serpcalls.com
Mailing address: NorfBay LLC, 4402 Montgomery Dr, Santa Rosa, CA 95405