Cookie notice
What we store on your device on this website, and what you can do about it. Last updated: 8. September 2026.
The short version
Our English landing page and the signup flow that follows it carry advertising measurement from Meta (Facebook) and page-view counting through Vercel Web Analytics. Both only run if you say yes, neither is needed to use anything on this site, and you can take your answer back at any time — including right here, in section 8. Everywhere else on makeseo.co — the blog, the docs, the free SEO check, the app, and the blogs we host on our customers’ own domains — we run no advertising cookies and no analytics at all.
1. Who is responsible
Keplerstr. 7/1
71686 Remseck am Neckar
Deutschland
Email: contact@makeseo.co
We have not appointed a data protection officer; the conditions of § 38 BDSG do not apply. Write to the address above for anything concerning your data.
2. The rule we are working from
Two separate laws apply, and they apply one after the other. § 25(1) TDDDG (the German implementation of the ePrivacy Directive) governs storing anything on your device: without your consent we may only store what is strictly necessary for a service you asked for. Art. 6(1)(a) GDPR then governs what we do with the data afterwards.
Advertising measurement is not strictly necessary for anything. So it waits for your consent — the Meta script is not merely idle before you accept, it is not loaded onto the page at all.
3. Cookies we set without asking
These carry no advertising data. They exist so that the consent banner itself can work, which is why § 25(2)(2) TDDDG covers them.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| ms_consent | Your answer to this banner, so we do not ask again on every page. | 6 months | makeseo |
| ms_geo | Your country code, which decides whether we have to ask you at all. | 1 day | makeseo |
Being logged in to the app additionally requires a session cookie, and arriving through a referral link stores the referral code until you register. Both are the function you asked for.
4. Cookies we set only after you accept
If you accept, we load the Meta Pixeland start sending the same events a second time from our own server through Meta’s Conversions API. Both carry the same event ID so that Meta counts one event, not two.
| Name | Purpose | Duration | Set by |
|---|---|---|---|
| _fbc | Stores the click identifier of the ad you came from (fbclid). | 3 months | Meta |
| _fbp | A random browser identifier Meta uses to recognise this device. | 3 months | Meta |
| ms_click | The campaign parameters of your first visit (utm_*, ad and campaign IDs). | 3 months | makeseo |
You also switch on Vercel Web Analytics, which counts page views on the landing page and through the signup flow so we can see where people stop. Vercel Web Analytics appears in neither table because it stores nothing on your device — no cookie, no local storage. Vercel tells apart repeat visits with a hash it computes on its own servers from the incoming request, and discards it after 24 hours.
5. What is sent to Meta and to Vercel, and what is not
Two recipients, and they get different things. Meta Platforms Ireland Ltd., Dublin, Ireland, and its parent Meta Platforms, Inc. in the USA: we send the same events from your browser (Meta Pixel) and from our server (Conversions API) — the event name, a random event ID, the page address, your IP address, your browser identification, and, once you have an account, your email address as an irreversible SHA-256 hash. When you buy a subscription, the billing details you typed into the payment form travel the same way — your name, your phone number if you gave one, and your city, region, postcode and country — each one hashed separately, never in the clear, and only from our server, never read off the page. Meta uses them to tell whether the purchase belongs to someone who saw the ad; it is the difference between paying for ads that work and guessing. We never send your email address or any of these in the clear, and we never send your payment details in any form. On top of those events, Meta’s pixel reads what the page you are on shows publicly — its title and description, and, where a page displays them, prices and ratings — and sends that along; Meta uses it to describe the page an event happened on. That is the whole of it, and the line it does not cross is this one: the pixel reads what the page shows to everyone, never what you type. Meta’s automatic collection of your own input is switched off (autoConfig = false), so the pixel does not read your form fields and does not report which buttons you click. Vercel Inc., USA, our hosting provider, for Vercel Web Analytics: the page address and route, the referrer, filtered query parameters, your country, region and city, your device type, operating system and browser. Vercel states that it uses no cookies for this and identifies visitors by a hash computed from the incoming request, which is discarded after 24 hours; it receives no email address, no account data and nothing you type.
- Purpose
- Measuring which ad or campaign led to a visit, a signup and a subscription, so we can stop paying for ads that do not work, and counting how many people reach each page and where they stop. This is measurement — none of it is needed to run the site.
- Legal basis
- Your consent — § 25(1) TDDDG for storing on your device, Art. 6(1)(a) GDPR for the processing that follows. Vercel Web Analytics stores nothing on your device, so nothing is stored there for it to cover; we ask you about it under Art. 6(1)(a) GDPR anyway, rather than run it on a legitimate-interest argument you were never told about.
- Storage
- The cookies live on your device for the durations listed above. What Meta does with the events afterwards is governed by Meta's own retention rules — see their privacy policy.
- Joint controllership
- For the measurement of these events, Meta Platforms Ireland Ltd. and we are joint controllers under Art. 26 GDPR. Meta provides an addendum for exactly this. You may exercise your rights against either of us.
- Vercel's role
- Vercel is different: it hosts this website for us and processes the analytics data on our instructions under a data processing agreement (Art. 28 GDPR), not as a controller of its own. It receives no email address, no account data and nothing you type into the app.
What we never send: your email address in the clear, your payment details in any form, the content of anything you write in the app, or any data from a website you connect to makeseo.
What we do send when you buy: the billing details you typed into the payment form — your name, your phone number if you gave one, and your city, region, postcode and country. Each one is hashed separately with SHA-256 before it leaves our server, exactly like your email address, and none of it is ever read off the page you are looking at. Meta uses these to work out whether a purchase belongs to somebody who saw one of our ads. Card numbers and bank details are not part of this and never leave Stripe.
Our own measurement endpoint deliberately accepts only three low-value events from a browser (page view, content view, lead). Everything with a monetary value — registration, trial, subscription — is raised by our own server, never by anything a visitor could call.
The pixel reads the page, not your typing. Meta’s “automatically add more page and product information” setting is on: the pixel also collects the publicly visible content of the page you are on — its title and description, and, where a page shows them, prices and ratings — and sends it with the event, so Meta can describe the page an event happened on. It is the same information every other visitor to that page can see, and it says nothing about you.
Meta’s automatic collection of your input is switched off. The pixel is initialised with autoConfig = false. Left at Meta’s default it would additionally read the form fields on the page (automatic advanced matching) and report which buttons you click. It does neither — and that is where the line runs: it reads what the page shows to everyone, never what you type or click. We would rather send Meta less and be able to tell you exactly what we send.
6. Our record that we asked you
We keep a record that this question was answered, so we can show a supervisory authority that we asked and honoured your answer (Art. 7(1) GDPR). It holds a random ID — also stored in the ms_consent cookie — your answer, the time, this notice’s version and a fingerprint of the exact wording you are reading, your two-letter country code and the page path. It holds no IP address, no browser identification and no name. We keep it for three years. This record exists because the law requires the proof, not because you consented — so withdrawing does not erase it.
- Legal basis
- Art. 6(1)(c) GDPR together with Art. 7(1) GDPR — a legal obligation, not your consent. If this record ran on consent, withdrawing would destroy the proof that you withdrew.
- What it holds
- A random decision ID, your answer, the time, the version of this notice, a SHA-256 fingerprint of its exact wording, your two-letter country code and the page path.
- What it does not hold
- No IP address, no browser identification, no name, no email address, and no query string — the ad parameters in the URL never reach it.
- Retention
- Three years from the decision, then deleted.
A “no” is recorded exactly like a “yes”. A log that only contains the people who agreed does not show that anybody was asked.
7. Transfer to the USA
Your data is transferred to the USA — to Meta and to Vercel. Both are certified under the EU–US Data Privacy Framework, but US authorities can still gain access under certain conditions and you may not have the same legal remedies as inside the EU. By accepting, you also consent to this transfer (Art. 49(1)(a) GDPR).
The European Commission decided on 10 July 2023 that companies certified under the EU–US Data Privacy Framework offer an adequate level of protection. An action against that decision is pending before the Court of Justice of the European Union (Case C-703/25 P). We name this openly rather than presenting the transfer as risk-free.
8. Withdrawing, and your other rights
You can withdraw at any time with effect for the future — it takes exactly one click, the same as giving it. Use “Privacy choices” in the footer of the landing page, or the buttons in section 8 of the cookie notice. On withdrawal we delete the Meta cookies from your device immediately, switch the pixel off in the page you are on, and stop counting page views. Withdrawing does not make what happened before it unlawful.
Withdrawal takes effect immediately and for the future. It does not affect the lawfulness of processing that happened while your consent was in place. If you would also like Meta to delete what it already holds, use the controls in your Facebook or Instagram account settings — we cannot delete data inside Meta’s systems on your behalf.
Clearing cookies in your browser has the same effect on this site as declining: you will simply be asked again.
You also have the rights to access, rectification, erasure, restriction, data portability and objection under Art. 15–21 GDPR, and the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
9. Everything else
This notice covers the website only. Our full privacy policy — accounts, generated content, AI providers, connected CMS credentials, payments, email, retention periods — is the authoritative document and is written in German, the language of our establishment:
Datenschutzerklärung (German, full privacy policy) · Imprint
Where the two texts describe the same processing, they are kept in sync from the same source. If you spot a discrepancy, write to us — that is a defect, not a nuance.