Privacy Policy
Version 5 — the same document you accept at signup.
Privacy Policy
Version: 5 Last updated: 2026-09-29
ScrapeOra is operated by Md Toufiquzzaman, Bangladesh.
This policy explains what personal data ScrapeOra collects about you, the customer, why, and what you can do about it.
It is deliberately short, because we collect little. If you are looking for what happens to the product data you collect, that is section 5.
1. Who is responsible
The data controller is MD TOUFIQUZZAMAN, a sole trader registered in Bangladesh, trading as ScrapeOra.
Registered address: Basa/Holding-326, Vill-Vaturia, PO-Chachra, Jashore Sadar, Jashore - 7402, Khulna, Bangladesh Contact for any privacy question or request: contact@scrapeora.com
2. What we collect about you
| What | Why | Lawful basis |
|---|---|---|
| Name, email address, password hash | To create and secure your account | Performance of contract |
| Time zone | To fire your scheduled runs at the right local time | Performance of contract |
| IP address and browser user-agent at sign-in | Security: to show you your own active sessions and detect account takeover | Legitimate interest |
| Approximate city, derived from that IP | To label a session as "London" rather than an IP address, so you can recognise your own devices | Legitimate interest |
| Usage counts (runs, products, exports) | To enforce plan limits and bill correctly | Performance of contract |
| Support messages, bug reports, feedback you send us | To answer you | Performance of contract |
We do not collect: card numbers, government identifiers, precise location, biometric data, or anything about your customers.
We do not use advertising trackers and we do not sell personal data. There is no third-party analytics script on the marketing site or in the app.
3. Passwords
Passwords are hashed with bcrypt (cost factor 12) and never stored in a form we can reverse. We cannot tell you your password; we can only let you reset it.
4. Payment data
We never see your card. Payments are handled by Gumroad, Inc., trading as Gumroad, which acts as Merchant of Record and is an independent controller of the payment data you give it. Gumroad tells us what we need to run your plan and nothing more: the email address used for the purchase, the plan and billing period, the membership's status and renewal dates, its license key, and whether a payment was refunded or disputed. When you start a purchase from ScrapeOra we pass your ScrapeOra account ID and email address to Gumroad's checkout, so the purchase can be matched to your account. See Gumroad's privacy policy.
5. The data you collect
Product data you collect through ScrapeOra is stored in your account and belongs to you. We do not sell it, share it, or use it to train AI models.
Do not use ScrapeOra to collect personal data. It is a product-sourcing tool, our terms forbid it, and any personal data appearing in your collected results is there because you pointed it at a page that showed it — which makes you its controller, not us.
Collected product data is sent to an AI provider only when you explicitly request enrichment, and only the product fields needed to rewrite a description.
6. Credentials you give us
Store connections (Shopify, WooCommerce, BigCommerce, Google Sheets) require credentials or OAuth tokens. These are encrypted at rest with Fernet (AES-128-CBC + HMAC), using keys held separately from the database, and are never returned by our API — not to you, not to an administrator, not in a support view. They are decrypted only in the worker process at the moment a push runs.
7. Who else processes your data
| Processor | What they see | Where |
|---|---|---|
| Hetzner Online GmbH | Everything — they host the servers | Germany |
| Gumroad, Inc. | Payment and subscription data | US |
| Brevo (Sendinblue) | Your email address and the content of emails we send you | EU |
| Cloudflare | DNS, and inbound email routed to us | Global |
| Anthropic, OpenAI, Google and other AI providers | Product fields, only when you request enrichment | US |
| Sentry | Error reports, which may contain your user id | EU |
| Webshare | Network access used to reach supplier pages — it sees the supplier page being read, never your identity | Global |
Export files you generate are stored on our own object storage, on the Hetzner servers above — no third-party file store is involved.
We use no other processors. If that changes, this table changes with it.
8. Where your data lives
Our servers are in Germany. Some processors above operate outside the EEA; where they do, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
9. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Collected items and runs | Until you delete them, or your account |
| Run logs | 90 days |
| Export files | 7 days, then automatically deleted from object storage |
| Sign-in / session records | Until the session expires or you revoke it |
| Deleted accounts | Hard-deleted 30 days after you request deletion |
| Invoices and payment records | 7 years, where tax law requires it |
10. Your rights
Wherever you live, you can:
- Access — export everything in your account at any time from the app. - Correct — edit your profile directly. - Delete — delete your account from Settings → Privacy. It is hard-deleted after 30 days; the grace period exists so an accidental or malicious deletion can be undone. - Object or restrict — email us. - Port — your data exports as JSON, CSV and XML already. - Withdraw consent — for the optional emails, from Settings → Notifications, or the unsubscribe link in any of them.
You do not need to justify a request and we will not charge for one. We reply within 30 days.
Some emails are transactional and cannot be turned off while you have an account: email verification, password resets, security alerts, and billing notices such as a failed payment. Switching those off would mean you could lose access to your account or your subscription without ever being told.
11. Cookies
We set cookies for one purpose: keeping you signed in.
| Cookie | Purpose | Duration |
|---|---|---|
| Session token | Keeps you signed in | Session |
| Refresh token | Renews your session without asking you to sign in again | 30 days, HttpOnly + Secure |
| Theme preference | Remembers light or dark | 1 year |
No advertising, analytics or tracking cookies are set, which is why the site does not ask you to accept any.
12. Children
ScrapeOra is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.
13. Security incidents
If a breach affects your personal data and is likely to result in a risk to you, we will tell you and the relevant supervisory authority without undue delay, and within 72 hours where the law requires it.
14. Changes
We will bump the version number on any material change and ask you to acknowledge it the next time you sign in. Your acknowledgement is recorded with a timestamp.
15. Contact and complaints
MD TOUFIQUZZAMAN (trading as ScrapeOra) Basa/Holding-326, Vill-Vaturia, PO-Chachra, Jashore Sadar, Jashore - 7402, Khulna, Bangladesh contact@scrapeora.com
If you are in the EEA or UK and are unhappy with how we have handled a privacy request, you may complain to your local data-protection authority. We would rather you told us first, and we will try to fix it.