Short version: we collect an email address if you ask us to send you something; an account holds a password hash; a Terminal subscription adds billing details held by Stripe and a count of API calls. Nothing beyond what the table below lists. No advertising, no tracking pixels, no third-party analytics, no cookies for marketing.
The Crawl Price Index is operated by Alexander Balieu, sole trader, based in Luxembourg, acting as data controller. Contact: hello@crawlpriceindex.com. Postal address available on request.
| Data | Why | Legal basis (GDPR Art. 6) | Kept |
|---|---|---|---|
| Account (sign-in): email address, password hash, session | To run the free and Terminal tiers of the dashboard; held by our sign-in provider (Clerk), never stored by us in plain form | Contract — 6(1)(b) | Until you delete the account |
| Email address (newsletter) | To send The Weekly Crawl and the welcome note | Consent — 6(1)(a), given by confirming via the double opt-in email | Until you unsubscribe, then deleted |
| Email address + domain (change alerts) | To tell you when AI-crawler access to that domain changes | Consent — 6(1)(a), confirmed by email | Until you stop the alert, then deleted |
| Email address, name, billing details (subscribers) | To provide the subscription, issue your API key, and meet invoicing and tax obligations | Contract — 6(1)(b); legal obligation — 6(1)(c) for accounting records | Duration of the subscription, then as long as tax law requires |
| API key usage counts | To enforce the monthly rate limit (5,000 requests per key per calendar month since 4 September 2026) and detect abuse | Contract — 6(1)(b); legitimate interests — 6(1)(f) | Rolling monthly counter |
| Watchlist lists (Terminal) | Not collected, unless you press Share this cohort (the row below). Lists of domains you save on the Watchlist tab are held in your own browser’s storage only; we do not store them, and they are not part of your account | — (no processing by us) | Until you clear them or your browser’s site data |
| Shared cohort (the Share this cohort button) | Pressing it uploads the list of domain names in the cohort on screen and returns a link whose identifier cannot be guessed. Nothing else goes with it: no email address, no account identifier, no IP address, no filter and no label you have not typed. The stored record is a list of website names and is not linked to you or to your account. Anyone holding the link can read it; nobody without it can find it, and it is not listed anywhere | Consent — 6(1)(a), given by pressing the button | One year from the day the link is made, then deleted automatically |
| Aggregate series CSV download | Served as a static file from the free edition of the dashboard; a request for it is a server log entry like any other page (see below), nothing more | Legitimate interests — 6(1)(f), for the log only | As server logs |
Each is bound by a data-processing agreement. Some may process data outside the EEA under the European Commission's standard contractual clauses.
Our hosting provider processes standard request data (IP address, user agent, timestamp) transiently to deliver the site and protect it from abuse, on the basis of legitimate interests — GDPR Art. 6(1)(f). We do not build analytics from it, and we do not use it to identify visitors.
Under the GDPR you may request access to your data, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time — every email we send carries a one-click unsubscribe link, which deletes the record rather than merely flagging it.
Email hello@crawlpriceindex.com and we will respond within 30 days. You also have the right to lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD), or with the authority in your country of residence.
The index itself measures how websites respond to automated crawlers: robots.txt directives, HTTP status codes and payment headers. That is information about domains and their configuration, not about individuals, and we store no page content. Our full method is published in the methodology · about. If you operate a site and do not want it named on our public pages, email us from a domain-verifiable address and we will stop naming it in the examples and named tables on our public pages and in the newsletter; the domain stays in the frame, in every published count, in the licensed per-domain data and in the domain checker, because a census that drops rows on request measures nothing. See crawl etiquette.
Data is held in Cloudflare infrastructure. Secrets are stored encrypted and are never in source control. Our crawler signs its own requests cryptographically so sites can verify our traffic. To report a vulnerability, see security.txt.
Material changes to this policy will be noted in the changelog with a date. The "last updated" date above always reflects the current version. 4 September 2026: the API cap in the table above, and two rows stating that Watchlist lists are browser-local and that the aggregate series CSV involves no collection.