Privacy notice

Last updated 25 August 2026

This explains what personal data ReportMagnet collects, why, and what you can do about it. It covers two different situations that are easy to confuse, so they are kept separate throughout.

Two roles, kept separate

We handle personal data in two distinct capacities, and your rights differ depending on which applies.

  • Your account. When you sign up, we decide what to collect and why. We are the controller for that data, and this notice governs it.
  • Leads captured by your widget. When a visitor to your website enters their name and email into your audit widget, that person is your contact, not ours. You decide why you collected it and what you do next. You are the controller; we only store and transmit it for you, which makes us your processor. Our obligations to you for that data are set out in the terms.

The practical consequence: if a lead asks to be deleted, they should ask you, and you can delete them from your dashboard. If they contact us directly we will tell them to contact you, and let you know.

What we collect about you

  • Account details — your name, email address and a hashed password. We never store your password in a readable form.
  • Your branding — company name, contact details, colours and any logo you upload.
  • Audits you run — the addresses you submit, the findings produced, and the reports and PDFs generated from them.
  • Billing details — your subscription status and a customer reference held by Stripe. Card numbers go directly to Stripe and never reach our servers.
  • Technical data — IP addresses, used to apply rate limits and prevent abuse of the audit service.

We do not use advertising trackers, we do not sell personal data, and we do not build profiles for marketing.

What your widget collects

The embeddable widget asks a visitor for their name and email before showing their audit report, and records the address they asked us to scan and the site the widget was embedded on. That information appears in your dashboard as a lead and is emailed to the contact address on your brand profile.

You are responsible for telling those visitors what you will do with their details, and for having a lawful basis to contact them. We provide the mechanism; the relationship is yours.

Why we are allowed to hold it

  • To perform our contract with you — running audits, producing reports, taking payment.
  • Legitimate interests — keeping the service secure and available, including rate limiting by IP address and preventing misuse.
  • Legal obligation — retaining billing records for the period tax law requires.

Who else processes it

We use the following providers. Each processes data only to deliver the service described and under contract with us.

ProviderPurposeLocation
ConvexApplication database, file storage and backend hostingUnited States
VercelWebsite and application hostingUnited States
StripeSubscription billing and payment processingUnited States
ResendTransactional email deliveryUnited States
Google (PageSpeed Insights API)Performance measurement of the pages you submit for auditUnited States

These providers are based in the United States, so data is transferred there. Where the UK or EU GDPR applies, those transfers rely on the providers' standard contractual clauses.

How long we keep it

  • Account and audit data — for as long as your account is open. If you close it, we delete it within 30 days, except where we must keep billing records.
  • Leads — until you delete them or close your account.
  • Rate-limiting records — hours to days, then deleted automatically.
  • Billing records — as long as tax law requires.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to how we use it, or receive a copy in a portable form. You can also complain to your data protection authority.

To exercise any of these, email sean@swansonx.com. We will respond within one month.

Security

Traffic is encrypted in transit. Passwords are hashed. Secrets are held server-side and never sent to the browser. Access to a customer's data is checked on every request against the account it belongs to.

No system is perfectly secure. If a breach affects your data and is likely to put you at risk, we will tell you and the relevant authority without undue delay.

Changes

If we change this notice in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.

Contact

SwansonX LLC, registered in Minnesota under file number 1663839400022, 202 N Cedar Ave STE #1, Owatonna, MN 55060, United States.

sean@swansonx.com