Privacy policy

Last updated: August 23, 2026

This policy explains what personal data AITraffic processes, why we process it, who receives it and the choices available to you. It applies to the AITraffic website, SaaS application and WordPress plugin.

Who is responsible for your data

The data controller is BoostYou Technologies LLC. It is registered in Wyoming, United States. You can review the public operator record on the About AITraffic page.

Contact [email protected] for privacy questions or to exercise a data right. No account is required to contact us.

Data we process

Account data

Your email address, name if you provide one, a hashed password, organization name, account role and email-verification status. Passwords are stored as bcrypt hashes and are never recoverable.

Store and product data

When you connect a WooCommerce store we receive store configuration (URL, name, currency, language, timezone, country, software versions, permalink settings, robots directives and policy configuration) and, for products you choose to monitor, catalogue data including titles, descriptions, prices, stock status, SKU, GTIN, brand, attributes, variations, categories, images and alt text, aggregate rating and review counts.

Monitoring and optimization data

We process tracked prompts, AI-provider responses, detected citations and mentions, readiness issues, recommendations, change commands and the history needed to reverse an approved change.

Billing, support and technical data

We process subscription status, plan, billing period and Stripe customer identifiers. Stripe handles card details; they do not reach our servers. When you contact us, we process the message and contact details you provide. We also process ordinary security and diagnostic logs such as timestamps, request identifiers, IP addresses and error details.

Data we never request from your store

  • Orders or order contents
  • Customer names, email addresses, phone numbers or shipping addresses
  • Payment card data of any kind
  • WordPress user accounts, passwords or password hashes
  • Individual review authors or review text

The WordPress plugin does not read these records, and our plugin API has no endpoint intended to accept them. Do not include customer data or secrets in prompts, product copy or support emails.

Why we process data

  • To create and secure your account and deliver the service you requested.
  • To synchronize selected products, run audits and produce recommendations.
  • To send buyer-intent prompts to enabled AI providers and store the returned evidence.
  • To administer subscriptions, prevent abuse, troubleshoot failures and meet legal duties.
  • To communicate about service changes, security, billing and support requests.

Depending on your location, the legal basis is performance of our contract, our legitimate interests in operating and securing the service, compliance with law, or consent where the law requires it. You may withdraw consent for future processing where consent is the basis.

Service providers and international transfers

Prompt text is sent to the AI providers you enable—currently OpenAI, Google and Perplexity—so they can answer it. These are buyer-intent questions and should not contain customer data. Stripe processes payments. Resend delivers transactional email when configured. Hosting, database, cache and error-monitoring providers may process technical data to operate the service.

These providers may process data in countries other than yours. Where applicable, we rely on contractual safeguards or another lawful transfer mechanism. Provider-specific processing is also governed by that provider’s terms and privacy documentation.

Retention and deletion

Account, store and monitoring evidence is retained while your account is active because visibility trends depend on historical comparisons. Cancelling a subscription stops renewal but does not itself delete the account. You may request deletion at any time by emailing [email protected].

After a verified deletion request, we delete or anonymize account and product data unless we must retain limited records for legal, fraud-prevention, security or accounting reasons. Residual encrypted backups expire through the ordinary backup cycle. We retain billing and transaction records for the period required by applicable tax and accounting law.

Security

Store credentials are encrypted at rest with AES-256-GCM. Requests between the plugin and our API are signed with HMAC-SHA256 and protected against replay. Database access is scoped to the customer organization. No internet service is risk-free, so these measures reduce rather than eliminate risk.

Your rights

Depending on your location, you may have rights to access, correct, export, restrict, object to or delete your personal data, and to complain to a data-protection authority. We may need to verify that a request comes from the account owner. We will not discriminate against you for exercising a privacy right.

Business customers and data processing agreements

AITraffic is generally a controller for account, billing and service-operation data. If we process personal data on your documented instructions as a processor, the parties may enter into a data processing agreement. Request one at [email protected].

Children

AITraffic is a business service and is not directed to children. Do not create an account if you are not legally able to enter into a binding business contract in your jurisdiction.

Changes to this policy

We may update this policy when the service, providers or law changes. The date above identifies the current version. We will give account holders reasonable notice of material changes when required.

Contact

Privacy and deletion requests: [email protected]. General support: [email protected]. Public company details are available on our About page.