AICrawlSuccess
Privacy Policy
Effective September 3, 2026
This Privacy Policy explains how DFS MediaLabs, LLC, operating the AICrawlSuccess service (“AICrawlSuccess,” “we,”
“us,” or “our”), collects, uses, discloses, retains, and protects information when you use our websites, scans,
reports, checkout, and support channels (collectively, the “Service”). It also describes privacy choices and rights.
This policy does not apply to third-party services governed by their own notices.
Privacy at a glance
- We scan only public website locations and do not request customer website credentials or private-site access.
- Stripe handles payment-card data; AICrawlSuccess does not receive full card numbers.
- Optional Meta campaign measurement and purchase optimization require Marketing consent. You can withdraw
that consent at any time.
- Security controls use bounded request data and pseudonymous network identifiers to prevent abuse.
- Internal service-usage summaries use scan lifecycle data and approximate city, state or region, and country,
when available, without retaining a raw visitor IP address in the summary.
- Google Analytics remains off until you accept Analytics, and its advertising, Signals, user-provided-data,
and automatic Enhanced Measurement features are disabled.
- Meta Pixel remains off until you accept Marketing, is disabled when Global Privacy Control is active, and
does not load on private scan or report routes.
1. Scope and roles
This policy applies to information we process as the business or controller responsible for the Service. When a
customer submits a public website, public page content may incidentally contain information about other people. The
website owner or submitting customer remains responsible for that website content and for having authority to
request the scan. We process the public content to provide the requested diagnostic report.
2. Information we collect
Website and scan information
The submitted website address; discovered public URLs; publicly available page text, markup, headers, links,
metadata, and technical signals; scan status; page counts; diagnostic evidence; scores; findings; ruleset and
model versions; generated report content; and operational identifiers. We obtain this information from you and
the public website you ask us to inspect.
Purchase and delivery information
Email address, selected tier, page limit, price, currency, transaction and payment-provider identifiers,
payment status, timestamps, report-access records, delivery status, and Stripe Checkout's required Terms
acceptance status. Stripe collects payment method and fraud-prevention information under its own privacy policy.
We receive transaction details, not full payment-card numbers.
Support communications
Name, email address, selected topic, message, and related correspondence when you contact us. A hidden form
field
may be used to identify automated spam, but legitimate users are not expected to complete it.
Security, request, and device information
Request time, route, response status, browser and device characteristics contained in standard HTTP headers,
referring origin where supplied, limited network information available to Cloudflare and our infrastructure,
Turnstile verification outcome, rate-limit events, provider response metadata, error and performance logs, and
pseudonymous keyed network identifiers. Our application uses keyed one-way digests for admission and rate-limit
identity rather than retaining raw visitor IP addresses in those records. For internal service-usage reporting,
Cloudflare may supply an approximate city, state or region, and two-letter country code derived from the
visitor's IP address. The usage record does not store the raw IP address, coordinates, postal code, metro code,
or timezone. IP-derived location may be inaccurate, particularly for VPN, mobile, and corporate networks.
Cookies and local choices
Privacy preferences, time-limited private report sessions, and payment-related technologies used when checkout
begins. Details, current technologies, durations, and controls are on our Cookie Policy.
Optional website analytics
If you accept Analytics, Google Analytics processes a sanitized page category, privacy-limited campaign
parameters, an origin-level referring site, browser and device characteristics, approximate geography, and
predefined events for page views, FREE-scan progress, checkout progress, report upgrades and downloads, and a
successfully submitted contact form. We do not send submitted website addresses, contact-form contents, email
addresses, payment identifiers, scan or report identifiers, private access grants, URL fragments, or
non-campaign query parameters to Google Analytics.
Optional Meta campaign measurement
If you accept Marketing, Meta Pixel processes a public-page view, browser and device characteristics, referring
site, Meta click identifier when supplied, and a Purchase event after our server confirms a completed
full-report checkout. The event includes the amount actually paid, currency, and a pseudonymous event identifier
to help prevent duplicate reporting. A full-report order completed with a 100% discount is reported with a value
of zero. FREE scans do not generate Purchase events.
Meta Pixel does not load on private scan or report routes. We do not send the submitted website address,
scan or report identifiers, private access grants, email addresses, operational payment identifiers, or
private URL fragments to Meta Pixel.
3. How we use information
We use information to:
- validate a request, retrieve eligible public pages, perform the scan, calculate results, generate and deliver a
report, and provide private report access;
- create and reconcile checkout, process transaction status, send purchase and report communications, preserve
Stripe Checkout Terms-acceptance status, and administer the limited terminal-failure refund process;
- respond to questions, investigate delivery or payment issues, and provide support;
- authenticate private access, detect bots and fraud, enforce rate and capacity limits, protect systems, debug
failures, prevent duplicate effects, and maintain reliability;
- measure aggregate website performance, understand Service operation, improve rules and user experience, and
develop features using appropriately limited or de-identified information;
- with consent, measure website acquisition, page engagement, FREE-to-paid funnel activity, report interactions,
and successful support-form engagement through privacy-limited Google Analytics events;
- with Marketing consent, measure Meta advertising visits and completed full-report purchases, and optimize
campaigns for purchases through Meta Pixel;
- prepare restricted internal daily usage reports covering submitted URLs, scan timing and outcome, page counts,
selected paid tier and value, FREE-to-paid attribution, and approximate city, state or region, and country when
available;
- comply with law, tax and accounting requirements, valid legal process, and enforce our agreements; and
- establish, exercise, or defend legal claims and protect users, third parties, and the Service.
Where a law requires a legal basis, we rely as applicable on performance of a contract or steps requested before a
contract; our legitimate interests in operating, securing, supporting, and improving the Service; compliance with
legal obligations; protection of legal rights; and consent for optional technologies or another purpose where we
specifically request it. You may withdraw consent prospectively, but withdrawal does not affect prior lawful
processing.
4. How we disclose information
We disclose information only as reasonably necessary for the purposes above:
- Cloudflare provides network proxying, security, bot verification through Turnstile, and
cookie-free aggregate web performance measurement.
- Amazon Web Services provides U.S.-region application hosting, queues, encrypted object and
database storage, logging, monitoring, and transactional email infrastructure.
- Stripe provides hosted payment collection, transaction processing, fraud prevention, and
payment
records.
- Google Analytics provides optional, consent-based website traffic and engagement measurement.
Google Signals, user-provided data, Enhanced Measurement, and advertising personalization are disabled, and we do
not authorize Google Analytics data for targeted advertising. Google's processing is described in How Google uses information from sites or apps
that use its services.
- Meta provides optional, consent-based campaign visit and conversion measurement through Meta
Pixel. We limit the integration to public-page views and completed full-report purchases, including the paid amount,
currency, and pseudonymous deduplication identifier. We do not load it on private scan or report routes.
Meta's processing is described in Meta's Privacy Policy.
- Email and support providers route and store communications needed to deliver reports and
respond
to requests.
- Professional advisers and authorities may receive information when reasonably necessary for
legal, security, accounting, insurance, dispute, or compliance purposes, or in response to valid legal process.
- Transaction participants may receive information in connection with a financing,
reorganization, merger, acquisition, sale, insolvency, or transfer of some or all of the business, subject to
appropriate safeguards and applicable law.
Providers may process information under their own privacy notices when acting independently, particularly for
payments, fraud prevention, and communications. We do not authorize our service providers to use information for
unrelated advertising.
5. Advertising measurement and choices
Google Analytics is used only for consented measurement, with its advertising features disabled. With Marketing
consent, Meta Pixel measures campaign visits and completed full-report purchases and supports purchase-focused
ad optimization. Meta receives the event data described above under its own privacy policy. We do not send customer
email addresses or private report contents to Meta. You can decline or withdraw Marketing consent through the
cookie controls. Global Privacy Control disables Meta Pixel, including for previously saved Marketing choices.
6. Retention
We retain information for the shortest period reasonably necessary for the Service, security, legal, and accounting
purposes described here. Current application lifecycles include:
- FREE scan requests and generated report access generally expire after 24 hours;
- paid scan and report-access artifacts generally expire after 180 days;
- checkout delivery-contact artifacts and application contact-form intake records are generally scheduled to
expire after 90 days;
- terminal scan-usage summaries used for restricted internal daily reporting are generally scheduled to expire
after 90 days;
- Turnstile verification receipts generally expire after 24 hours, while short-lived idempotency, admission, and
security records generally expire between 1 and 30 days;
- central application logs are generally retained for 30 days; and
- Google Analytics user-level and event-level data is configured for 14-month retention, without resetting the
user-retention period when new activity occurs; its first-party cookies are configured to expire no later than 400
days after first placement without refreshing that expiration on later page loads; and
- encrypted backups, point-in-time recovery data, and noncurrent object versions may remain for approximately 30
to
35 additional days after primary data is changed or expires.
Deletion by distributed systems may not be instantaneous. Transaction, Stripe Terms-acceptance, tax, accounting,
anti-fraud, dispute, and provider records may be retained longer where reasonably necessary or required by law.
Previously collected Google Analytics data remains subject to the configured retention period after consent is
withdrawn.
Support correspondence may be retained beyond the application intake record when needed to resolve the matter or
preserve legal rights. Stripe and other independent providers determine retention for records they control. We may
retain de-identified information that cannot reasonably identify a person.
7. Cookies, browser controls, and Global Privacy Control
Essential technologies support saved privacy choices, private report access, security, and payment. Google
Analytics remains off unless you accept Analytics. You can review, withdraw, or change choices on our Cookie Policy; withdrawal stops future Google Analytics collection and removes the Google
Analytics cookies known to this site. Clearing cookies may remove a saved preference or report session. When
recognized, a Global Privacy Control signal disables Meta Pixel, even if Marketing was previously accepted.
Withdrawing Marketing consent stops future Meta collection and removes the known first-party Meta cookies.
8. International processing
The Service is operated in the United States, and information may be processed in the United States or other
countries where a provider operates. Those countries may have different privacy laws. Where applicable law requires
a transfer mechanism, we use the provider and contractual safeguards reasonably available for the transfer. By
requesting the Service, you understand that cross-border processing may occur subject to applicable legal
protections.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including bounded
input contracts, abuse controls, least-privilege access, encryption in transit and at rest where supported,
restricted private report access, security monitoring, and limited retention. No internet transmission, website,
provider, or storage system is completely secure, and we cannot guarantee absolute security. Do not submit
credentials, private-system URLs, confidential source material, health records, government identifiers, or other
sensitive personal information through scan or support fields.
10. Your privacy rights
Depending on where you live and subject to exceptions, you may have rights to request access, confirmation,
correction, deletion, portability, restriction, or objection; withdraw consent; opt out of certain sales, sharing,
targeted advertising, or profiling; and appeal a denied request. You may also have a right to complain to a privacy
regulator. We do not discriminate against anyone for exercising an applicable privacy right.
To submit a request, email [email protected] with the subject “Privacy
Request” and describe the right you wish to exercise. We may ask for information reasonably necessary to verify your
identity and authority, such as control of the relevant email address or transaction details. An authorized agent
must provide proof of authority, and we may verify the request directly with you. We will respond within the period
required by applicable law. We may deny or limit a request where an exception applies, including where retention is
required for security, fraud prevention, transaction records, legal obligations, or legal claims.
11. U.S. state disclosures
For residents of states with comprehensive privacy laws, the categories of personal information we may collect are
identifiers and contact information; internet or network activity; commercial and transaction information; and
inferences represented by diagnostic findings about a submitted website. The sources, purposes, recipient
categories, and retention approach are described above. We do not knowingly collect sensitive personal information
for the Service and do not use or disclose it to infer characteristics. We do not offer financial incentives for
personal information.
12. EEA, United Kingdom, and similar rights
Where the GDPR, UK GDPR, or a similar law applies, we act as controller for the processing described in this
policy.
The applicable legal bases are identified in Section 3. You may object to processing based on legitimate interests;
we will stop unless we demonstrate compelling legitimate grounds or need the information for legal claims. You may
lodge a complaint with the supervisory authority where you live, work, or believe a violation occurred. Nothing in
this section limits rights that applicable law makes mandatory.
13. Children
The Service is intended for adults and business use and is not directed to anyone under 18. We do not knowingly
collect personal information from children. If you believe a child submitted personal information, contact us so we
can investigate and take appropriate action.
14. Third-party websites and public content
A report may identify or link to public pages and third-party services. We do not control those parties’ privacy or
security practices. The submitted website’s own operator is responsible for notices and lawful publication of its
content. Do not use AICrawlSuccess to submit personal information or public content that you lack authority to
process.
15. Changes to this policy
We may update this policy to reflect changes in the Service, providers, law, or processing. The effective date
identifies the current policy. We will provide additional notice or request consent when required by law. Stripe
Checkout presents the current Privacy Policy link and separately records required acceptance of the Terms of
Service.
16. Contact
Privacy questions and rights requests may be sent to
[email protected]. Email is the designated contact method for the Service.