Skip to content

Privacy policy

BatScrape is a data API. This policy covers the data we hold about you as a customer, and the data that passes through the platform on your behalf — two different things with two different sets of rules.

What we collect about you

Account and billing data you give us directly, and operational data generated by your use of the API.

  • Account: name, work email, organisation, and the API keys issued to you.
  • Billing: handled by our payment processor. We store the last four digits of a card and an invoice history, never a full card number.
  • Operational: request timestamps, actor called, row counts, response status, and the IP the request came from.

What we do not collect

We do not run analytics or advertising trackers on this site, and we do not sell, rent, or share personal data with third parties for their own purposes.

Data that passes through the platform

When an actor runs, it fetches content from a source you nominated and writes it to a destination you nominated. That content is yours.

  • We retain raw payloads for 30 days so a normalisation bug can be re-derived without re-scraping, then delete them.
  • Normalised rows are written to your destination and are not retained by us beyond the run.
  • We do not read, index, or train on the content of your runs.
  • If a run targets a source that returns personal data, you are the controller of that data and we are the processor. Our data processing terms cover that relationship.

Why we hold what we hold

  • To authenticate you and enforce the quota on your plan.
  • To meter usage accurately, which is also what your invoice is derived from.
  • To keep an audit trail — who called what, when — because you will eventually need it and so will we.
  • To investigate abuse and to keep the platform available.

Retention

  • Raw run payloads: 30 days.
  • Operational and audit logs: 13 months.
  • Account and billing records: for as long as the account exists, then 7 years where tax law requires it.
  • Deleted accounts: purged within 30 days, except records we are legally required to keep.

Processors we rely on

We use a small number of third parties to run the service. Each is bound by a data processing agreement and none of them receives your data for their own purposes.

  • [Cloud provider] — compute and storage, hosted in [region].
  • [Payment processor] — billing and invoicing.
  • [Transactional email provider] — account and run notifications.

Your rights

If you are in the UK, EU, or another jurisdiction with equivalent law, you can ask us to give you a copy of your data, correct it, delete it, or stop processing it. Write to [email protected] and we will answer within 30 days.

Security

  • Payloads are encrypted in transit and at rest.
  • API keys are stored hashed; the full key is shown once, at creation.
  • Access to production data is limited to the engineers who need it, and every access is logged.
  • We do not use customer data in development or staging environments.

Cookies

This site sets no cookies. The dashboard sets one session cookie, which is required to keep you signed in and is removed when you sign out.

Changes

If this policy changes materially we will email account holders before the change takes effect. The date at the top is the last revision.

Contact

[email protected], or [postal address]. Our data protection contact is [name].