Privacy Policy
Effective 1 June 2026
We collect the minimum we need to run Scrapless, hand off payments to Stripe, and keep your account secure. Plain-language summary below; defined terms in our Terms.
1. Who is the controller
Scrapless Ltd, a company registered in England and Wales, is the data controller for personal data processed by the Scrapless application. Contact: privacy@scrapless.co.
2. What we collect
Account data
- Name, email, profile image — supplied during Clerk sign-up.
- Organisation name and members — when you create a workspace.
- Authentication metadata (last sign-in, IP, device) — handled by Clerk.
Billing data
- Billing address, VAT number, tax status — collected by Stripe at checkout. We don’t see or store card details — Stripe owns that flow end-to-end (PCI scope: SAQ-A).
- Subscription status, invoice history — synchronised back to our DB via Stripe webhooks so we can reflect plan state in-app.
Job data
- Parts lists, stock libraries, customer/order labels you assign to jobs, optimisation settings, generated layouts and files.
- This is your business data — see “Your content” in the Terms. We don’t sell, share, or use it to train models.
Technical data
- Server logs (request paths, response status, timestamps, truncated IP) — retained for 30 days for security and debugging.
- Error reports (stack traces, the path that triggered the error).
3. Why we process it
- Contractual necessity — running the service you signed up for (your account, your jobs, your files).
- Legal obligation — invoice records, tax records, fraud prevention.
- Legitimate interest — keeping the platform secure, debugging, and improving the product based on aggregated, de-identified usage patterns.
4. Who we share with
We use a small number of processors. Each has a Data Processing Agreement in place with us.
- Clerk (auth, user profile, session management).
- Stripe (payments, subscription billing, tax).
- Amazon Web Services (hosting, Postgres, S3 for generated files; UK region).
- Stell Software AB(CutGLib engine licensor — processes job data on our infrastructure under our control, doesn’t receive personal data).
- Resend (transactional email — welcome message, payment receipts, trial reminders).
- Sentry (error monitoring; PII scrubbed at the client before sending).
We don’t sell personal data. We don’t share it with advertisers.
5. International transfers
Most of our processors are UK or EU-based. Where data is transferred outside the UK (e.g. some Stripe and AWS regions), we rely on UK International Data Transfer Agreements and the European Commission’s Standard Contractual Clauses.
6. Retention
- Account data: for the lifetime of your account plus 30 days, then deleted.
- Jobs and libraries: same as account data.
- CNC files: 90 days on Workshop tier; permanent on Studio+ (per APP retention tier).
- Invoices: 7 years (UK statutory minimum).
- Server logs: 30 days.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (most of this you can do in Settings).
- Delete your account (closes the workspace and triggers data removal after retention windows).
- Export your data — request a JSON dump via privacy@scrapless.co.
- Object to processing for legitimate interest grounds.
- Complain to the UK Information Commissioner’s Office (ICO) if you think we’ve mishandled your data — ico.org.uk.
We respond to rights requests within 30 days. Email privacy@scrapless.co.
8. Cookies
See our Cookie Policy for the full list. Short version: we use strictly-necessary cookies for sign-in and CSRF protection; we don’t set marketing or ad-tracking cookies.
9. Children
The service is not for under-16s. We don’t knowingly collect data about children. If you think we have, contact us and we’ll delete it.
10. Changes to this policy
We’ll flag material changes in-app and via email at least 30 days before they take effect.
11. Contact
For any privacy question or rights request: privacy@scrapless.co.