Legal

Privacy Policy

What personal data Crawle processes, on what legal basis, who it is shared with, and how long it is kept.

Version 1.1 - Last updated August 23, 2026

Data controller

Crawle AB (Swedish company registration number 559595-6862, VAT number SE559595686201) operates crawle.io and the signed-in app at app.crawle.io, and is the data controller for the account, billing, and website-monitoring data described here. Crawle's registered address is available on request.

Send privacy and data protection requests to [email protected]. Crawle has not appointed a data protection officer; that address reaches the people responsible for these requests.

When Crawle processes personal data on a customer's behalf — the content of the websites they have crawled, their Search Console data, their alert recipients, and the access logs they upload — it acts as their processor under the Data Processing Addendum, and the customer is the controller. This policy covers the data Crawle controls itself.

What we process and why

Account and workspace data — name, email address, password hash or Google profile, workspace and team membership, and role. Processed to create and run your account under Article 6(1)(b) GDPR, performance of the contract.

Authentication and security data — session records, two-factor state and trusted-device markers, sign-in IP address and user agent, and rate-limiting counters. Processed to keep accounts secure under Article 6(1)(f), our legitimate interest in preventing unauthorized access and abuse.

Website, crawl, alert, export, and integration data — processed to deliver the monitoring service under Article 6(1)(b). Where this contains personal data belonging to your own users, you are the controller and Crawle is your processor.

Billing data — subscription, plan, invoice, and payment status from Stripe. Processed to take payment under Article 6(1)(b) and to meet accounting obligations under Article 6(1)(c). Crawle does not receive or store full card numbers.

Support correspondence — the messages you send us and our replies. Processed to answer you under Article 6(1)(b) and Article 6(1)(f).

Diagnostics and error reports — application errors, performance traces, and operational logs. Processed to keep the service reliable and secure under Article 6(1)(f). For a signed-in session an error report may include your account id and email address so we can trace a fault to a reproducible case.

Marketing site analytics — measured only after you allow analytics or marketing cookies on crawle.io, under Article 6(1)(a), your consent, which you can withdraw at any time.

Historical trial records

Crawle does not currently offer free trials. If Crawle holds records from a previously offered free trial, those records may include the normalized signup email address (lowercased, with any plus-tag removed), the signup IP address, and the fingerprint Stripe reported for the payment card. Crawle does not collect these trial-abuse fields for new paid subscriptions under the current checkout.

If those historical records exist, Crawle keeps them only while needed to resolve disputes about the earlier offer or to establish, exercise, or defend legal claims, under Article 6(1)(f). The card fingerprint is an opaque identifier from Stripe, not a card number. Contact [email protected] with a request about these records.

Integrations you connect

When a workspace owner or admin connects Slack or Microsoft Teams, Crawle processes provider credentials, workspace and directory metadata, selected delivery routes, notification content, delivery records, and interaction data. Crawle uses this data to connect and administer the integration, show the destinations available for selection, deliver the notifications you configure, secure provider requests, and apply incident actions. Crawle shares the identifiers and notification content required for those tasks with Slack or Microsoft respectively. Crawle does not sell this data or use it for advertising.

Slack data — Crawle stores an encrypted OAuth bot token; the Slack workspace id and name; bot and installer user ids; and the ids and names of the default and per-site channels you select. While an admin chooses a destination, Crawle also processes the channel ids, names, and public or private status returned by Slack. Signed Slack lifecycle events and button-action payloads are processed to secure the connection and apply incident actions. When someone acknowledges an incident from Slack, Crawle stores the actor name supplied by Slack, or the label Slack when no name is available, together with the acknowledgement time. Reopening the incident clears both acknowledgement fields. Crawle's Slack app posts notifications and setup messages; it does not request or read channel message history.

Microsoft Teams data — Crawle stores the Microsoft OAuth grant encrypted at rest, including the access and refresh credentials and their expiry and granted scope; the tenant and organization identifiers; the connecting user's id, name, and email; and the ids and names of the default and per-site teams and channels you select. While an admin chooses a destination, Crawle also processes the team and channel ids, names, and membership type returned by Microsoft Graph. For bot delivery, Crawle stores conversation references such as tenant, team, channel, conversation, and service identifiers, installation metadata, and the Bot Framework activity used to establish or update the reference. When someone acknowledges an incident from Teams, Crawle stores the actor name supplied by Teams, or the label Teams when no name is available, together with the acknowledgement time. Reopening the incident clears both acknowledgement fields. Microsoft Graph is used for connection and channel selection; Crawle's bot posts notifications and does not request or read channel message history.

Notification and delivery data — Slack and Microsoft Teams notifications contain information about monitored sites, including incidents, changed pages, and crawl status. Crawle's queue and delivery records can include the destination, state, attempt count, timestamps, outcome codes, and provider message identifiers. The underlying incidents, digests, and site data are Crawle workspace records. Disconnecting a chat integration does not delete those records.

Disconnecting Slack — Disconnect in Crawle attempts to revoke the OAuth bot token and removes Crawle's stored token and default Slack route, clears per-site Slack channel selections, disables OAuth-backed Slack notification delivery, and removes Slack from pending digest deliveries. A signed Slack app-uninstall or bot-token-revocation event applies the same local cleanup. A separately configured legacy Slack webhook remains until that notification setting is removed. Disconnect does not delete Slack channel-setup delivery receipts, incident or digest records, or messages already delivered to Slack.

Disconnecting Microsoft Teams — Disconnect in Crawle removes the integration record that contains the encrypted Microsoft Graph grant and default Teams route, so Crawle no longer sends Teams bot notifications for that workspace. Per-site Teams selections and stored conversation references and Bot Framework activities are separate workspace records and are not deleted merely by disconnecting. Revoking delegated Microsoft Graph access stops directory access once Crawle detects the revocation, but bot delivery uses the separately installed Teams app and can remain available while that app is installed. Removing the app in Microsoft Teams can prevent further delivery, but does not delete Crawle records or messages already delivered in Teams.

Retention and requests: Crawle does not state a separate fixed retention period for Slack or Microsoft Teams routing, delivery, or conversation-reference records. The disconnect behavior above is the immediate integration cleanup Crawle currently provides; it does not delete the retained operational records named there. A completed account or workspace deletion removes the stored Slack OAuth token, Microsoft Teams integration grant and default route, and Teams conversation references for that workspace. Messages already delivered into a customer-controlled Slack or Microsoft Teams workspace remain under that customer's provider retention settings. To request access, transfer, correction, or deletion of integration data, contact [email protected].

When a user connects Google Search Console, Crawle requests read-only Search Console access for verified properties. Crawle uses this data to show search performance, URL Inspection indexation snapshots, and Google field Core Web Vitals context inside the connected workspace. Crawle does not use Google Search Console data for advertising, does not sell it, and does not transfer it to unrelated third parties.

Crawle's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Users can revoke Google access from their Google Account permissions page or disconnect the integration in Crawle; deletion requests can be sent to [email protected].

Cookies and consent

On crawle.io, necessary cookies are always active, and analytics and marketing cookies are used only after you consent through the cookie banner. app.crawle.io uses strictly necessary cookies only and shows no banner. The Cookie Policy lists each cookie and explains how to change or withdraw consent.

Who we share data with

Crawle does not sell personal data. It is shared with the service providers that run the service on Crawle's behalf under contract, and with authorities where the law requires it. The current providers are listed in full in the sub-processor annex of the Data Processing Addendum: Hetzner (hosting and backup storage), HostUp (dedicated infrastructure where enabled), Cloudflare (DNS, delivery, and bot protection), Amazon Web Services (transactional email and access-log infrastructure where enabled), Stripe (billing), Google (sign-in and Search Console; marketing-site analytics only when enabled after consent), Slack and Microsoft (alert delivery), and Sentry (error monitoring).

Crawle gives at least 30 days' notice before adding or replacing a provider that processes customer data.

International transfers

Crawle hosts the service in the EU and EEA. Where one of the providers above processes personal data outside the EEA, the transfer relies on that provider's own European Commission Standard Contractual Clauses and the supplementary measures documented in its data processing agreement. Copies of the relevant provider terms are available on request.

How long we keep data

Account and workspace data — for as long as the account exists. Deleting an account starts a 30-day grace period. At the end of that period the deletion workflow begins across the active services that hold workspace data. Backup copies cannot be erased individually and age out under the applicable retention schedule. Contact [email protected] for a completion record; Crawle does not promise a fixed completion window without that record.

Historical crawl records in a paid workspace — up to 2 years as baseline, event, and change records, so you can review changes, produce audit trails, and generate exports. Hot crawler stores may keep recent operational data separately for performance.

Audit and security records — retained beyond account deletion in anonymized form, with the account identifier removed, so that a record of what happened on the platform survives without identifying you.

Historical trial records - if Crawle holds records from a previously offered free trial, the normalized email, signup IP, and card fingerprint are kept only while needed to resolve disputes about that earlier offer or to establish, exercise, or defend legal claims.

Billing and tax records — for as long as Swedish accounting law requires. Error reports and operational logs — for a limited diagnostic window, then discarded.

Your rights

You have the right to access your personal data, to correct it, to have it deleted, to restrict or object to processing, to receive a copy in a portable format, and to withdraw consent at any time without affecting processing already carried out.

You can export workspace data and request account deletion from the app, and you can withdraw cookie consent from Cookie settings in the footer of any crawle.io page. For anything else, contact [email protected]. Crawle responds within one month and may ask you to confirm your identity first.

If you are unhappy with how Crawle handles your data you can complain to a supervisory authority. Crawle AB is established in Sweden, so its lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). You can also complain to the authority where you live or work.

Invitation requests

If you request an invitation to Crawle, Crawle stores the email, optional company, selected current tool, buyer type, notes, source, referrer, IP address, and user agent needed to operate the invitation request, prevent abuse, and send invitation-related transactional email, under Article 6(1)(f). This data is deleted on request by contacting support.

Changes to this policy

Crawle updates this policy as the service changes. The version and date at the top of the page show which text is current, and material changes are announced by email to account holders before they take effect.

Contact

To request access, correction, deletion, or other privacy help, contact [email protected].