privacy policy
effective 2026-09-07 · version 1.2.0
This policy explains how we process personal data when you use crawlbrulee — our website, dashboard, documentation, and api. It is written for the people we work with directly: visitors, account holders, and their team members.
Personal data that appears inside content you scrape through the api is covered separately: for that data we act as your processor, not as a controller. Section 5 explains how that works, and the data processing agreement governs it.
1. who we are
Unless a section says otherwise (payments — section 6), the controller for the processing described in this policy is:
SC YLEMBYTES SRL (operating the crawlbrulee service) Trade register no. J12/4422/2018 · VAT RO39940193 Cluj-Napoca, Romania contact@crawlbrulee.com
We are a company established in Romania, in the European Union, and we host the service on infrastructure located in the EU.
2. scope
crawlbrulee is a service for businesses and professionals. This policy covers:
- the marketing website and documentation at crawlbrulee.com,
- the customer dashboard,
- the api and related client tools (sdks, cli, mcp server),
- our support and communication channels.
3. the short version
- we collect what we need to run your account, bill you, keep the service secure, and support you — and we aim to collect no more.
- we process customer content on your instruction, not as our own content. We can create technical and statistical service data from it only where that information no longer contains or reproduces the customer content, cannot reasonably reconstruct it, and does not identify you, a person, or a specific target. We keep scrape results for a limited time so caching can work — at most 90 days, covering every copy we hold, including backup and content-delivery copies.
- we do not send scraped content, results, your account data, or your support conversations to any provider for ai/llm processing or model training.
- we do not sell personal data. We use it for advertising or retargeting only with your consent, given in the cookie banner.
- our infrastructure runs in the EU. A small number of tools we use (listed on the provider page) are operated by non-EU providers, under appropriate safeguards.
- Google's analytics and advertising cookies are set only if you accept them in the cookie banner.
The rest of this policy is the precise version of the statements above.
4. data we process, and why
4.1 account and organization data
When you create an account we process your name, email address, password (stored only as a secure hash), organization name and membership, and your plan and settings.
We receive this data in three ways: you enter it when you register; you sign in with Google, in which case Google sends us your name, email address and profile identifier; or an existing account holder invites you to their organization, in which case we receive the email address they entered in order to send the invitation.
If your visit came through one of our ads or campaign links, we may also record the campaign parameters from that visit (utm tags, an ad click id) and the referring site with your account when you sign up, to measure which of our marketing efforts work.
- Purpose: providing the service you signed up for; authentication; team and organization management; measuring which of our marketing efforts bring customers.
- Legal basis: performance of a contract (GDPR art. 6(1)(b)) where you are personally a party to the contract with us. Where you use the service as an employee, contractor or team member of a customer — so that the contract is with your organization rather than with you — the basis is our legitimate interest (art. 6(1)(f)) in providing the service our customer has contracted for and in identifying who acts within its account. Where we record campaign parameters at signup, the basis is our legitimate interest in measuring our marketing. You can object; see section 11.
4.2 api tokens, usage data, and service data
We issue api tokens scoped to your organization. Tokens are stored only as cryptographic hashes — we cannot read your token back after it is created. We record usage metrics per organization (request counts, credits consumed, proxy tier used, cache hits) to meter your plan and show usage in your dashboard.
We also create technical, operational, statistical, and analytical information about how the service performs and is used ("service data"). Service data can include information derived from customer content only after it has been processed so that it does not contain or reproduce customer content, cannot reasonably be used to reconstruct it, and does not identify you, a person, or a specific target. Merely cleaning content, changing its format, or removing an element does not meet that standard. Other service data, such as ordinary usage records, can remain associated with your organization where needed for service delivery, metering, billing, security, abuse prevention, support, or troubleshooting.
- Purpose: operating the api; metering and billing; showing you your usage; measuring reliability and performance; capacity planning; preventing abuse; analysing and improving the service; and producing aggregate statistics.
- Legal basis: performance of a contract (art. 6(1)(b)) for service delivery, metering, billing, and showing your usage; our legitimate interests (art. 6(1)(f)) in operating, securing, analysing, and improving the service for the remaining purposes. You can object to processing based on legitimate interests; see section 11.
4.3 request metadata and logs
Our systems log technical metadata about api requests and dashboard activity: timestamps, requested endpoints and options, response codes, ip addresses, and diagnostic identifiers. We use these logs to keep the service reliable and secure, to investigate incidents, and to prevent abuse.
Our logs include the target urls you ask us to scrape, in full, including their query strings. We say so explicitly because a url can itself contain personal data — an email address or an identifier in a query parameter, for example — so where that is true of the pages you target, that data is present in our technical logs.
What we deliberately keep out of them:
- the page content we retrieve is never logged;
- customer-supplied target headers and cookies are excluded from our application logs;
- webhook urls are logged as the hostname only, never the full url;
- marketing attribution parameters (
utm_*,gclid,fbclidand similar) are stripped before logging.
These logs are retained for up to 90 days, then rotated out. They are held by our logging provider, listed on the subprocessor page.
- Purpose: security, reliability, abuse prevention, troubleshooting, and creating service data that meets the safeguards in section 4.2. Specific target urls remain customer content and do not themselves become service data.
- Legal basis: legitimate interest (art. 6(1)(f)) — running a secure and reliable service and understanding and improving how it performs. You can object; see section 11.
4.4 support and communication
If you contact us — by email or through the chat widget — we process the content of the conversation and the contact details you provide.
When you are signed in and use the chat widget, we also pass your account context to the chat provider so we can answer without asking you to repeat it: your email address, display name, company or organization name, your user and organization identifiers, your plan and account status, and the routing segments we use to sort conversations internally.
- Purpose: answering your questions and resolving issues.
- Legal basis: performance of a contract (art. 6(1)(b)) for customers; legitimate interest (art. 6(1)(f)) for pre-sales questions.
4.5 transactional email
We send operational emails (account confirmations, password resets, billing and usage notices) through email delivery providers. Creating an account does not subscribe you to marketing. We currently send only operational email; if we add marketing email, we will use a separate opt-in and provide an unsubscribe route.
- Purpose: operating your account.
- Legal basis: performance of a contract (art. 6(1)(b)).
4.6 website visitors and analytics
When you visit crawlbrulee.com we process technical data (ip address, browser type, pages viewed) in server logs, on the legal basis described in 4.3.
We run Google Tag Manager and Google Analytics with Google's consent mode, so the cookie banner controls them. Analytics cookies are set only if you accept them in the banner; if you decline or have not yet chosen, no Google cookies are set. As with any consent-mode setup, we may still measure site traffic in aggregate through cookieless signals, which set no cookies and use no persistent identifiers. Advertising and retargeting tags, where we use them, run only with your consent through the same banner; the cookie table in section 12 lists what is in use.
- Purpose: understanding how the website is used and measuring our own marketing.
- Legal basis: consent (art. 6(1)(a)) for cookies and the tools they enable, which you can withdraw at any time (section 12); legitimate interest (art. 6(1)(f)) for aggregate, cookieless traffic measurement. You can object; see section 11.
4.7 anti-abuse verification
The dashboard sign-in, sign-up, and password-reset forms are protected by hCaptcha, which processes technical browser data to distinguish people from bots.
- Purpose: protecting the service from automated abuse.
- Legal basis: legitimate interest (art. 6(1)(f)).
5. personal data inside scraped content
This is the section to read if you want to know what happens to data that appears in the pages you scrape.
When you send a scrape request, you choose the target. Web pages can contain personal data of third parties. For that data:
- you are the controller — you decide what to scrape and what to do with the results, and you are responsible for having a lawful basis for it;
- we are your processor — we fetch, render, and return the content on your instruction (each api call is an instruction), under the terms of our data processing agreement;
- we keep scrape results only to make caching work — results are deleted automatically no later than 90 days after they are created, and may be deleted earlier; the maximum covers every copy we hold, including backup and content-delivery copies;
- we do not treat customer content as our own product data — we process it to operate the service: caching, delivering your results, verifying defect reports, and investigating abuse or security incidents. We can transform it into service data only under the strict boundary in section 4.2; changing its format or cleaning it is not enough. We do not build profiles from customer content, train anything on it, or send it to any ai/llm provider;
- the cache is shared between customers. To avoid fetching the same public page twice, a result produced for one customer's request can be served to another customer who requests the same url while it is still cached — and vice versa. The shared cache is intended for publicly accessible, non-personalized content and is not designed to hold crawlbrulee account data, credentials, or request history. The dpa and section 6 of the terms describe it in full, including the available cache controls and when a customer may submit requests for non-public or personalized content;
- traffic to target websites may be routed through proxy network operators. They act as independent controllers for connection metadata they process for their own network-delivery, billing, security, and abuse-prevention purposes. Our provider page explains what they can see on HTTPS and plaintext HTTP connections and how their retention is determined.
If you believe content relating to you was scraped through our service by one of our customers, the customer is the controller for that processing — we cannot decide on your behalf what they may do with it. We will still help: write to contact@crawlbrulee.com with the exact urls and any result or job identifiers you have. We use reasonable efforts to identify responsive cached copies and, where we can reliably identify them, remove them early. The shared cache is not attributed to an organization, so we may be unable to prove which customer caused a url to be cached or locate every item from a time range; anything we cannot reliably identify expires automatically under the 90-day maximum above. We pass the request to an identifiable customer where the information available to us permits it.
6. payment data
Purchases are handled by Creem (Armitage Labs OÜ, Estonia), our merchant of record. When you buy a subscription or credits, our merchant of record is an independent controller of your payment and billing data under its privacy policy. We never see or store your full card details; we receive transaction summaries needed to provision your plan.
7. who we share data with
We share personal data only with providers that help us run crawlbrulee — each bound by data-protection terms appropriate to its role (data processing agreements for processors; their own controller obligations for independent controllers like our merchant of record) — and only what each provider needs. The categories of recipients are:
- cloud infrastructure and hosting for the core service;
- payments and billing — our merchant of record, acting as an independent controller (section 6);
- support chat, business email, and transactional email providers;
- application performance monitoring and log and metrics providers;
- internal team communication and operational notifications;
- content delivery networks for screenshot delivery and public website assets;
- website analytics (cookies only with your consent) and anti-abuse verification providers;
- third-party proxy network operators — independent controllers for the connection metadata they process for their own network-delivery, billing, security, and abuse-prevention purposes (section 5).
The provider page is the authoritative, maintained list of these recipients. It names each provider or provider category and gives, for each one: where the company is established and where your data is held (the two often differ, in both directions), the personal data we send, and the available retention information. Read this section together with that page.
Providers that process customer content on your behalf (rather than our controller-side data above) are identified there by role. Its subprocessor table also explains how we announce subprocessor changes. Independent network operators are disclosed separately from that table and are not covered by the subprocessor authorization and objection process.
Beyond service providers, we disclose personal data only if the law requires it (for example, a binding request from a competent authority), to establish or defend legal claims, or — under equivalent commitments — to a successor in a corporate reorganization or transfer of the business.
8. international transfers
We are an EU company and our core infrastructure runs in the EU, so for most processing your data does not leave the EU/EEA.
Several providers on the provider page are established outside the EU/EEA or process data outside it. Where a controller-side provider's processing requires a transfer safeguard, we rely on the safeguard applicable to that provider and transfer — such as an adequacy decision, its certification under the EU–US Data Privacy Framework, or the European Commission's standard contractual clauses incorporated into the applicable agreement.
We will tell you which safeguard applies to which provider on request: contact@crawlbrulee.com.
For customer content, request options may route target traffic through proxy gateway and exit locations worldwide. The provider page explains the data exposed on HTTPS and plaintext HTTP connections, and section 11 of the data processing agreement explains the transfer posture. A customer-directed non-EU/EEA exit remains a processing location and may require a transfer safeguard depending on the parties, roles, and route involved.
9. how long we keep data
| data | retention |
|---|---|
| account and organization data | while your account is active. After closure we delete or anonymize it when it is no longer needed, and in any case keep only what we must keep by law. You can ask for earlier deletion under section 11; we apply the right subject to its legal conditions and any required retention |
| scrape, map, and screenshot results | deleted no later than 90 days after creation, and may be deleted earlier; the maximum covers every copy we hold, including backup and content-delivery copies |
| api usage and billing records | for the period required by Romanian accounting and fiscal law |
| request metadata and technical logs | up to 90 days, then rotated out |
| support conversations | while your account is active, and afterwards while we may still need the history to handle a related question or claim |
| analytics data | user- and event-level data for up to 14 months; standard aggregate reports under Google's retention policies; cookies only with your consent |
Where a row above gives a range rather than a fixed number, that is deliberate: we would rather state a criterion we actually apply than a deadline we do not enforce automatically. You can ask us to delete data sooner at any time.
10. security
We protect personal data with technical and organizational measures appropriate to the risk, including: EU-only hosting for the core service, encryption between customers and the service and on internal data-store connections (with certificate pinning for those data stores), target TLS for HTTPS target connections, api tokens stored only as hashes, per-organization data scoping for account, organization, credential, usage, and job-history data, encrypted secret management, and access on a need-to-know basis. The provider page explains the separate plaintext-HTTP treatment. If a personal data breach is likely to result in a risk to individuals, we will notify the competent authority and, where required, the affected people, in line with GDPR arts. 33–34.
11. your rights
Under the GDPR you can ask us for:
- access to the personal data we hold about you (art. 15),
- rectification of inaccurate data (art. 16),
- erasure (art. 17),
- restriction of processing (art. 18),
- portability of data you provided to us (art. 20),
- objection to processing based on legitimate interest (art. 21).
Where processing is based on consent, you can withdraw it at any time, without affecting processing that happened before the withdrawal.
Write to contact@crawlbrulee.com — we respond within one month (for complex requests the GDPR allows an extension of up to two further months; we tell you if we need it). We have not designated a data protection officer; privacy questions reach the people who run the service directly.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Romanian supervisory authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, dataprotection.ro) — though we would appreciate the chance to resolve your concern first.
We do not make automated decisions with legal or similarly significant effects (GDPR art. 22).
12. cookies
We keep cookies to a minimum. The banner you see on your first visit controls the optional ones; your choice is stored locally in your browser.
| name / source | type | purpose | duration |
|---|---|---|---|
cookie-consent (local storage) | essential | remembers your cookie choice | until you clear it |
| dashboard session cookies | essential | keeping you signed in to your account | session / limited |
| hCaptcha | essential (security) | anti-abuse verification on forms | per hCaptcha policy |
Crisp chat (crisp-client/*) | essential — set only if you open the chat | operating the support chat conversation | 6 months |
Google Analytics (_ga and related) | analytics — consent only | usage statistics | up to 2 years |
To change your choice, clear the stored cookie-consent value in your
browser's site data and the banner will ask again. Declining analytics does not
limit the service in any way.
13. children
crawlbrulee is a service for businesses and professionals. It is not directed at children, and you must be at least 18 to create an account. We do not knowingly collect personal data from children through our website, dashboard or support channels.
This statement is about the data we collect as a controller. It cannot extend to the content our customers choose to scrape: public web pages can contain personal data relating to children, and we have no way to detect it. Responsibility for having a lawful basis for that content sits with the customer directing the scraping — see section 5 and the dpa.
14. changes to this policy
When we change this policy, we update the version and effective date at the top and publish the new text at this address. For materially adverse changes we notify account owners by email at least 14 days before the change takes effect. Non-material clarifications and changes that do not adversely affect you may take effect when published. A change required immediately for security, law, or abuse prevention may take effect immediately; where reasonably practicable, we notify you promptly. Previous versions are archived and available on request.
15. contact
SC YLEMBYTES SRL · Cluj-Napoca, Romania · contact@crawlbrulee.com