Privacy Notice
This Privacy Notice explains how Hobbyland Group ("we", "us") handles personal data in the SEO Command Center (the "App"). The App is an internal business tool. It is operated solely for Hobbyland Group and its authorised staff and contractors. It is not offered to the public, it is not a subscription service, and no payments are taken through it.
This notice covers two groups of people: (1) the authorised users who sign in to the App, and (2) third parties whose data passes through the App when we manage our own websites and social accounts (for example, people who comment on a Hobbyland Instagram account, or businesses that appear in a lead list).
1. Who is responsible
The data controller is Hobbyland Group. You can reach us about anything in this notice at [email protected].
2. Data about App users
If you have been given an account, we process the following about you:
| Data | Why we process it | Kept for |
|---|---|---|
| Work email address, role (admin or user), whether the account is active, who created it, when it was created | To operate your account and enforce role-based access | While you are authorised to use the App. Accounts are deactivated, not deleted, so that audit history stays intact. |
| Password, stored only as a salted bcrypt hash | To authenticate you. We never store or can read your plain password. | Until you change it or the account is deactivated |
| Time of your last sign-in | Security and account housekeeping | Overwritten on each sign-in |
Session identifier (the sid cookie) and server-side session record |
To keep you signed in | Up to 7 days from your last request, or until you sign out |
| IP address, at sign-in | Rate limiting of sign-in attempts to protect against password guessing | Held in memory for about 15 minutes, then discarded |
| Standard server and hosting logs (request path, time, status, IP) | Security, troubleshooting and abuse prevention | Per our hosting provider's default log retention |
Actions you take in the App (for example publishing a post, running a scan, or changing another user's role) are recorded against your account so that we can trace changes to company assets.
3. Cookies
The App sets one cookie, named sid. It is strictly necessary to keep you signed in.
It is marked HttpOnly, Secure in production and SameSite=Lax, and expires after 7 days of inactivity.
The App itself does not use analytics, advertising or tracking cookies. Because this cookie is
essential for the service you have requested, no consent banner is shown.
4. Data the App processes on behalf of the business
The App connects to third-party platforms to manage Hobbyland Group's own websites and social media accounts. In doing so it may process personal data about people who are not App users:
- Website analytics. Aggregated traffic and search data from Google Analytics 4 and Google Search Console for our own sites. This data is aggregated by Google and does not identify individual visitors to us.
- Instagram engagement. When an Instagram account owned by Hobbyland Group is connected, the App receives comments and direct messages sent to that account and may send automated replies based on rules we configure. We store the Instagram user ID of the sender and the time and outcome of each automated reply so that the same person is not messaged twice. We also store public metrics for our own posts.
- Public content research. The App can fetch publicly available Instagram Reels from accounts we place on a watchlist, including the creator's username, public engagement counts and any transcript, for content research.
- Business leads. Admin users can generate lists of businesses from public sources such as Google Maps and business websites. A lead record can include the business name, website, publicly listed phone number, publicly listed contact email address and social media links. Where a listed contact is a named individual, that is personal data. Leads are used only for legitimate business-to-business outreach by Hobbyland Group and must be handled in accordance with applicable marketing and data-protection law.
- Site audits and screenshots. The App scans our own websites and takes screenshots of them. It does not scan or screenshot third-party sites other than as described under business leads.
5. Service providers we use
The App relies on the following providers, each acting on our instructions:
| Provider | What it does | What it may receive |
|---|---|---|
| Hosting and PostgreSQL database provider | Runs the App and stores its database | All data described in this notice |
| Google (Analytics, Search Console, OAuth) | Provides analytics and search data for our sites | Our Google account authorisation; requests for our own sites' data |
| Meta (Instagram Graph API) | Publishing, insights, comments and messages for our accounts | Our account tokens; content we publish; replies we send |
| GitHub | Applies automated code fixes to our own website repositories | Code changes and pull requests for our repositories |
| Apify | Runs the Google Maps business scraper and the public Instagram Reels scraper | Search parameters we supply; returns public business and Reel data |
| Anthropic (Claude API) | AI analysis of our site code and screenshots, page drafting, caption drafting and lead scoring | Our website code and screenshots; lead records being scored; text we ask it to draft |
| Image generation API (OpenAI-compatible) | Generates images for social posts | The prompts we write |
| Resend, or Hobbyland Group's own email service | Sends health and alert emails to our operations mailbox | Alert content and the internal recipient address |
Some of these providers are located outside your country, including in the United States. Where that involves an international transfer of personal data, we rely on the provider's standard contractual clauses or an equivalent recognised safeguard.
6. Legal basis
- For App users: performance of your employment or contractor relationship with Hobbyland Group, and our legitimate interest in securing our systems.
- For Instagram engagement and content research: our legitimate interest in operating and promoting our own social media accounts, and in the case of direct messages, responding to a message the person chose to send us.
- For business leads: our legitimate interest in business-to-business marketing, subject to the marketing rules that apply in the recipient's country.
7. Retention
- User accounts: for as long as you are authorised, then deactivated.
- Sessions: up to 7 days of inactivity.
- Instagram reply logs, lead records, audit results and scan history: until an admin deletes them or they are no longer needed for the purpose they were collected for. We review these periodically.
- Third-party platform access tokens: until the connection is disconnected in the App or the token expires.
8. Security
Access to the App requires a personal account. Passwords are hashed with bcrypt. Sessions use HttpOnly, Secure cookies. Sign-in attempts are rate limited per IP address and per account. Access is role based, so standard users cannot reach admin features such as user management or lead generation. Third-party access tokens are stored server-side and are never sent to the browser.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or restrict the processing of your personal data, to object to processing based on legitimate interests, and to complain to a data-protection authority. To exercise any of these rights, or if you are a third party whose data appears in the App (for example in a lead list or an Instagram reply log) and you want it removed, email [email protected] or follow our data deletion instructions. We will respond within the time required by applicable law.
10. Changes
We may update this notice when the App or our providers change. The date at the top shows the current version. Material changes will be communicated to App users directly.