Skip to content
Screaming Data

Legal

Privacy Policy

Last updated: [EFFECTIVE DATE]

Template — must be reviewed by a lawyer before use.

This document is a starting point, not legal advice. It must be reviewed and adapted by a qualified lawyer for your company, jurisdiction and customers before the service is offered to the public. Replace every highlighted [PLACEHOLDER].

This policy explains what personal data [COMPANY LEGAL NAME] (“we”, “us”) processes when you use the Screaming Data website, dashboard and API (the “Service”), why, and what rights you have.

01Who is responsible

[COMPANY LEGAL NAME], [COMPANY ADDRESS], is the controller of the personal data described in this policy. Contact us at support@screamingdata.dev. Data protection officer or representative: [DATA PROTECTION CONTACT, IF APPOINTED].

02Data we collect

  • Access requests: e-mail address, name, company, the description of your use case, your expected volume, the marketplaces you are interested in and your message, and the IP address and time of the request.
  • Account data: API login, e-mail address, name and company, plan, balance and billing records (payments, charges and refunds).
  • API usage: the time, endpoint and parameters of each request (for example ASINs, marketplaces, tags and webhook URLs), the IP address it came from, the identifier of the key used (never the full key) and its cost.
  • Webhook deliveries: the destination URL, the response status and the number of attempts.
  • Monitoring attributions: platforms may send an opaque external_user_id with subscriptions. It must not contain personal data; values that look like e-mail addresses are rejected.

The website does not use cookies, analytics or tracking scripts. The dashboard keeps your API login and key in your browser’s sessionStorage for the current tab only, and the site remembers your theme and code-language preferences in localStorage. This information stays in your browser; the dashboard sends the credentials only to the API. Our hosting providers may keep standard server logs, such as IP addresses and requested pages.

Data returned by the Service comes from publicly available sources, such as product pages, and can include names published there — for example the brand, manufacturer or creators shown with a product.

03Why we use it

  • To review access requests, prepare pricing offers and communicate with you (steps before entering into a contract, and our legitimate interest in answering enquiries).
  • To provide the Service: authenticate requests, run tasks, deliver webhooks and show your usage (performance of our contract with you).
  • To bill usage and keep accounting records (contract and legal obligations).
  • To secure the Service, enforce rate limits and prevent abuse (legitimate interests).
  • To comply with legal obligations.

We do not sell personal data and do not use it for advertising.

04How long we keep it

  • Task results: 30 days after the task is created.
  • Access requests that do not lead to an account: [RETENTION PERIOD].
  • Account and billing records: for the life of the account and afterwards for as long as the law requires ([RETENTION PERIOD]).
  • Request logs and usage records: [RETENTION PERIOD].

05Who we share it with

  • Service providers that host or operate the Service for us: [LIST OF PROCESSORS, E.G. HOSTING, E-MAIL, PAYMENTS]. They act on our instructions under contracts that protect your data.
  • Authorities, when the law requires it.
  • A successor, if our business is merged or sold. We will tell you before your data becomes subject to a different policy.

06International transfers

[DESCRIBE WHERE DATA IS STORED AND THE TRANSFER SAFEGUARDS USED, E.G. STANDARD CONTRACTUAL CLAUSES].

07Security

API keys are stored only as hashes, all traffic is encrypted with TLS, webhook deliveries are signed, and access to personal data is limited to people who need it to run the Service.

08Your rights

Depending on where you live, you can ask for access to, correction or deletion of your personal data, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. Write to support@screamingdata.dev; we answer within the period the law requires. You can also complain to your data protection authority: [SUPERVISORY AUTHORITY].

09Children

The Service is intended for businesses and developers and is not directed at children under 16.

10Changes to this policy

We will update the date at the top of this page when the policy changes, and tell account holders about material changes by e-mail.