Skip to content
WebScrap

Privacy Policy

This policy describes what WebScrap collects, why, how long it stays and how you get rid of it. It is written to be read, not to be survived.

Last updated: 17 September 2026

The operator of this service

WebScrap operates the web scraping API available at webscrap.com. Questions about this policy and every privacy request go to support@webscrap.com.

Data you give us

  • Your email address, when you create an account or ask us a question.
  • Account settings: API keys you generate, extraction schemas you save, scheduled jobs you configure and team members you invite.
  • Billing details, when you subscribe to a plan. Card numbers are handled by our payment processor and never reach our servers.

Data created when you use the API

  • The target URLs you request, the parameters you send and the response metadata: status code, elapsed time, exit country and whether a browser was used.
  • The response payload itself, held only for the retention window of your plan.
  • Technical logs: IP address, user agent, timestamps and error traces, kept for 30 days for security and debugging.

Data collected on the website

  • The demo on this site stores the requests you run for the length of your browser session so the console can show you the result.
  • We count page views and signups. We do not build advertising profiles and we do not sell anything about you to anyone.

Our purposes and their basis

  • To provide the service you asked for: performance of the contract between us.
  • To bill you and keep accounting records: contract and legal obligation.
  • To keep the service secure, detect abuse and debug failures: our legitimate interest in running a working service.
  • To answer your emails: contract and legitimate interest.

We do not use your requests or your payloads to train models, to build datasets or to inform anyone else about what you collect.

Retention

  • Response payloads: 24 hours on Starter, 7 days on Growth, 30 days on Scale, and the period agreed on Enterprise. After that they are deleted, including rendered HTML and screenshots.
  • Request metadata used for your usage counters: 13 months, so you can compare a month with the same month last year.
  • Technical logs: 30 days.
  • Account and billing records: for as long as the account exists, and afterwards only as long as accounting law requires.
  • Unconfirmed signups: deleted automatically after 30 days.

Processors

We use a small number of suppliers to run the service: cloud hosting, proxy network providers, an email provider for confirmation and notification messages, and a payment processor for subscriptions. Each acts on our instructions under a data processing agreement, and none of them receives your payloads for any purpose other than delivering them to you.

We do not sell personal data and we do not share it with advertisers. We disclose data to an authority only where the law requires it and, where we are permitted to, we tell you first.

Location

Requests are processed in the region assigned to your account. Enterprise accounts choose data residency in the European Union or the United States, and requests do not leave the region they were routed to. Transfers between regions, where they happen at all, rely on standard contractual clauses.

What you can ask for

  • A copy of the data we hold about you.
  • Correction of anything inaccurate.
  • Deletion of your data, which you can also trigger yourself from the account.
  • A machine readable export of your account data.
  • Objection to processing based on our legitimate interest.
  • Withdrawal of consent, where the processing rests on consent.

Write to support@webscrap.com and we answer within 30 days. If our answer does not satisfy you, you can complain to your local data protection authority.

You are the controller of your own results

When you point the API at a page, you decide what is collected and why. For that data you are the controller and we are your processor: we hold it for the retention window of your plan, we act on your instructions and we delete it on request. Your obligations under GDPR and similar laws follow the data you choose to collect, which is the part we cannot decide for you.

How the data is protected

Traffic runs over TLS, payloads are encrypted at rest, API keys are stored hashed and access to production is limited to the people who operate it, with every access recorded. The full description is on the enterprise web scraping page.

Updates to this policy

When this policy changes materially we email account holders before the change takes effect and update the date at the top of this page. Earlier versions are available on request.