Legal
Privacy Policy
Last updated: 2 September 2026
This policy explains what Scrapebento ("we", "us") collects when you use the Scrapebento API, dashboard, and website, why we collect it, how long we keep it, and what rights you have. It covers both the personal data of our own customers and the content retrieved on your behalf when you call the API.
1. Who is responsible
The controller of your personal data is Scrapebento, 30 N Gould Street, #47580, Sheridan, WY 82801, United States. For privacy questions and to exercise any of the rights below, contact [email protected] or use the contact page.
Where we process content you retrieve through the API, you are the controller and we act as your processor. Our respective obligations for that processing are set out in our data processing addendum, available on request.
We are established in the United States and have no establishment in the EU. We have not designated a representative in the Union under Article 27 of the GDPR. People in the EEA and the UK can reach us directly at [email protected], and we answer those requests on the same terms as everyone else's.
2. What we collect
We collect the following, and no more than we need:
- Account data — name, email address, organisation name, and the credentials you set. Provided by you at signup.
- Billing data — plan, billing period, invoices, and payment status. Card details are collected and stored by our payment processor, Stripe; we never see or store a full card number.
- Request metadata — for each API call, the endpoint, action code, timestamp, duration, outcome, error code, credits spent or refunded, and the API key used. This is what makes usage reporting, refunds, and the published success rates possible.
- Request payloads — the URLs, queries, and parameters you submit, retained with the job record so that results are re-collectable and disputes are resolvable.
- Technical data — IP address, user agent, and request headers, used for rate limiting, abuse prevention, and security investigation.
- Support correspondence — anything you send us by email or through the contact form, together with our replies.
- Website analytics — see the cookies section below.
3. Scraped content and the URLs you submit
When you call a scraping, search, or research endpoint, we fetch the target you named, process the response, and return a result to you. Both the request and the returned content are stored server-side as part of the job record.
Slow-moving result kinds are cached server-side so that a repeated lookup inside the cache window is free and does not re-hit the target. Cache windows, and how to bypass them, are documented under Auth & Credits. For research endpoints, retrieval also spans prior runs within your own workspace — that retrieval is scoped to your organisation and is never shared across customers.
Retrieved content may contain personal data about third parties — names on a company page, authors of public posts, employees listed on a professional network. We process that content on your instructions, as your processor. You are responsible for having a lawful basis for the processing, for providing any notice those people are owed, and for honouring their rights in the data you hold. If you tell us to delete a job or a cached result, we will.
We do not sell retrieved content, use it to train models, or make it available to any other customer.
4. Cookies and analytics
This marketing site sets one cookie of its own: `scrapebento-landing-locale`, which remembers the language you chose so the site does not have to guess again. It is strictly necessary for that function, holds nothing but a language code, and lasts one year.
The dashboard sets a session cookie needed to keep you signed in.
Where analytics are enabled for this site, we use Google Analytics to understand aggregate traffic — pages viewed, referrers, approximate region. It sets its own cookies and processes data under Google's terms. Analytics are configured per environment and may be off entirely on the site you are reading.
We do not run advertising trackers, and we do not sell or share personal data for cross-context behavioural advertising.
5. Why we process it, and on what basis
We use the data above to:
- Provide the Service — authenticate requests, run jobs, return results, and meter credits. Basis: performance of our contract with you.
- Bill you and keep accounting records. Basis: contract, and our legal obligations.
- Protect the Service — rate limiting, abuse detection, fraud prevention, and security investigation. Basis: our legitimate interest in keeping the Service available and safe.
- Measure and publish per-endpoint reliability. Basis: legitimate interest. The published figures are aggregate and identify no customer.
- Support you, and respond to what you send us. Basis: contract and legitimate interest.
- Send service notices such as changes to these documents, incidents, or deprecations. Basis: contract. These are not marketing and cannot be opted out of while your account is open.
- Send product updates, where you have asked for them. Basis: consent, withdrawable at any time.
6. Who we share it with
We do not sell personal data. We share it only with the sub-processors that make the Service work, each under a contract limiting them to our instructions:
- Amazon Web Services (AWS) — infrastructure and storage.
- Stripe — payment processing and invoicing.
- Email and support tooling, used to send service notices and answer your messages.
- Analytics, where enabled, as described above.
- Upstream search and data providers used to fulfil specific endpoints, which receive the query needed to serve your request and nothing about your identity.
7. Legal disclosure
We may disclose data where we are legally required to, or where it is necessary to establish or defend a legal claim, or to protect the rights and safety of our users or the public. Where we are permitted to tell you about such a request, we will.
If we are involved in a merger, acquisition, or sale of assets, data may transfer as part of it. You will be told before that happens and before any different privacy policy applies.
8. How long we keep it
Account data is kept while your account is open and for 90 days after you close it. Billing records are kept for as long as tax and accounting law requires, typically seven years.
Request metadata is kept for 24 months to support usage reporting, billing disputes, and reliability measurement. Job payloads and returned content are kept for 30 days, and cached results only for the documented cache window. Technical logs used for security are kept for 90 days.
You can delete individual jobs from the dashboard at any time, and deleting your account removes account and job data on the schedule above, except where we are required to retain it.
9. International transfers
We operate from the United States and use sub-processors that may process data outside your country. Where data leaves the EEA or the UK, we rely on adequacy decisions where they exist, and on Standard Contractual Clauses with additional safeguards where they do not. A copy of the relevant safeguards is available on request.
10. Your rights
Depending on where you live, you have some or all of the following rights over your personal data: access, correction, deletion, restriction of processing, objection to processing based on legitimate interests, portability, and withdrawal of consent where consent is the basis.
To exercise any of them, contact [email protected] or use the contact page and select Privacy. We will respond within thirty days, and will ask you to verify your identity first. We do not charge for this and will not treat you differently for asking.
If you are in the EEA or the UK and are unhappy with our response, you may complain to your local supervisory authority.
11. California residents
Under the CCPA as amended by the CPRA, California residents have the right to know what personal information is collected and how it is used and shared, to delete it, to correct it, to opt out of sale or sharing, and to limit the use of sensitive personal information.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not knowingly collect sensitive personal information beyond account credentials. The categories collected, the purposes, and the recipients are set out in the sections above. Use the contact page to exercise a right; an authorised agent may act on your behalf with proof of authorisation.
12. Security
We encrypt data in transit and at rest, restrict internal access to those who need it, and log administrative access. API keys are stored hashed and are shown in full only once, at the moment they are created.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law. To report a vulnerability, use the security address on our contact page — good-faith research is welcome.
13. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect their personal data; if we learn we have, we will delete it.
14. Changes to this policy
We will update this policy as the Service changes. Material changes will be notified by email or in the dashboard before they take effect, and the date at the top of this page will be updated.