OrbiCrawl AI

Legal

Privacy policy

Effective date:

This policy explains how OrbiCrawl AI (“OrbiCrawl”, “we”, “us”) collects, uses and protects personal data when you use our website, dashboard, API, SDKs and browser extension (together, the “Service”).

Two roles matter throughout this document. For your account data (who you are, how you pay, how you use the Service) we act as the data controller. For crawled data that you collect through the platform, you are the controller and we act as your data processor under our Data Processing Addendum.

1. Data we collect

Account data. When you sign in with Google we receive your name, email address and profile picture. We never see your Google password.

Billing data. Payments are processed by Razorpay. We store your plan, credit balance, invoices and transaction references. We never store card numbers, UPI handles or bank credentials — those are handled entirely by the payment provider.

Usage data. Crawl jobs you create, schedules, workflows, API-key metadata (never the raw key after creation), security events (sign-ins, key creation/revocation) and service logs needed to operate and secure the platform.

Support data. Messages you send to support, including any attachments you choose to share.

2. Crawled data (you are the controller)

When you run a crawl, the platform collects publicly available information from the websites you target: contact emails, phone numbers, social profiles, company details, technology and SEO signals. This data may include personal data of third parties (for example, a business owner’s published email address).

  • You decide which websites to crawl, what to extract and how long to keep it; we process it only to provide the Service to you.
  • You are responsible for having a lawful basis to collect and use this data (e.g. legitimate interest for B2B outreach under GDPR) and for honoring objections and unsubscribe requests you receive.
  • Our Acceptable Use Policy prohibits crawling for unlawful purposes.

3. How we use data

  • Provide, operate and secure the Service (contract performance).
  • Process payments, prevent fraud and keep required financial records (legal obligation).
  • Run AI features you invoke — enrichment, scoring, outreach drafts. Content sent to our AI inference provider is used only to generate your result and is not used to train models.
  • Send transactional email (receipts, job completion, security alerts). We send marketing email only with consent, and every message has an unsubscribe link.
  • Improve the Service using aggregated, de-identified usage statistics.

4. Sharing and subprocessors

We never sell personal data. We share it only with subprocessors that help us run the Service, under contracts that protect it:

  • Cloud infrastructure and managed databases (hosting, PostgreSQL, Redis).
  • S3-compatible object storage (exports, uploaded CSVs).
  • Razorpay (payment processing).
  • Google (sign-in).
  • An AI inference provider (only for AI features you invoke).
  • Integrations you connect (your CRM, webhook endpoints, Zapier/Make/n8n) — data flows there only when you push it or a workflow you configured does.

We may disclose data if required by law, after verifying the request is valid and, where lawful, notifying you.

5. Retention and deletion

  • Account data: kept while your account is active.
  • Crawled data and exports: kept until you delete them or your account closes; export download links expire automatically.
  • On account deletion we erase personal data within 30 days, except invoices and records we must keep for tax and accounting law.
  • Backups roll off within 35 days of deletion.

6. Security

  • TLS encryption in transit; encryption at rest for stored data.
  • Session tokens are short-lived and kept in memory; refresh tokens live in HttpOnly cookies unreadable by page scripts.
  • API keys are shown once and stored only as salted hashes.
  • Role-based access, audit logging and least-privilege access internally.
  • If a breach affects your data we will notify you without undue delay, within 72 hours of confirmation where GDPR applies.

7. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, India’s DPDP Act), you may have the right to access, correct, export, delete or restrict the processing of your personal data, and to object to processing or withdraw consent.

Exercise any of these by emailing privacy@orbicrawl.com from your account email. We respond within 30 days. You may also lodge a complaint with your local supervisory authority.

Third parties found in crawled data: if your information was collected by one of our customers through the platform, contact that customer (the controller); we will also forward requests we receive to the relevant customer and remove data from our systems where the law requires.

8. Grievance redressal

For users in India, our Grievance Officer handles complaints about the processing of your personal data under the DPDP Act. Contact the Grievance Officer at privacy@orbicrawl.com. We acknowledge and respond within 30 days, consistent with our response commitment above.

9. International transfers

Our infrastructure may process data in more than one region. Where data moves across borders from the EEA/UK we rely on adequacy decisions or Standard Contractual Clauses. A current list of subprocessor locations is available on request.

10. Children

The Service is for business use and not directed at anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Service evolves. Material changes are announced by email or an in-app notice at least 14 days before they take effect. The effective date above always reflects the current version.

Questions about this document? Contact legal@orbicrawl.com. For privacy requests use privacy@orbicrawl.com; for billing, billing@orbicrawl.com.