Scrape.Email policy center

Privacy Policy

This policy explains how Scrape.Email handles account information, business-contact records, connected email data, payments, support requests, and security information.

Information we process

We process account name and email, password hash, workspace and plan information, usage and redemption records, payment references, API-key metadata, webhook settings, brand profiles, saved lead snapshots, campaigns, encrypted SMTP credentials, mailbox connection status, synchronized plain-text inbox messages, sent-email activity, support correspondence, audited administrative support-access events, and security telemetry. Plaintext account and SMTP passwords are not stored.

First-party traffic analytics may record page paths, page views, sessions, clicks on controls, engagement time, scroll depth, referral and campaign parameters, browser, operating system, device class, language, and approximate country, region, city, timezone, and coordinates supplied by network infrastructure. Network IP addresses are encrypted at rest and available only to authorized administrators for traffic analysis, abuse prevention, and security investigation. Form values, passwords, message contents, and API credentials are not collected by this analytics system.

Purposes and legal bases

We use account and service data to perform the contract, authenticate users, deliver requested searches and exports, operate email and API features, fulfill verified purchases, prevent abuse, secure the service, answer requests, and maintain required financial records. Security and reliability processing relies on legitimate interests. Marketing communications, where used, rely on consent or another applicable lawful basis and may be opted out of.

Business-contact data

The catalog contains professional and company-related information intended for lawful B2B use. Scrape.Email acts as an independent data provider for catalog records; a customer becomes an independent controller of records it reveals or exports. Customers must determine their own lawful basis, provide required notices, and honor objections and suppression requests.

Public directory pages may show a person's business identity only: name, job title, employer, industry, and location drawn from public business data. Email addresses, phone numbers, and other contact values are never published on public pages and remain available only through authenticated, credit-approved discovery. Countries where publishing a named business profile requires a documented lawful basis are excluded from public person pages by default.

To request access, correction, objection, or removal from the catalog, email waconzy@live.com or use the public removal form with the relevant business email, profile URL, company domain, and requested action. We may verify identity and retain a minimal suppression record so removed data is not reintroduced.

Retention periods

Active account profiles, saved leads, campaigns, brands, connected-sender configuration, and email activity are retained while the workspace is active. On a verified account-closure request, operational copies are deleted or anonymized within 30 days. Encrypted sender credentials are deleted when the sender is removed and otherwise within that same closure period. Synchronized inbox message bodies are retained for no more than 180 days; sent-email activity is retained for 24 months.

Traffic analytics and aggregate trends may be retained for the life of the service to measure long-term product performance. Encrypted IP-level traffic records are access-restricted and may be deleted or anonymized when no longer needed for analytics, fraud prevention, or security. Security, authentication, and administrative support-access logs are retained for up to 12 months. Support correspondence is retained for 24 months after closure of the request. Failed or abandoned checkout records are retained for 90 days. Payment, tax, refund, and fraud-prevention records are retained for seven years where required. Encrypted backups may persist for up to 90 additional days before rotation. Suppression records may be retained as long as necessary to honor an objection.

Named subprocessors

Cloudflare provides private object storage and related network services. Stripe processes card checkout and subscription events. Cryptomus processes optional cryptocurrency checkout. DeepSeek processes limited prompts for user-requested AI search interpretation and email drafting. A customer's chosen SMTP or IMAP provider processes email credentials and messages under the customer's own provider agreement. Our managed application host and database operator processes account control data only to run the service.

Payment providers receive the details necessary for billing. AI requests are limited to the selected brand context, user instruction, and allowlisted lead facts; private API credentials remain server-side.

International transfers

Providers may process data outside the customer's country. Where transfer restrictions apply, we rely on an adequacy decision, the EU Standard Contractual Clauses or UK International Data Transfer Addendum, an applicable certified transfer framework, or another legally recognized safeguard. Customers may request available transfer information through the contact address below.

Disclosure and individual rights

We disclose information to subprocessors, professional advisers, authorities acting under valid legal process, and a successor in a properly controlled business transaction. We do not sell account credentials or mailbox content. Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection and may complain to their data-protection authority.

Effective and last updated: September 11, 2026. Dv8 Media Publishing operates Scrape.Email. Contact waconzy@live.com for legal, privacy, billing, or support requests.