Privacy Policy
Last updated: 21 July 2026
1. Who We Are
FlinnSchema is operated by Flinn G Evans, an AI visibility and automation consultant based in Kent, United Kingdom. We are the data controller for the personal data processed through this platform. For any privacy-related enquiries, contact us at admin@flinnschema.com.
2. Information We Collect
Account Information
When you create an account, we collect:
- Full name
- Email address
- Website URL
- Encrypted password (we never store plaintext passwords)
Audit Data
When we audit your website, we collect publicly available information from your site, including:
- Page HTML content, meta tags, and structured data (JSON-LD)
- Robots.txt, sitemap.xml, and llms.txt file contents
- Publicly listed reviews from Trustpilot, Google Places, Feefo, and Reviews.io
- Page performance metrics and internal link structure
- Individual page scores from site-wide crawl analysis
This data is used solely to generate your audit report and is stored securely in our database.
LLM Test Data
When you run LLM prompt tests (premium feature), we send your business name, website URL, industry, and location to AI search engine APIs. The responses from these engines are stored in our database as part of your report, including whether your business was mentioned and the type of mention. AI-generated verification classifications are also stored.
Blog Request Data
When you use the blog post feature, we store the keyword, generated content, and publication status. Blog posts are generated using AI and can be published directly to your connected Shopify or WordPress site.
Integration Data
When you connect a Shopify or WordPress site, we store your store URL, access tokens (encrypted), and connection status. For Shopify, an OAuth token is stored. For WordPress, an application password is stored. This data is used solely to manage your integration and is deleted when you disconnect.
Specialist Account Data
If you use a Specialist account, we store your specialist code, profile information, and a log of client account access events. If you are a client connected to a specialist, we store the connection status and a log of when the specialist accessed your account.
Partner Programme Data
If you join our partner programme as an SEO specialist, we store records about the clients you refer and the commission you earn:
- Referral records — which client you referred, that client’s email address, the affiliate code used, the start and end of the 12-month commission window, the associated Stripe customer and subscription identifiers, and the referral’s status
- Commission ledger — an append-only record with one entry per payment event, holding the client’s email address, the Stripe invoice, charge, customer and subscription identifiers, the gross amount actually charged, the commission amount, and timestamps. Entries are never edited or deleted; a refund or chargeback is recorded as a further, negative entry.
- Payout requests — the amount requested, its status, timestamps, and masked bank details only (the first initial of the account name, the last 2 digits of the sort code, and the last 4 digits of the account number)
- Bank details — when you request a payout we store the account name, 6-digit sort code and 8-digit account number needed to make the transfer. This table has row-level security enabled with no access policies at all, so it cannot be read by any user session, including your own; exactly one admin-only server route can read the full digits. The record is deleted as soon as the payout is marked as paid, so it exists only between your request and our payment.
- Affiliate click log — when a visitor follows a partner’s affiliate link we record the affiliate code, the landing path, the referring website’s hostname, the browser user agent, a timestamp, and a one-way SHA-256 hash of the visitor’s IP address salted with a server-side secret. The raw IP address is never stored. If that visit later results in an account, the resulting user ID is recorded against the click.
Payment Information
Payments are processed by Stripe. We do not store your credit card details. Stripe handles all payment data in accordance with PCI DSS standards. We store only the Stripe session ID, payment confirmation, subscription status, billing period dates, and the email associated with the payment.
Funnel & Usage Analytics
When you visit our landing pages, we collect:
- Page view events (which page, timestamp)
- Referrer URL (where you came from)
- User agent string (browser and device type)
- A one-way hash of your IP address (we do not store raw IP addresses — the hash uses SHA-256 with a salt and is truncated to prevent reversal)
We also use Google Analytics (ID: G-5VX5SD7MCY) to understand how visitors interact with our website. This includes anonymised data such as pages visited, time on site, and device type. You can opt out of Google Analytics by using a browser extension or ad blocker.
Browser Storage
We store data in your browser’s localStorage for functionality purposes:
- Authentication session — keeps you logged in between visits
- Roadmap progress — tracks which implementation tasks you’ve marked as complete
- LLM dispute flags — remembers which test results you’ve disputed
This data is stored only in your browser and is not transmitted to our servers.
3. How We Use Your Information
- To provide the Service: Running audits, generating reports, processing payments, managing subscriptions
- To enforce quotas: Tracking LLM test counts and blog post requests per billing period
- To improve the Service: Understanding usage patterns via analytics and fixing issues
- To communicate: Sending account-related emails (confirmation, password reset)
- To run the partner programme: Crediting a referral to the correct partner, calculating commission on payments that clear, and making payouts
- For case studies: With your consent, we may publish a case study about your AI visibility improvements
We will never sell your personal data to third parties.
4. Data Sharing
We share data only with the following third-party services, strictly to operate the platform:
- Supabase — Database and authentication hosting
- Stripe — Payment and subscription processing
- Vercel — Application hosting and serverless functions
- OpenAI — ChatGPT LLM testing (Responses API with web search), blog topic generation (GPT-4o-mini)
- Anthropic — AI verification classifier (Claude Haiku) to validate LLM test results
- Perplexity — LLM testing (Sonar model with search)
- Google — Gemini LLM testing (with Google Search grounding), Google Places API for review data, Google Analytics
- Resend — Transactional email delivery (audit results, booking confirmations, specialist notifications)
- Shopify — Store integration for schema injection and blog publishing (via OAuth)
- Upstash — Redis-based rate limiting (request metadata only, no personal data stored)
For LLM testing, your business name, website URL, industry, and location are included in the prompts sent to these APIs. No other personal data is shared.
5. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of account deletion.
- Audit data & reports: Retained for the lifetime of your account to enable score tracking and history.
- LLM test results: Retained for the lifetime of your account. Previous results are replaced when you run a new test on the same audit.
- Funnel analytics: Retained for up to 12 months, then aggregated or deleted.
- Payment records: Retained for 7 years for accounting and legal compliance.
- Blog posts: Retained for the lifetime of your account.
- Integration tokens: Retained while integration is connected. Deleted on disconnect.
- Specialist access logs: Retained for the lifetime of the specialist or client account.
- Partner referral records: Retained for the life of the partner relationship plus the 6-year accounting period.
- Partner commission ledger & payout records: Retained for 6 years to meet UK accounting and HMRC record-keeping requirements.
- Partner bank details: Deleted as soon as the payout is marked as paid.
- Affiliate click log: Retained for 12 months.
6. Your Rights (UK GDPR)
Under UK data protection law, you have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your data (“right to be forgotten”)
- Portability — Request your data in a machine-readable format
- Object — Object to processing of your data for specific purposes
- Restrict — Request restricted processing of your data
- Withdraw consent — Where processing is based on consent, withdraw it at any time
To exercise any of these rights, email admin@flinnschema.com. We will respond within 30 days. For more detail on your rights and how to exercise them, see our GDPR Compliance page.
7. Cookies & Local Storage
We use:
- Essential cookies: Supabase authentication cookies to keep you logged in
- Analytics cookies: Google Analytics cookies for anonymised usage data
- Affiliate referral cookies: two first-party cookies, fs_ref and fs_ref_hint, set by our servers when a visitor follows a partner’s affiliate link (an address beginning /r/). fs_ref carries the affiliate code so that, if the visitor goes on to create an account, the referral can be credited to the right partner; it is httpOnly, so page scripts cannot read it. fs_ref_hint carries no code and only signals that a referral is still pending; it is readable by page scripts. Both are set with SameSite=Lax and Secure, both last 30 days, and both are cleared once the referral has been resolved. Neither is used for advertising and neither is shared with a third party.
- LocalStorage: Authentication session persistence, roadmap task completion, LLM dispute flags
Google Analytics and the Meta Pixel are loaded only if you accept them in our cookie banner; if you reject, neither is loaded. You can manage cookies through your browser settings. Clearing localStorage will log you out and reset your roadmap progress.
8. Security
We take reasonable measures to protect your data, including:
- HTTPS encryption on all pages
- Encrypted password storage (bcrypt via Supabase Auth)
- Row-level security on all database tables
- Server-side quota enforcement for premium features
- API keys stored as environment variables, never exposed to the browser
- Stripe webhook signature verification for payment events
- IP address hashing (SHA-256 with salt) — raw IPs are never stored
- Partner bank details held in a table with row-level security and no access policies — unreadable by any user session, readable only by a single admin-only server route, and deleted once the payout is made
9. International Data Transfers
Our hosting and data processing infrastructure includes services based in the US (Vercel, Supabase, Stripe, OpenAI, Anthropic, Perplexity) and globally (Google). Where data is transferred outside the UK, we rely on standard contractual clauses and the data protection measures implemented by each provider.
10. Children
The Service is not intended for users under 18. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email. The “last updated” date at the top reflects the most recent revision.
12. Contact
For privacy-related enquiries or to exercise your data rights:
Email: admin@flinnschema.com
Location: Kent, United Kingdom