Skip to content
Neoval

Privacy

Privacy notice

Last updated 2026-09-07

Who we are

Neoval, Switzerland (“we”). Contact: seo-geo@neoval.net. This notice covers neoval.net and the SEO + GEO audit and monitoring service.

Audit data

When you submit a domain we record the domain, the time of the request and technical rate-limit counters. Counters are keyed by a keyed hash; we do not store your IP address. The audit itself reads publicly accessible pages of the submitted website and public answers from search and AI answer engines. Website text is treated as untrusted content and is not used to instruct our systems.

Reports are stored privately and are reachable only through unguessable links. A link can be revoked on request. Free-audit requests that are never completed are deleted after 90 days. Completed reports are kept for 12 months unless you ask us to delete them earlier.

Email delivery

The snapshot of a free audit (scores, failing technical controls and the buyer-prompt table) needs no address. For the full report we email you a link, and opening that link is what shows the rest: we ask for the click so a report is only ever opened by an address that receives mail. You can run the snapshot without ever giving an address. We use the address to send that report and, for subscribers and deep-audit buyers, sign-in links, monitoring updates, delivery confirmations and payment notices. Transactional email is sent through Brevo from neoval.net. Marketing email is sent only if you tick the separate, unchecked consent box, comes from go.neoval.net, and carries an unsubscribe link and our postal address in every message. Unsubscribing from marketing never affects report delivery.

Accounts and subscriptions

Accounts use passwordless email links through Firebase Authentication (Google). Payments are processed by Stripe; we never see or store card details. We store your Stripe customer and subscription identifiers, the plan, its status and the next analysis date. Cancellation and payment-method changes happen in the Stripe customer portal. Refunds for missed monitoring cycles are recorded with the Stripe refund identifier.

Where data is processed

Our application and database run on Google Cloud in the Netherlands (europe-west4). Stripe, Brevo and Google may process data outside Switzerland and the EU under their own safeguards.

Cookies and analytics

We use functional cookies only: one to limit abuse of the free audit, one session cookie when you are signed in, and, around a subscription checkout, short-lived signed cookies that tie the payment page you return from to your browser (they hold checkout and subscription identifiers, the plan, the monitored domain and a masked email, never card data, and expire within two hours). We also use Google Analytics 4 with IP anonymisation and Cloudflare Web Analytics (cookie-free) on public pages to understand which pages are read and how the free audit is used; Google Analytics sets its own cookies. No analytics run on the audit, report, checkout, sign-in, dashboard or admin pages: those URLs carry a private token, which is never sent to a third party. On those pages we instead record the step reached (for example “report opened”) on our own servers, identified by a one-way hash of the abuse-prevention cookie and kept for 90 days, so we can see where people stop without tracking anyone. There is no advertising tracking. You can block analytics with a browser extension or by disabling third-party cookies without affecting the audit or your dashboard.

Your rights

You can ask for access, correction, deletion or a copy of your data, and revoke a report link, by writing to seo-geo@neoval.net. Swiss and EU data-protection rights apply as relevant.