Privacy Policy
1. Introduction and Scope
Welcome to Backlinks Monitor. This Privacy Policy explains how WEB MEDIA SOLUTIONS LLC (“we,” “us,” “our,” or the “Company”) collects, uses, processes, discloses, and protects personal information when you use our backlink monitoring and analysis platform (the “Service”). This policy applies to all users worldwide and complies with applicable data protection laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and other relevant privacy regulations.
We are committed to protecting your privacy and handling your personal data with transparency, security, and respect for your rights. By using our Service, you acknowledge that you have read, understood, and agree to the data practices described in this Privacy Policy.
2. Information We Collect
We collect various types of personal information to provide, maintain, protect, and improve our Service. The information we collect falls into several categories as described below:
2.1 Information You Provide Directly
This is information you voluntarily provide when creating an account, using our Service, or communicating with us:
| Data Category | Specific Information | Collection Method | Purpose |
|---|---|---|---|
| Account Information | Full name, email address, password (encrypted), phone number (optional), company name (optional) | Registration form, account settings | Account creation, authentication, communication, service delivery |
| Billing Information | Billing address, payment method details (last 4 digits only), transaction history, invoicing details | Subscription checkout, payment processors (Stripe, PayPal) | Payment processing, subscription management, tax compliance, fraud prevention |
| Website Information | Domain names you monitor, target URLs, backlink URLs, anchor texts, custom notes, monitoring preferences | Dashboard input, API submissions, CSV uploads | Providing backlink monitoring services, generating reports, sending alerts |
| Communication Data | Support tickets, email correspondence, feedback, survey responses, chat messages | Support forms, email, in-app messaging, feedback surveys | Customer support, service improvement, resolving disputes, collecting feedback |
| Preferences | Notification settings, email preferences, dashboard customization, language selection, timezone | Account settings, preference center | Personalizing your experience, delivering relevant notifications |
2.2 Information Collected Automatically
When you access or use our Service, we automatically collect certain technical and usage information:
| Data Category | Specific Information | Collection Method | Purpose |
|---|---|---|---|
| Device Information | Device type, operating system, browser type and version, screen resolution, device identifiers | Browser headers, device sensors | Compatibility optimization, security analysis, technical support |
| Log Data | IP address, access times and dates, pages viewed, features used, referring URLs, search queries | Server logs, analytics tools | Security monitoring, troubleshooting, service optimization, detecting abuse |
| Usage Analytics | Feature usage patterns, session duration, click paths, error reports, performance metrics | Google Analytics, internal analytics | Understanding user behavior, improving features, identifying issues |
| Cookies & Tracking | Session IDs, authentication tokens, preference cookies, analytics cookies | Cookies, local storage, similar technologies | Maintaining sessions, remembering preferences, analytics (see Cookie Policy) |
| Location Data | Approximate geographic location based on IP address (country, region, city) | IP geolocation services | Fraud prevention, regional content delivery, tax compliance |
2.3 Information from Third Parties
We may receive information about you from third-party sources:
- Payment Processors: Stripe and PayPal provide transaction confirmation, payment status, and limited payment method information necessary for billing and fraud prevention
- Data Providers: We use third-party data sources and APIs to discover backlinks and collect backlink-related information (page authority, domain authority, indexing status)
- Social Login Providers: If you authenticate using social login (Google, Microsoft), we receive basic profile information (name, email, profile picture) that you authorize
- Business Partners: If you register through a partner or affiliate program, we may receive referral information
2.4 Sensitive Personal Information
Under CPRA regulations, we want to clarify that we do not intentionally collect sensitive personal information such as:
- Social Security numbers, driver’s license numbers, passport numbers, or state identification card numbers
- Precise geolocation data (we only collect approximate location from IP addresses)
- Racial or ethnic origin, religious beliefs, or union membership
- Genetic data, biometric data for identification purposes
- Health information or sex life/sexual orientation data
If you inadvertently provide such information (for example, in support communications), we will handle it with additional care and delete it when no longer necessary for the specific purpose.
3. How We Use Your Information
We process your personal information for specific, legitimate purposes as described below. Under GDPR, we rely on different legal bases for processing, which we specify for each purpose:
3.1 Service Delivery and Performance
Legal Basis: Contract Performance (GDPR Art. 6(1)(b)) and Legitimate Interest
- Creating and managing your account
- Authenticating your identity and maintaining secure access
- Monitoring your specified backlinks and websites
- Performing discovery scans to identify new backlinks
- Executing manual checks and force indexing requests
- Generating backlink reports, analytics, and insights
- Sending notifications about backlink status changes (lost links, new links, indexing updates)
- Providing access to historical backlink data and trends
- Calculating and tracking monitoring credit usage
3.2 Billing and Payment Processing
Legal Basis: Contract Performance and Legal Obligation (tax compliance)
- Processing subscription payments through Stripe and PayPal
- Managing billing cycles and automatic renewals
- Generating invoices and receipts
- Handling refunds and payment disputes
- Preventing payment fraud and unauthorized transactions
- Maintaining transaction records for accounting and tax purposes
- Complying with financial regulations and tax laws
3.3 Communication and Support
Legal Basis: Contract Performance, Consent, and Legitimate Interest
- Responding to your support requests and inquiries
- Sending transactional emails (account confirmations, password resets, subscription receipts)
- Providing product updates and service announcements
- Sending monitoring alerts and notifications based on your preferences
- Collecting feedback about your experience with the Service
- Conducting customer satisfaction surveys (with your consent)
- Resolving disputes and enforcing our Terms of Service
3.4 Service Improvement and Development
Legal Basis: Legitimate Interest
- Analyzing usage patterns to understand how users interact with our Service
- Identifying technical issues, bugs, and performance bottlenecks
- Testing new features and improvements
- Conducting A/B tests to optimize user experience
- Developing new products, features, and services
- Training machine learning models to improve discovery accuracy
- Aggregating and anonymizing data for research and analytics
3.5 Security and Fraud Prevention
Legal Basis: Legitimate Interest and Legal Obligation
- Detecting and preventing unauthorized access, fraud, and abuse
- Monitoring for security threats and suspicious activity
- Investigating security incidents and data breaches
- Enforcing our Terms of Service and acceptable use policies
- Protecting the rights, property, and safety of our users and the Company
- Complying with legal obligations and law enforcement requests
- Maintaining backup systems for disaster recovery
3.6 Marketing and Analytics (Optional)
Legal Basis: Consent (can be withdrawn at any time)
- Sending promotional emails about new features, special offers, and product updates (only if you opt in)
- Personalizing marketing content based on your usage patterns
- Conducting targeted advertising campaigns
- Measuring the effectiveness of our marketing campaigns
- Understanding which marketing channels drive conversions
You can opt out of marketing communications at any time by clicking the “unsubscribe” link in our emails or updating your preferences in your account settings.
3.7 Legal Compliance and Obligations
Legal Basis: Legal Obligation and Legitimate Interest
- Complying with applicable laws, regulations, and legal processes
- Responding to subpoenas, court orders, and law enforcement requests
- Maintaining records required by tax and accounting regulations
- Enforcing our legal rights and defending against legal claims
- Preventing illegal activities and policy violations
4. How We Share Your Information
We do not sell your personal information to third parties. We only share your information in the limited circumstances described below:
4.1 Service Providers and Processors
We engage trusted third-party service providers to perform functions on our behalf. These providers act as data processors under GDPR and are contractually obligated to:
- Process data only according to our instructions
- Implement appropriate security measures
- Not use your data for their own purposes
- Maintain confidentiality
- Delete or return data upon termination of services4.2 Business Transfers
If we are involved in a merger, acquisition, sale of assets, bankruptcy, or other business transaction, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website before your information is transferred and becomes subject to a different privacy policy.
4.3 Legal Requirements and Protection
We may disclose your information if required to do so by law or if we believe in good faith that such disclosure is necessary to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms of Service and other agreements
- Protect the rights, property, or safety of WEB MEDIA SOLUTIONS LLC, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
- Defend against legal claims or investigations
4.4 Aggregate and Anonymized Data
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you. This may include:
- Industry research and trend reports
- Aggregated usage statistics
- Anonymized benchmarking data
This information does not constitute personal data and is not subject to this Privacy Policy.
4.5 With Your Consent
We may share your information with third parties when you have explicitly consented to such sharing. For example, if you authorize integrations with third-party tools or participate in co-marketing initiatives.
5. International Data Transfers
WEB MEDIA SOLUTIONS LLC is based in the United States, and our Service infrastructure is primarily hosted in the United States. If you access our Service from the European Economic Area (EEA), United Kingdom, Switzerland, or other regions with data protection laws, your personal information will be transferred to and processed in the United States and potentially other countries where our service providers operate.
5.1 Transfer Mechanisms for EEA Users
When transferring personal data from the EEA to countries that have not received an adequacy decision from the European Commission, we implement appropriate safeguards as required by GDPR:
- Standard Contractual Clauses (SCCs): We use the European Commission’s approved Standard Contractual Clauses (also known as Model Clauses) with our U.S.-based service providers and processors
- Binding Corporate Rules: Some of our service providers (such as AWS and Google Cloud) have implemented Binding Corporate Rules approved by EU data protection authorities
- Data Processing Agreements: All our service providers sign comprehensive Data Processing Agreements that include security commitments, data subject rights procedures, and breach notification obligations
- Supplementary Measures: We implement additional technical and organizational measures such as encryption in transit and at rest, access controls, and regular security audits to ensure data protection equivalent to EU standards
5.2 Transfer Mechanisms for Other Jurisdictions
For users in other jurisdictions with cross-border data transfer restrictions (such as China, Brazil, South Korea), we comply with local data protection requirements including:
- Obtaining consent where required by local law
- Implementing appropriate contractual safeguards
- Conducting transfer impact assessments
- Registering transfers with local authorities when required
5.3 Your Rights Regarding International Transfers
You have the right to request information about the safeguards we have implemented for international data transfers. You can also object to specific transfers in certain circumstances. Contact us at [email protected] for more information.
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
6.1 Retention Periods by Data Category
| Data Category | Retention Period | Justification |
|---|---|---|
| Account Information | Duration of active account + 30 days after account deletion | Service provision, grace period for account recovery |
| Website & Backlink Data | Duration of active subscription + 90 days after cancellation | Service provision, dispute resolution, data export opportunity |
| Billing & Transaction Records | 7 years from last transaction | Tax compliance, accounting regulations, dispute resolution |
| Payment Method Details | Until subscription cancellation or payment method removal | Recurring payment processing |
| Support Communications | 3 years from last communication | Quality assurance, dispute resolution, service improvement |
| Usage Logs & Analytics | 26 months from collection | Security monitoring, service optimization, fraud prevention |
| Marketing Consent Records | Duration of consent + 3 years after withdrawal | Compliance documentation, proving consent |
| Security Incident Logs | 5 years from incident | Security analysis, legal defense, regulatory reporting |
6.2 Deletion Process
When retention periods expire or you request deletion of your data, we follow a multi-stage deletion process:
- Logical Deletion: Data is marked for deletion and becomes inaccessible to users and most systems (immediate)
- Backup Retention: Data remains in encrypted backups for up to 90 days for disaster recovery purposes
- Permanent Deletion: Data is permanently and securely deleted from all systems including backups using cryptographic erasure or secure deletion methods
6.3 Exceptions to Deletion
We may retain certain information beyond standard retention periods when:
- Required by law, regulation, or legal process
- Necessary to resolve disputes, enforce agreements, or defend legal claims
- Essential for fraud prevention and security purposes
- Data has been aggregated and anonymized (no longer considered personal data)
7. Your Privacy Rights
Depending on your location, you have various rights regarding your personal information. We honor these rights globally to the greatest extent possible.
7.1 Rights Under GDPR (EEA/UK Users)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR:
- Right of Access (Art. 15): Request confirmation of whether we process your data and obtain a copy of your personal information
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal information
- Right to Erasure (Art. 17): Request deletion of your personal information in certain circumstances (right to be forgotten)
- Right to Restriction of Processing (Art. 18): Request that we limit how we use your data in specific situations
- Right to Data Portability (Art. 20): Receive your personal information in a structured, machine-readable format and transmit it to another controller
- Right to Object (Art. 21): Object to processing based on legitimate interests, direct marketing, or profiling
- Right to Withdraw Consent (Art. 7): Withdraw consent at any time for processing based on consent
- Right Not to Be Subject to Automated Decision-Making (Art. 22): Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects
- Right to Lodge a Complaint (Art. 77): File a complaint with your local supervisory authority if you believe we are violating data protection laws
7.2 Rights Under CCPA/CPRA (California Users)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of categories and specific pieces of personal information we collected, sources of collection, purposes of use, and categories of third parties with whom we share information (up to 12 months prior)
- Right to Delete: Request deletion of personal information we collected from you, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell personal information, but if we did, you would have the right to opt out
- Right to Limit Use of Sensitive Personal Information: Request limitation on use and disclosure of sensitive personal information (we do not collect sensitive personal information as defined by CPRA)
- Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your CCPA/CPRA rights
- Right to Designate an Authorized Agent: Authorize an agent to submit requests on your behalf
7.3 How to Exercise Your Rights
To exercise any of your privacy rights, you can:
- Email Us: Send a request to [email protected] with subject line “Privacy Rights Request”
- Use Our Web Form: Submit a request through our Data Subject Rights Request Form at backlinks-monitor.com/privacy-request
- Account Settings: Some rights can be exercised directly through your account dashboard (data export, account deletion, preference management)
7.4 Verification Process
To protect your privacy and security, we must verify your identity before processing rights requests. Our verification process includes:
- Initial Request: You submit a request with your name and email address associated with your account
- Email Verification: We send a verification link to your registered email address
- Additional Verification: For deletion or sensitive requests, we may require additional information (such as recent transaction details or account activity) to confirm your identity
- Agent Authorization: If using an authorized agent, we require written authorization signed by you and proof of the agent’s authority
7.5 Response Timeline
- GDPR Requests: We respond within 30 days, extendable to 60 days for complex requests with notification
- CCPA Requests: We respond within 45 days, extendable to 90 days for complex requests with notification
- Urgent Requests: Security-related requests and data breach notifications are prioritized and handled immediately
7.6 Limitations on Rights
In certain circumstances, we may decline requests if:
- We cannot verify your identity despite reasonable efforts
- The request is manifestly unfounded, excessive, or repetitive
- Disclosure would adversely affect the rights of others
- Processing is necessary for legal compliance or legitimate legal claims
- Data has been anonymized and can no longer be associated with you
If we decline a request, we will explain our reasoning and inform you of your right to complain to a supervisory authority.
8. Data Security
We implement comprehensive technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction.
8.1 Technical Security Measures
- Encryption: All data in transit is encrypted using TLS 1.3 or higher; sensitive data at rest is encrypted using AES-256 encryption
- Access Controls: Role-based access control (RBAC) ensures employees access only data necessary for their job functions
- Authentication: Multi-factor authentication (MFA) available for user accounts; mandatory for administrative access
- Password Security: Passwords are hashed using bcrypt with individual salts; we never store passwords in plain text
- Network Security: Firewalls, intrusion detection systems (IDS), and regular vulnerability scanning protect our infrastructure
- Database Security: Database access is restricted, logged, and monitored; regular security patches applied
- Secure Development: Code reviews, security testing, and secure coding practices minimize vulnerabilities
- Regular Backups: Encrypted, geographically distributed backups enable disaster recovery
8.2 Organizational Security Measures
- Employee Training: Regular security awareness and privacy training for all employees
- Confidentiality Agreements: All employees and contractors sign comprehensive confidentiality agreements
- Vendor Management: Due diligence assessments and contractual security requirements for all service providers
- Incident Response Plan: Documented procedures for detecting, responding to, and recovering from security incidents
- Regular Audits: Internal and external security audits, penetration testing, and compliance assessments
- Data Minimization: We collect only necessary data and regularly review data retention practices
8.3 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify affected users via email within 72 hours of discovering the breach (GDPR requirement)
- Notify relevant supervisory authorities as required by law
- Provide information about the nature of the breach, likely consequences, and mitigation measures
- Post a public notice on our website if the breach affects a significant number of users
- Take immediate steps to contain the breach and prevent further unauthorized access
8.4 User Responsibility
While we implement robust security measures, you also play a role in protecting your information:
- Use a strong, unique password for your Backlinks Monitor account
- Enable two-factor authentication in your account settings
- Do not share your account credentials with others
- Log out of your account when using shared or public devices
- Keep your contact information up to date so we can reach you about security matters
- Report suspicious activity or security concerns immediately to [email protected]
9. Children’s Privacy
Our Service is not intended for, and we do not knowingly collect personal information from, children under the age of 16 (or the applicable age of digital consent in your jurisdiction, which may be 13 in the United States or other ages in different countries).
If we become aware that we have collected personal information from a child under the applicable age without verified parental consent, we will take immediate steps to delete that information from our servers. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected].
Our Terms of Service explicitly prohibit use of the Service by individuals under 18 years of age or the age of majority in their jurisdiction, whichever is higher.
10. Third-Party Links and Services
Our Service may contain links to third-party websites, applications, or services that are not owned or controlled by WEB MEDIA SOLUTIONS LLC. This Privacy Policy applies only to information collected by our Service.
We are not responsible for the privacy practices, content, or security of third-party sites or services. When you navigate to a third-party website (for example, when verifying a backlink), you are subject to that website’s privacy policy and terms of service.
We encourage you to review the privacy policies of any third-party services before providing them with personal information. Some third parties we integrate with include:
- Payment processors (Stripe, PayPal) – see their respective privacy policies
- Analytics providers (Google Analytics) – see Google’s Privacy Policy
- Backlink data providers – see their respective privacy policies
- Cloud infrastructure providers (AWS, Google Cloud) – see their respective privacy policies
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. When we make material changes, we will notify you through one or more of the following methods:
- Email notification to your registered email address at least 30 days before changes take effect
- Prominent notice on our website homepage and within your account dashboard
- In-app notification when you next log in
- For significant changes affecting your rights, we may request your renewed consent
We will also update the “Last Updated” date at the top of this Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy. If you do not agree to the changes, you must stop using the Service and may request deletion of your account.
12. California “Shine the Light” Law
California Civil Code Section 1798.83 permits California residents to request information about our disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes. If you are a California resident and have questions about this, contact us at [email protected].
13. Do Not Track Signals
Some web browsers have a “Do Not Track” (DNT) feature that signals to websites you visit that you do not want to have your online activity tracked. Currently, there is no uniform technology standard for recognizing and implementing DNT signals, and different browsers interpret DNT signals differently.
At this time, our Service does not respond to DNT browser signals. However, you can control cookies and tracking through your browser settings and our Cookie Preference Center as described in our Cookie Policy.
14. Nevada Privacy Rights
Nevada residents have the right to opt out of the sale of certain personal information to third parties. We do not sell personal information as defined under Nevada law (NRS 603A). If you are a Nevada resident and have questions, contact us at [email protected].
15. Supervisory Authority Contact Information
If you are located in the EEA, UK, or Switzerland and believe we have violated data protection laws, you have the right to lodge a complaint with your local supervisory authority:
- EU Member States: Find your Data Protection Authority at edpb.europa.eu
- United Kingdom: Information Commissioner’s Office (ICO) – ico.org.uk
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) – edoeb.admin.ch
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
WEB MEDIA SOLUTIONS LLC
312 W 2ND ST
CASPER, WY 82601
United States
General Privacy Inquiries:
Email: [email protected]
Data Protection Officer:
Email: [email protected]
Security Concerns:
Email: [email protected]
Data Subject Rights Requests:
Email: [email protected]
Web Form: backlinks-monitor.com/privacy-request
Response Time: We aim to respond to all privacy inquiries within 48 hours during business days and to formal data subject rights requests within the timeframes specified in Section 7.5.
By using Backlinks Monitor, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal information as described in this Privacy Policy.

