Legal Document

Privacy Policy

Version 2.0. Effective date: 20 September 2026 (replaces the version dated 20 December 2025)

This Privacy Policy explains how MB "Reikalita", trading as ScrapeBadger, collects and uses personal data when you visit scrapebadger.com or docs.scrapebadger.com, create an account, use the ScrapeBadger services, contact us, or otherwise interact with us. It also explains what happens to personal data that our customers retrieve through the services, and what you can do if you think that includes data about you (section 6).

Capitalised terms not defined here have the meaning given in the ScrapeBadger Terms of Service ("Terms") or the Third-Party Content and Intellectual Property Policy ("Content Policy").

1. Who we are

The controller of the personal data described in this Policy is:

MB "Reikalita" (trading as ScrapeBadger) A small partnership (mažoji bendrija) registered in the Republic of Lithuania Legal entity code: 306684138 Registered office: Ramioji g. 12, Bajorų k., Vilniaus raj., Lithuania Email for privacy matters: legal@scrapebadger.com (subject line "Privacy Request")

We have not appointed a data protection officer, because we are not required to. Privacy questions and requests go to the address above and are handled by the founders.

2. Who this Policy covers

This Policy applies to:

(a) visitors to our websites and documentation;

(b) customers and their users: people who create an Account, generate API keys, buy Credits or use the Services, including team members added to an Account and people who use the Services through our SDKs, CLI, MCP server or marketplace integrations (for example Apify);

(c) business contacts: people who contact us, request a demo or sample, take part in our affiliate or free-credit programmes, or whom we contact about the Services in their professional capacity;

(d) people whose personal data appears in Output retrieved by our customers. For that data we are a processor acting for the customer, not the controller; section 6 explains what that means for you.

3. Personal data we collect

We collect the following categories of personal data. Where we get it from someone other than you, we say so.

3.1 Account data. Name, email address, password (stored as a salted hash, never in clear text), company name, country, VAT number where you provide one, billing address, the Access Channels you use, API keys, team members you add, and your Account settings and configurations, including filter rules, stream-monitor settings and webhook URLs, which we keep for as long as your Account is open. Your name, email address and billing details are needed to conclude and perform the contract with you; without them we cannot open an Account or issue invoices. A VAT number is needed only to apply the correct tax treatment. If you add team members, we inform them of this Policy in the invitation email. If you sign in with Google or GitHub, we receive from them your name, email address and profile picture, and an identifier for your account with them; we do not receive your password.

3.2 Usage Data. When you use the Services we record metadata about each Request: the endpoint used, the Source URL or query parameters you submitted, the timestamp, the originating IP address, the response status, Credits consumed and error information. We also record dashboard activity such as logins, key creation and plan changes. Usage Data does not include the content returned by the Services (see 3.5).

3.3 Payment data. Our payment processors handle card details; we never see or store full card numbers. We receive from them the payment status, the last four digits and card brand, the billing name and address, and invoices. If you pay in cryptocurrency, our crypto-payment processor gives us the transaction status and a reference; we do not store wallet addresses beyond what appears in that reference.

3.4 Communications. Emails, support requests, chat messages, survey answers, reviews you tell us about, and anything else you send us, together with our replies.

3.5 Output (content retrieved for customers). We do not store the content that the Services retrieve for customers. Output is delivered to the customer in the response to their Request and is not written to our databases, logs or backups. It is processed only in memory for the seconds it takes to retrieve, parse and return it.

3.6 Website data. When you visit our websites our servers and Cloudflare record security and access logs: IP address, browser and device information, the pages requested, the referrer and timestamps. Separately, and only with your consent, our analytics tools record analytics events (pages viewed, clicks, feature usage) as described in our Cookie Policy.

3.7 Business-contact data. If you contact us, or if we contact you about the Services in your professional capacity, we hold your name, role, company, business email, the contents of our correspondence, and notes about the conversation. We obtain prospect data from your company's own website, your public professional profiles, and business directories, or from you directly. Where we obtained your details from a public source, we link to this Policy in the first message we send you.

3.8 Programme data. If you join the affiliate programme or claim free credits for a review or a social follow, we record the referral link or code, the reviews or follows you tell us about, and the credits granted.

We do not knowingly collect special categories of personal data (such as health, religion, political opinions or biometric data) about the people described in this section, and we ask you not to send us any.

4. Why we use personal data and on what legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Creating and administering your Account, authenticating you, providing the Services, metering Credits, sending service emails (invoices, usage alerts, security notices)Account data, Usage Data, payment dataPerformance of a contract with you, Art. 6(1)(b)
Billing, invoicing, tax and accounting recordsAccount data, payment dataLegal obligation, Art. 6(1)(c) (Lithuanian accounting and tax law)
Securing the Services: detecting abuse, fraud, credential compromise, multi-account abuse, breaches of the Terms and Acceptable Use PolicyUsage Data, Account data, website dataLegitimate interests, Art. 6(1)(f): protecting our systems, our customers and the Sources; performance of a contract
Handling notices and complaints from rights holders, Sources, data subjects and authorities under our Content Policy, including identifying the customer responsible for a RequestUsage Data, Account data, communicationsLegitimate interests, Art. 6(1)(f): meeting our obligations as a diligent operator and defending legal claims; legal obligation where a request is binding on us
Customer supportAccount data, communications, Usage DataPerformance of a contract; legitimate interests
Improving the Services: aggregate analytics about which endpoints are used, error rates, performanceUsage Data (aggregated or de-identified), website dataLegitimate interests, Art. 6(1)(f)
Website analytics (PostHog, Google Analytics)Analytics events, cookiesConsent, Art. 6(1)(a), given through the cookie banner; you can withdraw it at any time
Remembering your preferences on the Sites (for example dark mode, dashboard layout)Functional cookies and local storage, set only when you choose the preferenceLegitimate interests, Art. 6(1)(f), in providing the customisation you asked for
Emails to Account holders about new scrapers, features, offers and free-credit promotionsAccount dataLegitimate interests, Art. 6(1)(f), in keeping the people who use our Services informed about them and in marketing our own similar services to them (Article 13(2) of Directive 2002/58/EC as transposed in the Lithuanian Law on Electronic Communications). You can opt out when you create your Account and through the link in every email, and we stop immediately
Marketing emails to people who do not hold an AccountBusiness-contact dataConsent, Art. 6(1)(a), or, for people we contact in their professional capacity, the legitimate interest described in the next row
Business-to-business outreach to prospects in their professional capacityBusiness-contact dataLegitimate interests, Art. 6(1)(f), in promoting the Services to businesses that may need them; we honour every opt-out immediately
Affiliate and free-credit programmesProgramme data, Account dataPerformance of a contract
Establishing, exercising or defending legal claims; complying with court orders and lawful requests from authoritiesAny of the aboveLegitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c)

Where we rely on legitimate interests we have assessed that our interests are not overridden by your rights, taking into account what you would reasonably expect and the limited nature of the data. You can ask us for a summary of that assessment and you can object (section 10).

We use automated checks to detect abuse, fraud and compromised credentials (for example unusual request patterns or multiple accounts), and our payment processor runs automated fraud screening on payments. An automated flag may lead to a temporary restriction, but no Account is terminated and no dispute is decided without human review, and you can contest any automated decision by writing to us.

5. Usage Data and what it reveals

Because Usage Data includes the Source URLs and query parameters that customers submit, it may reveal what a customer is researching and, occasionally, may itself contain personal data (for example a URL that includes a username). We keep Usage Data for ninety (90) days, and for longer only where a specific notice, complaint, dispute or legal claim requires it, in which case we keep only the records relevant to that matter until it is closed. We use Usage Data for the purposes in section 4 and do not use it to profile customers for marketing or to build datasets about the people whose data customers retrieve.

6. Personal data in Output: if you think our customers retrieved data about you

6.1 Our role. ScrapeBadger is a technical tool. Customers decide which publicly available Sources to query and what to do with the results. For any personal data contained in Output, the customer is the controller and we act only as their processor for the seconds it takes to retrieve and deliver the content, under the Data Processing Agreement. We do not keep Output, do not build profiles or datasets from it, and do not sell it.

6.2 What we require from customers. Our Terms, Acceptable Use Policy and Content Policy require customers to have a lawful basis for any personal data they collect, to inform data subjects where the law requires it, to honour data-subject rights, and not to target special categories of data, data about children, or data for surveillance, harassment, facial recognition or unlawful profiling. We can suspend or terminate customers who breach those rules.

6.3 Your rights against the customer. Your rights of access, erasure, objection and the others listed in section 10 are exercisable against the customer that holds your data. If you know which company that is, contact them directly.

6.4 What we can do for you. If you do not know who the customer is, or you believe the Services were used to collect data about you unlawfully, write to legal@scrapebadger.com with the subject line "Privacy Request", telling us as precisely as you can what data is concerned and where you saw it. Where our Usage Data allows us to identify the customer, we will forward your request to them and ask them to respond to you. Separately, where a request shows a breach of our Terms or Acceptable Use Policy, we may exercise our own rights under the Terms (clauses 6.3 and 16.3(b)) to restrict the customer's access to the relevant Source or content or to suspend the Account. We will confirm within one month whether we have been able to forward your request. We cannot give you a copy of the data itself, because we do not hold it.

7. Who we share personal data with

We share personal data only with the recipients below, only for the purposes described, and under contracts that require them to protect it. Recipients marked "processor" act on our instructions under Article 28 GDPR; recipients marked "independent" decide for themselves how they use the data, under their own privacy notices.

RecipientPurposeDataLocation and transfer safeguardRole
Hetzner Online GmbHHosting of our servers, databases and backupsAccount data, Usage Data, communicationsGermany and Finland (EU)Processor
Cloudflare, Inc.Content delivery, DDoS protection, bot protection (Turnstile) on our websites and API edgeIP address, request headers, website data; Output in transit (see DPA Annex III)Global network; EU-US Data Privacy Framework and EU Standard Contractual ClausesProcessor
Stripe Payments Europe, Ltd. (and Stripe, Inc.)Card and subscription payments, invoicing, fraud screeningPayment data, billing name and address, emailIreland; US processing under the EU-US Data Privacy Framework and Standard Contractual ClausesProcessor for payment processing; independent controller for its own fraud-prevention and regulatory obligations
UAB CoinGateCryptocurrency payments for pay-as-you-go top-upsEmail, transaction reference, amountLithuania (EU)Independent controller (regulated payment provider)
PostHog, Inc.Product analytics and session recordings on our website and dashboard (with your consent)Analytics events, session recordings with inputs and API responses masked, pseudonymous identifiers, and in the dashboard your Account identifierUnited States (PostHog Cloud US); Standard Contractual ClausesProcessor
Google Ireland Ltd. (Google Analytics)Website analytics (with your consent)Website data, pseudonymous identifiersIreland; US processing under the EU-US Data Privacy FrameworkProcessor
Google LLC and GitHub, Inc.Sign-in with Google / GitHub, where you choose itName, email, profile picture, account identifierUS; EU-US Data Privacy FrameworkIndependent controllers for their own services
Hostinger International Ltd.Hosting of our mailboxes (support@, legal@) and delivery of the emails we send youName, email, communications, email delivery eventsEuropean UnionProcessor
AI model providers and proxy and network infrastructure providersSub-processors of the content retrieved for customers (Output), as described in Annex III of the Data Processing AgreementOutput in transit, no Account dataSee DPA Annex IIIProcessor (for Output, acting for the customer)
Apify Technologies s.r.o.Where you use ScrapeBadger through the Apify platformData you provide to ApifyCzech Republic (EU)Independent controller for the Apify platform
Accountants, lawyers, auditors, insurersProfessional advice, accounting, disputesAs necessary for the matterLithuania / EUIndependent controllers or processors depending on the service
Courts, authorities, rights holdersWhere required by law, court order or lawful request, or to establish, exercise or defend legal claims, including under our Content PolicyAccount data, Usage DataAs requiredIndependent controllers

The sub-processors that handle personal data on behalf of our customers (Output) are listed separately in Annex III of the Data Processing Agreement. We will not sell personal data and do not share it with third parties for their own marketing.

If we sell or reorganise our business, personal data may be transferred to the buyer or successor, who must continue to honour this Policy.

8. International transfers

Our own servers are in the European Union. Some of the providers in section 7 process data in the United States or route traffic through global networks. Where personal data leaves the European Economic Area we rely on one of the following safeguards: an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for certified US companies), or the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented where needed by additional measures such as encryption in transit and at rest. You can ask us at legal@scrapebadger.com for a copy of the relevant safeguard.

9. How long we keep personal data

DataRetention
Account dataFor as long as your Account is open, then deleted or anonymised within thirty (30) days of closure, except as stated below
Usage DataNinety (90) days from the Request, or longer only for a specific notice, complaint, dispute or legal claim
OutputNot stored
Invoices, payment records and other accounting documentsTen (10) years from the end of the financial year in which they were issued, as required by Lithuanian accounting law
Support and other correspondenceTwo (2) years from the last message, or longer if needed for a dispute
Records of marketing consent and of unsubscribesFor as long as the consent is valid and three (3) years afterwards, so that we can prove it; cookie choices are stored in your browser for twelve (12) months (Cookie Policy)
Business-contact data of prospectsTwelve (12) months from our last contact if you have not responded; immediately on request
Notices, complaints, Strike records and enforcement decisions under the Content PolicyTwenty-four (24) months or, if later, until the related dispute is closed
Website analytics dataGoogle Analytics: fourteen (14) months; PostHog: twelve (12) months, after which event data and session recordings are deleted or aggregated
BackupsBackups of our databases are overwritten in the ordinary course and kept for no longer than ninety (90) days; deleted data may persist in backups until then

We may keep data for longer where a law requires it or where it is needed to establish, exercise or defend legal claims, in which case we restrict its use to that purpose.

10. Your rights

If you are in the European Economic Area or the United Kingdom, or another jurisdiction with similar rights, you can:

(a) access the personal data we hold about you and receive a copy;

(b) rectify inaccurate or incomplete data;

(c) erase your data, where we have no overriding reason to keep it (for example accounting records must be kept);

(d) restrict processing while a dispute about accuracy or lawfulness is resolved;

(e) receive the data you provided to us in a portable format, where processing is based on contract or consent;

(f) withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; and

(g) complain to a supervisory authority. Our lead authority is the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, LT-10312 Vilnius, ada@ada.lt, vdai.lrv.lt. You can also complain to the authority in the country where you live or work. We would appreciate the chance to resolve your concern first.

Your right to object. You have the right to object at any time, on grounds relating to your particular situation, to any processing we base on legitimate interests, including any profiling; we will then stop unless we can show compelling legitimate grounds that override your interests. You also have the right to object at any time to direct marketing, and we will stop immediately.

To exercise your rights, email legal@scrapebadger.com with the subject line "Privacy Request", or use the account-deletion feature in the dashboard. We may ask you to verify your identity. We respond within one month; for complex requests we may extend this by up to two further months and will tell you if so. Exercising your rights is free unless a request is manifestly unfounded or excessive.

You can unsubscribe from marketing emails by using the link in any email or by writing to us; service emails about your Account (invoices, security notices, changes to the Terms) cannot be unsubscribed from while you hold an Account.

11. United Kingdom

To the extent the UK GDPR and the Data Protection Act 2018 apply to our processing of your data, you have the rights in section 10 and you may complain to the Information Commissioner's Office (ico.org.uk). We have not appointed a representative in the United Kingdom, relying on the exemption in Article 27(2)(a) UK GDPR for occasional, low-risk processing.

12. California and other US states

To the extent the California Consumer Privacy Act or another US state privacy law applies to us, residents of those states have the right to know what personal information we collect and how we use and disclose it (this Policy), to access, correct and delete it, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising their rights. We do not sell personal information and do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information other than as necessary to provide the Services. To exercise these rights, email legal@scrapebadger.com; we will verify the request and respond within the time required by the applicable law. The categories of personal information we collect, the sources, purposes and recipients are described in sections 3, 4 and 7.

13. Security

We protect personal data with measures appropriate to the risk, including encryption in transit (TLS 1.2 or higher) and at rest, hashed passwords, access to production systems limited to named personnel with multi-factor authentication, network firewalls and DDoS protection, logging of administrative access, regular software updates, code review and a separate staging environment before changes reach production, and a documented incident-response procedure. The measures are described in more detail in Annex II of our Data Processing Agreement. No system is perfectly secure; if we become aware of a breach affecting your personal data that is likely to result in a high risk to you, we will inform you and the supervisory authority as the law requires.

14. Children

The Services are not directed to children. You must be at least 18 to create an Account. We do not knowingly collect personal data from anyone under 18; if you believe we have, contact us and we will delete it.

15. Third-party links

Our websites link to Sources, documentation of third parties, and services such as Apify, GitHub and review platforms. Their privacy practices are their own and are not covered by this Policy.

16. Changes to this Policy

We will update this Policy when our practices, providers or the law change. Material changes will be announced by email to Account holders or by a prominent notice on the website at least fourteen (14) days before they take effect, unless a change is required by law sooner. The effective date at the top tells you when the current version started to apply; previous versions are available on request.

17. Contact

MB "Reikalita" (ScrapeBadger) Ramioji g. 12, Bajorų k., Vilniaus raj., Lithuania legal@scrapebadger.com, subject line "Privacy Request" For general support: support@scrapebadger.com

We do not store the content retrieved for customers (section 3.5).