Privacy Policy
Privacy Policy
Last updated: July 2, 2026
This Privacy Policy explains how BotRefund and Seatext LLC (collectively, “BotRefund,” “Seatext,” “we,” “us,” or “our”), including our website personalization, translation, A/B testing, analytics, bot detection, invalid-click reporting, and related ad spend recovery services, collect, use, store, and protect personal information.
In this Privacy Policy, “Seatext,” “BotRefund,” “we,” “us,” or “our” means Seatext LLC, the operator of BotRefund.com and Seatext.com. “Website” means BotRefund.com, Seatext.com, and any related websites we operate. “Services” means BotRefund and Seatext products, scripts, APIs, dashboards, reports, integrations, and related services.
This Privacy Policy applies to visitors to BotRefund.com and Seatext.com, customers and prospective customers of BotRefund and Seatext, users of our dashboards or APIs, people who communicate with us or request a demo, and end users who visit websites where our customers have installed BotRefund or Seatext.
By using our Website or Services, you acknowledge that you have read this Privacy Policy and understand how we process personal information.
Information We Collect
We collect information in several ways. Like most websites, we automatically collect technical and usage information when you visit Seatext.com. This may include your IP address, device type, browser type, operating system, approximate location based on IP address, referring website or campaign source, pages viewed, content interacted with, the date and time of your visit, and session and usage information. We may use cookies, pixels, local storage, server logs, and similar technologies to collect this information.
When you create an account, request a demo, contact us, subscribe to updates, communicate with sales or support, or use our Services, we may collect your name, email address, company name, website domain, role or job title, billing information, account login information, communication history, support requests, product preferences, subscription information, and usage information.
When our customers install Seatext on their websites, we may process information about their visitors. Depending on the customer’s configuration, this may include page URL, referrer, advertising keyword or campaign information, UTM parameters, browser and device information, approximate location, language preference, session behavior, pages viewed, clicks, scrolls, other interaction events, conversion events, A/B test exposure, personalization or translation variants shown, bot-detection signals, fraud and invalid-click indicators, and customer-provided identifiers where enabled.
Bot Detection, Fraud Forensics, and Recording of Bot Information
BotRefund and Seatext provide bot detection, invalid-click analysis, real-time pixel suppression, and ad spend recovery. In delivering these services, BotRefund records and processes technical, network, and behavioral information from website visitors, specifically including:
- IP Addresses & Network Identifiers: We record and retain IP addresses—especially of identified or suspected bots, proxy exit nodes, VPN servers, automated click farms, and scraper networks—along with ASN, ISP, connection type, and approximate geolocation data. Recording IP addresses is strictly necessary to log invalid traffic, formulate formal refund claims with advertising platforms (such as Google Ads and Meta Ads), enforce pixel suppression, and recognize recurring bot networks across future sessions.
- Browser & Device Fingerprints: Canvas rendering hashes, WebGL GPU profiles, audio context entropy, screen parameters, installed fonts, user-agent details, and WebRTC candidate leaks to expose automated emulators, headless browsers, and spoofed device environments.
- Session Behavioral Telemetry: Mouse movements, cursor trajectory linearity, tremor entropy, touch patterns, scroll speeds, keystroke timing, and event velocity to distinguish natural human interactions from automated headless scripts.
- Campaign & Conversion Markers: Click identifiers (including GCLID, FBCLID, MSCLKID), referring URLs, UTM parameters, and conversion pixel trigger states required to assemble forensic audit dossiers for ad credit recovery.
Purpose and Future Recognition: This information is recorded and retained to help customers identify suspicious traffic, suppress conversion pixels in real time to prevent ad algorithm poisoning, generate audit reports and dispute dossiers for ad platform refund claims, continually train and improve bot-detection heuristics, and recognize returning bots, emulators, and automated syndicates across future sessions.
Customer Privacy Policy Disclosure Obligations (Data Processor Status)
When you deploy BotRefund or Seatext on your website or web properties, you act as the Data Controller (or "Business" under the CCPA/CPRA), and Seatext LLC / BotRefund acts as a third-party Data Processor (or "Service Provider") processing visitor data solely on your behalf and in accordance with your instructions.
Mandatory Customer Disclosure: As a client utilizing our Services, you must maintain and prominently publish a privacy policy on your website that discloses to your end users and visitors that:
- You use third-party service providers and data processors—specifically Seatext LLC and BotRefund—to assist with website security, ad fraud detection, bot mitigation, and traffic verification.
- These third-party processors may collect, record, and process technical and behavioral information about visitors, including IP addresses, browser and device fingerprints, hardware configurations, referral URLs, and mouse/touch/scroll interaction patterns.
- Such data is collected and recorded specifically where needed for security and fraud forensics, detecting and preventing bot traffic, validating legitimate ad clicks, establishing dispute evidence with advertising networks, and recognizing fraudulent bots and automated agents across future sessions.
You are solely responsible for providing all required legal notices, disclosures, and obtaining any necessary visitor consents (such as for client-side telemetry, cookies, or device fingerprinting under the EU ePrivacy Directive, GDPR, CCPA, or other applicable privacy laws) before activating BotRefund or Seatext scripts on your properties.
Information From Integrations and Third Parties
If a customer connects Seatext to third-party tools such as CRM systems, analytics tools, advertising platforms, data-enrichment services, or marketing automation tools, we may receive information from those integrations according to the customer’s configuration. This may include company information, lead information, campaign information, customer segment information, or other data the customer chooses to make available to Seatext. We may also collect limited business contact information from third-party sources and publicly available platforms to identify potential customers, improve our business contact database, support sales and marketing efforts, and understand companies that may benefit from Seatext.
Direct Customer Identity vs. Forensic Telemetry
No Names, Emails, or Direct Identity Required: BotRefund does not require, collect, or store direct customer identity—such as visitor names, personal email addresses, phone numbers, postal addresses, or payment card numbers—to perform bot detection. Our forensic detection operates purely on technical network telemetry, device characteristics, and interaction physics.
Enterprise Legal Classification: We recognize that enterprise legal teams and global data protection authorities (including under the GDPR and CCPA) classify IP addresses, browser fingerprints, and unique behavioral telemetry as personal data or pseudonymous identifiers. We treat all such data accordingly with enterprise-grade security and confidentiality, processing it strictly under the legal grounds of legitimate interest (fraud prevention and security forensics) and contractual necessity on behalf of our clients.
Sensitive Information Excluded: Seatext and BotRefund do not intentionally collect sensitive personal information such as genetic data, biometric identifiers for individual authentication, health data, religious information, government IDs, or information from children under 18. Customers must not configure our tools to capture sensitive personal inputs.
How We Use Personal Information
We use personal information to create and manage accounts, authenticate users, provide access to the Seatext dashboard and API, deliver website personalization, translation, A/B testing, and traffic-routing functionality, detect bots and invalid traffic, generate analytics and reports, process payments and subscriptions, provide technical support, send service-related communications, and maintain the security and reliability of the Services.
We also use personal information to improve and develop our products, debug and improve product performance, understand how customers use Seatext, improve personalization, translation, testing, and bot-detection features, develop new features, improve internal systems, and measure product quality and reliability. Where possible, we use aggregated or de-identified data for product improvement.
We may use customer data, visitor interaction data, website text, translation data, experiment data, bot-detection data, and related usage information to develop, test, evaluate, and improve our products, internal systems, algorithms, analytics, and machine-learning models. We do not sell customer content to third parties for model training, and we do not permit third parties to use customer content to train their own models unless the customer has expressly authorized that use.
Legal Bases for Processing
Where applicable law requires a legal basis for processing personal information (such as under the GDPR or UK GDPR), we rely on:
- Legitimate Interests: Processing network telemetry, IP addresses, and device fingerprints is strictly necessary for the legitimate interests of our clients and BotRefund in preventing ad fraud, securing web infrastructure, detecting automated attacks, and establishing factual dispute records with advertising networks (expressly recognized under GDPR Recital 47 as a legitimate interest).
- Contract Performance & Processor Instructions: When processing visitor data on behalf of our business clients, we act as a data processor performing services under our client agreements and Data Processing Agreements.
- Legal Obligations: Complying with applicable accounting, tax, regulatory, or court-mandated legal obligations.
- Consent: Where required by local law (such as the ePrivacy Directive for certain cookies or client-side storage), our clients are responsible for obtaining end-user consent on their respective websites.
How We Share Information
We may share personal information with trusted third parties only as described in this Privacy Policy, as needed to provide the Services, or with your consent. These service providers may include cloud hosting, databases, payment processing, customer support, analytics, email delivery, CRM and sales operations, security and monitoring, internal communications, product infrastructure, and data-enrichment tools. These service providers may process personal information on our behalf only as necessary to provide their services to us and must protect the information according to contractual obligations.
When Seatext is installed on a customer website, the customer may configure Seatext to send data to advertising platforms, analytics tools, CRM systems, or other third-party services. In those cases, the customer controls the configuration and is responsible for ensuring appropriate notice, consent, and legal basis.
We may disclose personal information to government authorities, courts, law enforcement, regulators, or other third parties if we believe disclosure is necessary to comply with law, respond to a subpoena, court order, or legal process, protect our rights or property, protect the safety of users or the public, investigate fraud, abuse, or unlawful activity, defend against legal claims, or comply with regulatory obligations. If Seatext is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, personal information may be transferred as part of that transaction, subject to appropriate protections. We may also share aggregated or de-identified information that cannot reasonably identify an individual or customer, including for analytics, benchmarking, product development, research, marketing, or reporting.
We may use the name and logo of companies using Seatext for promotional purposes unless otherwise agreed in writing. Customers who want to opt out can contact us at [email protected].
International Data Transfers
Seatext may process and store personal information in the United States and other countries where we, our service providers, or our infrastructure providers operate. If personal information is transferred from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with data-transfer restrictions to a country that has not been recognized as providing adequate protection, we will use appropriate safeguards where required by law, such as Standard Contractual Clauses or other approved transfer mechanisms.
Cookies, Tracking, and Do Not Track
Seatext and our customers may use cookies, local storage, pixels, server logs, JavaScript tags, and similar technologies. We use these technologies to remember preferences, keep users logged in, understand website usage, measure campaign performance, run A/B tests, deliver personalization and translation, detect bots and invalid traffic, improve security, and analyze product performance. You can control cookies through your browser settings. If you disable cookies or similar technologies, some features of the Website or Services may not work properly.
Seatext may use third-party service providers for analytics, infrastructure, advertising, or product operations. Where required by law, we or our customers will request consent before using cookies or similar technologies that require consent. Because there is no uniform industry standard for responding to Do Not Track signals, Seatext does not currently respond differently to such signals unless required by law. Where required by applicable law, we will honor recognized opt-out preference signals.
Data Retention
We retain personal information for as long as necessary to provide the Services, manage accounts, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, and protect our rights. Account information is generally retained while the account is active. Billing and transaction records may be retained as required by tax and accounting laws. Support and communication records may be retained to provide customer service and maintain business records. Security and fraud-prevention logs may be retained as needed to protect the Services. Customer data processed through the product may be retained according to the customer’s account settings, contract, or instructions. We may delete, anonymize, or aggregate information when it is no longer needed.
Data Security
We take reasonable technical and organizational measures to protect personal information from unauthorized access, use, alteration, disclosure, or destruction. These measures may include access controls, encryption in transit, infrastructure monitoring, logging and auditing, secure development practices, limited employee access, vendor security review, and backups and recovery procedures. No system is perfectly secure. We cannot guarantee absolute security, but we work to protect personal information using reasonable safeguards appropriate to the nature of the data.
Your Privacy Rights
Depending on where you live, you may have rights regarding your personal information, including the right to access personal information we hold about you, correct inaccurate or incomplete information, delete personal information, restrict or object to processing, withdraw consent, opt out of marketing communications, opt out of certain sharing or targeted advertising, request data portability, and complain to a data protection authority. These rights may be limited in some cases, for example if we need to retain certain information to comply with law, protect security, prevent fraud, complete transactions, or maintain business records. To exercise your rights, contact us at [email protected]. If your request relates to data processed by Seatext on behalf of one of our customers, we may refer your request to that customer or ask you to contact the customer directly.
California Privacy Notice
This section applies to California residents. For personal information processed on behalf of our customers, Seatext acts as a service provider or contractor under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We process that information only to provide the Services to our customers, as permitted by our agreements and applicable law. Seatext does not sell customer personal information in the traditional sense of selling personal information for money. Depending on how Seatext or our customers use advertising, analytics, or marketing integrations, some data sharing may be considered sharing or targeted advertising under certain privacy laws. Where required, we or our customers will provide applicable opt-out rights. California residents may have the right to know what personal information is collected, access personal information, request deletion, correct inaccurate information, opt out of sale or sharing, limit use of sensitive personal information where applicable, and not be discriminated against for exercising privacy rights. To exercise these rights, contact us at [email protected].
Data Processing Agreement (DPA)
For all business customers deploying BotRefund or Seatext, we offer a comprehensive Data Processing Agreement (DPA) that governs our role as a Data Processor, details technical and organizational security measures, outlines sub-processor commitments, and incorporates Standard Contractual Clauses (SCCs) for international transfers. Business customers can request and execute a DPA by contacting us at [email protected].
Job Applications
If you apply for a job with Seatext, we may collect your name, email address, phone number, location, resume or CV, employment history, education, skills, portfolio or public professional profiles, interview notes, application status, and communications with us. We use applicant information to manage recruiting, evaluate candidates, communicate with applicants, comply with legal obligations, and consider candidates for future opportunities. We do not use applicant personal information for marketing. Applicant information may be processed by recruiting tools, communication tools, and other service providers we use. We retain applicant information for as long as reasonably necessary for recruiting, legal, and business purposes, unless a shorter or longer period is required by law. Applicants may contact us at [email protected] to request access, correction, or deletion of applicant information.
Communications and Policy Changes
If you provide your email address, we may send you service messages, product updates, security notices, support communications, billing messages, and marketing communications. You can unsubscribe from marketing emails at any time, though you may still receive transactional or service-related messages where necessary. We may update this Privacy Policy from time to time. If we make material changes, we may notify customers by email, through the Services, or by posting a notice on our Website. Your continued use of the Website or Services after an updated Privacy Policy becomes effective means you acknowledge the updated Privacy Policy.
Contact Information
The data controller for personal information processed through Seatext.com is:
Seatext LLC
San Ysidro — 511 E. San Ysidro Blvd #713, San Ysidro, CA 92173