Privacy Policy
Last updated: 8 September 2026
Visitemap reads the statistics Google already keeps about your website and shows them back to you. This page explains exactly what that involves, in plain terms.
The short version: we collect your email, read-only access to your own Google data, and the statistics about your own sites. We do not sell any of it, we do not advertise, and you can revoke our access or delete everything at any time.
1. What we collect
Three things, and nothing else.
- Your account. Your email address and the name you enter during onboarding. That is the whole account record.
- Access to your Google data. When you connect Search Console or Analytics you grant read-only access through Google OAuth. We store the resulting tokens, encrypted, so the daily sync can run without you being present.
- Statistics about your websites. Clicks, impressions, click-through rate and position from Search Console; sessions, engagement and key events from Analytics. These describe your pages and the countries your visitors came from.
We do not place any script on your website. There is nothing to install, no tag, no crawler, and Visitemap never sees your visitors directly. Everything we show you is data Google already holds about your site.
2. How we use Google data
Visitemap’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means:
- We read your Search Console and Analytics data only to show it back to you inside your own account.
- We do not sell it, transfer it, or share it with anyone, and there are no advertisers involved.
- We do not use it to train machine learning models.
- No human at Visitemap reads it, except where you explicitly ask us to look at something in support of a problem you have reported, or where the law requires it.
The access we request is read-only. Visitemap cannot change anything in your Search Console or Analytics property, and cannot write to your website.
3. Where it is stored, and for how long
Your data is held in a Postgres database hosted by Supabase, and the application runs on Vercel. Access to your rows is restricted at the database level so one account cannot read another’s.
OAuth tokens are encrypted before they are written, and are used only to call Google on your behalf.
How long we keep it:
- Search Console statistics: up to 485 days, which is as far back as Google itself retains them.
- If you delete a site: its statistics are deleted with it, immediately.
- If you move to a smaller plan: you choose which sites to keep. The rest stop updating straight away and are deleted seven days later. Restoring your plan within those seven days brings everything back untouched.
- If you delete your account: everything goes, including your statistics and your stored tokens.
4. Who else is involved
We use a small number of services to run Visitemap. Each one sees only what it needs to do its job.
- Google (Search Console, Analytics, sign-in). The source of your website statistics, and how you log in.
- Supabase. Database and authentication.
- Vercel. Hosting.
- Inngest. Runs the scheduled jobs that fetch your data once a day.
- Ahrefs. We look up the public Domain Rating for the website addresses you add. Only the address is sent, and nothing about you or your traffic.
- Lemon Squeezy. Handles payment if you subscribe. They take your billing details directly; we never see or store a card number.
- Resend. Sends the emails described below.
5. Email
We send you two kinds of email, and neither is marketing.
- About your account. A welcome message, and a note when your plan starts, changes or is due to end. You cannot switch these off while you have an account, because they tell you things you need to know.
- The weekly digest, on paid plans. What moved on your sites and what to do about it, and only in weeks when something actually changed. Every one carries an unsubscribe link, and you can turn it off at any time in Settings, or mute individual sites.
Your receipts come from Lemon Squeezy rather than from us, at whichever address you gave them.
7. Your choices
- Revoke our access at any time, from your Google account permissions. You do not need to ask us, and it takes effect immediately.
- Delete a site, from its settings page. Its stored statistics go with it.
- Delete your account, from Settings. This removes your profile, your sites, your statistics and your tokens.
- Ask us for a copy of what we hold about you, or ask us to correct it, by writing to the address below.
8. Contact
Questions about any of this, or a request about your data, go to contact@visitemap.com.
If we change this policy we will update the date at the top of this page. If a change materially affects how your data is used, we will tell you by email first.
See also our Terms of Service.