Privacy Policy
Last updated: June 5, 2026
The SEO Pros (“we,” “our,” or “us”) operates the client management platform at seo-pros-crm-production.up.railway.app and provides digital marketing services to businesses. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
By using our services or connecting your accounts to our platform, you agree to the practices described in this policy. If you do not agree, please do not use our services.
1. Information We Collect
We collect the following types of information:
- Account information: Your name, email address, and password when you create a client account.
- Business information: Your business name, website URL, and service preferences.
- Payment information: Billing details processed securely through Stripe. We do not store card numbers on our servers.
- Connected platform credentials: OAuth tokens for YouTube, Instagram, Facebook, and TikTok when you authorize our platform to manage your accounts.
- Content data: Topics, scripts, and video metadata generated as part of your content marketing service.
- Usage data: Log files, IP addresses, and browser information for security and performance purposes.
2. How We Use YouTube Data
When you connect your YouTube channel to our platform, we request the following Google OAuth scopes:
https://www.googleapis.com/auth/youtube.upload— to upload AI-generated marketing videos to your YouTube channel on your behalf.https://www.googleapis.com/auth/youtube.readonly— to read your channel ID and verify the connection is active.
We use this access only to:
- Upload marketing videos that you have approved as part of your content package.
- Set video titles, descriptions, and tags on your behalf.
- Verify your channel ID during the setup process.
We do not:
- Read, access, or store any of your existing YouTube videos or analytics.
- Delete, modify, or interact with any content you did not directly request us to upload.
- Share your YouTube credentials or channel data with any third party.
- Use your YouTube data for advertising, profiling, or any purpose beyond the service you subscribed to.
Your YouTube OAuth refresh token is stored encrypted in our secure database and used exclusively to authenticate video uploads on your behalf. You can revoke this access at any time through your Google account at myaccount.google.com/permissions.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How We Use TikTok Data
When you connect your TikTok account to our platform, we request the following permissions:
video.upload— to upload AI-generated marketing videos to your TikTok account on your behalf.video.publish— to publish uploaded videos to your TikTok profile.user.info.basic— to verify your account identity and confirm the connection is active.
We use this access only to:
- Upload and publish marketing videos that you have approved as part of your content package.
- Set video captions and hashtags on your behalf.
- Verify your TikTok account is connected and active.
We do not:
- Read, access, or store your existing TikTok videos, followers, messages, or analytics.
- Post anything without your prior approval as part of your content plan.
- Share your TikTok credentials or account data with any third party.
- Use your TikTok data for advertising, profiling, or any purpose beyond the service you subscribed to.
Your TikTok access token is stored encrypted in our secure database and used exclusively to publish content on your behalf. You can revoke access at any time through TikTok’s app settings under Manage Account Permissions.
Our use of TikTok API data complies with TikTok’s Developer Terms of Service and Platform Policy.
4. How We Use Instagram and Facebook Data
When you connect your Instagram or Facebook account, we request only the permissions needed to publish content:
instagram_content_publish— to publish AI-generated videos to your Instagram account.pages_manage_posts— to publish content to your Facebook Page.pages_read_engagement— to verify your Facebook Page is active.
We do not read your messages, contact lists, followers, or any data beyond what is required to publish your approved content. Access tokens are stored encrypted and used solely for publishing on your behalf. You can revoke access at any time through Facebook’s Apps and Websites settings.
5. How We Share Your Information
We do not sell your personal information. We share data only in these cases:
- Service providers: Stripe (payments), Railway (hosting), HeyGen (AI video generation). Each bound by their own privacy policies.
- Legal requirements: If required by law or court order.
- Business transfer: In the event of a merger or acquisition, with advance notice to you.
6. Data Retention
We retain your account data for as long as your account is active. Connected platform tokens (YouTube, Instagram, etc.) are deleted immediately upon your request or when you disconnect the integration. Payment records are retained for 7 years as required by applicable tax law.
7. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and all associated data.
- Revoke any platform connection (YouTube, Instagram, etc.) at any time.
- Export your data in a portable format.
To exercise any of these rights, email us at info@theseopros.ca. We respond within 5 business days.
8. Security
We protect your data using industry-standard security practices including encrypted connections (HTTPS/TLS), hashed passwords (bcrypt), and HTTP-only session cookies. Access to client data is restricted to authorized personnel only. No system is 100% secure and we cannot guarantee absolute security, but we take every reasonable measure to protect your information.
9. Cookies
We use a single session cookie (seo-pros-session) to keep you logged in.
This cookie is HTTP-only, expires after 8 hours, and contains no personal information
beyond an encrypted session identifier. We do not use advertising or tracking cookies.
10. Children’s Privacy
Our services are intended for business use and are not directed at children under 13. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or by posting a notice in the client portal. Continued use of our services after changes take effect constitutes your acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
- Email: info@theseopros.ca
- Website: theseopros.ca
