Privacy Policy
Son güncelleme: 2 Eylül 2026
TürkçeEffective date: September 1, 2026
This Privacy Policy explains how [Company legal name] ("we", "no404") collects, uses and protects personal data when you use https://no404.tr. We act as the data controller for account data, and as a data processor for the visitor telemetry we handle on your behalf.
1. Data we collect
1.1 Account data
Your name, email address and a hashed password (we never store passwords in plain text). If you sign in with Google, we also store your Google account identifier and the OAuth tokens needed to call the Search Console API on your behalf.
1.2 Google Search Console data
With your explicit consent we request the read-only scope webmasters.readonly. We use it solely to (a) list the properties you have verified so you can pick one, and (b) list the sitemaps you have submitted for that property. We do not modify anything in your Search Console account and we do not read your search performance data.
1.3 Website catalog
URLs, paths and page titles imported from the sitemap you select. This is business data about your website, not personal data about individuals.
1.4 404 event telemetry
When a visitor reaches a 404 page on your website, our endpoint records the requested path, the referring URL, the user agent string, a derived device/browser/bot classification, an approximate country, and the matching result. Regarding IP addresses:
- we never store the raw IP address;
- we store a salted, irreversible SHA-256 hash of it for unique-visitor counting;
- we store a masked form with the final segment removed (e.g.
85.34.78.x) for network context in your dashboard.
1.5 Billing data
Payments are processed by Stripe. We receive only a customer identifier, subscription identifier, plan and billing period. We never receive or store your full card number.
1.6 Cookies
We set a strictly necessary, HttpOnly session cookie to keep you signed in. If the site operator has configured Google Analytics, an analytics cookie may also be set on the public marketing pages; the signed-in dashboard and admin areas are excluded from analytics entirely.
2. How we use data
- to create and secure your account and authenticate you;
- to verify website ownership through Google Search Console;
- to import your catalog and compute redirect suggestions;
- to enforce plan limits, quotas and rate limits and to prevent abuse;
- to bill you and to provide support;
- to comply with legal obligations.
We do not sell personal data, and we do not use your data to train machine-learning models.
3. Legal bases (GDPR)
- Contract — providing the service you subscribed to.
- Consent — connecting your Google account and the Search Console scope; you may withdraw it at any time by disconnecting Google in your account settings or revoking access in your Google account.
- Legitimate interests — security, abuse prevention and service improvement.
- Legal obligation — tax, accounting and lawful requests.
4. Sharing and sub-processors
We share data only with providers that help us run the service:
- Stripe — payment processing and subscription billing;
- Google LLC — sign-in and the Search Console API;
- our hosting and database provider — infrastructure on which the service runs.
We may also disclose data where required by law or to protect our rights. We do not otherwise share, rent or sell personal data.
5. International transfers
Data may be processed in the United States and other countries. Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
6. Retention
404 event records are retained for the retention window of your plan and are then deleted automatically by a scheduled cleanup job. Account and billing records are kept while your account is active and afterwards only as long as required for legal, tax and accounting purposes. When you delete your account, your websites, catalog entries and event records are deleted with it.
7. Security
We use encrypted connections (TLS), hashed passwords (bcrypt), HttpOnly session cookies, per-website API keys with origin locking, and rate limiting. No system is perfectly secure, but we work to protect your data and will notify you of a personal data breach where legally required.
8. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. Residents of California may request disclosure of the categories of personal information collected and may opt out of "sale" or "sharing" — we do neither. Residents of Türkiye have equivalent rights under KVKK (Law No. 6698).
To exercise any right, contact [support email address]. We respond within 30 days. You may also lodge a complaint with your local supervisory authority.
9. Children
The service is not directed to children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us data, contact [support email address] and we will delete it.
10. Changes
We may update this policy. Material changes will be announced by email or in-product notice before they take effect, and the effective date above will be updated.
11. Contact
[Company legal name] — [entity type]
United States
Privacy requests: [support email address]
General support: [support email address]