Skip to content

Privacy Policy

Last updated: 24 July 2026

This policy explains how GRL Index, based in the United Kingdom, collects, uses and protects personal information when you use this website and our services. We process personal data in accordance with UK data protection law, including UK GDPR.

Who we are

GRL Index is a UK-based AI visibility service founded and operated by George Riley. For anything relating to this policy or your personal data, contact contact@grlindex.com.

Information we collect

We collect information you provide directly:

  • Free audit requests — business name, website URL and business email address.
  • Contact form enquiries — your name, business name, website, email, industry, enquiry type, your message and preferred follow-up method.
  • Account information — your name, business name, website, email address and a password (stored only as a secure hash by our authentication provider).
  • Service orders — the business details, industry and project information you submit when ordering Professional AI Optimisation.

We also collect limited technical information automatically, produced by our hosting and security providers as part of delivering the website securely:

  • IP address and approximate location, used to keep the service secure and prevent abuse.
  • Browser type, device type and operating system, taken from the request your browser sends.
  • Server access logs — pages requested, with dates and times — retained for security and troubleshooting.

We do not use analytics or advertising trackers on this website, and we do not build marketing profiles from this technical information.

How we use your information

  • To prepare and deliver the free audit you request.
  • To respond to enquiries and provide the follow-up you asked for.
  • To operate your account and show you your orders and their status.
  • To deliver the paid services you purchase and communicate about that work.
  • To meet legal obligations, such as accounting records for payments.

We do not sell personal data, and we do not send marketing email without your consent.

Legal bases

We rely on contract performance (delivering services you request), legitimate interests (responding to business enquiries and running this website securely) and legal obligation (financial records). Where we ask for consent — for example the contact form consent box — you can withdraw it at any time.

Payment processing

Card payments are processed by Stripe. Your card details are entered on Stripe's secure checkout and are never received or stored by us. We receive confirmation of payment and basic order details only. Stripe processes your data under its own privacy policy.

Third-party processors

We use a small number of service providers to run this website, each processing data only as needed to provide their service:

  • Vercel — website hosting.
  • Supabase — account authentication and secure storage of accounts, orders and enquiries.
  • Stripe — payment processing.
  • Resend — transactional email delivery (for example enquiry notifications).

International data transfers

Some of our providers are based outside the United Kingdom, or may process data on servers outside the UK. Where personal data is transferred internationally, we rely on the safeguards those providers put in place — such as UK "adequacy" decisions, the UK International Data Transfer Agreement or Addendum, or Standard Contractual Clauses — so your data continues to receive an equivalent level of protection. You can ask us for more detail about the safeguards that apply.

How we keep your data secure

Access to accounts, orders and enquiry data is restricted to GRL Indexand the processors listed above, each acting under our instructions. Passwords are never stored in plain text — they are held only as a secure hash by our authentication provider — and card details are handled entirely by Stripe and never reach our systems. We keep the number of people and services that can access personal data to the minimum needed to run the service, and we review our providers' security practices when we choose them. No online service can be guaranteed completely secure, but we take reasonable steps to protect the information you share with us.

Data storage and retention

We keep personal data only as long as needed for the purposes above: enquiry and audit data while we correspond with you and for a reasonable period afterwards; account and order data for as long as your account exists; and payment records for the periods required by UK tax law. You can ask us to delete your account and associated data at any time.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data deleted where there is no lawful reason to keep it.
  • Object to or restrict certain processing.
  • Data portability for information you provided to us.
  • Complain to the Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, email contact@grlindex.com.

Cookies

This website uses only essential cookies, which are required for signing in to your account. We do not use analytics or advertising cookies. See the Cookie Policy for details.

Children's privacy

GRL Index provides services to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

If we change this policy, we will update it here and revise the "Last updated" date above. Significant changes affecting account holders will be communicated by email.

This document is provided for transparency and does not constitute legal advice. Questions about this policy? Contact contact@grlindex.com.