Privacy Policy
This Privacy Policy explains how SupaWeb Labs collects, uses, shares, and protects information when you use our website, services, and desktop scan agent (together, the “Services”). We are a Revenue Intelligence platform — the desktop application performs scanning, while reporting and results are delivered via our web dashboard.
1) Overview
What this policy covers and how the Services work.
What SupaWeb is (and is not)
SupaWeb Labs provides a Revenue Intelligence platform that connects technical, UX, and performance findings to business impact. The desktop application is an execution agent: it authenticates your account, verifies your subscription entitlement, scans within plan limits, and uploads the results to the web dashboard.
We do not sell personal data. We aim to store only what is required to operate the service, enforce plan limits, prevent abuse, and deliver the reporting experience.
2) Data We Collect
Information you provide, information generated by the Services, and technical logs.
Account & Identity
- • Email address, authentication identifiers, and basic account metadata.
- • Subscription entitlement indicators (e.g., plan tier, status, renewal period).
- • Support communications you send to us.
Scan & Usage Data
- • Website targets you submit for scanning (URLs, crawl scope settings).
- • Scan outputs (issue findings, factor results, summaries, scoring, and calculated impact models).
- • Operational metrics (scan start/end, counts of pages/factors, errors, timing).
Payment & Billing
Payments are processed by a third-party payment provider. We receive limited billing metadata to activate or modify subscription access (e.g., plan, status, timestamps, and identifiers).
Device & Log Data
- • IP address, device/browser identifiers, and security logs.
- • API request logs (rate limiting, abuse prevention, error diagnostics).
- • Cookie and analytics identifiers (where enabled).
3) How We Use Data
Purpose limitation: we use data to run the service, secure it, and improve it.
Primary purposes
- • Provide account access and authenticate users.
- • Verify subscription entitlements and enforce plan limits (pages/factors).
- • Run scans, generate reports, and deliver results on the web dashboard.
- • Prevent fraud, abuse, and unauthorized usage.
- • Provide customer support and troubleshoot issues.
- • Improve product reliability, performance, and user experience.
4) Legal Bases (GDPR)
If you are in the EEA/UK, we process personal data under these bases.
GDPR legal bases
- • Contract: to provide the Services you request, including authentication, plan enforcement, scanning, and reporting.
- • Legitimate interests: to secure our Services, prevent abuse, and improve performance (balanced against your rights).
- • Consent: where required for certain cookies or marketing communications (you can withdraw anytime).
- • Legal obligation: where required to comply with applicable laws.
Service providers & disclosures
We may share limited data with trusted vendors that support our infrastructure, authentication, database, hosting, and payments. These providers are authorized to process data only as necessary to provide services to us under contractual safeguards.
We may also disclose information if required by law, to protect users, prevent fraud/abuse, or enforce our terms and policies.
6) Subprocessors
Transparency for enterprise buyers. This list may evolve as the product scales.
Current subprocessors (high-level)
We use modern infrastructure vendors for hosting, database/auth, and payments. Exact names may vary by region or deployment. For enterprise due diligence, request our latest Subprocessor List by emailing support@supaweblabs.com.
Enterprise add-on: a formal DPA and Subprocessor List are available on request.
7) Security
How we protect data and reduce risk.
Security controls
- • Encryption in transit (TLS) for web/API communications.
- • Access control and least-privilege principles for internal operations.
- • Rate limiting and abuse protection for APIs.
- • Segmentation between scanning (desktop) and reporting (web) architecture.
- • Continuous monitoring and incident response procedures as the product matures.
No system is 100% secure. If you believe you found a security issue, email support@supaweblabs.com with details.
8) Data Retention
We keep data only as long as needed for business and legal purposes.
Retention principles
We retain account information while your account is active. Scan results may be retained to provide reporting access and historical comparisons (when enabled). We may delete or anonymize data when it is no longer necessary for the purposes described in this policy, subject to legal requirements.
You can request deletion of your account data by emailing support@supaweblabs.com.
9) International Transfers
Where data may be processed and the safeguards we apply.
Transfers & safeguards
Depending on your region and configuration, data may be processed in multiple countries. When required by applicable law, we rely on appropriate transfer mechanisms and contractual safeguards (e.g., SCCs) to protect personal data in transit and at rest.
Cookie usage
We may use cookies and similar technologies for authentication, security, and improving user experience. For details and controls, see our Cookie Policy.
11) Your Rights (GDPR / CCPA)
Your privacy rights and how to exercise them.
GDPR (EEA/UK)
- • Right to access, rectify, or delete your personal data.
- • Right to object or restrict processing in certain circumstances.
- • Right to data portability.
- • Right to withdraw consent (where processing relies on consent).
To exercise these rights, contact support@supaweblabs.com.
CCPA/CPRA (California)
- • Right to know what personal information is collected and how it is used.
- • Right to request deletion (subject to exceptions).
- • Right to correct inaccurate personal information.
- • Right to opt-out of “sale” or “sharing” (we do not sell personal data).
Requests may be verified to protect your account and prevent fraud.
12) Children
Our Services are not intended for children.
Age restrictions
Our Services are not directed to individuals under the age of 16 (or the age required by local law). If you believe a child has provided personal data, contact support@supaweblabs.com.
13) Policy Changes
We may update this policy as the product evolves.
Updates
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and may provide additional notice if required by law.
14) Contact
How to reach us about privacy questions or requests.
Contact us
For privacy inquiries, rights requests, or enterprise compliance questions, email support@supaweblabs.com.
Optional enterprise add-ons (available on request): Data Processing Addendum (DPA), Subprocessor List, and security documentation suitable for procurement and investor diligence.
Need enterprise compliance docs?
If you need a DPA, Subprocessor List, or a procurement-ready compliance pack, contact us and we’ll provide the latest materials.