Privacy Policy
Last updated: November 22, 2025
1. Introduction
ShowToAI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI readiness audit service.
2. Information We Collect
2.1 Information You Provide
- Email Address: Required for authentication, audit delivery, and account management
- Website URL: The website you want to audit
- Payment Information: Processed securely through Stripe (we never store credit card details)
- Business Information: Industry type and optional business details for customized recommendations
2.2 Information We Collect Automatically
- Website Data: Public HTML, JSON-LD structured data, robots.txt, and metadata from your website
- Usage Analytics: Page views, feature usage, and interaction data via Google Analytics
- Technical Data: IP address, browser type, device information, and access times
- Cookies: Session cookies for authentication and analytics cookies (see Section 8)
3. How We Use Your Information
We use collected information for:
- Service Delivery: Crawling your website, analyzing structured data, generating AI visibility scores, and creating PDF reports
- AI Analysis: Processing your website data through OpenAI's GPT-4 to generate recommendations
- Authentication: Sending magic link emails and managing OAuth sessions
- Payment Processing: Managing subscriptions, one-time payments, and billing through Stripe
- Communication: Sending audit results, report notifications, and subscription updates via email (Resend)
- Product Improvement: Analyzing usage patterns and optimizing our service
- Security: Detecting fraud, abuse, and protecting against unauthorized access
4. Third-Party Services
We share data with these trusted service providers:
4.1 OpenAI
- Data Shared: Your website's HTML content, structured data, and industry information
- Purpose: AI-powered industry detection and recommendation generation
- Privacy Policy: OpenAI Privacy Policy
4.2 Stripe
- Data Shared: Email, payment details, purchase history
- Purpose: Payment processing and subscription management
- Privacy Policy: Stripe Privacy Policy
4.3 Resend
- Data Shared: Email address, audit results
- Purpose: Transactional email delivery
- Privacy Policy: Resend Privacy Policy
4.4 Google Analytics
- Data Shared: Anonymous usage data, page views, session information
- Purpose: Understanding user behavior and improving our service
- Privacy Policy: Google Privacy Policy
5. Data Retention
- Audit Results: Stored indefinitely for paid customers, deleted after 90 days for free audits
- Website Data: Cached crawl data retained for 30 days for performance optimization
- Account Information: Retained while your account is active, deleted 90 days after account closure
- Payment Records: Retained for 7 years for tax and accounting compliance
6. Your Rights (GDPR & CCPA)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate information
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Export your audit data in machine-readable format
- Opt-Out: Unsubscribe from marketing emails (transactional emails continue for active services)
- Withdraw Consent: Revoke consent for data processing where consent was the legal basis
To exercise these rights, email us at privacy@showtoai.com
7. Data Security
We implement industry-standard security measures:
- HTTPS encryption for all data transmission
- Secure JWT-based authentication with HTTP-only cookies
- Database encryption at rest
- Regular security audits and vulnerability assessments
- Rate limiting to prevent abuse
- Stripe-level PCI compliance for payment data (we never store card details)
8. Cookies
We use the following types of cookies:
- Essential Cookies: Required for authentication and core functionality (cannot be disabled)
- Analytics Cookies: Google Analytics for usage tracking (can be disabled via browser settings)
We do not use advertising or tracking cookies.
9. Children's Privacy
Our service is not intended for users under 18. We do not knowingly collect data from children. If you believe we've collected data from a minor, contact us immediately at privacy@showtoai.com
10. International Data Transfers
Your data may be transferred to and processed in countries outside your residence. We ensure adequate safeguards through:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Privacy Shield framework compliance where applicable
- Service providers certified under recognized privacy frameworks
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be notified via:
- Email to registered users (at least 30 days before taking effect)
- Prominent notice on our website
Continued use after changes constitutes acceptance.
12. Contact Us
For privacy questions or concerns:
- Email: privacy@showtoai.com
- General Support: hello@showtoai.com
13. Legal Basis for Processing (GDPR)
We process your data based on:
- Contract Performance: Delivering audits and managing subscriptions
- Legitimate Interest: Improving our service, fraud prevention, security
- Consent: Analytics cookies and marketing communications (where required)
- Legal Obligation: Tax records, payment compliance
14. Do Not Track
We honor "Do Not Track" browser signals for analytics cookies. Essential authentication cookies remain active to ensure service functionality.
Related Legal Documents: Terms of Service | Refund Policy