Privacy Policy
01What data we collect
We collect only what's necessary to provide and improve the ScrapingIsNotACrime API service. Here is a precise breakdown:
- Account data β your email address and, if you choose, a display name. If you sign in with Google, we also store your profile picture URL from your Google account. This is used to identify your account, send invoices, and communicate service updates.
- API usage data β every API call logs a timestamp, endpoint called, credits consumed, response status code, and latency. No request body content or response payload is stored.
- Billing data β payment is processed via a third-party processor (Stripe). We store only a tokenized reference to your payment method β never a raw card number, CVV, or bank detail.
- IP address β collected at signup and on each API call for security, abuse detection, and rate-limit enforcement. Retained for 90 days.
- Support communication β if you contact us via email or a support channel, we retain those messages to provide follow-up assistance.
02How we use your data
We use collected data only for the purposes listed below. We do not sell your data, and we do not build advertiser profiles from it β the sole exception, detailed in Β§5, is a single anonymous "signup happened" signal we send to Google Ads (no personal data included) so we can measure ad campaign performance.
- Authenticating your requests via your
X-API-Key - Deducting credits and managing your account balance
- Sending transactional emails (receipts, low-credit alerts, service notices)
- Detecting and blocking abusive usage patterns
- Generating aggregate, anonymized usage analytics to guide product development β including Google Analytics on our public pages (see Β§5)
- Complying with legal obligations
03Data we do NOT collect
To be explicit about what we don't do:
- We do not store social media data retrieved through our API
- We do not sell, rent, or trade your personal data
- We do not use your data to train AI or machine learning models
- We do not track you across other websites for general profiling β Google Signals and ad personalization are disabled. The one exception is our Google Ads conversion tag (see Β§5), which β by design β links an ad click to a signup on our site so we can measure whether our ad spend is working; it does not build a broader cross-site profile beyond that single measurement
- We do not collect device fingerprints or session recordings, and we do not use behavioral analytics inside the authenticated dashboard
- We do not share identifiable data with advertisers
04Data storage & retention
Your account data is stored in encrypted form on servers located in the United States and European Union. We use industry-standard AES-256 encryption at rest and TLS 1.3 in transit.
- Account data β retained for the lifetime of your account, plus 30 days after deletion
- API usage logs β retained for 90 days, then automatically purged
- Billing records β retained for 7 years to comply with financial regulations
- IP logs β retained for 90 days for security purposes
- Support messages β retained for 2 years after last contact
You may request deletion of your account and associated personal data at any time. See Your rights below.
05Third-party services
We use a small number of third-party services to operate the product. Each is subject to their own privacy policy:
- Stripe β payment processing. stripe.com/privacy
- Postmark / Resend β transactional email delivery
- Cloudflare β DDoS protection and DNS. May log IP addresses per their policy. We also use Cloudflare Web Analytics, a cookieless, no-PII traffic-measurement tool, on all pages
- AWS / GCP β cloud infrastructure hosting
We offer Sign in with Google as an alternative to email/password β when you use it, we read only your email, name, and profile picture from your Google account, solely to create or link your account. We request no additional scopes, never post on your behalf, and don't use this for anything beyond authentication.
We do use Google Analytics (GA4) β but only on our public marketing and documentation pages, never inside the authenticated dashboard, and only after you explicitly accept via the cookie banner. Google Signals and ad personalization are disabled, and IP addresses are anonymized. See Google's privacy policy. You can withdraw consent anytime via "Cookie preferences" in the footer.
We also use a Google Ads conversion tag on the sign-up and sign-in pages, gated by the same cookie banner. It fires a single, anonymous "a signup happened" signal when your account is created β no personal data (name, email) is included β so we can measure whether our ad campaigns are working. It is not used for remarketing or ad personalization.
06Cookies & tracking
We use a minimal set of cookies in the authenticated dashboard β only what's necessary to keep you logged in.
- Session cookie β keeps you logged in to the dashboard. Expires on logout or after 30 days of inactivity.
- CSRF token β prevents cross-site request forgery attacks. Session-scoped.
On our public marketing and documentation pages only, we optionally set a Google Analytics cookie β but only after you explicitly accept it via the cookie banner. It is never active in the authenticated dashboard. You can accept, decline, or change your mind at any time via "Cookie preferences" in the footer.
On the sign-up and sign-in pages, we also use a Google Ads conversion cookie β again, only after you accept the cookie banner β to measure signup conversions from ad campaigns. It is not used for remarketing or ad personalization.
We do not use any other advertising cookies or tracking pixels. You can disable cookies in your browser, though this will prevent you from using the dashboard.
07Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access β request a copy of all personal data we hold about you
- Correction β request correction of inaccurate personal data
- Deletion β request deletion of your account and personal data
- Portability β request your data in a machine-readable format
- Objection β object to processing in certain circumstances
- Restriction β request restriction of processing
To exercise any right, email us at [email protected]. We will respond within 30 days.
08Children's privacy
ScrapingIsNotACrime is a developer API service intended for adults and businesses. We do not knowingly collect personal data from individuals under 16 years of age. If you believe we have inadvertently collected data from a minor, contact us immediately and we will delete it.
09Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify registered users by email at least 14 days before the change takes effect.
Continued use of the service after a policy change constitutes acceptance of the updated policy.
10Contact
For privacy-related questions, data requests, or concerns:
- Email: [email protected]
- Response time: within 30 days