privacy-policy
The short version
Most of the tools here run inside your browser and send nothing anywhere. Three of them have to fetch a web page, so those keep a record of the scan. If you ask for a report by email, that address is stored so the report can be sent. Nothing is sold, and nothing is shared with advertisers.
The rest of this page explains that in detail, because a policy that only says trust us is not worth reading. If anything here is unclear, ask the contact page.
Tools that store nothing at all
The compliance checker, the GBP suspension risk checker, the schema generator, the SERP snippet preview, the keyword cannibalization mapper, and the reconsideration request builder all run entirely on your own device. The text you paste, the answers you select, and the results you see never reach this server, so there is nothing to store, log, or hand over.
That is a deliberate design choice rather than a claim. These tools are meant for unpublished campaigns and live keyword strategy, and they would be useless if you had to think twice before pasting a draft.
Tools that fetch a page, and what they record
The site check, the menu visibility checker, the location page similarity checker, and the AI readability checker cannot work without requesting the page you name. When you run one, this server fetches that public web page and analyses the HTML it receives.
A record of the scan is then saved so the shareable report link keeps working. That record holds the address you scanned, the results, the time it ran, and a one way cryptographic hash of your IP address. The hash exists only to enforce rate limits so nobody can hammer the scanner. It cannot be turned back into an IP address, and your IP is never written down in readable form.
If you ask for a report by email
After a scan you can ask for the report to be emailed. If you do, the name, email address, company, and number of locations you enter are stored with that scan record, and the address is used to send you the report. The form says so before you submit it, and consent is an explicit tick rather than something assumed from your visit.
Those details are used to send the report, and to follow up only if you agreed to that. They are never sold, rented, or passed to third parties for marketing. To have them deleted, email the contact page and it will be done, usually the same day.
Enquiries and contact forms
What you send through a contact form is stored so the enquiry can be answered and referred back to later. It is not added to a marketing list, and it is not used for anything other than the conversation you started.
Analytics and cookies
This site may use Google Analytics to see which pages are useful and which are ignored. That sets cookies and sends limited information, including a shortened IP address, to Google. No advertising, remarketing, or social tracking pixels run on this site, and nothing here follows you around the web afterwards.
Blocking analytics cookies changes nothing about how the site works. Every tool functions identically with them refused.
Where the data sits and who can reach it
Scan records and enquiries live in this site's own database on its hosting account. Access is limited to the site operator. Where a service provider is involved, such as the host or the email service that delivers reports, they only process what is needed to provide that service.
How long anything is kept
Scan records and any contact details attached to them are kept while the report link is still useful, and removed on request at any time. Enquiries are kept for as long as the working relationship or its records reasonably require.
Your rights over your information
You can ask what is held about you, ask for it to be corrected, or ask for it to be deleted. Email the contact page and it will be handled promptly and without argument.
Depending on where you live you may hold further rights, including under the GDPR in the United Kingdom and the European Union, or the CCPA and CPRA in California. Those rights are honoured regardless of where this site is operated from, because the sensible position is to treat everyone the same rather than by postcode.
Why any of this is lawful to collect
Where the GDPR applies, information is handled on one of three grounds. Consent, for the email address you give when asking for a report, which you tick rather than have assumed. Legitimate interests, for the scan records and the hashed address behind rate limiting, because a free tool that cannot defend itself against abuse stops being available to anyone. Contract, for the details exchanged once an engagement begins.
Consent can be withdrawn at any time and the withdrawal takes effect immediately. Withdrawing it does not make the earlier processing unlawful, but it does mean no further use.
Sites you scan, and what reaches them
When you run one of the tools that fetches a page, this server makes an ordinary public request to the address you entered, identifying itself honestly rather than pretending to be a browser. That request appears in the target site's own logs the way any visit would, showing this server's address rather than yours.
Where information travels
This site is operated from outside the United Kingdom, the European Economic Area, and the United States, and its hosting and email providers may process information in other countries again. Where information about someone in the UK or EEA is involved, it is handled to the standard those rules require regardless of where the processing physically happens.
The practical protection is that very little is collected in the first place. Six of the ten tools transmit nothing at all, and the rest hold a scan record and, only if you asked for one, an email address.
If something goes wrong
If information held here were exposed in a way likely to affect you, you would be told directly and promptly rather than through a notice buried on a page nobody reads, and the relevant regulator would be notified where the law requires it. The account of what happened would be specific about what was affected and what was not.
No automated decisions about you
Nothing here profiles you, scores you, or makes an automated decision that produces a legal or similarly significant effect. The tools analyse the website you name. They do not analyse the person running them.
If you are not satisfied
Raise it through the contact page first, because most concerns are settled faster that way than through a formal route. If that does not resolve it, you have the right to complain to your own data protection authority: the Information Commissioner's Office in the United Kingdom, your national supervisory authority in the EEA, or the Attorney General's office in California.
Children
This site is intended for licensed cannabis businesses and adults aged 21 and over. It is not directed at children and no information is knowingly collected from them.
Changes to this policy
If this changes, the updated date at the top of the page changes with it. Material changes to how information is handled will be described here rather than slipped in quietly.
Who is responsible for this site
- Operated by
- Dispensary Rank
- Questions
- Anything on this page can be queried by email, and it will be answered by the person who wrote it.
Something here unclear?
Ask, and it will be answered by the person who wrote it rather than a form response.
Get in Touch