Privacy Policy
Last updated: 21 July 2026 · [Operating entity & registered address — to confirm before launch]
This policy explains what personal data QuanticData ("we", "us") collects when you use quanticdata.io, our dashboard and our APIs, why we collect it, and the rights you have over it. We keep data collection to what the service actually needs.
1. Data we collect
- Account data — the email address and password (stored only as a salted hash) you provide at sign-up, or the profile returned by an SSO provider (Google, GitHub, Microsoft) if you sign in that way: name and email only.
- Usage data — API requests you make (endpoint, timestamp, outcome, latency, cost), which we log so you can see your own usage and so we can bill accurately and prevent abuse.
- Billing data — handled by our payment processors; we store invoice records and the last four digits of a card, never full card numbers.
- Technical data — IP address and user-agent of requests to our sites, used for security, rate limiting and fraud prevention.
- Advertising & analytics identifiers — see section 4.
2. How we use it
- To provide the service: authenticate you, run your API calls, meter usage and bill you.
- To keep the platform secure and prevent abuse.
- To communicate service and account messages, and — only if you opt in — product updates.
- To measure marketing and improve the product (analytics), under the lawful bases in section 6.
3. Data you collect through our APIs
When you use our scraping, SERP, crawl or proxy services, you decide what public web data to collect and you are the controller of that data. We process it on your behalf only to fulfil your request and do not retain page content longer than needed to return your result. You are responsible for using the service lawfully and for any personal data you collect through it.
4. Cookies and advertising measurement
We use a small number of cookies. Strictly necessary cookies (session, security, consent choice) are always set. Marketing and analytics cookies are only set after you accept them in our consent banner — and in the EEA, UK and Switzerland nothing is set until you choose. Specifically we may use:
| Purpose | Provider | What it does |
|---|---|---|
| Advertising measurement | Google Ads, Microsoft Ads | Attributes a sign-up or purchase to the ad you clicked (click identifiers such as gclid / msclkid), so we know which campaigns work. We may pass a hashed email for enhanced conversions. |
| Advertising | Measures conversions from Reddit campaigns. | |
| Product analytics | PostHog (EU hosting) | Aggregate funnel metrics (sign-up → first call → top-up) to improve onboarding. Runs without device storage until you consent. |
| Error reporting | Sentry | Captures technical errors so we can fix them. No advertising use. |
| Affiliate attribution | Awin | Credits partners who referred you, if applicable. |
You can change your choice at any time by clearing the qp_consent cookie or contacting us. We honour Global Privacy Control and browser Do-Not-Track signals where technically feasible.
5. Sharing
We share data only with processors that help us run the service — payment providers, email delivery, hosting, the analytics and advertising providers listed above — under contracts that bind them to protect it. We do not sell your personal data. We may disclose data if required by law.
6. Lawful bases (GDPR)
- Contract — account, usage and billing data, to provide the service you signed up for.
- Legitimate interests — security, fraud prevention and basic service analytics, balanced against your rights.
- Consent — marketing cookies and advertising measurement; you can withdraw it at any time.
- Legal obligation — tax and accounting records.
7. Retention
We keep account and billing records for as long as your account is active and as required by law afterwards (typically up to the statutory accounting period). Usage logs are retained for a limited operational window. Scraped page content is not retained beyond delivering your result.
8. International transfers
Where data is processed outside your region, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
9. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA and similar laws), you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to withdraw consent. California residents may opt out of "sharing" for cross-context behavioural advertising. To exercise any right, email [email protected]; you also have the right to complain to your local data protection authority.
10. Security
We use encryption in transit, hashed passwords, scoped API keys you can rotate, and access controls. No system is perfectly secure, but we work to protect your data and to notify you of a breach where the law requires.
11. Children
The service is for business and professional use and is not directed to anyone under 16. We do not knowingly collect data from children.
12. Changes
We will update this policy as the service evolves and revise the date above. Material changes will be notified in the dashboard or by email.
13. Contact
Questions or requests: [email protected]. See also our Terms of Service.