BotCruncher
ProductDetectionROIPricingFAQ
Sign inStart free
Legal

Privacy Policy

Last updated: 12 March 2026

1. Who we are

BotCruncher ("we", "us", "our") is operated by Botcruncher.com, a sole trader (enskild firma) registered in Sweden. We provide an AI-powered bot detection and ad fraud intelligence platform at botcruncher.com.

Contact: [email protected]

2. Data we collect

We collect different categories of data depending on how you interact with our service:

2.1 Account data (dashboard users)

When you register for BotCruncher, we collect:

  • Name and email address
  • Password (stored as a bcrypt hash — we never store plaintext passwords)
  • Site domains you register for monitoring

2.2 Visitor behavioural data (collected via the JS snippet)

When a website owner installs our JavaScript snippet on their site, we collect the following data from their visitors:

  • IP address — used for geolocation, datacenter/residential classification, and bot detection. We do not use IP addresses for advertising or user profiling.
  • User-agent string — to identify browser, OS, and known bot signatures
  • Page URL and referrer — to detect ad click parameters (gclid, fbclid, etc.)
  • Behavioural signals — mouse movement counts, scroll depth, click count, time on page, key press count. These are aggregate counts, not recordings of what was typed or where clicks occurred.
  • Browser capabilities — WebGL support, WebRTC support, canvas fingerprint hash, audio fingerprint hash, screen resolution, timezone, language headers. These are used solely for bot vs. human classification.
  • Automation markers — navigator.webdriver flag, headless browser indicators, bot library signatures

2.3 What we do NOT collect

  • No form input content (we do not read what users type)
  • No personal names, email addresses, or phone numbers of site visitors
  • No payment card information of site visitors
  • No cross-site tracking — each site is isolated
  • No cookies are set by our snippet

3. Legal basis for processing (GDPR Art. 6)

DataLegal basis
Account dataContract performance (Art. 6(1)(b)) — necessary to provide the service you signed up for
Visitor behavioural dataLegitimate interest (Art. 6(1)(f)) — the website owner has a legitimate interest in detecting fraudulent bot traffic and protecting their advertising spend
IP addressesLegitimate interest (Art. 6(1)(f)) — necessary for security, fraud detection, and IP intelligence classification

4. Where your data is stored

All data is stored and processed exclusively within the European Union. Our infrastructure runs on Hetzner servers in Germany. Your data never leaves EU jurisdiction.

We do not use US cloud providers (AWS, Google Cloud, Microsoft Azure) for data storage or processing. This is a deliberate architectural decision to ensure full compliance with EU data protection regulations and to provide our customers with genuine data sovereignty.

5. Data retention

PlanVisitor data retention
Free7 days
Starter30 days
Pro90 days
Agency365 days

Account data (email, name) is retained until you delete your account. Aggregated daily reports (non-personal statistics) may be retained indefinitely for trend analysis.

6. Data sharing and sub-processors

We share data only with the following parties, all for the purposes described:

ProviderPurposeData shared
Hetzner (Germany)Server infrastructureAll data (stored on their hardware)
CloudflareCDN, DDoS protection, DNSHTTP requests (transient, not stored)
StripePayment processingEmail, payment details (handled by Stripe directly)
MaxMindIP geolocation databaseNone — database is stored locally, no IPs are sent to MaxMind

We do not sell, rent, or trade personal data to any third party. We do not use advertising networks or third-party analytics tools on our site.

7. Cookies & local storage

Our snippet stores a persistent visitor identifier in your browser's localStorage to distinguish repeat visits for fraud scoring. EU regulators treat localStorage identifiers as equivalent to cookies under the ePrivacy Directive. The site operator using BotCruncher is responsible for obtaining visitor consent, or for relying on Legitimate Interest under GDPR Article 6(1)(f) — a template LIA is linked below. BotCruncher stores the IP address, user agent, and a device fingerprint (canvas/WebGL/audio) tied to each visitor for scoring.

The BotCruncher dashboard (for logged-in users) uses the following strictly necessary cookies:

  • bc_token — authentication session token (7-day expiry)
  • bc_active_site — remembers which site you're viewing in the dashboard

These are strictly necessary cookies under GDPR Art. 5(3) and ePrivacy Directive, and do not require consent as they are essential for the service to function.

8. Your rights (GDPR)

As an EU data subject, you have the following rights:

  • Right of access (Art. 15) — request a copy of your personal data
  • Right to rectification (Art. 16) — correct inaccurate data
  • Right to erasure (Art. 17) — request deletion of your data
  • Right to restrict processing (Art. 18)
  • Right to data portability (Art. 20) — receive your data in a structured format
  • Right to object (Art. 21) — object to processing based on legitimate interest

Site owners can erase all data associated with a specific IP address via the Data Rights tool in dashboard Settings. You can also delete your entire account and all associated data from Settings > Data Rights.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.

9. Data processing for website owners

When a website owner installs the BotCruncher snippet on their site, they are the data controller for their visitors' data, and BotCruncher acts as a data processor. Website owners are responsible for informing their visitors about BotCruncher's data collection in their own privacy policy.

We process visitor data solely for the purpose of bot detection and ad fraud analysis as instructed by the website owner. We do not use visitor data for any other purpose.

A Data Processing Agreement (DPA) governing this relationship is available at botcruncher.com/dpa. We also provide a Legitimate Interest Assessment template to help website owners document their lawful basis for using BotCruncher.

10. Security

We protect your data with:

  • TLS encryption for all data in transit
  • PostgreSQL Row-Level Security (RLS) for site-level data isolation
  • bcrypt password hashing
  • fail2ban intrusion prevention
  • UFW firewall with minimal open ports
  • Cloudflare DDoS protection
  • Hetzner ISO 27001-certified data centres for physical security

11. Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated via email to registered users. The "last updated" date at the top of this page reflects the most recent revision.

12. Contact

For any questions about this privacy policy or our data practices, contact us at:

Botcruncher.com
Email: [email protected]
Sweden, EU

© 2026 BotCruncher · Copenhagen
PrivacyTermsDPALIAStatus · all systems go