Draft — pending legal review. Do not publish to a paying customer as it stands.
This document was written to describe accurately what the product does, how it charges, and where data goes. It was not written by a lawyer, it makes no claim about which laws it satisfies, and every value shown as [LIKE THIS] still has to be decided and filled in by a human.
Legal
Privacy Policy
Effective [EFFECTIVE DATE] · Last updated [EFFECTIVE DATE]
1. Who is responsible
Scrape Supply is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], registered in [COUNTRY OF INCORPORATION]. For questions about data, contact [CONTACT EMAIL] or [DPO CONTACT].
This policy covers two quite different things, and it keeps them separate throughout: data about you, our customer (section 2), and data the service collects for you, the business listings a scrape returns (section 4).
2. What we collect about you
- Your email address — used to sign you in, to send account emails, and to contact you about your account.
- Your password, if you did not sign in with Google — stored only as a one-way hash by Supabase Auth. We never see or store the password itself.
- Your organisation’s name, which you choose.
- Your credit balance and transaction history — every purchase, reservation and settlement, so you can audit what you were charged.
- Your scrape history — the search terms and locations you ran, when, and what they returned.
- A Stripe customer identifier, so a repeat purchase attaches to the same customer record at Stripe.
We never receive, hold or process your card details. Payment happens on a checkout page hosted by Stripe; your card number goes from your browser to Stripe and never passes through our systems.
Cookies
The service sets one kind of cookie: the authentication session cookie issued by Supabase Auth, which is what keeps you signed in. It is necessary for the service to work at all.
There are no analytics, advertising or tracking cookies, and no third-party tracking scripts on any page. If that changes, this section changes with it.
3. What we do with it
- Sign you in and keep you signed in.
- Run the scrapes you ask for and show you the results.
- Account for credits — take payment, grant credits, reserve them against a scrape and settle the difference.
- Send you account email: sign-up confirmation, password reset, and notices about the service.
- Keep the service working and secure — diagnose failures, investigate abuse.
We do not sell your personal data, and we do not use it for advertising. We do not send you marketing email unless you ask for it.
4. The data the service collects for you
When you run a scrape, we retrieve publicly listed business information from Google Maps for the term and place you chose: business name, phone number, street address, website, rating, review count and coordinates, plus the raw listing record.
This is business contact information as published by the business itself on a public directory. It is not, by intent, information about private individuals — we do not scrape consumer profiles, personal social accounts or contact details that were not published as a business listing.
That said: a sole trader’s business number is often also a personal number, and in some countries information about an identifiable individual acting in a business capacity is still personal data. We state this plainly rather than assume it away. Whether we act as a controller or a processor for this data, and what that means for you as our customer, is a legal determination: [CONTROLLER / PROCESSOR DETERMINATION].
Under the Terms of Service, having a lawful basis to contact the businesses in your results is your responsibility.
Phone verification
Where a listing has a phone number, that number is sent to ClearoutPhone, a third-party verification provider, which returns whether the number is valid and what type of line it is. That result decides whether the lead is charged for. Only the phone number is sent — not your account details, and not the rest of the listing.
5. Who else sees data
We use the following service providers. Each sees only what it needs to do its job.
Supabase
Database, authentication and file storage
Sees: Your account, your organisation, your scrapes and all lead records
Vercel
Hosting for the web application
Sees: Request metadata (IP address, user agent) as part of serving pages
Stripe
Payment processing and hosted checkout
Sees: Your email, the amount, and your card details — which go to Stripe directly and never through us
Resend
Transactional email delivery
Sees: Your email address and the content of account emails (confirmation, password reset)
ClearoutPhone
Phone number verification
Sees: The phone numbers found on scraped business listings
A dedicated server we operate
Runs the scraping engine
Sees: Your search terms, and the listing data retrieved for them
These providers operate in [SUB-PROCESSOR LOCATIONS]. Where data moves between countries, the mechanism relied on is [INTERNATIONAL TRANSFER MECHANISM].
We may also disclose data where we are legally required to, or to establish or defend legal claims.
6. How long we keep it
Your account, credit history and scrape results are kept for as long as your account is open, and then for [DATA RETENTION PERIOD].
To delete your account and its data, [ACCOUNT DELETION PROCESS]. Some records may have to be kept longer where the law requires it — for example, records of payments for tax purposes.
No retention or deletion period has been set yet, and rather than print a plausible-looking number we have left it blank. A published retention period is a promise, and this one has to be made by a human.
7. How it is protected
- All traffic to the service is encrypted in transit (HTTPS).
- Every record belongs to exactly one organisation, and the database enforces that with row-level security — one customer cannot read another’s data even if the application asked it to.
- Passwords are stored only as one-way hashes, by Supabase Auth.
- Administrative database credentials are held on the server side only and are never sent to the browser.
No system is perfectly secure, and we do not claim otherwise.
8. Your rights over your data
Depending on where you live, you may have rights to access, correct, delete, export or restrict the use of your personal data, and to object to certain processing. The rights that actually apply to you, and the legal basis we rely on, depend on [APPLICABLE PRIVACY LAW] — which is a determination for legal review, not one this document makes.
This policy makes no claim to comply with any particular privacy law. It describes what actually happens, so that a lawyer can decide what that satisfies and what has to change.
To make a request, or to complain about how we have handled your data, contact [CONTACT EMAIL] or [DPO CONTACT]. You may also have the right to complain to a data protection authority in your country.
9. Children
The service is a business tool and is not directed at children. We do not knowingly collect data from anyone under the age at which they can consent on their own behalf under [APPLICABLE PRIVACY LAW].
10. Changes
If we change this policy we will update the date at the top, and where the change materially affects you we will tell you by email with [TERMS CHANGE NOTICE PERIOD] notice.
11. Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Email [CONTACT EMAIL]. Data protection contact: [DPO CONTACT].