Public-page scope
LandingQA is designed to inspect pages available on the public web. Do not submit passwords, private dashboards, or confidential URLs.
YOUR DATA, EXPLAINED
A LandingQA scan produces detailed evidence. This notice explains just as clearly what information enters the service, why it is needed, who may process it, how long it stays, and the choices you have.
LandingQA is designed to inspect pages available on the public web. Do not submit passwords, private dashboards, or confidential URLs.
Measurements, page captures, model interpretations, and optional analytics observations remain labelled so one is not mistaken for another.
You can disconnect integrations and request access, correction, export, or deletion, subject to identity checks and legal retention duties.
This Privacy Notice applies when you visit LandingQA, create or use an account, submit a public page for review, connect an optional data source, communicate with us, or purchase access to a report. It should be read together with the Terms of Service and any information shown at checkout.
This notice covers personal information processed through the LandingQA marketing site, account and authentication flow, scan workflow, reports, correction previews, optional integrations, customer communications, and related security and operational systems.
It does not govern the privacy practices of a website you ask LandingQA to scan, an analytics platform you choose to connect, a payment page operated under its own privacy notice, or another third-party service linked from LandingQA.
LandingQA is not designed to log in to private areas or receive production customer databases. If a URL needs credentials or contains confidential information, do not submit it.
For information about visitors, account users, buyers, support contacts, and service operation, the LandingQA provider identified at checkout or on your invoice acts as the controller: it determines why and how that information is processed.
If an organization gives you access to LandingQA, that organization may separately control your account membership and the page context it submits. Direct questions about your relationship with that organization to it; questions about LandingQA’s own processing can come to us.
A public page may incidentally contain a name, photograph, testimonial, author attribution, or other personal information. We process that content only as needed to capture and analyze the page at your request. Section 13 explains your responsibility when asking us to scan a page you do not own.
| Category | Examples | Why it is needed |
|---|---|---|
| Account and identity | Email address, workspace or organization membership, authentication events, session identifiers, and account status. | To authenticate you, keep the account secure, and provide the service. |
| Scan request and context | The submitted URL and context you provide, such as conversion goal, audience, traffic source, page type, language, or category. | To run the requested scan and interpret the page in the right context. |
| Public-page evidence | Redirect path, screenshots and crops, visible copy, DOM and computed presentation data, accessibility structure, metadata, links, network and console diagnostics, and performance observations from supported viewports. | To measure the page, substantiate findings, and produce a reproducible report. |
| Report and correction data | Scores, strengths, findings, evidence labels, model interpretations, proposed copy or style corrections, preview results, and validation plans. | To create, display, preserve, and compare your deliverable. |
| Optional integration data | Authorization tokens, property or project identifiers, selected date windows, and aggregated observations from a connected service such as Search Console, GA4, or PostHog. | To add an analytics-observed evidence layer when you explicitly connect it. |
| Transaction and entitlement | Order, invoice, payment-status, currency, tax, entitlement, and refund-status information. Full card details are generally handled by the checkout provider rather than LandingQA. | To complete a purchase, unlock the report, prevent fraud, and keep financial records. |
| Communications | Support requests, feedback, survey responses, legal requests, and the content and metadata of messages you send us. | To answer you, resolve issues, and improve support. |
| Device and service logs | IP address, browser and device type, timestamps, requested routes, error records, security events, and diagnostic identifiers. | To deliver pages, protect the service, investigate failures, and prevent misuse. |
Do not put passwords, private keys, payment-card data, health information, government identifiers, children’s data, or other sensitive personal information into scan context or support messages.
Account email, the URL and scan context you submit, connected-service choices, purchase information, and messages.
The page response and evidence available to an ordinary browser during the requested capture.
Standard request, session, security, error, and feature-use information generated while the service operates.
Limited account, property, project, and aggregated observation data returned by an optional integration.
We may also receive transaction status from a checkout provider and abuse or security signals from infrastructure providers. We do not purchase consumer profiles or data-broker lists for the purpose of producing a scan.
Where laws such as the GDPR require a legal basis, we rely on the bases below. The precise basis can depend on whether you act as a consumer, business user, site visitor, or representative of a customer.
| Purpose | Typical information | Legal basis |
|---|---|---|
| Provide the scan and report | Account, request context, public-page evidence, report, integration observations, and entitlement. | Performance of our contract with you; steps requested before entering a contract. |
| Authenticate and secure the service | Email, session, device, IP, security events, and service logs. | Contract; legitimate interests in access control, fraud prevention, and service security. |
| Operate, troubleshoot, and improve | Feature-use, error, performance, support, and de-identified or aggregated service data. | Legitimate interests in maintaining and improving a reliable product. |
| Process orders and keep records | Transaction, entitlement, account, invoice, tax, and refund information. | Contract; compliance with tax, accounting, and consumer-protection obligations. |
| Communicate with you | Email and support or legal correspondence. | Contract; legitimate interests in service communication; consent where required for optional marketing. |
| Enforce terms and comply with law | Relevant account, request, transaction, security, and communication records. | Legal obligation; legitimate interests in protecting users, rights, and the service. |
When we rely on legitimate interests, we assess whether the use is necessary and whether your interests, rights, or reasonable expectations override ours. You can object to qualifying uses as described in section 12.
We do not sell personal information. We do not use scan evidence to create an advertising profile about visitors shown on the scanned page. We do not send optional marketing where consent is required unless you have provided it.
LandingQA combines deterministic checks with model-assisted interpretation. Relevant public-page evidence and request context may be sent to approved model infrastructure so the service can classify the page, interpret evidence, identify possible problems, synthesize findings, or propose a bounded correction.
We require service providers to process information for the contracted service and under applicable data-protection terms. The provider or route used for a particular operation may change as we maintain quality, security, availability, and regional requirements.
Model-assisted findings can be wrong or incomplete. Review the evidence and validation plan before acting on a correction, especially where brand, legal, accessibility, or commercial risk is involved.
LandingQA uses strictly necessary browser storage and similar technologies to authenticate users, maintain sessions, route requests, protect forms, remember security-relevant state, and keep the service functioning. These technologies cannot be switched off through a consent preference because the requested service would not work without them.
The current marketing site does not deploy advertising pixels or non-essential analytics cookies. Pages may request assets such as fonts from third-party infrastructure, which can receive an IP address and standard browser request information. If we introduce optional analytics or advertising technologies, we will update this notice and provide consent controls where required.
You can configure your browser to block or delete storage, but doing so may sign you out or prevent account and checkout features from working.
We disclose only the information reasonably needed for the recipient’s role. Recipient categories may include:
Providers act under contracts that limit their use of the information. We may publish or share aggregated information that does not reasonably identify an individual. We do not disclose a customer’s non-public report as a testimonial or public example without authorization.
LandingQA and its service providers may process information in countries other than the one where you live. Privacy laws and government-access rules may differ in those locations.
When a restricted transfer requires safeguards, we use an approved mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the United Kingdom’s approved transfer terms, or another lawful mechanism, together with supplementary protections where appropriate. You may ask for more information about the safeguards relevant to your information.
We keep information only for the period reasonably necessary for the purpose described, including delivering the purchased report, maintaining evidence integrity, resolving disputes, protecting the service, and complying with accounting or legal duties. The period can differ by record type.
| Record | Retention approach |
|---|---|
| Sign-in links and sessions | Magic sign-in links are short-lived and normally expire after 15 minutes. Browser sessions normally expire after no more than 7 days unless ended sooner. |
| Scan artifacts, model runs, observations, and reports | Kept for the retention period stated in the service, account, or order information applicable to your purchase, then deleted or de-identified under the configured retention process. |
| Connected integrations | Authorization access ends when you disconnect or revoke the integration. Tokens and imported observations are then deleted under the applicable operational deletion window, except where a record must be retained by law. |
| Account and support records | Kept while the account is active and for a limited period afterward when needed for support, security, disputes, or legal obligations. |
| Transaction, invoice, tax, and legal records | Kept for statutory accounting, tax, anti-fraud, chargeback, and legal limitation periods. |
| Security logs and backups | Rotated on limited operational schedules. Deleted information may persist temporarily in protected backups until the relevant cycle completes and is not restored except for recovery. |
When you request deletion, we remove or de-identify eligible information and communicate the outcome. We may retain a minimal record of the request and information that must remain for law, fraud prevention, dispute resolution, or the protection of legal rights.
We use administrative, technical, and organizational safeguards appropriate to the information and risk. These include access controls, short-lived authentication links, secure session settings, encryption for sensitive integration credentials, network and input restrictions around page capture, provider access limits, monitoring, logging, backups, and controlled deletion processes.
No online service can promise absolute security. You are responsible for protecting access to your email account and devices, signing out of devices you do not control, and telling us promptly if you suspect unauthorized use.
Do not include exploit details in a public post. Send enough information for us to reproduce and contain the issue to hello@landingqa.com.
Depending on where you live and the circumstances, you may have the right to:
Ask whether we process your personal information and receive a copy with required details.
Ask us to correct inaccurate or incomplete personal information.
Ask us to erase eligible information, subject to lawful exceptions.
Limit qualifying processing or object where we rely on legitimate interests.
Receive qualifying information in a structured, commonly used, machine-readable format.
Withdraw consent for future processing where consent is the basis, without affecting earlier lawful use.
You may also have the right to appeal a decision on a request and to complain to the data-protection or privacy authority where you live, work, or believe an infringement occurred. EEA users can find their authority through the European Data Protection Board; UK users may contact the Information Commissioner’s Office.
We will not discriminate against you for exercising a privacy right. We may be unable to locate information about a person merely shown on a scanned public page unless the request includes enough detail to identify the relevant scan and content.
You must have the right to submit the URL and direct LandingQA to process the page. For a page you own or operate, this normally follows from your role. For a third-party page, you are responsible for ensuring your request is lawful and does not violate contractual restrictions, intellectual-property rights, privacy rights, access controls, or applicable computer-misuse rules.
Do not use LandingQA to monitor a person, collect personal profiles, target a protected group, bypass a login or paywall, scan a private staging environment without authority, or repeatedly burden a third-party service.
LandingQA captures what a normal browser can access during the requested public-page review. We may block a URL, restrict a capture, remove an artifact, or suspend an account when needed to protect people, systems, rights, or the service.
LandingQA is a professional website-review service and is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account or purchase the service. Do not submit information about a child in scan context, integrations, or support messages.
If you believe a child provided personal information directly to LandingQA, contact us so we can investigate and delete it where required.
We may update this notice when the service, providers, legal requirements, or processing practices change. The “Last updated” date identifies the current version.
If a change materially affects how we use information already collected, we will provide additional notice through the service, by email, at checkout, or by another appropriate channel before the change takes effect where required. Earlier versions may be requested from the privacy contact.
For a privacy question, rights request, or complaint, email hello@landingqa.com. Include the email tied to your account and enough detail to understand the request, but do not send passwords or identity documents unless we specifically request a secure method.
The responsible legal provider and its business address are identified on the checkout page, order confirmation, or invoice for your purchase. If you use LandingQA through an organization, you may also contact that organization’s account administrator.
If we cannot resolve a concern, you may contact the competent supervisory or privacy authority. Nothing in this notice limits a right available under mandatory data-protection law.
A REAL PERSON, NOT A FORM MAZE
Tell us what you need and which account or scan it concerns. We will verify the request and route it to the responsible provider.