Legal
Privacy policy.
What personal information Southpaw SEO collects, why, where it lives and what you can do about it. Written in plain English to the shape of Australian Privacy Principle 1.4.
1. Who we are
Southpaw SEO is a local SEO and website development consultancy based in Sydney, working with gyms, boxing and martial-arts studios and boutique fitness businesses across Australia. In this policy “we”, “us” and “our” mean Southpaw SEO; “you” means anyone whose personal information we handle, whether a website visitor, someone who sends an enquiry, or a client and the people who work for them.
We are a small business. The Privacy Act 1988 (Cth) may not require a business of our size to comply with the Australian Privacy Principles (the APPs), but we have chosen to follow them anyway, because clients trust us with access to their Google accounts and their customer enquiries, and that trust should not depend on a turnover threshold.
2. What we collect
We collect the minimum we need to answer you, do the work and get paid. In practice that is:
Enquiries and the free teardown
When you use the form on this site or email us, we collect your name, your gym’s name, its suburb, your email address, your phone number, your website address, anything you write in the message box, and which page of the site you sent the form from. None of these fields are hidden; everything we store is what you typed.
Client accounts
Once you become a client we also hold:
- Business and billing details — your legal entity name, ABN, trading name, business address, the contact details of the people we work with, invoices and payment records. Direct-debit and card details are collected and stored by our payment provider, not by us; we never see your full account or card number.
- Google account data — data we read from your Google Business Profile (search terms, impressions, calls, direction requests, website clicks, bookings, reviews and your replies), Google Search Console (queries, clicks, impressions, index status, Core Web Vitals) and Google Analytics 4 (aggregate traffic and conversion data). We access these through manager or user invitations to our own Google account, never through your password.
- Website and listing data — content, images, timetables and pricing you give us to publish; access to your website’s hosting or content system; the directory listings we create or correct on your behalf; and the rank-tracking and map-grid scans we run for your suburb.
- Correspondence — emails, call notes, meeting notes and the monthly reports we send you.
Your members and customers
We do not deliberately collect personal information about your gym’s members. We may see it incidentally: a reviewer’s name and photo on Google, a name on an enquiry that comes through a website we manage for you, a testimonial you ask us to publish. We treat that information as yours, use it only for the purpose you gave it to us, and we will not publish a member’s name, image or story without your confirmation that you hold their consent.
Website visitors
If you only browse this site, we collect nothing that identifies you. Cloudflare Web Analytics gives us aggregate page-view counts without cookies or personal identifiers (see section 7), and Cloudflare keeps short-lived request logs to run and protect the site.
3. How we collect it
- Directly from you — through the form on this site, by email, by phone and in meetings.
- From Google, with your authorisation — through Google’s Business Profile, Search Console and Analytics interfaces and APIs after you invite our account as a manager or user. You can revoke that access at any time from your own Google account, and we remove ourselves when an engagement ends.
- From public sources — when we prepare a teardown or an audit we look at your public website, your public Google Business Profile, public directory listings and public reviews. We do not scrape or buy contact lists.
4. Why we collect it
We use personal information to:
- reply to your enquiry and prepare the teardown you asked for;
- deliver the services in your agreement — profile and listing management, website work, review responses, reporting;
- invoice you and keep the financial records the tax law requires;
- send you the monthly report and talk to you about the work;
- keep our own records of what was done for which client, and improve how we work;
- meet our legal obligations and deal with any complaint or dispute.
We do not sell personal information, we do not share client data with other clients, and we do not use your data to train or feed any advertising system. Where we quote a client’s results publicly, we do it with the gym owner’s written approval and without publishing any member’s personal information.
5. Where it is held
Everything we hold sits with a short list of providers, each chosen for a specific job:
- Supabase — the database behind this site’s enquiry form and our private staff portal. Our project is hosted in Sydney, Australia, and data is encrypted in transit and at rest. Only our two staff accounts, each protected by a password and a second factor, can read it. The same database keeps an activity log: a short line recording that a record was created, changed or deleted, when, and by which staff account. For an enquiry that line includes the name that was on it, so section 8 covers it too.
- Cloudflare — hosts this website and the portal, handles DNS and TLS, and provides the cookieless analytics described below. Cloudflare’s network is global, so request logs may be processed outside Australia.
- GitHub — stores the code for this site and our reporting tools. That code can include a client’s business name, website address and profile identifiers so the tools know which account to read. It never includes passwords, member lists, payment details or exported personal data.
- Google — your Business Profile, Search Console and Analytics data stays in Google’s systems; we read it through Google’s interfaces and keep dated snapshots of the metrics we report on.
- Email and payments — our email provider holds our correspondence with you, and our direct-debit provider holds the bank details you give it under its own privacy policy.
6. Overseas disclosure
Some of the providers above are based in, or operate from, the United States and run global networks. That means personal information may be stored or processed overseas by Cloudflare (United States and its global edge network), GitHub (United States) and Google (United States and the countries in which Google operates its services). Our Supabase database itself is in Sydney.
Before using any provider we check that it publishes a privacy policy and security commitments that are at least as protective as the APPs, and we only give each one the data it needs to do its job. We do not otherwise disclose personal information overseas.
7. Cookies and analytics
This site uses Cloudflare Web Analytics, which measures page views and site performance without cookies, without fingerprinting and without any identifier that follows you between sites. We see counts, not people. Because of that there is no cookie banner: there is nothing to consent to.
We do not run advertising pixels, remarketing tags or third-party trackers. Our content security policy allows scripts only from this site and Cloudflare, blocks inline scripts entirely, and lets the page connect to nothing beyond this site, Cloudflare and our own database. The enquiry form sets no cookies. The staff portal at portal.southpawseo.com uses browser storage only for the login session itself and the one-time code that completes a password-reset link; it holds no data of yours, and it is invitation-only.
8. Security and retention
The practical steps we take:
- every connection to this site, the portal and our providers is encrypted (TLS);
- every staff account uses a long password and two-factor authentication; the portal refuses to show data until both are in place;
- we work in your Google accounts through named invitations and never ask for, store or share your passwords;
- database access is limited by row-level rules so the public site can only write an enquiry, never read one;
- we keep the list of people with access short — currently two — and review it when anyone’s role changes.
How long we keep things:
- Enquiries that do not become an engagement are deleted within 12 months of your last contact with us, sooner if you ask. Deleting the enquiry also leaves entries in the activity log described in section 5, which can carry the name that was on it. When you ask us to erase your details we clear those entries in the same pass, and we will tell you when it is done.
- Client records are kept for the life of the engagement and then for as long as the tax and consumer laws require us to keep financial and contractual records (currently five years), after which they are deleted.
- Google data snapshots we captured for your reports are handed over as part of your exit pack and deleted from our systems within 30 days of the end of the engagement.
No system is perfect. If we become aware of a data breach that is likely to cause you serious harm we will tell you and, where the law requires it, the Office of the Australian Information Commissioner, as soon as we practicably can.
9. Access and correction
You can ask us at any time what personal information we hold about you, ask for a copy, or ask us to correct it. Email [email protected]. We will confirm that it is you we are talking to, respond within 30 days and not charge you for it. A correction updates the record itself; the activity log in section 5 keeps a line saying the record was changed, and we clear any of your details out of that line at the same time. If for some reason we cannot give you access or make a correction, we will tell you why in writing and how to complain about that decision.
10. Complaints
If you think we have mishandled your personal information, email [email protected] with “privacy complaint” in the subject line and tell us what happened. We will acknowledge your complaint within seven days, investigate it, and give you a written response within 30 days. If we need longer we will tell you why and when to expect an answer.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au. The OAIC is independent of us and its service is free.
11. Marketing emails
We only send marketing email to people who have asked for it or who have an existing business relationship with us, in line with the Spam Act 2003 (Cth). Every such email identifies us and carries a working unsubscribe link; opting out takes effect within five business days. Emails about your own engagement (reports, invoices, access requests) are not marketing and will continue while you are a client.
12. Changes to this policy
We will update this policy when our providers, practices or the law change. The effective date at the top of the page tells you which version you are reading. If a change materially affects how we handle client data, we will email current clients before it takes effect.
13. Contact
Privacy questions, access requests and complaints all go to [email protected], which is monitored on business days and is the channel we answer them on. We operate from Sydney and serve clients Australia-wide; we do not publish a street address, and we do not accept walk-ins.