Privacy Policy
last updated 21.08.2026This Privacy Policy explains what personal data Crawlert collects, why, and how it is used when you visit crawlert.com or use the app at app.crawlert.com. The data controller is FOP Ihnatusha V.V., a registered individual entrepreneur (sole proprietor) in Ukraine. Contact: [email protected].
1. Data we collect
Account data — name, email address and a hashed password when you register.
Monitoring data — the domains and URLs you add, their Google index status returned by the Google Search Console API, and integration credentials you provide (for example a Collaborator API key or a WordPress site token). Integration keys are stored encrypted.
Notification settings — your email preferences, Telegram chat ID and Slack webhook URL if you connect those channels, plus your chosen timezone and language.
Billing data — handled by our Merchant of Record, Paddle. We do not receive or store your full card details; we receive the subscription status and invoice references.
Technical data — server logs (IP address, user agent, request time) kept for security and troubleshooting.
2. Why we process it
To provide the Service (contract performance): run index checks, show dashboards, send the alerts you enabled. To bill paid plans (contract performance, via Paddle). To secure the Service and prevent abuse (legitimate interest). To send occasional service announcements (legitimate interest); marketing emails are sent only with your consent and always contain an unsubscribe link.
3. Subprocessors
We share data only with the providers needed to run the Service:
- Paddle.com Market Ltd — Merchant of Record, payment processing and invoicing.
- Google LLC — Search Console API (index status of your URLs).
- Brevo (Sendinblue SAS) — transactional email delivery.
- Telegram / Slack — only if you connect them, to deliver your notifications.
- Hosting provider — infrastructure where the Service and its database run.
4. Cookies
The app uses strictly necessary cookies only: a session cookie and a CSRF token required for signing in. The marketing site does not set advertising cookies.
5. Retention
Account and monitoring data are kept while your account is active. When you delete a project, its URLs, history and reports are permanently purged after 30 days. When your account is deleted, all associated personal data is removed within 30 days, except records we must keep for accounting or legal reasons (kept by Paddle as Merchant of Record).
6. Your rights
You may request access to, correction, export or deletion of your personal data, object to processing, or withdraw consent at any time by writing to [email protected]. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
7. International transfers
Our subprocessors may process data outside your country, including in the EU and the US. Where required, transfers are protected by standard contractual clauses or equivalent safeguards provided by those vendors.
8. Security
Data is transmitted over TLS, passwords are stored hashed, integration keys are stored encrypted, and access to production systems is restricted. No method of transmission or storage is 100% secure, but we work to protect your data using industry practices.
9. Children
The Service is not directed at children under 16 and we do not knowingly collect their data.
10. Changes
We may update this Policy from time to time. The “last updated” date above reflects the current version; material changes will be announced by email or an in-app notice.