Preview environment
CrawlPact

Privacy policy

This page describes CrawlPact's actual technical data practices as implemented.

Effective and last updated: 30 July 2026.

1. Who operates CrawlPact

CrawlPact operates the CrawlPact service. For privacy questions, personal-data requests, or objections, contact info@crawlpact.com.

2. Information collected

CrawlPact distinguishes two kinds of information. Neither is "secret customer content" in the same sense — the first is information about your account and use of the service; the second is public information CrawlPact fetched from a website you asked it to audit.

Account and service data

  • Your account (a display name, and either passkey credentials or a connected Google identity — never a password). If you sign in with Google, CrawlPact stores Google's stable account identifier and, if provided, your Google email address as connected-account metadata only; email is never required, and no other Google data (Gmail, Drive, contacts, etc.) is ever requested or received
  • Billing metadata, limited to identifiers needed to link your account to a Paddle customer and subscription (never full payment-card details)
  • Saved domains, groups, monitoring preferences, and notification history
  • Support communications you send to CrawlPact
  • Security and operational logs, including a salted hash of your IP address (never the raw address) used for rate-limiting and abuse detection
  • First-party product-usage events (see below)

Public website audit data

  • The public domain or URL you submit for audit
  • Bounded, publicly accessible policy resources CrawlPact fetched (e.g. robots.txt, llms.txt, relevant HTTP headers) and their evidence snippets and timestamps
  • The crawler registry version a scan was evaluated against

A domain or URL may sometimes identify a person or organisation — CrawlPact does not treat public audit data as automatically non-personal. CrawlPact does not store copies of entire websites, only the specific, bounded resources relevant to AI crawler policy.

3. How information is collected

Information reaches CrawlPact from:

  • You directly, when you create an account, save a domain, or contact support
  • Automatically through your use of the service (usage events, security logs)
  • Public websites, during an audit you requested
  • Paddle, for billing and subscription status
  • Google Analytics, on public marketing pages only (see below)

4. Purposes

CrawlPact uses information to:

  • Run audits and save baselines
  • Operate accounts and monitor saved domains for change
  • Process subscriptions and provide billing support
  • Provide product and account support
  • Maintain security and detect misuse
  • Improve reliability and measure product usage
  • Maintain crawler-registry evidence and meet legal obligations

5. Public website audit data

  • CrawlPact fetches publicly accessible website resources you ask it to audit.
  • Audits may include public policy signals and response metadata.
  • Results describe publicly published information at the time of the scan.
  • CrawlPact does not require access to private website content for a standard audit.
  • CrawlPact does not prove actual crawler compliance — see limitations.

6. Cookies and local storage

CrawlPact sets two first-party cookies:

  • An essential, HttpOnly, Secure, SameSite=Lax session cookie used for authentication. It is required for the service to function and cannot be disabled while signed in.
  • A non-essential crawlpact_analytics_consent cookie recording your accept/decline choice for Google Analytics on public marketing pages, and the policy version that choice applies to. It contains only that preference and a version number — never an identifier, email, or IP address. It is set for around six months and is not required to use CrawlPact.

CrawlPact does not use local storage or session storage. Google Analytics sets its own analytics cookies (e.g. _ga) on public marketing pages, and only after you accept — never before, and never on the authenticated app or admin areas.

7. Analytics and your choice

Google Analytics is optional and off by default. It only loads on a public marketing page (this page, the homepage, pricing, guides, and similar content pages — never the authenticated app, admin, billing, private shared reports, or a specific audit result page) after you explicitly accept it, and never in local or preview environments. You can accept, decline, or change your choice at any time using the "Analytics preferences" control available on every public page — declining has no effect on your ability to use CrawlPact. When accepted, the page address sent to Google Analytics excludes query strings and any token; no account, domain, or report identifier is ever sent. This is a disclosed, deliberate deviation from a general no-external-analytics preference, made by CrawlPact's product owner. CrawlPact's own first-party product analytics (see the next section) remains the authoritative measurement of how the product itself is used, independent of this choice.

Separately, CrawlPact records a small number of first-party product-usage events (e.g. that an audit started, or that monitoring was enabled) to understand and improve the product. These never include your full domain, full URL, email, IP address, or any authentication or report token — see CrawlPact's security page for more detail. This first-party analytics is not affected by yourGoogle Analytics preference above.

8. Billing and Paddle

Payments are processed by Paddle, which acts as the merchant of record for applicable transactions. Paddle processes your payment information directly — CrawlPact never receives or stores full payment-card details. CrawlPact does receive and retain billing-related metadata (a Paddle customer and subscription identifier, transaction status, and amounts) necessary for account entitlements, support, refunds, and accounting. Paddle operates under its own privacy and contractual terms.

9. Sharing and processors

CrawlPact shares information only with:

  • Cloudflare — hosting, storage, and scheduled execution
  • Paddle — billing and payment processing
  • Google Analytics — public-page visit analytics
  • Legal authorities, where required by law

CrawlPact does not use any third-party email, SMS, push-notification, or AI API service. If you choose "Sign in with Google," Google acts as an identity provider for that one action: CrawlPact receives only the identity information needed to authenticate you (a stable account identifier, and optionally your name and email), never your Google password, and never requests or receives access to your Gmail, Drive, or any other Google data. Signing in with a passkey involves no external identity provider at all.

10. International processing

CrawlPact may be used from any country. Infrastructure and service providers listed above may process information outside your own country. CrawlPact does not currently maintain a published list of specific data-centre locations.

11. Data retention

DataRetention
Anonymous scan cache24 hours to 7 days
Free account scan history30 days
Solo plan history12 months
Pro plan history24 months
Agency plan history36 months
Deleted account private dataPurged within 30 days where permitted

Beyond this table, information is retained only as long as reasonably necessary for the purposes described above, subject to operational, security, billing, legal, and accounting requirements. Billing records required for accounting or legal purposes may be retained separately from the rest of an account's data after deletion — see "Account deletion" below.

12. Security

CrawlPact uses reasonable technical and organisational safeguards, including passkey and Google sign-in authentication, signature-verified billing webhooks, and an isolated scanner with SSRF protections — see security. No method of storage or transmission is completely secure, and CrawlPact does not claim absolute security.

13. Your choices and rights

Depending on your location, you may have rights relating to your personal information, such as access, correction, deletion, or objection. To exercise any of these, contact info@crawlpact.com. CrawlPact may need reasonable verification before fulfilling a sensitive request; this is a manual process, not an automated self-service workflow, and CrawlPact does not guarantee that a specific legal right applies to every user.

Account deletion

You can request account deletion at any time from account settings. This begins a cancellable 30-day grace period, during which the request can be reversed; your account remains otherwise usable during that window. After the grace period, private account data is purged. Billing records required for accounting or legal purposes (e.g. transaction and subscription history) are retained separately and are not deleted with the rest of the account, consistent with the retention table above.

Subscription cancellation

Paid subscriptions are cancelled through Paddle's customer portal, linked from your billing settings. CrawlPact does not independently process refunds; refund and chargeback decisions are Paddle's, and CrawlPact only records the outcome Paddle reports.

14. Children

CrawlPact is not directed at, or intended for use by, children. CrawlPact does not knowingly collect personal information from children and does not operate any age-verification functionality.

15. Third-party websites

Websites you audit with CrawlPact, and any external link from CrawlPact's own site, are governed by their own separate privacy practices, not this policy.

16. Policy changes

Material updates to this policy are reflected here with a new effective and last-updated date. CrawlPact does not currently send email notice of changes, since account registration does not collect an email address.

17. Contact

For privacy questions or requests, contact info@crawlpact.com. See also the contact page for other categories.