Privacy Policy
Last Updated: July 2026
1. Introduction and Scope of This Privacy Policy
At OutreachDeskPro, we recognize that privacy is a fundamental human right and a core component of building trust in the digital ecosystem. As a platform that facilitates high-stakes SEO transactions, guest posting, and the integration of highly sensitive Google Search Console (GSC) data, we are committed to maintaining the highest standards of data protection, transparency, and accountability. This Privacy Policy is a comprehensive document designed to explain, in exhaustive detail, exactly how we collect, use, process, store, and protect the personal and non-personal data of our users.
This policy applies to all individuals and entities that interact with OutreachDeskPro, including but not limited to: SEO agencies, brand representatives, independent webmasters, freelance content writers, and digital marketing consultants. By accessing our marketplace, registering for an account, linking your Google OAuth credentials, or simply browsing our informational pages, you are actively consenting to the data practices described in this document. If you find any aspect of this policy unacceptable, you must immediately cease using our services and request the deletion of any data we may have already collected.
We have designed this policy to comply with the most stringent global privacy frameworks, including the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada. We believe that regardless of your geographic location, you deserve the highest level of data privacy.
2. Exhaustive Breakdown of Data We Collect
To operate a complex, data-driven marketplace like OutreachDeskPro, it is necessary to collect various categories of data. We adhere to the principle of data minimization, meaning we only collect what is strictly necessary to provide and improve our services.
2.1 Personal Identification Information (PII)
When you create an account, whether as a Buyer or a Publisher, we require certain Personal Identification Information (PII) to establish your identity and ensure the security of the platform. This includes your full legal name, a valid and verifiable email address, and an encrypted password. If you choose to utilize Single Sign-On (SSO) providers such as Google or Microsoft, we collect the basic profile information authorized by those providers, which typically includes your name, email address, and a profile picture URL. We do not scrape your social media profiles or attempt to gather additional PII from external sources without your explicit consent.
2.2 Financial and Billing Data
Because OutreachDeskPro involves financial transactions (buying guest posts, funding escrow wallets, and withdrawing earnings), financial data collection is a critical component of our operations. When you deposit funds or pay for an order, your credit card information, billing address, and associated banking details are collected directly by our PCI-DSS compliant third-party payment processors (such as Stripe or PayPal). OutreachDeskPro does not store your raw credit card numbers, CVV codes, or bank account routing numbers on our servers at any time. We only store tokens representing your payment methods, records of transaction amounts, timestamps, and the current balance of your OutreachDeskPro Escrow Wallet. For Publishers requesting withdrawals, we collect your payout preferences, which may include your PayPal email address, Payoneer account details, or cryptocurrency wallet addresses.
2.3 Sensitive Google Search Console (GSC) Data
The unique value proposition of OutreachDeskPro is our ability to verify website traffic using Google Search Console. This requires Publishers to grant us specific permissions via Google's OAuth 2.0 protocol. When you authorize this connection, we receive an Access Token and a Refresh Token. These tokens allow our servers to communicate with Google's servers on your behalf.
It is imperative to understand exactly what we do and do not collect from GSC:
- We DO collect: Aggregated traffic metrics for the specific domains you explicitly choose to import into our marketplace. This includes Total Clicks, Total Impressions, Average Click-Through Rate (CTR), and Average Position over a maximum historical period of 16 months. We also collect aggregated data regarding the top-performing search queries (keywords) and the geographic distribution of your traffic (top countries).
- We DO NOT collect: Data for any websites in your GSC account that you have not explicitly selected for import. We do not collect individual user data, personally identifiable information of your website visitors, or any data that could compromise the privacy of your audience. Furthermore, we only request read-only access. Our system cannot alter your sitemaps, submit URL removal requests, or make any changes to your Google Search Console configuration.
2.4 Automatically Collected Technical and Usage Data
As you navigate and interact with the OutreachDeskPro platform, our servers and third-party analytics tools automatically record certain technical information. This includes your Internet Protocol (IP) address, which may reveal your general geographic location (city or country level). We collect details about your device, including the operating system, browser type and version, screen resolution, and language preferences.
We also collect extensive usage data, often referred to as "clickstream data." This involves tracking the specific pages you visit, the time spent on those pages, the links you click, the marketplace searches you perform, and the filters you apply. This data is crucial for understanding how users interact with our platform, allowing us to identify UI/UX bottlenecks, optimize the performance of our search algorithms, and personalize the user experience.
3. The Purposes of Data Processing: How We Use Your Information
The data we collect is not left to stagnate; it is actively processed to power the OutreachDeskPro ecosystem. We utilize your data for the following specific, legitimate business purposes:
3.1 Core Platform Functionality and Service Delivery
Your PII and financial data are essential for maintaining your account, processing your payments, funding your escrow wallet, and facilitating the purchase and sale of guest posts. Without this data, the platform simply could not function. The GSC data provided by Publishers is processed by our proprietary algorithms to calculate the Site Power Score, a central metric used by Buyers to evaluate the quality of a website. This data is displayed publicly on the marketplace to facilitate informed purchasing decisions.
3.2 Security, Fraud Prevention, and Dispute Resolution
The SEO industry is unfortunately targeted by bad actors attempting to sell links on manipulated domains or execute fraudulent chargebacks. We use your IP address, device information, and usage patterns to detect anomalous behavior that may indicate fraud, bot activity, or unauthorized account access. If a dispute arises between a Buyer and a Publisher regarding the delivery or quality of a guest post, we access communication logs and transaction histories to fairly mediate and resolve the issue.
3.3 Communication and Customer Support
We use your email address to send transactional communications, such as order confirmations, escrow release notifications, password reset links, and alerts regarding changes to our Terms of Service. If you contact our customer support team, we use your communication history to provide context and resolve your inquiries efficiently. With your explicit opt-in consent, we may also send you marketing emails, newsletters, or promotional offers. You reserve the right to unsubscribe from marketing communications at any time.
3.4 Legal Compliance and Auditing
We may process your data to comply with applicable legal obligations, such as tax reporting requirements, anti-money laundering (AML) regulations, or lawful requests from government agencies and law enforcement.
4. Data Sharing and Third-Party Disclosures
OutreachDeskPro is committed to the principle that your data is not a commodity to be sold. We do not, under any circumstances, sell your Personal Identification Information to third-party data brokers, marketing agencies, or advertising networks. However, to operate effectively, we must share specific subsets of your data in controlled environments.
4.1 Sharing Within the Marketplace (User-to-User)
The nature of a marketplace requires sharing information between Buyers and Publishers. If you are a Publisher, the domain name of your imported website, its niche, its price, its Site Power Score, and its aggregated GSC traffic metrics will be publicly visible to registered Buyers. However, your personal name and email address remain hidden to prevent spam and off-platform solicitation. When a Buyer places an order, the Publisher receives the Buyer's target URL, anchor text, and content instructions, but not their financial details.
4.2 Trusted Third-Party Service Providers
We employ carefully vetted third-party companies to perform vital operational tasks on our behalf. These include cloud hosting providers (e.g., AWS, Vercel) where our databases reside; payment gateways (e.g., Stripe) that process financial transactions; transactional email services (e.g., SendGrid, Postmark) that deliver our system notifications; and analytics platforms (e.g., Google Analytics) that help us understand platform usage. These service providers are contractually obligated to implement strict security measures and are strictly prohibited from using your data for any purpose other than providing the specific service we have contracted them for.
4.3 Legal and Regulatory Disclosures
We reserve the right to disclose your information if we believe in good faith that such disclosure is necessary to comply with a legal obligation, a valid subpoena, a court order, or a lawful request from a government regulatory agency. We may also disclose information to protect the rights, property, or safety of OutreachDeskPro, our users, or the public, which includes exchanging information with other companies for fraud protection and credit risk reduction.
5. Google API Services User Data Policy Compliance
Given our deep integration with Google Search Console, we are bound by Google's strict developer policies. OutreachDeskPro’s use and transfer to any other app of information received from Google APIs will strictly adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we affirm that:
- We only use the GSC data to provide the core functionality of our marketplace (displaying verified traffic metrics).
- We do not transfer this data to third parties unless strictly necessary to provide our service (e.g., hosting the data on our cloud servers), to comply with the law, or as part of a merger or acquisition.
- We do not use GSC data to serve advertisements or for any retargeting purposes.
- We have implemented robust security procedures to protect this sensitive data from unauthorized access or exfiltration.
6. International Data Transfers
OutreachDeskPro is a global platform. Your information, including Personal Data, may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
For our users residing in the European Economic Area (EEA) or the United Kingdom, we ensure that any transfer of your personal data outside of the EEA or UK is safeguarded by implementing Standard Contractual Clauses (SCCs) approved by the European Commission, or by ensuring the receiving entity is certified under a recognized data privacy framework.
7. Your Comprehensive Data Protection Rights
We believe that you should have ultimate control over your data. In accordance with GDPR, CCPA, and other major privacy laws, you possess the following rights regarding the personal information we hold about you:
- The Right to Access (Data Portability): You have the right to request a comprehensive copy of all personal data we hold about you. We will provide this data in a structured, commonly used, and machine-readable format within 30 days of your request.
- The Right to Rectification: If you discover that any information we hold about you is inaccurate, outdated, or incomplete, you have the right to request immediate correction. You can update most of your information directly through your account settings.
- The Right to Erasure (The Right to be Forgotten): You have the right to request the permanent deletion of your personal data from our active databases. When you invoke this right, we will delete your account, remove your websites from the marketplace, and destroy your OAuth tokens. Please note that we may retain certain transactional records for legal, tax, and auditing purposes, as mandated by law.
- The Right to Restrict Processing: Under certain conditions, you have the right to demand that we halt the active processing of your data, even if we continue to store it.
- The Right to Object: You have the right to object to the processing of your personal data for specific purposes, particularly for direct marketing or profiling.
To exercise any of these rights, please submit a formal request to our Data Protection Officer at privacy@outreachdeskpro.com. We will not discriminate against you for exercising your privacy rights; you will not face denial of service, altered pricing, or degraded service quality as a result of invoking these protections.
8. Data Security Protocols and Infrastructure
Protecting your data against unauthorized access, alteration, disclosure, or destruction is a critical priority for our engineering team. We implement a multi-layered security architecture:
- Encryption in Transit: All data transmitted between your browser and our servers is secured using Transport Layer Security (TLS 1.2 or higher), ensuring that your passwords, financial data, and OAuth tokens cannot be intercepted over the network.
- Encryption at Rest: Highly sensitive data, such as your Google Refresh Tokens and password hashes (using bcrypt with a high work factor), are encrypted at rest within our databases using AES-256 encryption.
- Access Controls: Access to our production databases and servers is strictly limited to authorized senior engineering personnel on a "need-to-know" basis. We utilize multi-factor authentication (MFA) and strict Identity and Access Management (IAM) policies to govern internal access.
- Regular Audits: We conduct regular vulnerability scans, dependency audits, and penetration testing simulations to identify and patch potential security weaknesses before they can be exploited.
9. Children's Privacy
Our services are expressly not intended for use by individuals under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us immediately. If we become aware that we have collected Personal Data from children without verification of parental consent, we will take immediate steps to remove that information from our servers and terminate the associated account.
10. Changes to This Privacy Policy
The digital landscape and regulatory environments are constantly evolving. As such, we may update our Privacy Policy from time to time to reflect changes in our operational practices, new features, or updated legal requirements.
When we make material changes to this policy—changes that significantly affect how we process your data or alter your rights—we will provide prominent notice. This may include sending an email to the primary address associated with your account and displaying a clear notification banner on our website prior to the changes taking effect. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
11. Contact Our Data Protection Team
We welcome your questions, feedback, and concerns regarding this Privacy Policy or our data handling practices. If you wish to file a complaint, exercise your data rights, or simply seek clarification on any point within this document, please contact our dedicated Data Protection Officer (DPO) and legal team via the following channels:
Email: privacy@outreachdeskpro.com (Expected response time: 24-48 business hours)
Mailing Address:
OutreachDeskPro LLC, Legal & Privacy Dept.
[Insert Physical Corporate Address Here]
United States