Privacy Policy
Last updated: July 20, 2026
This Privacy Policy describes how CRWLR Ltd. ("CRWLR", "we", "us") collects, uses, and protects information when you use our firewall audit platform ("Service").
1. What We Collect
Account Information
- Email address (for authentication and notifications)
- Organization name (for multi-tenant isolation)
- Payment information (processed by Stripe — we never store card numbers)
Firewall Configuration Data
- Raw configuration files are never stored. Parsed in memory, discarded immediately after analysis.
- We store normalized analysis results only: policy structure (zone names, service names, profile assignments), findings, and device metadata (hostname, firmware version).
- Passwords, pre-shared keys, private keys, and SNMP secrets are never extracted. This is an architecture decision — the system has no fields for them.
For full technical details on what we read, skip, and how scans are isolated, see our Security page.
Usage Data
- Pages visited, features used, scan frequency
- Browser type, device type, general location (country level)
- Error logs and performance metrics
2. How We Use Your Information
- Provide the Service: Analyze configurations, generate findings, deliver reports
- Security alerts: Notify you of new vulnerabilities affecting your firmware versions
- Support: Respond to your requests and troubleshoot issues
3. What We Do NOT Do
- We do not sell your data to third parties
- We do not share your configuration data with other customers
- We do not use your data for advertising
- We do not train AI models on your individual configuration data
4. Data Security
We implement encryption in transit and at rest, tenant-level database isolation, and sandboxed scan processing. For full technical details, see our Security page.
5. Data Retention
- Raw configurations: Never stored (parsed in memory, discarded)
- Scan results & account data: Duration of subscription + 30 days
- Anonymized aggregates: Retained indefinitely for service improvement (can never identify you or your network)
You may request deletion of all your data at any time. We process deletion requests within 30 days.
6. GDPR (EU Customers)
- Legal basis: contract performance and legitimate interest
- Data processed in the EU (Frankfurt)
- Your rights: access, correct, delete, export, object, complain to your DPA
- Data Processing Agreement available on request for enterprise and MSP customers
7. Sub-Processors
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication | EU (Frankfurt) |
| Render | API hosting | EU (Frankfurt) |
| Vercel | Web hosting | Global CDN |
| Stripe | Payment processing | EU/US |
| Resend | Transactional email | US |
| Sentry | Error monitoring (server-side only, no browser tracking) | EU (Germany) |
| Anthropic | AI summary (optional, opt-in) | US* |
*AI summaries are opt-in. When enabled, only structured analysis outputs (findings, scores, check results) are sent to Anthropic — never raw configuration data, IP addresses, or network topology. Anthropic does not retain inputs for model training under our API agreement.
8. Cookies
Essential cookies only (authentication, session). No advertising or tracking cookies. No third-party analytics.
If you arrive from an ad, we store the click ID (e.g. gclid, fbclid) in your browser's local storage for up to 90 days, first-party only, to credit the campaign if you later sign up. It is not used for cross-site tracking and is not shared with ad networks beyond conversion reporting.
Server-Side Ad Conversion Measurement
If you arrive from a Google or Meta ad and later complete the signup process to create a CRWLR account, our server sends Google Ads and/or Meta: the click identifier stored above, the type and time of the conversion event (e.g. "signup"), and a one-way SHA-256 cryptographic hash of your email address — never your email in plain text, and never your name. For Meta specifically we also include your IP address and browser user-agent string, which Meta uses to match the conversion across devices; Google does not receive your IP address or user-agent. We never send firewall configuration data, scan results, or browsing history to either platform. This transmission happens directly between our server and the ad platform — it does not involve a browser-side pixel or any additional cookie.
Purpose: to measure which ad campaigns lead to signups, so we can spend ad budget effectively. Legal basis: legitimate interest (see Section 6). You can opt out of ad personalization directly through Google's Ads Settings or Meta's Ad Preferences. Blocking or clearing local storage in your browser (private/incognito browsing does this automatically) before visiting an ad link prevents the click identifier from ever being captured, which prevents this attribution.
9. Changes
We may update this policy. Material changes notified via email or in-app notice.
10. Contact
Version History
- July 20, 2026 — Disclosed server-side ad conversion measurement (Google Ads / Meta): on signup, a hashed email + ad click ID is sent to measure campaign performance
- April 1, 2026 — Added cookie consent banner; clarified Anthropic data handling (opt-in, no raw config sent, no training); added version history
- March 30, 2026 — Initial version