Skip to content

Privacy

Last updated October 1, 2026

LandingConnect Measure is run by Beachcliff Tech. We collect as little as we can, keep it only as long as it is useful, and never sell it.

What we store about you

  • Your name, email address and profile picture from Google sign-in. We ask Google only for openid email profile.
  • The organizations, sites and roles you create or are invited to, and invite emails you send.
  • An audit log of security-relevant changes (who connected what, on whose behalf), with a hashed IP address, never the raw address.

Google data

Search Console and Google Analytics are connected separately from sign-in, read-only, in one of two ways: a service account you add to your property, or your own Google account through Google's consent screen (OAuth). We use that data only to rank recommendations for the site it belongs to, show it back to people with access to that site, and never use it for advertising or to train models.

When you connect your own Google account we store the refresh token Google returns, encrypted at rest (AES-256-GCM), the email address of that Google account so your team can see whose access a connection uses, the scopes you granted (read-only Search Console and Analytics) and when you connected. We never store your Google password. Short-lived access tokens are kept in memory only. Press Disconnect under Settings → Connections to revoke the token at Google and erase it here, or remove LandingConnect Measure's access in your Google account at any time: the next check marks the affected connections broken and stops reading.

Service-account keys are encrypted the same way and never shown again after you paste them.

LandingConnect Measure's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

WordPress

When you connect WordPress we store the site address, the WordPress user name and an application password (encrypted at rest, never shown again), plus the titles, descriptions and other SEO fields of your published pages so findings can be matched to them. Nothing is written to your site until someone with approval rights approves a change; every change keeps the earlier value so it can be reverted. Revoke the application password in WordPress to cut access at once.

Website visitors (the tracker)

  • Cookieless by default: a session lives in the tab only, and a visitor is a server-side hash that changes every day.
  • IP addresses are hashed with a daily salt and dropped; we keep country and region only, and a parsed browser name, not the full user agent.
  • We never record what people type into forms. Do Not Track and Global Privacy Control are honoured.

Crawling

Our crawler reads public pages of sites that were added by their owners or agencies. It stores page HTML for comparison between audits and keeps only the last three audits.

Your rights

You can ask for a copy of your data, or for it to be erased, at any time. Deleting a site deletes its scans, findings, connections and metrics; deleting an organization deletes everything in it. Write to privacy@beachclifftech.com and we will answer within 30 days.