Enterprise PrivacyGDPRCCPA/CPRASecurity-first

Privacy Policy

This Privacy Policy explains how SupaWeb Labs collects, uses, shares, and protects information when you use our website, services, and desktop scan agent (together, the “Services”). We are a Revenue Intelligence platform — the desktop application performs scanning, while reporting and results are delivered via our web dashboard.

Last updated: February 18, 2026

1) Overview

What this policy covers and how the Services work.

What SupaWeb is (and is not)

SupaWeb Labs provides a Revenue Intelligence platform that connects technical, UX, and performance findings to business impact. The desktop application is an execution agent: it authenticates your account, verifies your subscription entitlement, scans within plan limits, and uploads the results to the web dashboard.

We do not sell personal data. We aim to store only what is required to operate the service, enforce plan limits, prevent abuse, and deliver the reporting experience.

2) Data We Collect

Information you provide, information generated by the Services, and technical logs.

Account & Identity

  • • Email address, authentication identifiers, and basic account metadata.
  • • Subscription entitlement indicators (e.g., plan tier, status, renewal period).
  • • Support communications you send to us.

Scan & Usage Data

  • • Website targets you submit for scanning (URLs, crawl scope settings).
  • • Scan outputs (issue findings, factor results, summaries, scoring, and calculated impact models).
  • • Operational metrics (scan start/end, counts of pages/factors, errors, timing).

Payment & Billing

Payments are processed by a third-party payment provider. We receive limited billing metadata to activate or modify subscription access (e.g., plan, status, timestamps, and identifiers).

Device & Log Data

  • • IP address, device/browser identifiers, and security logs.
  • • API request logs (rate limiting, abuse prevention, error diagnostics).
  • • Cookie and analytics identifiers (where enabled).

3) How We Use Data

Purpose limitation: we use data to run the service, secure it, and improve it.

Primary purposes

  • • Provide account access and authenticate users.
  • • Verify subscription entitlements and enforce plan limits (pages/factors).
  • • Run scans, generate reports, and deliver results on the web dashboard.
  • • Prevent fraud, abuse, and unauthorized usage.
  • • Provide customer support and troubleshoot issues.
  • • Improve product reliability, performance, and user experience.

GDPR legal bases

  • Contract: to provide the Services you request, including authentication, plan enforcement, scanning, and reporting.
  • Legitimate interests: to secure our Services, prevent abuse, and improve performance (balanced against your rights).
  • Consent: where required for certain cookies or marketing communications (you can withdraw anytime).
  • Legal obligation: where required to comply with applicable laws.

5) Sharing & Disclosures

We share data only with service providers needed to run SupaWeb, or when required by law.

Service providers & disclosures

We may share limited data with trusted vendors that support our infrastructure, authentication, database, hosting, and payments. These providers are authorized to process data only as necessary to provide services to us under contractual safeguards.

We may also disclose information if required by law, to protect users, prevent fraud/abuse, or enforce our terms and policies.

6) Subprocessors

Transparency for enterprise buyers. This list may evolve as the product scales.

Current subprocessors (high-level)

We use modern infrastructure vendors for hosting, database/auth, and payments. Exact names may vary by region or deployment. For enterprise due diligence, request our latest Subprocessor List by emailing support@supaweblabs.com.

Provider
Purpose
Data Processed
Region
Hosting/CDN
Web delivery, API routing
Requests, logs, report access
Global
Database/Auth
User accounts, entitlements
Email, user ID, plan status
Configurable
Payments
Subscriptions, invoicing
Billing metadata (limited)
Global

Enterprise add-on: a formal DPA and Subprocessor List are available on request.

7) Security

How we protect data and reduce risk.

Security controls

  • • Encryption in transit (TLS) for web/API communications.
  • • Access control and least-privilege principles for internal operations.
  • • Rate limiting and abuse protection for APIs.
  • • Segmentation between scanning (desktop) and reporting (web) architecture.
  • • Continuous monitoring and incident response procedures as the product matures.

No system is 100% secure. If you believe you found a security issue, email support@supaweblabs.com with details.

8) Data Retention

We keep data only as long as needed for business and legal purposes.

Retention principles

We retain account information while your account is active. Scan results may be retained to provide reporting access and historical comparisons (when enabled). We may delete or anonymize data when it is no longer necessary for the purposes described in this policy, subject to legal requirements.

You can request deletion of your account data by emailing support@supaweblabs.com.

9) International Transfers

Where data may be processed and the safeguards we apply.

Transfers & safeguards

Depending on your region and configuration, data may be processed in multiple countries. When required by applicable law, we rely on appropriate transfer mechanisms and contractual safeguards (e.g., SCCs) to protect personal data in transit and at rest.

10) Cookies

How cookies are used and how you control them.

Cookie usage

We may use cookies and similar technologies for authentication, security, and improving user experience. For details and controls, see our Cookie Policy.

11) Your Rights (GDPR / CCPA)

Your privacy rights and how to exercise them.

GDPR (EEA/UK)

  • • Right to access, rectify, or delete your personal data.
  • • Right to object or restrict processing in certain circumstances.
  • • Right to data portability.
  • • Right to withdraw consent (where processing relies on consent).

To exercise these rights, contact support@supaweblabs.com.

CCPA/CPRA (California)

  • • Right to know what personal information is collected and how it is used.
  • • Right to request deletion (subject to exceptions).
  • • Right to correct inaccurate personal information.
  • • Right to opt-out of “sale” or “sharing” (we do not sell personal data).

Requests may be verified to protect your account and prevent fraud.

12) Children

Our Services are not intended for children.

Age restrictions

Our Services are not directed to individuals under the age of 16 (or the age required by local law). If you believe a child has provided personal data, contact support@supaweblabs.com.

13) Policy Changes

We may update this policy as the product evolves.

Updates

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and may provide additional notice if required by law.

14) Contact

How to reach us about privacy questions or requests.

Contact us

For privacy inquiries, rights requests, or enterprise compliance questions, email support@supaweblabs.com.

Optional enterprise add-ons (available on request): Data Processing Addendum (DPA), Subprocessor List, and security documentation suitable for procurement and investor diligence.

Need enterprise compliance docs?

If you need a DPA, Subprocessor List, or a procurement-ready compliance pack, contact us and we’ll provide the latest materials.