Privacy Policy
Last updated: July 23, 2026
This Privacy Policy explains what BotAudit collects, why, and what rights you have. It applies to our marketing website, dashboard, and the tracking script you embed on your own sites.
1. Who We Are
BotAudit ("we," "us") is a bot-detection and traffic-audit service. Contact: support@botaudit.co.
2. Data We Collect From You (Our Customers)
- Account information: email address and a hashed password (bcrypt — we never store passwords in plaintext).
- Billing information: handled by Stripe. We store only a Stripe customer ID, subscription status, and plan; we never see or store full card numbers.
- Site configuration: the sites you add, their names, and their generated tracking keys.
- Usage data: standard server logs (IP address, user agent, request path) for security and troubleshooting, retained for up to 30 days.
3. Data the Tracking Script Collects (Your Visitors)
When you embed the BotAudit tracking script on your site, it records the following about each visit:
- A SHA-256 hash of the visitor's IP address. By default we do not store the raw IP. The one exception: for visits arriving via a paid ad click (an ad-platform click identifier is present in the URL) that our system classifies as bot or suspicious, we additionally retain the raw IP address for up to 60 days, solely to document invalid-click refund claims that our customers submit to ad platforms (e.g., Google's Click Quality Form, which requires IP-level click logs). This processing rests on our customers' legitimate interest in detecting and disputing click fraud (GDPR Art. 6(1)(f)). After 60 days the raw IP is automatically and permanently deleted; only the hash remains.
- User agent, screen size, language, and browser automation signals (e.g.,
navigator.webdriver, headless-browser markers). - Approximate geolocation (country, region, city, ISP, hosting provider) derived from the IP before it is hashed.
- Referrer URL and ad-platform click identifiers (
gclid,gbraid,wbraid,fbclid,twclid,ttclid,msclkid) and UTM parameters from the page URL. - Interaction events (click, scroll, touchstart), time on page, and aggregate input counters — counts of mouse movements, wheel, scroll, touch, and key events plus first-input timing. We never record keystroke content, typed text, or cursor trajectories. Used for bot classification only.
- Any custom key/value pairs you choose to configure via
window.botaudit.
The tracking script does not set cookies, fingerprint devices, or use cross-site identifiers. It does not collect names, email addresses, form content, or payment details.
4. How We Use Data
- To provide the dashboard, classification, filtering, and CSV-export features.
- To prepare invalid-traffic evidence exports (e.g., for Google's Click Quality Form) at our customers' request.
- To operate, secure, and improve the Service.
- To send transactional emails (password reset, billing notices). We do not send marketing email without consent.
- To comply with legal obligations.
5. Cookies on This Website
- Session cookie (strictly necessary): an
httpOnlyJWT cookie keeps you signed in to the dashboard. Required for the Service to function. - Google Analytics (optional): used on our marketing pages to understand traffic sources. Loaded only after you accept cookies via our consent banner, with IP anonymization enabled. Decline at any time; to change a prior choice, clear your browser storage for this site.
6. Who We Share Data With
We do not sell your data. We share it only with service providers needed to run the Service:
- Stripe — payment processing.
- Our hosting provider — infrastructure (database, application servers).
- ip-api.com — IP geolocation lookup; the raw IP is sent for lookup before being hashed for storage, subject to ip-api.com's own terms.
- Google Analytics — marketing-site analytics only, after your consent.
7. Data Retention
Visit data is retained according to your plan (from 7 days on Free up to unlimited on Pro). Raw IP addresses retained for refund-claim evidence (see Section 3) are deleted after at most 60 days regardless of plan; the hashed IP follows the plan retention period. Account information is kept for as long as your account is active and for a reasonable period afterward for legal and accounting purposes.
8. Your Rights
Depending on your jurisdiction (including under GDPR and CCPA), you may have rights to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data.
- Export your data.
- Object to, or restrict, certain processing.
To exercise any of these rights, email support@botaudit.co. You can also delete your account at any time from the dashboard settings.
9. Visitor Data (Controller/Processor)
When our tracking script runs on your site, you are the data controller for your visitors and BotAudit is the data processor. Requests from your visitors about their data should go through you; we will cooperate with you to fulfill valid requests.
10. Security
We use HTTPS for all traffic, bcrypt password hashing, httpOnly session cookies, CSRF protection, and rate limiting. No system is perfectly secure; please report vulnerabilities to security@botaudit.co.
11. International Transfers
Data may be processed in the country where our infrastructure is hosted. By using the Service you consent to such transfers.
12. Children
The Service is not directed at children under 13, and we do not knowingly collect data from them. Do not deploy the tracking script on sites that primarily target children.
13. Changes to This Policy
We may update this Policy. Material changes will be announced via email or in-product notice. The "Last updated" date above shows the most recent revision.
14. Contact
Questions? Email support@botaudit.co.