Legal

Privacy at Scraper.io

How information is intended to be handled across the website and guided Live Market pilots.

Draft for legal and operational review

Do not rely on this as the final privacy notice. The controller identity, processor list, lawful bases, retention periods, transfer safeguards and deployed analytics must be verified before customer data is accepted.

Draft updated 5 August 2026

1. Scope

This draft describes the categories of information expected to be processed through the Scraper.io website, guided Live Market pilots and supporting communications. It does not yet contain the verified legal entity, registered address, processor schedule, retention periods or international-transfer details required for a final policy.

The final policy must identify the data controller and distinguish information supplied by customers from public-source observations collected to build a market.

2. Information customers provide

A visitor may provide a name, work email, organisation, market description, example sources, a spreadsheet or brief, support messages and feedback on delivered values. A customer should remove confidential or personal information that they are not authorised to share before sending an attachment.

If accounts or product analytics are enabled for the final service, the policy must also describe authentication data, usage events, device information and the analytics configuration actually deployed.

3. Public-source market information

A Live Market may contain observations derived from approved public sources. Each proposed source should have a recorded access basis, source URL, observation time, permitted fields, retention rule and takedown route. Personal-profile databases, private accounts and prohibited sources are outside the standard pilot scope.

Inferences should be labelled and unsupported fields should remain empty. A person or organisation represented in a market may contact privacy@scraper.io to request a correction, explanation or removal review.

4. Purposes and lawful bases

The final policy must map each processing purpose to a lawful basis. Expected purposes include answering enquiries, scoping and delivering a contracted pilot, maintaining service security, handling billing, improving customer-specific relevance and meeting legal obligations.

No lawful basis should be inferred from this draft. The controller must document the actual basis for public-source research, customer communications and any analytics or marketing before those activities begin.

5. Service providers and transfers

Scraper.io will rely on service providers for some combination of hosting, email, payment processing, data collection, model processing and support. The final policy must name the providers actually in production, explain their roles and link the applicable subprocessors or privacy information.

Any transfer of personal information outside the United Kingdom or relevant local region must use an appropriate transfer mechanism and be described in the reviewed policy.

6. Retention and deletion

Specific retention periods are not yet approved. Before launch, Scraper.io must define separate retention rules for enquiries, customer briefs, account records, payment records, source captures, delivered market data, corrections and support messages.

The final service must also define how a customer exports or deletes its market and what limited records must be retained for legal, security or financial reasons.

7. Your rights

Depending on applicable law, a person may have rights to access, correct, erase, restrict or object to processing, receive a portable copy, or complain to a supervisory authority. The reviewed policy must explain which rights apply and how identity will be verified before fulfilling a request.

Questions and requests can be sent to privacy@scraper.io. A final response timetable will follow the law that applies to the verified controller.

8. Security

Scraper.io is intended to limit access to customer information, keep credentials server-side and preserve an auditable evidence trail. This draft does not claim a certification, security standard or production control that has not been independently verified.

Security reports should be sent to security@scraper.io and should include enough detail to reproduce the issue without exposing unrelated data.

9. Cookies and analytics

The final policy and any consent mechanism must match the cookies, analytics tags and advertising tools actually deployed. Optional analytics or marketing tags must not be described as active merely because they appear in a roadmap or configuration file.

A cookie inventory and consent assessment are required before non-essential tracking is enabled.

10. Changes and contact

A final policy should carry an effective date and record material changes. This draft is dated 5 August 2026 for implementation review only.

Privacy questions: privacy@scraper.io. General enquiries: hello@scraper.io. The verified controller name and postal address must be added before this page is treated as an operative privacy notice.