Policy
Privacy Policy
Crawlbaby is not an ad-supported product. It does not sell personal data. It uses data to run the app, monitor websites, support collaboration, connect integrations, send transactional emails, secure the service, and troubleshoot problems.
1. Who this policy applies to
This Privacy Policy explains how Crawlbaby handles personal data and other information when you use Crawlbaby.io and the Crawlbaby app.
This is a plain-English privacy policy. It is not a contract, Terms of Service, or a data processing agreement.
2. What Crawlbaby is
Crawlbaby is a SaaS product that helps users track website changes over time. Users can add sites and URLs, connect certain integrations, and review stored snapshots, screenshots, links, and diffs.
3. The short version
We collect the information needed to operate the app and provide the service.
- Account and workspace details
- Site and tracked page information
- Stored website snapshots, screenshots, links, and diff records
- Integration connection details
- Webhook and change-event records
- Operational logs and error records
- Cookies and browser storage used to keep the app working
We use this data to operate the app, provide collaboration features, connect and maintain integrations, send transactional emails, secure the service, and troubleshoot reliability issues.
Crawlbaby is not ad-supported. We do not sell personal data. We do not share data for targeted advertising.
4. What we collect
A. Account and workspace data
When you create or use an account, we may store your email address, display name, user ID, team or workspace membership, and team, site, or access assignments.
We also use authentication cookies or session tokens to keep you signed in and to remember the workspace you are using.
We may send transactional emails related to the service, including welcome emails, team invites, site created or deleted notices, first snapshot notices, integration reauthorisation notices, and usage warnings.
B. Site and content data
When you use Crawlbaby to monitor a website, you may provide site names, base URLs, sitemap URLs, and tracked page URLs.
Crawlbaby captures and stores page HTML snapshots, screenshots, extracted links, and diff artefacts used to compare changes over time.
Captured website content may incidentally include personal data or sensitive information that appears on the tracked website itself. Crawlbaby stores that captured content as part of the monitoring and comparison features.
C. Integration data
Crawlbaby can connect to services such as Google Analytics 4, Google Search Console, HubSpot, Webflow, Shopify, and WordPress-related change-intake or setup flows.
When integrations are connected, Crawlbaby may store provider account email, property, account, or site identifiers, permission scopes, sync status, cursors, error states, and other connection metadata needed to keep the integration working.
OAuth or API tokens are stored in encrypted form. For Google Analytics 4 and Google Search Console, Crawlbaby uses read-only scopes where applicable.
D. Event and operational data
To operate the service, we may store webhook or change-event records, URLs, event types, timestamps, source event IDs or checksums, optional payload data sent by integrations, operational logs, error records, and cached or stored analytics metrics tied to tracked pages and dates.
This helps with reliability, debugging, sync handling, auditability of app actions, and product operation.
E. Cookies and browser-side storage
Crawlbaby uses cookies for authentication, session management, and workspace selection.
The frontend may also use localStorage or sessionStorage for UI preferences, recent URLs, collapsed or expanded interface state, and temporary workflow state.
5. How we use information
- Create and manage accounts, teams, workspaces, and permissions
- Store and display tracked sites, pages, snapshots, screenshots, links, and diffs
- Provide collaboration features inside workspaces
- Connect, maintain, and reauthorise integrations
- Process webhooks and change events
- Cache or show analytics-related metrics connected to tracked pages and dates
- Send transactional emails about account, team, site, integration, and service events
- Secure the service and detect abuse or misuse
- Investigate bugs, errors, sync failures, and support issues
- Maintain service performance, reliability, and internal operations
We do not use personal data for targeted advertising. We do not sell personal data.
6. Integrations
If you choose to connect a third-party service, Crawlbaby will receive and store the connection details needed to operate that integration.
Depending on the integration, that may include account email, identifiers for properties or sites, scopes, sync status, cursors, and error information. Connected providers may also send webhook or event data to Crawlbaby.
Integration providers have their own privacy practices and terms. Your use of those providers is also governed by their policies.
7. Cookies and local storage
Crawlbaby uses cookies and similar browser storage mainly so the app works properly. This includes keeping you signed in, maintaining session state, remembering workspace selection, and storing basic UI preferences and temporary state in the browser.
If you block cookies or clear browser storage, some parts of the app may stop working properly.
8. Sharing
We share data only where needed to operate the service or where required by law.
- Other users in your workspace or team, where you choose to invite them or grant them access to sites, snapshots, or related workspace data
- Hosting providers
- Database or storage providers
- Authentication providers
- Email delivery providers
- Infrastructure and service vendors needed to run Crawlbaby
- Connected integration providers, where a connection is initiated or maintained by the user
We may also disclose information if required by law, regulation, legal process, or lawful request; to protect the rights, security, or integrity of Crawlbaby, our users, or others; or in connection with a merger, acquisition, sale, or reorganisation.
We do not sell personal data. We do not share personal data for targeted advertising.
9. Retention
We keep data for as long as needed to operate the service, maintain records, resolve issues, and meet legal or operational requirements.
Some operational records currently appear to have specific retention windows in the implementation:
- Processed change-event rows: about 90 days
- Page-level snapshot worker rows: about 60 days
- Snapshot run rows: about 180 days
- GA4 metrics: about 180 days
Orphaned storage artefacts are cleaned up.
Some other data does not appear to have a fixed hard-coded deletion period in the current implementation. That includes snapshot history content, screenshots, diffs, and some account and workspace records.
For those categories, we generally retain data until deletion is requested, the relevant account or site is removed, or retention is no longer reasonably needed for service operation, recordkeeping, security, or legal obligations.
If you want data deleted, contact support. We will review the request and respond in line with applicable law and the role Crawlbaby plays in handling the data.
10. Security
We use reasonable technical and organisational measures to protect data handled by Crawlbaby.
This includes safeguards designed to protect account data, service data, and integration credentials. OAuth and API tokens are stored in encrypted form.
No system is perfectly secure, and we cannot guarantee absolute security.
11. User rights and choices
Depending on where you are located, you may have rights over your personal data, such as the right to request access to your data, request correction of inaccurate data, request deletion of certain data, object to or restrict certain processing where applicable, and request export of certain data where applicable.
These rights are not absolute and may depend on the law that applies and the role Crawlbaby plays in handling the data.
To make a privacy or deletion request, contact support and describe your request.
You can also manage some information directly in the app by removing tracked sites, changing workspace access, or disconnecting integrations, where those features are available.
12. International transfers
Crawlbaby currently operates from Australia and may use service providers or infrastructure that process or store data in Australia or other countries.
That means information may be processed or stored internationally, including in countries that may have different data protection rules than the country where you live.
Where required, we will use reasonable measures intended to support lawful cross-border handling of data.
13. Children
Crawlbaby is not directed to children, and we do not intend for children to use the service.
If you believe a child has provided personal data to Crawlbaby, contact support so we can review and take appropriate action.
14. Changes to this policy
We may update this Privacy Policy from time to time.
If we make material changes, we may update the date above and take reasonable steps to let users know through the app, email, or both, if appropriate.
The latest version will be posted at Crawlbaby.io.
15. Contact
If you have questions about this Privacy Policy or want to make a privacy-related request, contact Crawlbaby.io in Melbourne, Australia via contact support.