Privacy Policy

Last updated: April 5, 2026

1. Information We Collect

Account information: When you sign up, we collect your email address, name (optional), and password (hashed). If you subscribe to a paid plan, payment is processed by Stripe. We do not store credit card numbers.

Usage data: We collect information about how you use the Service, including crawl jobs, keyword searches, pages viewed, and feature usage. This helps us improve the product and enforce subscription limits.

Crawl data: When you crawl a website, we store page metadata (URLs, titles, meta descriptions, status codes, etc.) from the target domain. This data belongs to you and is stored in your workspace.

Cookies: We use httpOnly session cookies for authentication and a cookie consent preference cookie. We do not use third-party advertising cookies.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Authenticate your identity and manage your account
  • Process payments via Stripe
  • Send transactional emails (password resets, alerts, invitations)
  • Enforce subscription limits and feature gating
  • Improve the Service based on usage patterns

3. Data Sharing

We do not sell your personal data. We share data only with:

  • Stripe. For payment processing
  • Resend. For transactional email delivery
  • DataForSEO. For keyword and backlink data (we send domain names, not personal data)
  • OpenAI. For AI-powered features (we send SEO data context, not personal data)
  • DigitalOcean. Infrastructure hosting (data processing agreement in place)

4. Data Security

We protect your data using: HTTPS/TLS encryption in transit, AES-256 encryption for stored credentials (CMS tokens), hashed passwords (bcrypt), httpOnly session cookies with CSRF protection, and rate limiting on authentication endpoints. Our infrastructure runs on DigitalOcean with managed database encryption at rest.

5. Data Retention

We retain your data for as long as your account is active. Crawl data retention depends on your subscription tier (30 days for Free, up to 365 days for Enterprise). If you delete your account, we remove your personal data within 30 days, except where required by law.

6. Your Rights

You have the right to: access your data, correct inaccurate data, request deletion of your data, export your data (via CSV export features), and withdraw consent for optional processing. To exercise these rights, contact us at the email below.

7. Children

The Service is not intended for users under 16. We do not knowingly collect data from children.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance.

9. Contact

Questions about this Privacy Policy? Contact us at privacy@crawltide.com.