Privacy Policy
What Reputation Snapshot collects, why we collect it, and the control you have over it.
Last updated August 3, 2026
1. Who we are
Luis Gaytan d/b/a TechieDodo Web Design Studio operates Reputation Snapshot and is the controller of the personal data described here. You can reach us about privacy at privacy@techiedodo.com, or by post at Luis Gaytan d/b/a TechieDodo Web Design Studio, Los Angeles, California, United States.
2. What we collect
Account information
Your email address and name, collected when you register or sign in with Google. Passwords are handled by our authentication provider and stored only as salted hashes — we never see or store your password. If you sign in with Google we receive your email address, name, and profile identifier, but not your Google password.
Billing information
Your plan, subscription status, billing interval, and the customer and subscription identifiers issued by Stripe. We do not receive or store your card number, CVC, or expiry date — those go directly to Stripe, which is PCI-DSS compliant.
Your Anthropic API key
If you enable AI features, the API key you provide is encrypted with AES-256-GCM before it is written to our database and is decrypted only in memory when generating a report you requested. You can delete it at any time from your settings.
How you use the Service
The searches you run (city, category, and result counts), the audits and reports you generate, and per-day counters we use to enforce plan limits and rate limits.
Content you create
Analyst observations you write on an audit, outreach status and notes you record about a lead, corrections you make to business details, and — if you use white-label reports — your agency name and logo.
Business listing data
Information about the businesses you research, retrieved from the Google Places API: business name, address, phone number, website, rating, review count, and listing completeness. Website performance data may be retrieved from the Google PageSpeed Insights API. This is publicly available business information, but note that for sole traders it can also be personal data — see section 7.
Technical data
Standard server logs generated when you use the Service, such as IP address, browser type, and timestamps, used for security, debugging, and abuse prevention.
We do not use advertising cookies, tracking pixels, or third-party analytics. The only cookies we set are the essential session cookies that keep you signed in.
3. Why we use it, and our legal bases
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the Service and your account | Performance of a contract |
| Taking payment and managing subscriptions | Performance of a contract |
| Generating AI reports you request | Performance of a contract |
| Enforcing plan limits, preventing abuse, securing the Service | Legitimate interests |
| Service and security notices | Legitimate interests |
| Meeting tax, accounting, and legal obligations | Legal obligation |
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
4. Who we share it with
We share data only with the service providers needed to run the Service:
- Supabase — database, authentication, and file storage
- Stripe — payment processing and subscription management
- Google — business listing data (Places API), website performance data (PageSpeed Insights API), and sign-in if you use Google to authenticate
- Anthropic — generating report text. Content sent for analysis is transmitted under your API key and is governed by Anthropic’s terms and privacy policy
- Our hosting provider — running the application
We may also disclose data where required by law, to enforce our terms, or to protect the rights and safety of users, and we may transfer data as part of a merger, acquisition, or sale of assets — in which case we will notify you.
5. Public agency logos
If you upload a logo for white-label reports, it is stored in a publicly readable storage bucket so that generated PDFs can load it. Anyone who knows or guesses the file URL can view the image. Do not upload anything you would not want publicly accessible. Removing the logo from your settings deletes the stored file.
6. How long we keep it
- Account and content data — for as long as your account exists
- Business listing results — cached for up to 7 days to reduce duplicate lookups, then refreshed
- Billing records — retained by Stripe and by us for as long as tax and accounting law requires, typically 6–7 years, even after you close your account
- Server logs — retained for a short period for security and debugging
When you delete your account, your profile, searches, audits, reports, usage records, stored API key, and uploaded logo are permanently deleted from our systems. This is immediate and cannot be undone. Export your data first if you want to keep it.
7. Data about businesses you research
The Service processes information about third-party businesses so you can evaluate them as prospects. Most of this is company information, but for sole traders and small businesses it may constitute personal data.
When you use that data for your own outreach, you act as an independent controller of it. You are responsible for having a lawful basis for contacting those businesses and for complying with the marketing and privacy laws that apply to you, including the GDPR, PECR, CAN-SPAM, and CASL where relevant.
8. Your rights and controls
Two of these are built directly into the Service, under Settings:
- Export — download a complete JSON copy of your account, searches, audits, and reports at any time
- Deletion — permanently delete your account and its data at any time
Depending on where you live, you may also have the right to access, correct, or restrict processing of your personal data, to object to processing based on legitimate interests, to data portability, and to withdraw consent. California residents have the right to know, delete, correct, and to not be discriminated against for exercising those rights.
You can update your name and password directly in Settings. For anything else, contact privacy@techiedodo.com and we will respond within the time your law requires. If you are in the UK or EU and are unhappy with our response, you may complain to your local supervisory authority.
9. International transfers
Our providers may process data in countries other than yours, including the United States. Where data leaves the UK or EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
10. Security
We protect data in transit with TLS, isolate each account’s records with database-level row security policies, encrypt stored API keys with AES-256-GCM, and restrict administrative access. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and any regulator as required by law.
11. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@techiedodo.com and we will delete it.
12. Changes to this policy
We may update this policy as the Service changes. If a change materially affects how we handle your personal data, we will give reasonable notice by email or in the product before it takes effect. The date at the top shows when it was last revised.
13. Contact
Privacy questions and requests go to privacy@techiedodo.com, or by post to Luis Gaytan d/b/a TechieDodo Web Design Studio, Los Angeles, California, United States.