Privacy Policy
Last updated: 8 September 2026 · Version 2.0
This Privacy Policy explains how Bigdoor Ai Labs Pte. Ltd., the Singapore company operating MonitorMyGEO, collects, uses, discloses, protects and retains personal data in connection with the service.
1. Organisation and contact
Bigdoor Ai Labs Pte. Ltd. is registered in Singapore with ACRA, UEN / Company Registration No. 202618811Z. Registered office: 68 Circular Road, #02-01, Singapore, 049422. Privacy and data-protection enquiries can be sent to support@monitormygeo.com.
2. Personal data we may collect
- Account data such as name, work email, authentication information, role, workspace and organisation details.
- Subscription and transaction identifiers and billing status, while payment-card details are generally handled by the payment provider.
- Product inputs such as domains, brand and competitor information, prompts, configuration, support messages and content you choose to submit.
- Usage and technical information used for security, rate limiting, diagnostics or analytics.
- AI visibility evidence and derived analysis generated from monitored prompts, provider responses, public sources and website checks.
- Privacy-request records needed to verify, execute and document requests.
3. Purposes of collection, use and disclosure
- Create and administer accounts, workspaces and subscriptions.
- Provide audits, monitoring, reports, exports, competitor intelligence, AI Readiness and other requested functions.
- Authenticate users, protect accounts, detect abuse, troubleshoot incidents and maintain reliability.
- Process payments, administer billing, credits, promotions and support.
- Send transactional/service communications and, where permitted, marketing communications.
- Understand product usage and improve service quality, usability, performance and features.
- Produce eligible aggregated and de-identified benchmarks, research and industry insights as described below.
- Meet legal, regulatory, accounting, security and dispute-resolution obligations.
- Receive, verify, fulfil and document privacy requests.
4. Consent and notification
Where consent is required, we seek consent for the relevant purposes and provide information about those purposes at or before collection where appropriate. Creating an account requires acknowledgement of this Privacy Policy, while optional cookie analytics are controlled separately.
You may withdraw consent for a purpose where applicable by contacting us. Withdrawal does not affect processing already lawfully carried out and may mean we cannot continue a feature that requires the relevant data.
5. AI-provider processing
To perform visibility monitoring, prompts and related business context may be sent to configured third-party AI providers. Provider responses and citations may then be stored and analysed. Do not place confidential personal data or sensitive personal information into prompts unless a product feature expressly requires it and suitable terms are in place.
5A. Benchmarking, research and aggregated insights
For workspaces eligible under the applicable Terms or written agreement, we may derive a separate research dataset from completed service measurements for benchmarking, statistical analysis, product improvement, industry research, trend reports and aggregated marketing insights. The research surface is designed to exclude raw prompts, raw AI-provider responses, customer names, user names and emails, domains, billing identifiers and private competitor configurations.
Internal research records may use pseudonymous keys to prevent one customer's scan volume from dominating a cohort and to enforce disclosure controls. Pseudonymous records are treated as protected internal data and are not presented as anonymous merely because a direct identifier was removed.
Before an aggregate insight is approved for public use, we apply cohort-level controls including independent-customer and brand counts, observation volume and contribution concentration. Small or dominated cohorts are blocked from publication under the configured product policy. These operational thresholds are privacy safeguards, not representations that a particular threshold creates a legal safe harbour.
We do not publicly identify a customer or publish customer-specific performance, logos, named case studies, public leaderboard positions or public customer Wrapped content without separate permission. Enterprise or other written agreements may exclude a workspace from aggregated benchmarking.
6. Service providers and subprocessors
We may disclose data to service providers that support hosting, database infrastructure, authentication, payment processing, email delivery, analytics, security and AI-provider functionality. See the Subprocessors page for material integrations represented by the current product design.
7. Cookies and analytics
Essential storage is used for functions such as authentication, security and remembering privacy choices. Google Analytics and Microsoft Clarity are configured as optional analytics tools and load only after the user selects ‘Allow analytics’ in the cookie preference banner. More information is available in the Cookie Policy.
8. Overseas transfers
Because MonitorMyGEO uses global cloud, communications, payment and AI services, personal data may be processed outside Singapore. Where Singapore's Personal Data Protection Act applies to an overseas transfer, we take steps intended to provide a standard of protection comparable to the protection under the PDPA as required by the Transfer Limitation Obligation, including appropriate safeguards where applicable.
9. Retention
We retain personal data only for as long as reasonably needed for the purpose, security, dispute handling, legal or accounting requirements. The service maintains an operational retention registry and authenticated cleanup for data categories that can be automatically expired.
Genuinely aggregated or de-identified statistics that no longer identify a customer user or individual may be retained for longitudinal research and reporting. Where an internal research record remains linkable through a protected pseudonymous key, it continues to receive access and disclosure controls rather than being treated as irreversibly anonymous.
Live application deletion does not imply immediate surgical deletion from every immutable backup snapshot. Deleted data is not restored to ordinary active use and expires through the applicable backup rotation cycle.
10. Security
We use administrative, technical and organisational measures designed to protect personal data against unauthorised access, collection, use, disclosure, copying, modification or disposal. The Security page describes current public controls.
11. Access, correction and portability
Subject to applicable law and permitted exceptions, you may request access to personal data about you, correction of inaccurate or incomplete data, and portability where applicable. Authenticated users can download a structured core account export in Privacy & Data.
12. Erasure, account closure and restriction
Authenticated users may request account deletion after password verification and explicit confirmation. Shared workspace data is not deleted merely because one member leaves; shared workspace owners must transfer ownership first. Some information may be retained where required or permitted for legal, accounting, fraud-prevention, security, contractual or dispute purposes.
13. Privacy request operations
Privacy requests are tracked with request type, identity-verification state, status, target date and completion evidence. Authenticated users may use Privacy & Data. Other individuals may submit a request at /privacy-request or contact us by email.
14. Marketing choices
Service and transactional communications may be necessary to operate your account. Marketing communications, where used, should provide an available way to opt out. Acceptance of the Terms or acknowledgement of this Privacy Policy is not consent to optional cookie analytics and is not permission for named customer publicity.
15. Data incidents
We investigate personal-data incidents and, where applicable law requires it, will notify the relevant authority and affected individuals in accordance with applicable requirements.
16. Children
MonitorMyGEO is a business-oriented service and is not intended for children.
17. Changes to this Policy
We may update this Privacy Policy as the service or legal requirements change. The current version and effective date appear at the top of this page. Where an update materially changes account-data handling and re-acknowledgement is appropriate, the service may require users to acknowledge the current version before continuing.
18. Data-protection contact
For access, correction, withdrawal, deletion or other privacy enquiries, use the Privacy Request page or contact support@monitormygeo.com. Postal correspondence may be addressed to Bigdoor Ai Labs Pte. Ltd., 68 Circular Road, #02-01, Singapore, 049422.