Controller and contact
CrawlVolt, operated by Bastien Cantet in France, is the controller for account administration, service security, support and its own billing operations. Contact privacy@crawlvolt.com for privacy requests.
Data we process
- Account data: email address, authentication identifiers and account status.
- Billing data: plan, subscription, customer and invoice references. Payment-card details are handled by Stripe and are not stored by CrawlVolt.
- Developer data: API-key identifiers and scopes. Plaintext API keys are displayed once and are not stored for later retrieval.
- Operations data: submitted URLs or search queries, endpoint, status, duration, usage units, request ID, coarse network and device data needed for security and support.
- Customer content: pages, files, prompts, browser-session state and extraction results submitted through the API.
- Support data: messages and diagnostic information you choose to provide.
Purposes and legal bases
- Provide the service
- Performance of the contract, including authentication, API execution, quotas and support.
- Secure and prevent abuse
- Legitimate interests in protecting CrawlVolt, its users and third parties.
- Billing and accounting
- Performance of the contract and compliance with legal obligations.
- Optional analytics or marketing
- Consent, where a non-essential tracker is enabled.
Retention
Authenticated request traces are exposed for 30 days and purged from the operational request log after 90 days. Anonymous-demo identifiers expire after 30 days. Crawl results expire after 24 hours. Browser sessions expire between 5 minutes and 24 hours according to the selected TTL. Account and subscription records are retained while the account is active and afterwards only as required for security, dispute resolution, accounting or legal compliance.
Recipients and transfers
Access is limited to authorised operations personnel and providers needed to deliver the service. Stripe processes billing. Microsoft Bing receives search queries when the Search endpoint is used. Authentication and payments platform services operate within the same Bastos environment. Where a provider processes data outside the EEA, CrawlVolt relies on applicable provider transfer safeguards.
Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability or object to processing based on legitimate interests. You may withdraw consent at any time. Send requests to privacy@crawlvolt.com. You may also lodge a complaint with the CNIL.
Customer responsibilities
For personal data contained in URLs, pages and instructions submitted by a customer, the customer is generally the controller and CrawlVolt acts as processor. Customers must have a lawful basis for collection and crawling, respect applicable access restrictions, and avoid submitting special-category or highly sensitive data unless separately agreed.