GDPR Compliant

PrivacyPolicy

Last updated: August 4, 2026. We respect your privacy and protect your personal data in compliance with GDPR.

1. Introduction

ScrapLift SAS ("we", "our", "us") is committed to protecting the privacy and personal data of its users. This Privacy Policy explains how we collect, use, share, and protect your information when you use our B2B prospecting platform.

This policy applies to all ScrapLift users, whether they use our website, web application, or browser extension. By using our services, you accept the practices described in this policy.

We comply with the European Union's General Data Protection Regulation (GDPR) and applicable data protection laws.

2. Data collected

Account data: When creating your account, we collect notably: first name, last name, email address, company name, phone number (optional), and encrypted password.

Usage data: We automatically collect information about your use of the service (telemetry): pages viewed, features used, time spent, IP address, browser type, operating system, session identifier, as well as certain product events (e.g., list creation, campaign launches).

Payment data: For paid subscriptions, payment information is processed by our provider Stripe. We never store complete credit card data on our servers.

Prospecting data: The data you collect and manage via ScrapLift (companies, professional contacts, enrichment data, notes, tags, etc.) are stored in your workspace. You are the data controller for this data, and we act as a data processor within the meaning of GDPR.

Communications: Emails you send us, exchanges with support or via chat, as well as certain product feedback may be retained to respond to your requests and improve the service.

3. Use of data

We use your personal data to: (a) Provide the service: create and manage your account, authenticate users, process your payments, provide public source exploration, enrichment, and prospecting automation features, (b) Improve the service: analyze usage to fix bugs, optimize performance, and design new features, (c) Communicate with you: send transactional emails (account confirmation, billing, important notifications), as well as product communications and newsletters when you consent, (d) Customer support: answer your questions, assist with platform onboarding, and investigate technical incidents.

We never sell your personal data to third parties. We only share your data with subcontractors strictly necessary for service operation (hosting, payment, email, analytics) and only within the framework defined by our contracts.

Legal basis: We process your data on the basis of: (a) contract performance (service provision), (b) our legitimate interest (platform improvement, security, fraud prevention), and (c) your consent when required (particularly for marketing communications).

4. Data sharing

We share your personal data only in the following cases:

Subcontractors: We use service providers who help us provide the service, for example: (a) Hosting: cloud provider for our servers and databases (data hosted in Europe), (b) Payment: Stripe for secure payment processing, (c) Email: transactional and/or marketing email sending provider, (d) Analytics: usage analysis solution to better understand platform usage (aggregated and/or pseudonymized data when possible). All these subcontractors are subject to contractual data protection commitments compliant with GDPR.

Legal obligations: We may be required to disclose certain information if required by law, in response to a court decision, a request from a competent authority, or to protect our rights, our security, or that of other users.

Corporate operations: In the event of merger, sale, acquisition, or restructuring, your data may be transferred to the relevant entity, which must respect at least the same level of protection.

We do not share your data with data brokers or advertisers for resale or third-party advertising targeting purposes.

5. Data security

We implement technical and organizational measures to protect your data:

Encryption: All communications with ScrapLift go through HTTPS (SSL/TLS). Passwords are hashed (e.g., bcrypt). Certain sensitive data may be encrypted at rest.

Access control: Data access is limited to authorized persons who need it to operate and improve the service. All employees are subject to confidentiality commitments.

Infrastructure: Servers are hosted in secure and certified data centers (international security standards). Regular backups are performed to limit the risk of data loss.

Monitoring and logging: We monitor infrastructure and application logs to detect abnormal behavior, prevent abuse, and investigate incidents.

No technology offers absolute security, but we do everything we can to protect your information and respond quickly in case of incident.

6. Data retention

We retain your personal data for limited periods, proportionate to the purpose of processing and our legal obligations:

Account data: Retained as long as your account remains active. In case of account deletion, associated data is deleted or anonymized within a maximum of 30 days, unless legal retention obligations apply.

Prospecting data: You control this data in your ScrapLift workspace (creation, modification, deletion). After account deletion, all your prospecting data is deleted within a maximum of 30 days, unless specific retention obligation applies.

Billing data: Retained up to 10 years, in accordance with applicable accounting and tax obligations.

Technical logs: Retained up to 12 months maximum for security, traceability, and debugging purposes.

You can request early deletion of certain data, within the limits of our legal obligations and technical constraints.

7. Your rights

In accordance with GDPR, you have the following rights over your personal data:

Right of access: Obtain confirmation that data concerning you is being processed and, if so, receive a copy.

Right to rectification: Correct or complete inaccurate or incomplete personal data. Some of these modifications can be made directly from your account.

Right to erasure ("right to be forgotten"): Request deletion of your data in certain cases (for example, when data is no longer necessary or when you withdraw your consent).

Right to restriction: Request temporary restriction of processing of your data in certain situations.

Right to portability: Receive your data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON) and transmit it to another service.

Right to object: Object to certain processing, particularly processing of your data for direct marketing purposes.

Right to withdraw consent: When processing is based on your consent, you can withdraw it at any time (for example, via unsubscribe links in our emails).

Right to lodge a complaint: You can lodge a complaint with the competent supervisory authority, in France the CNIL (Commission Nationale de l'Informatique et des Libertés).

To exercise your rights, you can contact our DPO at: privacy@scraplift.io. We endeavor to respond to any request within a maximum of 30 days.

8. Cookies and similar technologies

We use cookies and similar technologies to ensure platform operation and improve your experience.

Strictly necessary cookies: Essential for service operation (authentication, session, security, basic preferences). They cannot be disabled from our interfaces.

Audience measurement cookies: Help us understand how ScrapLift is used (pages viewed, overall navigation) to improve experience and stability. When possible, this data is aggregated or pseudonymized.

Preference cookies: Allow remembering your language, display preferences (light/dark theme), and certain interface settings.

You can manage cookies via your browser settings. However, refusing certain cookies may degrade some platform features.

9. Protection of minors

ScrapLift is a B2B service intended for professional use. It is not intended for persons under 18 years of age.

If you are a parent or guardian and believe a minor has created an account or transmitted personal data to us, contact us at privacy@scraplift.io so we can delete the relevant information.

10. International data transfers

Your data is primarily stored and processed within the European Union. However, some subcontractors may be located outside the EU (for example for payment or email).

When data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place (standard contractual clauses, enhanced contractual commitments, or equivalents recognized by regulation).

Upon request, you can obtain more information about these safeguards and the countries to which your data may be transferred.

11. Changes to this policy

We may update this Privacy Policy to reflect platform evolution, legal requirements, or our internal practices.

In case of significant modification, we will inform you by email (to the address associated with your account) and/or via a visible notification within ScrapLift, within a reasonable time before the changes take effect.

The current version of the policy is always accessible on this page. The "Last updated" mention identifies the date of the last modification.

By continuing to use the service after the changes take effect, you accept the updated privacy policy.

12. Contact us

If you have questions about this Privacy Policy or how we process personal data, you can contact us:

DPO (Data Protection Officer) email: privacy@scraplift.io

Postal address: O2CODE (O2C), 55 rue Grignan, 13006 Marseille, France

General support: support@scraplift.io

We endeavor to respond to all legitimate requests within a maximum of 30 days.

Last updated: August 4, 2026

In summary

The essential points of our privacy policy

  • Your data belongs to you: you keep control over all prospecting data in your account.
  • No data sales: we do not resell your information to third parties and we do not do advertising enrichment from your data.
  • GDPR compliance: your rights (access, rectification, erasure, portability, objection) are respected, and a DPO is available for your requests.
  • Hosting in Europe: data is primarily stored within the European Union, with guarantees for any transfer outside the EU.
  • Security at the heart of the product: encrypted communications, hashed passwords, restricted access, and infrastructure monitoring.