GDPR Compliant

PrivacyPolicy

Last updated: September 25, 2026. We respect your privacy and protect your personal data in compliance with GDPR.

1. Introduction

O2CODE (“we”, “our”), the company that publishes and operates the ScrapLift product, is committed to protecting users' privacy and personal data. This Privacy Policy explains how we collect, use, share and protect information processed when you use our B2B prospecting platform.

This policy applies to all ScrapLift users, whether they use our website, web application, or browser extension. By using our services, you accept the practices described in this policy.

We comply with the European Union's General Data Protection Regulation (GDPR) and applicable data protection laws.

2. Data collected

Account data: When creating your account, we collect notably: first name, last name, email address, company name, phone number (optional), and encrypted password.

Usage data: We automatically collect information about your use of the service (telemetry): pages viewed, features used, time spent, IP address, browser type, operating system, session identifier, as well as certain product events (e.g., list creation, campaign launches).

Payment data: For paid subscriptions, payment information is processed by our provider Stripe. We never store complete credit card data on our servers.

Prospecting data: lists, notes, tags, projects and other data specific to your workspace remain isolated within your account or organization. For processing carried out on your behalf, you determine in particular the purpose of your prospecting and O2CODE acts as a technical service provider within the limits set by the GDPR and the contract.

Shared business reference layer: to avoid collecting the same information repeatedly, ScrapLift may retain and reuse across customers certain public business facts (for example identity, public contact details, website, category, public metrics, social profiles or legal identifiers) and non-named role addresses such as contact@company.com. Personal addresses, named individual addresses, your notes, tags, lists and organization-specific data are not added to this shared layer. We retain provenance and freshness information to limit reuse of stale data.

Communications: Emails you send us, exchanges with support or via chat, as well as certain product feedback may be retained to respond to your requests and improve the service.

3. Use of data

We use your personal data to: (a) Provide the service: create and manage your account, authenticate users, process your payments, provide public source exploration, enrichment, and prospecting automation features, (b) Improve the service: analyze usage to fix bugs, optimize performance, and design new features, (c) Communicate with you: send transactional emails (account confirmation, billing, important notifications), as well as product communications and newsletters when you consent, (d) Customer support: answer your questions, assist with platform onboarding, and investigate technical incidents.

We never sell your personal data to third parties. We only share your data with subcontractors strictly necessary for service operation (hosting, payment, email, analytics) and only within the framework defined by our contracts.

The shared reference layer is used only to provide and speed up ScrapLift features, improve data quality and freshness, and avoid unnecessary duplicate requests. It is not sold to data brokers or advertisers.

Legal basis: We process your data on the basis of: (a) contract performance (service provision), (b) our legitimate interest (platform improvement, security, fraud prevention), and (c) your consent when required (particularly for marketing communications).

4. Browser extension data use

The ScrapLift Chrome extension accesses publicly displayed business information on supported Google Maps pages only when you start a collection workflow.

During optional enrichment, the extension may access the public business websites associated with collected leads to identify publicly displayed business contact and company information.

The extension does not collect your general browsing history or your personal communications. Authentication tokens, preferences, consent state and workflow state may be stored locally in your browser to provide the extension's functionality.

Information received through the extension is used only to provide the ScrapLift features you request. It is not sold, not used for advertising and not transferred to third parties, except to the subcontractors needed to operate the service as described in this policy.

The use of information received through the ScrapLift Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

5. Data sharing

We share your personal data only in the following cases:

Subcontractors: We use service providers who help us provide the service, for example: (a) Hosting: cloud provider for our servers and databases (data hosted in Europe), (b) Payment: Stripe for secure payment processing, (c) Email: transactional and/or marketing email sending provider, (d) Analytics: usage analysis solution to better understand platform usage (aggregated and/or pseudonymized data when possible). All these subcontractors are subject to contractual data protection commitments compliant with GDPR.

Legal obligations: We may be required to disclose certain information if required by law, in response to a court decision, a request from a competent authority, or to protect our rights, our security, or that of other users.

Corporate operations: In the event of merger, sale, acquisition, or restructuring, your data may be transferred to the relevant entity, which must respect at least the same level of protection.

We do not share your data with data brokers or advertisers for resale or third-party advertising targeting purposes.

6. Data security

We implement technical and organizational measures to protect your data:

Encryption: All communications with ScrapLift go through HTTPS (SSL/TLS). Passwords are hashed (e.g., bcrypt). Certain sensitive data may be encrypted at rest.

Access control: Data access is limited to authorized persons who need it to operate and improve the service. All employees are subject to confidentiality commitments.

Infrastructure: Servers are hosted in secure and certified data centers (international security standards). Regular backups are performed to limit the risk of data loss.

Monitoring and logging: We monitor infrastructure and application logs to detect abnormal behavior, prevent abuse, and investigate incidents.

No technology offers absolute security, but we do everything we can to protect your information and respond quickly in case of incident.

7. Data retention

We retain your personal data for limited periods, proportionate to the purpose of processing and our legal obligations:

Account data: Retained as long as your account remains active. In case of account deletion, associated data is deleted or anonymized within a maximum of 30 days, unless legal retention obligations apply.

Prospecting data: You control this data in your ScrapLift workspace (creation, modification, deletion). After account deletion, all your prospecting data is deleted within a maximum of 30 days, unless specific retention obligation applies.

Billing data: Retained up to 10 years, in accordance with applicable accounting and tax obligations.

Technical logs: Retained up to 12 months maximum for security, traceability, and debugging purposes.

You can request early deletion of certain data, within the limits of our legal obligations and technical constraints.

8. Your rights

In accordance with GDPR, you have the following rights over your personal data:

Right of access: Obtain confirmation that data concerning you is being processed and, if so, receive a copy.

Right to rectification: Correct or complete inaccurate or incomplete personal data. Some of these modifications can be made directly from your account.

Right to erasure ("right to be forgotten"): Request deletion of your data in certain cases (for example, when data is no longer necessary or when you withdraw your consent).

Right to restriction: Request temporary restriction of processing of your data in certain situations.

Right to portability: Receive your data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON) and transmit it to another service.

Right to object: Object to certain processing, particularly processing of your data for direct marketing purposes.

Right to withdraw consent: When processing is based on your consent, you can withdraw it at any time (for example, via unsubscribe links in our emails).

Right to lodge a complaint: You can lodge a complaint with the competent supervisory authority, in France the CNIL (Commission Nationale de l'Informatique et des Libertés).

To exercise your rights, write to us through the contact form on the site. We endeavour to respond to any request within a maximum of 30 days.

9. Cookies and similar technologies

We use cookies and similar browser storage technologies to operate the platform.

Strictly necessary cookies: Better Auth uses a secure session cookie for authentication, and Stripe may set anti-fraud cookies during payment. These are necessary for the operation or security of the service.

Audience measurement: the website loads our self-hosted Umami instance, configured to measure audience without analytics cookies and without advertising profiles.

Preferences: some preferences, such as language or theme, may be stored in a cookie or browser local storage depending on the feature.

You can remove cookies and site data from your browser settings. Removing a strictly necessary item may sign you out or temporarily prevent some features from working.

10. Protection of minors

ScrapLift is a B2B service intended for professional use. It is not intended for persons under 18 years of age.

If you are a parent or guardian and believe a minor has created an account or transmitted personal data to us, write to us through the contact form so we can delete the relevant information.

11. International data transfers

Your data is primarily stored and processed within the European Union. However, some subcontractors may be located outside the EU (for example for payment or email).

When data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place (standard contractual clauses, enhanced contractual commitments, or equivalents recognized by regulation).

Upon request, you can obtain more information about these safeguards and the countries to which your data may be transferred.

12. Changes to this policy

We may update this Privacy Policy to reflect platform evolution, legal requirements, or our internal practices.

In case of significant modification, we will inform you by email (to the address associated with your account) and/or via a visible notification within ScrapLift, within a reasonable time before the changes take effect.

The current version of the policy is always accessible on this page. The "Last updated" mention identifies the date of the last modification.

By continuing to use the service after the changes take effect, you accept the updated privacy policy.

13. Contact us

If you have questions about this Privacy Policy or how we process personal data, you can contact us:

Data Protection Officer: reachable through the contact form on the site

Postal address: O2CODE (O2C), 55 rue Grignan, 13006 Marseille, France

General support: through the contact form on the site

We endeavor to respond to all legitimate requests within a maximum of 30 days.

Last updated: September 25, 2026

In summary

The essential points of our privacy policy

  • Your data belongs to you: you keep control over all prospecting data in your account.
  • No data sales: we do not resell your information to third parties and we do not do advertising enrichment from your data.
  • GDPR compliance: your rights (access, rectification, erasure, portability, objection) are respected, and a DPO is available for your requests.
  • Hosting in Europe: data is primarily stored within the European Union, with guarantees for any transfer outside the EU.
  • Security at the heart of the product: encrypted communications, hashed passwords, restricted access, and infrastructure monitoring.