Privacy Policy

Last updated: November 12, 2025 | Effective Date: November 12, 2025

🔒 Our Commitment to Your Privacy

SearchJet is committed to protecting your privacy and ensuring GDPR, CCPA, and UAE Federal Decree-Law No. 45 of 2021 (PDPL) compliance. We implement plan-based data retention, IP anonymization, and automated cleanup to minimize data collection while providing excellent search services.

This Privacy Policy describes how SearchJet ("we", "us", or "our") collects, uses, and discloses your information when you use our website, services, or applications (collectively, the "Services"). By using SearchJet, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

We collect the following types of information:

1.1 Account Information

  • Name: Your full name for account identification
  • Email Address: For authentication, communication, and account recovery
  • Password: Encrypted using industry-standard bcrypt hashing
  • Account Creation Date: Timestamp of registration

1.2 Search Data

  • Search Queries: Keywords entered by your website visitors
  • Search Results: Number and relevance of results returned
  • Timestamps: When searches were performed
  • Session IDs: Anonymous identifiers for tracking user sessions

1.3 Technical Data

  • IP Addresses: Anonymized based on your subscription plan (see Data Retention section)
  • User Agents: Browser and device information
  • Referrer URLs: Pages where searches originated
  • API Keys: Stored as hashed values for security

1.4 Subscription Data

  • Plan Type: Free, Pro, Growth, or Enterprise
  • Subscription Status: Active, cancelled, or expired
  • Payment Information: Processed and stored securely by PayPal (we do not store credit card numbers)
  • PayPal Subscription ID: Masked in exports (***1234)

1.5 Cookies and Tracking

  • Essential Cookies: Authentication tokens, session management (required)
  • Analytics Cookies: Google Analytics for usage patterns (optional, requires consent)
  • Preference Cookies: Your cookie consent choices

2. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: Provide and maintain search functionality for your websites
  • Authentication: Secure access to your SearchJet account
  • Analytics: Generate search analytics and insights for your dashboard
  • Billing: Process subscription payments via PayPal
  • Support: Respond to your inquiries and provide technical assistance
  • Improvements: Analyze usage patterns to improve our services
  • Security: Detect and prevent fraud, abuse, and unauthorized access
  • Compliance: Meet legal and regulatory requirements
  • Communications: Send service updates, security alerts, and (with consent) marketing emails

3. Data Retention (Plan-Based)

We implement automatic data deletion based on your subscription plan to minimize data storage and comply with GDPR's data minimization principle:

PlanSearch Logs RetentionIP AnonymizationSession Data
Free30 daysFully anonymized (SHA-256 hash)24 hours
Pro90 daysFully anonymized (SHA-256 hash)48 hours
Growth180 daysPartially anonymized (last octet masked)72 hours
Enterprise365 daysTemporary storage (7 days), then anonymized7 days

Automated Cleanup: Our system runs daily at 2:00 AM UTC to automatically delete data older than your plan's retention period. This ensures compliance with GDPR Article 5(1)(e) - storage limitation.

Permanent Data

The following data is retained until you delete your account:

  • Account information (name, email)
  • Site configurations and API keys
  • Subscription history
  • Aggregated analytics (non-personal, anonymized)

4. Your Rights (GDPR, CCPA & UAE PDPL)

We respect your data rights under GDPR (EU), CCPA (California), and PDPL (UAE). You have the following rights:

Right to Access (GDPR Article 15)

Download all your personal data in machine-readable JSON format.

How to exercise: Go to Settings → Privacy & Data and click "Download My Data"

Right to Erasure (GDPR Article 17)

Delete your account and all associated data permanently.

How to exercise: Go to Settings → Privacy & Data and follow the account deletion process

Right to Rectification (GDPR Article 16)

Update or correct your account information at any time.

How to exercise: Go to Settings → Account and edit your information

Right to Data Portability (GDPR Article 20)

Export your data in a structured, machine-readable format (JSON).

How to exercise: Same as Right to Access (download feature)

Right to Object (GDPR Article 21)

Object to specific data processing activities.

How to exercise: Contact [email protected]

Right to Restriction (GDPR Article 18)

Request limitation of processing in certain circumstances.

How to exercise: Contact [email protected]

CCPA Rights (California Residents)

California residents have the right to know, delete, and opt-out of data sales.

Note: We do not sell personal information to third parties.

Rights for UAE Residents (PDPL)

Under UAE Federal Decree-Law No. 45 of 2021, you have rights tailored to your jurisdiction, including:

  • Right to Access: (Article 14) Obtain information on your processed data.
  • Right to Rectification: (Article 15) Correct inaccurate data.
  • Right to Erasure: (Article 16) "Right to be forgotten".
  • Right to Stop Processing: (Article 19) In cases of marketing or violation of usage.
  • Right to Data Portability: (Article 18) Transfer your data to another controller.

⚡ Response Time: Within 30 days

We will respond to your rights requests within 30 days as required by GDPR.

5. Information Sharing & Disclosure

We do NOT sell your personal information to third parties.

We may share your information only in the following limited circumstances:

5.1 Service Providers

  • PayPal: Payment processing (subscription billing)
  • Google Analytics: Usage analytics (only with your consent)
  • Email Service: Transactional emails (account verification, password resets)
  • Cloud Hosting: Infrastructure providers (AWS, DigitalOcean, etc.)

All service providers are bound by confidentiality agreements and GDPR data processing agreements (DPAs).

5.2 Legal Requirements

We may disclose your information if required by law:

  • To comply with legal obligations, court orders, or subpoenas
  • To protect our rights, property, or safety
  • To prevent fraud or abuse of our services
  • In connection with law enforcement investigations

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new owner. We will notify you via email before your data is transferred and becomes subject to a different privacy policy.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to provide and improve our services. You have full control over cookie preferences.

Cookie TypePurposeConsent Required
EssentialAuthentication, session management, securityNo (required)
AnalyticsGoogle Analytics, usage patterns, performance monitoringYes (optional)
PreferencesYour cookie consent choices, language settingsNo (required)

Manage Cookies: You can manage your cookie preferences at any time:

  • Cookie Settings Page - Update your preferences
  • Browser Settings - Block or delete cookies via your browser
  • Cookie Banner - Update consent when re-prompted (every 6 months)

7. Data Security

We implement industry-standard security measures to protect your data:

🔐 Encryption

  • • HTTPS/TLS for data in transit
  • • Bcrypt for password hashing
  • • AES-256 for sensitive data at rest

🛡️ Access Control

  • • Laravel Sanctum authentication
  • • Role-based access control (RBAC)
  • • API key hashing and masking

📊 Monitoring

  • • Automated security scans
  • • Intrusion detection systems
  • • Comprehensive audit logging

🔄 Data Protection

  • • Regular backups
  • • Automated data cleanup
  • • IP anonymization

⚠️ Important: While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

8. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States and EU member states. These countries may have different data protection laws than your country.

When we transfer data internationally, we ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework compliance
  • Standard Contractual Clauses (SCCs) with service providers
  • GDPR-compliant Data Processing Agreements (DPAs)

Location of Data: Our primary servers are located in the European Union (EU). For users in the UAE, this transfer is compliant with Article 22 of the UAE PDPL, as the EU provides an adequate level of data protection (GDPR).

9. Children's Privacy

SearchJet is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us at [email protected], and we will take steps to delete such information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes:

  • We will update the "Last Updated" date at the top of this page
  • For material changes, we will notify you via email
  • We may also display a notice on our website
  • Continued use of our services after changes constitutes acceptance

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

11. Contact Us

For privacy-related questions, to exercise your rights, or to report a data breach, please contact us:

General Privacy Inquiries:

[email protected]

Data Protection Officer (DPO):

[email protected]

Customer Support:

[email protected]

Mailing Address:

SearchJet Engine
Data Privacy Department
Dynamic Web Lab FZE LLC
United Arab Emirates

EU Representative (for GDPR inquiries):

If you are in the European Economic Area (EEA), you can contact our EU representative at [email protected]

Supervisory Authority:

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

  • Europe: Your national Data Protection Authority (DPA)
  • UAE: The UAE Data Office

This Privacy Policy is governed by the laws of the United Arab Emirates. For our Terms of Service, please visit /terms-of-use.