Who operates WebsiteIQ
Osborn Ventures Inc. operates websiteiq.xyz and the WebsiteIQ audit service. Submit access, correction, or deletion requests through the privacy contact form.
Notice at collection
| Category | Purpose | Retention | Sold/shared for cross-context behavioral advertising? |
|---|---|---|---|
| Submitted public website URL | Run and deliver the requested audit; prevent duplicate or abusive work. | Retained with the unlisted report for historical reference until deletion is requested. | No. |
| White-label agency identity, presenter name, phone, email, CTA/marketing inputs, and consent | Prepare the requested white-label quote and, after the paid request settles, present agency contact actions in the report. These fields are not collected for the free browser, API, or MCP audit. | Retained with the white-label quote or report until deletion is requested. Contact-form messages and ordinary email systems may retain correspondence under their operational settings. | No. |
| IP address, target website, and Cloudflare request metadata, which may include country, ASN, user agent, and security signals | Rate limiting, abuse prevention, troubleshooting, and traffic-origin analysis. Rate counters cross-reference pseudonymous requester-IP, target-website, and requester-target-pair fingerprints. | Audit-linked origin metadata is retained with the audit until deletion is requested. Cloudflare security logs follow the configured account retention. | No. |
| Generated audit evidence | Produce the requested report and aggregate counts. | The unlisted report is retained until deletion is requested; aggregate counts do not identify a free requester. | No. |
| Contact-form message | Route a human inquiry to the operator, prevent abuse, and preserve correspondence context. | Retained as operational correspondence until deletion is requested or it is no longer needed. | No. |
Sources and processing
Information comes from the person or software submitting the URL, Cloudflare’s request context, and publicly accessible responses from the submitted website. The crawler does not authenticate to the target, buy access, or intentionally collect private target data.
Processing is used to perform the requested service, protect the service and target sites, and maintain records. Free audit intake does not request contact consent because it does not collect requester identity or contact details. White-label identity and contact fields require affirmative processing consent.
Providers and transfers
Cloudflare provides DNS, edge delivery, Worker execution, security controls, and KV storage. Configured email delivery may process operator notifications. These providers may process information in countries other than yours under their own contractual and legal safeguards.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy, or withdraw consent. A valid report access token can delete that audit early. You may also contact us; we may need to verify the request.
Because WebsiteIQ does not sell or share personal information for cross-context behavioral advertising under its stated practice, it does not present a sale/share opt-out link. If this practice changes, this notice and controls must change before collection.
Children and sensitive information
WebsiteIQ is a business and developer service, not directed to children. Do not submit sensitive personal information, credentials, private network targets, or content you are not authorized to process.
Security and limits
Reports use high-entropy identifiers and access tokens plus no-store/noindex responses. They are unlisted, not secret once shared: anyone with the complete link can view the report. No online service can promise absolute security. If a report token is exposed, delete the audit or request deletion through the contact form.
Regulatory references
This notice is a product baseline, not a guarantee that one page alone satisfies every law worldwide. The implementation follows data minimization and transparent collection principles reflected in EU Regulation 2016/679 (GDPR) and notice-at-collection guidance from the California Privacy Protection Agency. Local requirements and counsel may require additional terms, representatives, or processes.