Privacy policy
This page explains what CurlShot knows about you, what we do with it, who else receives it, and what you can ask us to do. We collect what the service needs to run and no more.
Last updated
1. Who is responsible for your data
CurlShot is the operator of this website and of the service. We decide why and how the personal data described on this page is used, which makes us its "controller" under the EU and UK General Data Protection Regulation (GDPR). You can reach us about privacy through the contact form or [email protected].
One case is different. The pages you capture and the HTML or Markdown you send may contain personal data of other people. For that data you are the controller and we only process it for you, under the data processing addendum. If you are one of those people and want to use your rights, contact the customer who made the screenshot; if you write to us, we will pass your request on where we can identify that customer.
2. What we collect
Account details
Your email address, your name and company if you give them, and a password stored only as a salted hash. If you sign in with Google and GitHub, we receive the basic profile that provider shares: your email address, name and picture. We also keep your email preferences, the time you last used the dashboard, and the link you arrived through if someone referred you.
Sign-up records
When someone tries to create an account we record the email address, the IP address, the browser's user agent and whether the attempt succeeded, to stop automated and repeated sign-ups.
What you send to the API
The address you ask us to capture and the options of the request. If you send HTML, Markdown, CSS or scripts, we process them to make the render. Values that look like credentials (cookies, authorization and similar headers) are removed or masked before a request is written to your history.
The results and your history
The rendered image, PDF or video is stored for a limited time so it can be cached and downloaded. For each request we keep a record in your history: the address, the options, the size, the timing, success or failure, the access key used and the IP address the request came from.
Technical data
IP addresses and basic request details, used to enforce rate limits, prevent abuse and investigate errors. Error reports from our own software include the page of the site where the error happened and technical details of the browser; they are set up not to include your account details.
Billing
Payments are handled by Dodo Payments, which collects your payment details, billing address and tax information as the merchant of record. We send it your email address and name to start the checkout, and receive the status of your subscription and payments, the amount, the currency and the invoice record. We never receive your full card number.
Messages and email
What you write to us through the contact form or by email, with your name and email address, so we can answer. For the email we send you, we keep a log of the message, and our delivery provider reports whether it was delivered or bounced and, where it measures that, whether it was opened or a link in it was clicked. We also keep a record of when you subscribed to or unsubscribed from a kind of email, as proof of your choice.
What we do not collect
We do not ask for, and the service is not meant for, special categories of data such as health, religion or political opinions. We do not buy data about you from anyone, and we do not build advertising profiles.
3. Why we use it and on what legal basis
Under the GDPR we need a legal basis for each use. These are ours:
- To provide the service you asked for: create and secure your account, render, cache and deliver screenshots, show your history, count usage against your plan, bill paid plans, answer your questions, and send account email such as verification, password resets, payment and quota notices. Basis: performing our contract with you.
- To keep the service safe: rate limits, detection of abuse, fraud and repeated free sign-ups, error reports, backups, and enforcing our terms. Basis: our legitimate interest in a secure and reliable service that is not misused.
- To understand and improve the service: page view counts that identify nobody, and measuring whether our email reaches people. Basis: our legitimate interest in knowing what works.
- To send product news and tips to account holders about the service they use, and the newsletter to people who signed up for it. Basis: our legitimate interest in keeping customers informed for account holders, and your consent for the newsletter. Every such message has an unsubscribe link, and you can switch each kind off in the dashboard settings.
- To meet legal duties: tax and accounting records, answering lawful requests from authorities, and handling requests about your rights. Basis: legal obligation.
- To establish, exercise or defend legal claims. Basis: our legitimate interest in protecting our rights.
You do not have to give us any data, but without an email address we cannot open an account, and without the address of a page we cannot capture it.
We do not sell your data, we do not share it for advertising, and we do not use the pages you capture or the content you send to train machine-learning models.
4. Cookies and page view counts
The cookies needed to keep you signed in, to protect forms and to remember your cookie choice are always on. Anything optional, such as remembering a referral link or the spam check by Google on some forms, is used only after you allow it in the cookie banner, on the basis of your consent, which you can withdraw at any time in the cookie settings at the bottom of every page. There are no advertising cookies and no outside analytics. The cookie policy lists every one of them.
We count page views ourselves to see which pages are useful. The count uses no cookie and no outside analytics service. It records the path of the page and the site a visit came from. To count visitors once a day, your IP address and browser type are turned into a scrambled value that changes every day and cannot be turned back; the address itself is never stored.
5. Who receives it
We share personal data only with the companies that help us run the service, and only what each one needs. Each of them works under a contract that binds it to our instructions and to confidentiality:
- hosting providers, which run the servers and the database;
- Dodo Payments, which sells the paid plans as merchant of record and is itself responsible for the payment data it collects;
- Cloudflare, which delivers our email;
- Sentry, which receives error reports from our software;
- Google and GitHub, if you choose to sign in that way: the provider learns that you signed in to CurlShot;
- a messaging service through which our own team receives operational alerts.
Beyond that, data is disclosed only in these cases:
- The sites you capture. When you ask us to capture a page, our browser visits that site, so the site sees a request from our servers and anything you told us to send with it. It does not see your identity or your IP address.
- Legal requests. We disclose data when the law requires it, or when it is needed to protect someone's safety or our rights. We check that a request is valid and hand over no more than it requires.
- A change of ownership. If the service is sold or merged, your data passes to the new operator, who stays bound by this policy. We will tell you before that happens.
6. Transfers to other countries
Some of these companies are located, or keep data, outside the country where you live, including in the United States. When personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country that has not been recognised as giving adequate protection, the transfer is covered by a safeguard the law accepts: the provider's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions, or the standard contractual clauses approved by the European Commission (with the UK addendum where it applies). Ask us if you want a copy of the safeguard used for a given provider.
7. How long we keep it
- Rendered files: until the end of their cache lifetime, which you can set per request and which is never longer than 30 days. Then the file is deleted automatically.
- Request history: 30 days, then deleted automatically.
- Account details: while the account exists.
- Email log: 180 days; the text of each message is dropped earlier.
- Contact messages and sign-up records: as long as we need them to answer you, to detect repeated abuse and to keep a record of how a request was handled, and then deleted.
- Page view counts: 400 days. They contain no personal data.
- Payment and invoice records: as long as tax and accounting law requires, which in most countries is between five and ten years.
- Backups: a small rolling set of recent backups, each overwritten by a newer one in turn.
When you delete your account, your email address, name, company, picture and password are erased from it at once, your access keys stop working and your sign-in links to other providers are removed. Your request history and stored files are then deleted on the schedule above. We keep the payment records the law requires, and for 30 days we use a scrambled, irreversible fingerprint of the old email address only to stop the free allowance from being claimed again by opening a new account.
8. Your rights
In the dashboard you can see and change your account details, change your email preferences, revoke your access keys and delete your account. Wherever you live, you can also ask us to:
- tell you whether we hold data about you and give you a copy of it;
- correct data that is wrong or incomplete;
- delete your data, where we have no legal reason to keep it;
- restrict how we use it while a complaint is looked at;
- hand you the data you gave us in a common, machine-readable format, or send it to another service;
- stop a use that is based on our legitimate interests, by objecting to it, and stop marketing email at any time;
- withdraw a consent you gave, without affecting what was done before.
To use any of these rights, write to us through the contact form or [email protected]. It costs nothing. We may ask for something that confirms the request comes from the account holder, and we answer within one month; if a request is complex we may need up to two more months and will tell you so.
If you think we handle your data wrongly, please tell us first so we can fix it. You also have the right to complain to the data protection authority of the country where you live or work, or where the problem happened.
9. Residents of California and other US states
This section adds what the privacy laws of California and other US states ask us to state. In the last 12 months we collected these categories of personal information, from you directly and from your use of the service, for the purposes listed above: identifiers (name, email address, IP address), commercial information (plan and payment history), internet activity (your requests to the API and your use of the dashboard), and the content you chose to send. We disclosed them only to the service providers listed above, for business purposes.
- We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so.
- We do not use or disclose sensitive personal information for anything other than providing the service.
- You have the right to know what we hold, to get a copy, to have it corrected or deleted, and to appeal if we refuse a request. Write to us as described above; an agent you have authorised in writing may do so for you.
- We will not treat you differently for using these rights.
Because we do not sell or share personal information, there is nothing to opt out of. If your browser sends a "Global Privacy Control" or "Do Not Track" signal, we still honour it: we treat it as a refusal of every optional cookie and outside service.
10. Children
The service is for adults who build or run software. It is not directed at children, an account requires you to be at least 18, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
11. Automated checks
Software checks sign-ups, requests and referral rewards for signs of abuse, for example a throwaway email address, too many accounts from one place, or requests aimed at private networks. A check can refuse a sign-up or a request, or hold a reward for review. We make no decisions about you by automated means that have legal or similarly significant effects, and if you think a check got it wrong, write to us and a person will look at it.
12. Security
Traffic is encrypted in transit. Passwords are hashed, and API secret keys and the tokens of connected services are stored encrypted. Every render runs in its own private browser context that is destroyed afterwards, so one customer's cookies or content never reach another's render. Access to production systems is limited to the people who need it.
No system is perfectly secure. If we learn of a breach that puts your data at risk, we will tell you and the competent authority without undue delay, as the law requires.
13. Changes
We update this policy when the service or the law changes. The date at the top shows the latest version. If a change matters for how your data is used, we will tell you by email or in the dashboard before it takes effect.
14. Contact
Privacy questions and requests: use the contact form or [email protected]. The rules for using the service are in the terms of service.