Legal

Privacy Policy

Last updated: June 22, 2026

1. Introduction

RenderlySEO is a product operated by Codoki AI Ltd, a company registered in England and Wales with its registered office at 86-90 Paul Street, London, England, EC2A 4NE ("Codoki," "RenderlySEO," "we," "our," or "us"). We provide a rendering service that serves fully-rendered HTML of client-side web applications to search engine crawlers and social media bots (the "Service"). This Privacy Policy explains how we collect, use, share, and protect personal information in connection with the Service, our website at renderlyseo.com, and our customer dashboard.

We are committed to handling personal information lawfully, fairly, and transparently. This Policy is designed to support our obligations under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection laws.

For questions about this Policy, contact privacy@renderlyseo.com.

2. About This Policy and Who It Applies To

RenderlySEO as Controller

Where we collect personal information directly from you when you visit our website, create an account, subscribe to the Service, or interact with us, we are the "controller" of that information. Examples include your name, email address, billing details, and account preferences.

RenderlySEO as Processor

Where we process personal information on behalf of our business customers (for example, request data flowing through the Service for our customers' websites), we act as a "processor" or "service provider." In that role, our customers are the controllers. If you are an end user of one of our customers' websites and have a question about your personal information, please contact that customer first; we will support them in responding.

3. Information We Collect

Account and Subscription Information

  • Identifiers: name, email address, organization name
  • Account credentials: passwords (stored as cryptographic hashes), API keys (stored as hashes)
  • Billing information: subscription plan, billing address, payment method (processed by our payment processor; we do not store payment card data)
  • Service configuration: domain names, DNS configuration, and routing preferences you provide

Technical and Usage Data

  • IP addresses and User-Agent strings (used transiently for bot classification and not persisted)
  • Request metadata: timestamps, request paths, HTTP status codes
  • Diagnostic information from our proxy and renderer systems
  • Aggregated analytics: cache hit rates, bot detection counts, request volumes

Website and Dashboard Data

  • Pages visited, session duration, and referring URL
  • Browser and device information
  • Information you submit through forms (contact, demo requests, support tickets)

Communications and Support

When you contact us for support, we collect the information you choose to share, including the contents of your messages and any attachments.

What We Do Not Collect

  • End-user PII from visitors to your websites (no persistent IP, cookie, or session data)
  • Payment card data (handled entirely by our PCI-compliant payment processor)
  • Plaintext credentials of any kind
  • Customer page content beyond auto-expiring cached HTML
  • Special categories of personal information (race, religion, health, biometrics, etc.)

4. How We Use Personal Information

We use personal information to provide and maintain the Service, process payments, authenticate users, detect bots and abuse, secure our infrastructure, communicate about your account, send marketing emails where you have opted in, improve and develop the Service using aggregated or de-identified data, and comply with legal obligations. Under GDPR, the legal bases we rely on are performance of a contract, legitimate interests (security and product improvement), consent (marketing), and legal obligation.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use personal information for automated decision-making that produces legal or similarly significant effects.

5. How We Share Personal Information

Sub-Processors

We engage a limited number of third-party service providers ("Sub-Processors") to deliver components of the Service (hosting, infrastructure, email delivery, analytics, customer support). Sub-Processors are contractually bound to process personal information only on our instructions and in line with this Policy.

Payment Processing

Billing transactions are processed by Stripe, Inc. Stripe collects payment card information directly from you and provides us only with the transaction metadata necessary to manage your subscription.

Legal and Safety Disclosures

We may disclose personal information if required by law, valid legal process, or to protect the rights, property, or safety of RenderlySEO, our customers, or others. We challenge overbroad government requests where appropriate.

Business Transfers

If RenderlySEO is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to standard confidentiality obligations.

6. International Data Transfers

Persistent customer data (account records, configuration, analytics, audit logs) is stored and processed in the United States. Transient request processing occurs at globally distributed edge locations operated by our infrastructure Sub-Processors and is not persisted outside of transient handling.

Where personal information is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, with supplementary measures including encryption in transit and at rest, strict access controls, and challenges to overbroad government access requests.

7. Data Retention

  • Account and configuration data: retained for the life of your account and a reasonable period thereafter; deleted on verified erasure request.
  • Billing records: up to 7 years, as required for tax and accounting purposes.
  • Cached HTML content: auto-expiring TTL with a maximum of 30 days.
  • Operational logs: up to 30 days.
  • Support communications: 2 years from the last interaction.
  • Marketing data: until you unsubscribe or 2 years of inactivity, whichever is first.

Where we cannot delete data due to a legal requirement, we will restrict its use to that requirement and delete it once the requirement no longer applies.

8. Cookies and Tracking Technologies

The Rendering Service

The rendering service itself does not set cookies. End-user IP addresses and User-Agent strings are used transiently for bot classification but are not stored.

The Dashboard and Marketing Site

  • Essential cookies: required to log you in, maintain your session, and remember settings.
  • Analytics cookies: help us understand how visitors use the site; only set with your consent in jurisdictions that require it.
  • Functional cookies: remember preferences such as language and theme; only set with your consent where required.

9. Your Privacy Rights

Depending on your jurisdiction you may have rights to access, correct, delete, restrict, or port your personal information; to object to processing based on legitimate interests; to withdraw consent; and to lodge a complaint with your supervisory authority. California residents have CCPA/CPRA rights including the right to know, access, delete, correct, opt out of sale or sharing (we do neither), and to be free from retaliation for exercising these rights.

To exercise any of these rights, email privacy@renderlyseo.com. We will verify your identity before processing your request. If you are an end user of a RenderlySEO customer's website, please contact that customer directly.

10. Security

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control and tenant isolation
  • Hashed credentials and API keys; never stored in plaintext
  • Continuous monitoring and automated alerting
  • Peer code review, static analysis, and dependency scanning in our deployment pipeline
  • Regular review of our security posture

Despite these measures, no online service is completely secure, and we cannot guarantee absolute security.

11. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If we learn we have collected personal information from a child, we will delete it promptly.

12. Automated Decision-Making

We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects on individuals. Bot classification performed by the Service is operational and does not result in decisions about individuals.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the law. Material changes will be communicated by email or in-product notice at least 30 days before they take effect. The "Last Updated" date at the top of this Policy reflects the most recent version.

14. Contact Us

Privacy and GDPR inquiries: privacy@renderlyseo.com
Security incident reports: security@renderlyseo.com
General support: support@renderlyseo.com

Codoki AI Ltd
86-90 Paul Street
London, England, EC2A 4NE
United Kingdom