Privacy Policy
Last updated
What this site records about the people who read it and buy from it, why, and for how long. It describes only what the site actually does.
In short
- No cookies and no browser storage: the site saves nothing on your device. It loads no ads, no outside scripts and no embedded content, and its fonts come from this site.
- Our own records of visits and clicks hold no IP address, no browser details and no identifier: a page, a time, a country and where the visit came from.
- Our host, Cloudflare, receives your IP address to deliver each page, but we keep no request log: logging is switched off.
- If you buy the book, Creem runs the checkout and takes the payment as the seller. We get your name, email address, country and order, never your card details.
- We don't sell personal data, share it with advertisers or build profiles of anyone.
Who is responsible
SEO Tool Cost (seotoolcost.com) is run by an independent publisher based in Sweden, called "we" on this page. For the data described here, we are the controller under the EU's General Data Protection Regulation (GDPR), except where Cloudflare or Creem act under their own policies, as explained below.
There's no contact address yet; one will appear here and in the footer as soon as mail to it is delivered. Until then, we hold no data about visitors that could identify anyone.
When you read a page
Cloudflare, the site's host
Every request goes through Cloudflare, which hosts the site. Like any web host it receives your IP address and what your browser sends with each request, such as its user agent, so that it can deliver the page and protect the site from attacks.
We have switched off request logging for the site, so no log of your requests with your IP address, browser details or location is kept for us. Cloudflare may process connection data for its own security and network purposes under its own privacy policy, and it asks your browser to report failed connections to it (Network Error Logging), which helps it spot network problems.
Legal basis: our legitimate interest in running a site that works and is secure (GDPR Art. 6(1)(f)). Cloudflare handles this data for us under its data processing addendum; see Cloudflare's privacy policy.
Our count of page views
When a page loads, a few lines of script on it send our server the page's path, the address of the page that linked to it, and the utm_source or ref tag in the link, if there is one. We store:
- the time and the page's path;
- the linking site's domain only (such as google.com), never its full address;
- the
utm_sourceorreftag, cut to 60 characters; - your country, as Cloudflare works it out from your IP address;
- whether the request looks automated, a yes or no worked out from the browser's user agent.
We don't store your IP address, your user agent, the full linking address or any identifier, and the script neither sets a cookie nor reads anything stored in your browser. A stored record therefore can't be tied to you or to your other visits. We use the counts to see which pages are read and how readers find them. Because they identify no one, we keep them with no fixed end date. If your browser blocks scripts, nothing is sent.
Legal basis: our legitimate interest in knowing which pages are useful (Art. 6(1)(f)).
Search engine crawlers
When a known search engine or AI assistant crawler fetches a page (recognised by the name in its user agent, such as Googlebot or Bingbot), we log the crawler's name, the page, the response status and the network it came from. Requests from people aren't logged this way.
The calculators
The price calculators run entirely in your browser. What you type into them isn't sent anywhere.
When you click through to a vendor
Buttons to vendors' sites go through this site's own redirect (addresses starting /go/). For each click we store the time, which vendor link it was, the page you clicked it on, your country (from Cloudflare) and the same yes-or-no flag for automated requests. No IP address and no user agent. We keep these with no fixed end date, for the same reason as the page views, and use them to see which links readers use. Legal basis: legitimate interest (Art. 6(1)(f)).
Your browser then opens the vendor's site, which is told which of our pages you came from. From there the vendor's own privacy policy applies. Once a vendor's affiliate programme accepts this site, its link carries our affiliate reference, and the vendor or its affiliate network may use cookies on its own site to credit us with a sale. No programme has accepted the site yet, so today no link here carries an affiliate reference.
When you email us
Once our address is live, if you write to it, your message passes through Cloudflare's email routing and is delivered to an inbox hosted by Google (Gmail), whose privacy policy also applies to it. We use your address and message only to reply and to deal with what you asked about, such as a correction, a refund or a request about your data.
Legal basis: our legitimate interest in answering you (Art. 6(1)(f)), or, if you bought the book, keeping our commitments to you (Art. 6(1)(b)). We delete correspondence once it's no longer needed, and at the latest two years after the last message, unless we need it to settle a dispute.
When you buy the book
The book isn't on sale yet. This section applies from the first sale.
The SEO Playbook for 2027 is sold through Creem (Armitage Labs OÜ, Estonia), the merchant of record: it resells the book to you in its own name, runs the checkout, takes payment, charges any VAT or sales tax due and sends your receipt and download link. Creem collects your payment and billing details and handles them under its own privacy policy. Your card or bank details never reach us.
From Creem we receive your name, email address and country, and the order: what you bought, the amount, the tax, the date and an order number. We use them to make sure you get the files, to help if a download fails, to give refunds and to keep our accounts.
Legal basis: keeping our commitments to you, including the refund guarantee (Art. 6(1)(b)), and our legal duty to keep accounts (Art. 6(1)(c)). Order records stay in our Creem account, where Creem keeps them under its own policy. Anything we keep for our accounts is kept for as long as Swedish bookkeeping law requires (up to seven years after the end of the year of the sale) and then deleted.
Who else handles data
- Cloudflare: hosting and email routing, on our behalf.
- Creem: checkout, payment, tax, receipts and file delivery for the book.
- Google: the inbox that receives our email.
- Authorities, if the law requires us to hand data over.
Cloudflare and Google may handle data outside the EU, including in the United States. Cloudflare relies on its certification under the EU-U.S. Data Privacy Framework and on the EU's standard contractual clauses; Google describes its safeguards in its privacy policy. Creem is based in Estonia, in the EU.
Your rights
Under the GDPR you can ask us for a copy of the personal data we hold about you, and ask us to correct it, delete it or restrict how we use it. Where we rely on our legitimate interests, you can object at any time. If you bought the book, you can also ask for your order data in a portable format. We answer within a month.
Our page-view and click records hold nothing that identifies you, so we can't find yours in them (GDPR Art. 11). For checkout and payment data you can also go straight to Creem, and for Cloudflare's own processing to Cloudflare.
If you think we've handled your data wrongly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) through its complaint form, or to the data protection authority where you live or work.
Changes to this policy
If what the site records changes, this page changes first, with a new date at the top. The terms of use and sale cover the rest of how the site and the book work.