HomeFeaturesPricingContact us Admin

CrawlSnap

HomeFeaturesPricingContact us
Sign Up

Privacy Policy

Effective date: 7 June 2026Last updated: 7 June 2026

This Privacy Policy explains how CrawlSnap Limited ("CrawlSnap", "we", "our", or "us") collects, uses, shares, and protects personal data when you use the CrawlSnap platform, websites, dashboards, marketplace, APIs, and related services (together, the "Services"), available at crawlsnap.com.

This Policy should be read together with our Terms of Service and Refund Policy. By using the Services, you acknowledge the practices described here.


1. Who is responsible for your data (Controller)

For the personal data described in this Policy, the data controller is:

  • CrawlSnap Limited, a company registered in England and Wales under company number 16099636
  • Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
  • Privacy contact: [email protected]
  • General support: [email protected]

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and, where it applies to our processing, the EU GDPR. Because CrawlSnap serves customers globally, we apply these standards as a baseline worldwide.

Note on payments. When you buy a paid plan, your purchase is processed by Polar as our reseller and Merchant of Record. Polar acts as an independent data controller for payment data, not as our processor. See Section 9.


2. The data we collect

We collect the following categories of personal data.

2.1 Information you give us

  • Account data: first name, last name, email address, and a hashed password. If you sign up using Google or GitHub, we receive your basic profile and email from that provider instead of a password.
  • Profile data: optional phone number and country.
  • Communications: the content of messages you send us (for example support requests).
  • Agreement records: the fact and time that you accepted our Terms of Service and this Policy.

2.2 Information generated through your use of the Services

  • API query data: the parameters you submit to our APIs — for example a URL, file hash, IP address, or domain you ask us to analyse. These are recorded in our request logs together with the endpoint called, HTTP method, response code, processing duration, cache status, your client IP address, and timestamp.
  • Usage and metering data: API keys (in identifiable form), credits consumed, request counts, rate-limit and quota usage, subscription and plan details.
  • Security and audit data: sign-in events and activity logs, including IP address, user agent, device/browser information, last-login IP, and login count. We keep these to secure accounts and detect abuse.

2.3 Information collected automatically

  • Cookies and similar technologies: strictly necessary authentication cookies and, where applicable, bot-protection technologies (see Section 10).
  • Technical data: IP address, browser type, and device information derived from your interactions with the Services.

2.4 Data we derive from public sources

A core function of the Services is to analyse publicly available information from the internet and apply our own processing to produce derived intelligence (such as reputation signals and indicators). This analysis may, incidentally, include personal data that is already publicly available (for example data associated with a domain or IP address). We process such data to provide the Services as described in Sections 3 and 4.

2.5 What we do not collect

We do not collect or store your full payment card number, card security code, or bank details. Those are handled by Polar and its PCI-DSS-compliant payment processor (Section 9). We do not knowingly collect data from children (Section 11).


3. Why we use your data and our lawful bases

Under the UK GDPR we must have a lawful basis for each processing purpose. The table below sets these out.

PurposeExamplesLawful basis
Provide the ServicesCreate and manage your account, authenticate you, issue API keys, run your API queries, return Output, meter usagePerformance of a contract
Billing and subscriptionsManage plans, renewals, quotas; coordinate with PolarPerformance of a contract; legitimate interests
Security, fraud prevention, and abuse detectionAudit logs, rate limiting, detecting credential sharing, quota circumvention, and Acceptable-Use violationsLegitimate interests (keeping the Services and users safe); legal obligation
Derived intelligence from public dataAnalysing publicly available information to produce insights and indicators that power the ServicesLegitimate interests (providing a data-intelligence service), balanced against the rights of data subjects
Service communicationsEmail verification, password resets, security and transactional notices, important service updatesPerformance of a contract; legitimate interests
SupportResponding to your enquiriesLegitimate interests; performance of a contract
Improve and develop the ServicesAggregated/de-identified analytics, troubleshooting, capacity planningLegitimate interests
Marketing (if any)Optional product news or offersConsent (you may opt out at any time)
Legal and complianceResponding to lawful requests, enforcing our Terms, establishing or defending legal claimsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms. You can object to such processing (see Section 7). Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.


4. Your responsibilities for query data

When you submit parameters to our APIs (such as URLs, hashes, IPs, or domains), you are responsible for ensuring you have a lawful basis to do so and that your queries comply with applicable law and our Terms of Service. You must not submit special-category personal data or any data you are not authorised to process. In relation to data you submit and the queries you run, you act as a controller in your own right.


5. How we share your data

We do not sell your personal data. We share it only as described below.

  • Service providers (processors) who process data on our behalf under contract and on our instructions — for example email delivery, hosting, and bot protection (see Section 9).
  • Polar, our reseller and Merchant of Record, which acts as an independent controller for payments (Section 9).
  • Authentication providers (Google, GitHub) when you choose to sign in with them.
  • Legal and safety disclosures where we reasonably believe disclosure is necessary to comply with a legal obligation, enforce our Terms, prevent fraud or abuse, or protect the rights, property, or safety of CrawlSnap, our users, or others.
  • Business transfers — if we are involved in a merger, acquisition, financing, or sale of assets, your data may be transferred as part of that transaction, subject to this Policy.

6. International data transfers

CrawlSnap operates globally, and some of our service providers are located outside the United Kingdom and the European Economic Area (for example in the United States). Where we transfer personal data internationally, we put in place appropriate safeguards required by UK and EU data-protection law, such as the UK International Data Transfer Agreement (IDTA) / UK Addendum and the European Commission's Standard Contractual Clauses (SCCs), together with any additional measures needed to protect your data. You can ask us for more information about these safeguards using the contact details in Section 13.


7. Your rights

Subject to applicable law, you have the following rights over your personal data:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — ask us to delete your data ("right to be forgotten") in certain circumstances.
  • Restriction — ask us to limit how we use your data in certain circumstances.
  • Portability — receive certain data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, withdraw it at any time.

You can exercise most of these rights directly in your account (for example updating your profile, or deleting your account) or by contacting [email protected]. We will respond within the timeframes required by law (generally one month under the UK GDPR). We may need to verify your identity first.

If you are unhappy with how we handle your data, you may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or to your local supervisory authority if you are in the EEA. We would, however, appreciate the chance to address your concerns first.


8. How long we keep your data

We keep personal data only for as long as necessary for the purposes set out in this Policy, after which it is deleted or anonymised. In general:

DataIndicative retention
Account dataFor the life of your account. After account deletion, removed or anonymised within a reasonable period, subject to backups and legal requirements.
API request logs (incl. query parameters and client IP)Retained for a limited operational period for security, troubleshooting, abuse detection, and metering, then deleted or aggregated.
Security and audit logsRetained for a period appropriate to detect and investigate security incidents and abuse.
Email verification / reset tokensShort-lived; expire automatically.
Billing recordsRetained by us and/or Polar as required by tax and accounting law (typically several years).

Where the law requires a minimum retention period (for example for tax records), we keep the relevant data for that period.


9. Service providers and sub-processors

We use carefully selected third parties to operate the Services. The main ones are:

ProviderRoleData protection role
Polar (Polar Software, Inc. and affiliates)Reseller and Merchant of Record; payment processing, billing, tax, invoicing, refundsIndependent controller. Polar collects payment data directly from you (through its payment processor, Stripe) and shares only limited buyer information with us (such as email, country, and transaction amount); it does not share your card or bank details. Governed by Polar's Privacy Policy and Buyer Terms.
GoogleSign-in with Google (OAuth) and bot protection (reCAPTCHA)Processor / independent controller as applicable
GitHubSign-in with GitHub (OAuth)Independent controller for your GitHub account data
ResendDelivery of transactional emails (verification, password reset, notices)Processor
DigitalOceanCloud hosting, compute, and storage for the ServicesProcessor
CloudflareContent delivery, DNS, and edge security/DDoS protectionProcessor

We require our processors to protect personal data and to process it only on our instructions. We may update this list as our providers change.


10. Cookies and similar technologies

We use a small number of cookies and similar technologies, primarily to make the Services work:

  • Strictly necessary cookies — for authentication and session management (for example tokens that keep you signed in and store your access permissions). The Services cannot function without these.
  • Security technologies — such as Google reCAPTCHA on sign-up and authentication flows to protect against bots and abuse. This may involve Google processing technical data subject to Google's privacy terms.

We do not use cookies for cross-site advertising. Where we use any non-essential cookies or analytics, we will ask for your consent where required and provide controls. You can also control cookies through your browser settings, though blocking strictly necessary cookies may prevent you from signing in.


11. Children

The Services are not directed to, and are not intended for use by, anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will take appropriate steps to delete it.


12. Security

We implement appropriate technical and organisational measures to protect personal data, including password hashing, encryption in transit (HTTPS/TLS), access controls, rate limiting, audit logging, and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your account credentials and API keys confidential (see our Terms of Service). If we become aware of a personal-data breach that is likely to affect your rights, we will notify you and the relevant authority as required by law.


13. Contact us

For any privacy question or to exercise your rights:

  • Privacy contact: [email protected]
  • General support: [email protected]
  • Postal address: CrawlSnap Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

For payment- and billing-related data handled by our Merchant of Record, see Polar's Privacy Policy.


14. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date above shows the latest version. If we make a material change, we will provide reasonable notice through the Services or by email before it takes effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

CrawlSnap

From web chaos to clean intelligence

71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
+44 744 061 70 35
[email protected]
Terms of Service Privacy Policy Refund Policy

Crawlsnap accepts legal notices including cease-and-desist letters, DMCA takedown requests, and GDPR data requests through the contact form or the [email protected] email address.

© 2026 CrawlSnap. All rights reserved.