Policies

Privacy Policy

What we collect when you use crawlnode.com and the CrawlNode API, what we do with it, and how to see it, correct it or have it deleted.

Last updated . Also: Terms of Service · Acceptable Use Policy · Refund Policy

Who we are

CrawlNode runs this website and the CrawlNode API: real Chrome browsers on Windows machines, reserved by the month and driven over HTTP. "We" on this page means CrawlNode. For anything about your data, write to support@crawlnode.com.

What we collect

When you create an account

  • Your name and email address.
  • Your password, stored only as a one-way hash. We cannot read it.
  • Whether your email address has been confirmed, and your two-factor setup if you turn it on.
  • The time and IP address of your last sign-in, and failed sign-in attempts against your email address, which is how repeated guessing is stopped.

When you buy and use physical nodes

  • What you ordered: the number of nodes, the requests you sent us and any note you wrote with them.
  • Your subscription and its status. Card payments are taken by Stripe. Your card details go to Stripe and never reach our servers; we keep only the identifiers Stripe gives us for your customer record and subscription.
  • Your API keys, of which we keep only the last few characters once you have seen them. A key issued for you by our team is held encrypted until you reveal it, once, and is then erased from our side.
  • Usage on each key for each billing period: sessions started, API calls and outbound data. This is what your limits and any invoice are measured from.

When you use a browser

  • Through the API. To run and meter the service we process the requests you send, including the addresses your browsers visit, and keep operational logs of them. The pages you load and what you take from them are yours.
  • The live demo on the home page. The address you enter and your IP address, which is how the demo limits each visitor.
  • The Live browser in the members area. The sessions you open and the steps you take in them, so the page can hand them back to you as a script. What you type into a password field is never kept.

When you write to us

  • Support messages: your name, email address, the category and what you wrote.
  • A record of the emails this site sends you, such as confirmations and receipts.

Automatically

  • Web server and application logs of requests and errors, which include IP addresses. API keys and passwords are kept out of them.

Cookies

This site sets one cookie, crawlnode_session, which keeps you signed in and protects forms against forgery. It is necessary for the site to work, cannot be read by scripts on the page, and is sent only over HTTPS. There are no advertising cookies, no analytics cookies and no tracking scripts.

The typeface on these pages is loaded from Google Fonts, so your browser makes a request to Google when a page loads and Google sees your IP address in doing so.

What we use it for

  • Providing the service you signed up for: your account, your keys, your browsers.
  • Billing, and measuring usage against the limits your nodes carry.
  • Answering you when you ask for help.
  • Keeping the service secure and stopping abuse, including enforcing the Acceptable Use Policy.
  • Meeting legal obligations, such as keeping billing records.

Where the law asks for a legal basis, ours is the contract with you for the first three, our legitimate interest in running a secure service for the fourth, and legal obligation for the fifth. We do not sell personal data, and we do not use it for advertising.

Who we share it with

Only the companies that help us run the service, and only what each one needs:

  • Stripe, for card payments.
  • Our email delivery provider, for the messages this site sends you.
  • Our hosting provider, where the website and its database run.
  • Proxy network providers, which carry the traffic of your browser sessions when you use the managed exits.
  • Challenge-solving providers, which receive a challenge when one cannot be handled by our own solvers.

We also disclose information when the law requires it, or when it is needed to investigate abuse of the service.

How long we keep it

Account information is kept for as long as your account is open. After you close it, we keep what we are required to keep, such as billing records, and what we need to resolve disputes and prevent abuse, and delete the rest. A browser session is not kept: when it ends, what was in the browser goes with it.

Your choices

  • Change your name and password, and turn two-factor authentication on or off, in your account settings. To change your email address, write to us so we can verify the new one.
  • Ask us for a copy of the data we hold about you, to correct it, or to delete it and close your account.
  • Object to something we do with your data, or ask us to restrict it.

Write to support@crawlnode.com from the address on your account and we will act on it. If you are not satisfied with our answer, you also have the right to complain to the data protection authority where you live.

Security

Passwords are hashed, the site is served over HTTPS, API keys are shown once and not stored in readable form, and two-factor authentication is available on every account. No system is perfectly secure; if we learn of a breach that affects your data, we will tell you.

Where it is processed

Our servers and the providers above may be in a different country from you, so your data may be processed outside the country you live in.

Children

CrawlNode is a service for developers and businesses. It is not intended for anyone under 18, and we do not knowingly collect their data.

Changes to this policy

When this policy changes we update this page and the date at the top.