This Privacy Policy explains how CRAFTAC SRL, a limited liability company incorporated under Romanian law, registered with the Romanian Trade Register under no. J22/725/2024 and having unique identification code (CUI) 49662167, with its registered office at Str. Bisericii 9, Bl. 65, Sc. A, Et. 4, Ap. 15, Cod 707085, Sat Lunca Cetatuii, Judetul Iasi, Romania ("CRAFTAC", "PageShield", "we", "us" or "our"), processes personal data in connection with pageshield.io, the PageShield dashboard, Protection Snippets, pixel fallback, Heartbeats, Detection Events, local IP-based location enrichment, technical bot/human classification, notification-suppression rules, alerts, webhooks, export and switching functionality and related services (together, the "Service").
The Service is primarily intended and optimised for online merchants, store owners, commercial website operators and their teams. This Policy also applies to natural persons who create or use an Account, contact us, interact with the Service, or visit a page on which a Customer has installed the Protection Snippet, to the extent that PageShield processes their personal data.
This Privacy Policy should be read together with the PageShield Terms of Service and, where PageShield processes Customer Personal Data on behalf of a Customer, the PageShield Data Processing Addendum ("DPA"). Where the PageShield EU Data Act Addendum applies, that addendum governs switching, portability, transition, retrieval and deletion within its stated scope. This Privacy Policy remains the transparency notice for personal data processed by PageShield and does not replace the Customer's own privacy, localStorage or similar notices. Capitalised terms not defined in this Privacy Policy have the meanings given in the Terms, DPA or EU Data Act Addendum, as applicable.
We process Account and authentication data to provide the dashboard, limited subscription metadata to manage Plans, support and communication data to answer requests, protection-profile and technical metadata to provide Heartbeat and clone-detection functionality, approximate country and city information, per-event bot/human/unknown classifications, daily deduplication and customer-configured notification suppression, Service Usage Data to operate and improve the Service, and security and request data to protect, administer and maintain the Service.
The Protection Snippet is not designed to solicit or intentionally collect directly identifying information such as names, payment-card details, order details, checkout or form content, health information, children's information or other sensitive content from visitors of protected or detected pages. URLs, referrers, IP addresses, user-agent strings and related request metadata may nevertheless constitute personal data and may sometimes contain information inserted by a Customer, visitor, browser, platform or third party. For Detection Event enrichment, the raw IP address is used transiently in memory and is not retained as a Detection Event field.
The Protection Snippet does not use cookies and is not intended for advertising tracking or cross-site profiling. It does not actively collect additional browser or device attributes commonly used for fingerprinting, such as canvas, WebGL, installed-font, hardware or similar high-entropy signals, and it does not create a persistent cross-site visitor identifier. The limited server-side daily deduplication and customer-scoped HMAC comparison described below use request metadata only for the stated Service purposes. The Protection Snippet uses localStorage on a Customer page only to limit the frequency of Heartbeats so that, under normal technical conditions, a Heartbeat is designed not to be sent more than once per hour for the same browser/device. The absence of cookies does not by itself make ePrivacy, terminal-equipment or similar rules inapplicable.
Lemon Squeezy processes payment transactions as Merchant of Record. PageShield does not receive or store full payment-card details. We do not sell personal data or use visitor technical metadata for behavioural advertising or advertising profiling.
Where a Customer requests an export or switching process, PageShield may process the request, destination and authorised-representative details necessary to validate, secure, document and complete the transfer. An EU Data Act switching request is separate from a data subject request under the GDPR, even though the relevant export may contain personal data.
CRAFTAC SRL acts as an independent controller when it determines the purposes and means of processing, including for Account administration, authentication, subscription and access management, support, Service communications, security, abuse prevention, rate limiting, Service reliability, Plan administration, switching-request administration, legal compliance and the establishment, exercise or defence of legal claims.
Where PageShield processes Customer Personal Data on a Customer's documented instructions in connection with Heartbeats, Detection Events, local geolocation and ASN lookup, bot/human/unknown classification, daily deduplication, customer-scoped notification-suppression rules, dashboard history, alerts, webhook payloads, redirect functionality, Customer-requested exports or switching transfers, PageShield acts as a processor. If the Customer itself acts as a processor for another controller, PageShield may act as a subprocessor. The DPA governs that processing. The Customer will ordinarily act as controller for its own website, protected pages, visitors, configurations and protection activity, including processing triggered when the Protection Snippet executes on a detected page; an agency or service provider using PageShield for a client may instead act as a processor and must ensure that it has the necessary instructions and authority.
PageShield may separately act as an independent controller for limited technical information that it needs for its own security, fraud and abuse prevention, rate limiting, Service reliability, incident investigation, switching-process security and documentation, legal compliance and the establishment, exercise or defence of legal claims. Controller and processor roles depend on the actual purposes and means of processing in the relevant context; contractual descriptions do not override the factual allocation required by applicable data-protection law.
If you are a visitor of a Customer's page, or your request generates a Detection Event on a page detected through a Customer's Protection Snippet, the Customer will ordinarily act as controller for the Customer-configured processing described in this Policy, and PageShield will ordinarily process the relevant Customer Personal Data as processor under the DPA. PageShield may act separately as an independent controller only for the limited security, reliability, legal-compliance and rights-protection purposes described above. Questions about why a Customer enabled or configured the Service should ordinarily be directed to that Customer. Each party remains responsible for the transparency, lawful-basis, data-protection and electronic-communications obligations that apply directly to it; this Policy does not transfer or exclude obligations imposed by applicable law.
This Policy may concern the following individuals:
Customers who are natural persons, authorised Account users, team members and business contacts;
people who contact PageShield for support, rights requests, switching requests or other Service-related matters;
visitors of pages on which a Customer has installed a Protection Snippet or pixel fallback;
people whose devices or requests generate limited security, authentication, Heartbeat or Detection Event metadata; and
representatives or personnel of destination providers or other third parties authorised by a Customer for an export or switching process.
We obtain personal data from the following sources:
directly from you when you register, configure the Service, contact us, exercise a right or submit a switching or export request;
automatically from your browser, device, network request and use of the website or dashboard;
through the Protection Snippet or pixel fallback when it runs on a configured or unexpected domain;
from Customers that configure profiles, users, webhooks, protected pages, redirect destinations, authorised representatives and switching destinations;
from Lemon Squeezy in the form of limited subscription, transaction-reference and status metadata;
from hosting, network, security or other providers where necessary to operate, secure, investigate or document the Service; and
from locally hosted IP geolocation and ASN datasets and a locally stored, manually maintained list of known cloud or hosting ASNs, used to derive approximate location and a technical network signal without sending the relevant IP address to the dataset provider or dynamically populating the list from an external service.
An email address, a password credential that PageShield stores only in hashed form, and the technical information required to authenticate and operate an Account are necessary to create and use the dashboard. Required protection-profile fields are necessary to activate the corresponding Service functionality. Information reasonably necessary to identify the Account, destination and authorised party is required to process a switching or third-party transfer securely. Optional profile fields and most support information are voluntary, although we may be unable to resolve a request without sufficient details. Heartbeat, Detection Event and request metadata are generated automatically when the relevant functionality or request occurs.
Where PageShield obtains personal data indirectly and acts as controller, this Policy is intended to provide the information required by applicable law. Customers remain responsible for making their own notices readily available at or before the collection or transmission that they control.
| Category | Examples | Purpose |
|---|---|---|
| Account and authentication data | Email address, password hash, Account identifiers, authentication/session token and, if provided or enabled, limited profile, organisation or authorised-user settings. | Create and administer Accounts, authenticate users, secure sessions, provide the dashboard and manage access. |
| Subscription metadata | Plan, subscription status, renewal or cancellation status, Lemon Squeezy customer and subscription identifiers, transaction references and related billing metadata. | Activate, manage, suspend, resume or terminate access to paid features. Full payment-card details are processed by Lemon Squeezy, not CRAFTAC. |
| Support and communication data | Messages, support requests, correspondence, issue details, screenshots or other information you choose to send. | Respond to requests, troubleshoot issues, communicate about the Service and maintain support and legal records. Ordinary support records are retained for up to two (2) years after the request is closed; unnecessary attachments and diagnostic material are deleted earlier where practicable. |
| Protection-profile data | Protected Domains and URLs, Redirect Destinations, authorised-domain lists, exclusions, schedules, triggers, percentages, webhook URLs, profile identifiers, notification-suppression settings and rules, and other Customer configurations. | Configure and operate Heartbeat, clone detection, approximate location and technical classification, alerts, notification suppression, redirect, webhook and dashboard functionality. Profiles above a downgraded Plan limit remain stored but inactive until reactivated or deleted. |
| Heartbeat metadata | Customer or protection-profile identifier, hostname, timestamp and related request metadata generated on an authorised original domain. | Confirm that the Protection Snippet is active, monitor Service reliability and display protection status. Raw Heartbeat records are automatically deleted after thirty (30) days. |
| Detection Event metadata | Hostname, URL, referrer if available, user-agent string, timestamp, redirect status, approximate country and city, a bot/human/unknown classification and related technical metadata generated on an unexpected domain. The raw IP address is processed transiently in memory for local GeoLite2 City and GeoLite2 ASN lookup, daily deduplication and customer-scoped rule comparison. The transient ASN is checked against a locally stored, manually maintained cloud/hosting ASN list that is not dynamically populated from an external service. The raw IP, ASN, list-match result and data-centre/residential signal are not retained as Detection Event fields. | Record, deduplicate and enrich Detection Events, display dashboard history, provide an informative technical classification, support optional notification suppression and redirect functionality, and generate alerts. Complete retained Detection Event metadata is kept for ninety (90) days. After that period, identifying, linkable or singling-out technical fields, including approximate country, city and the Classification Result, are deleted or irreversibly anonymised, with no conditional extension. |
| Notification-suppression rule data | Customer or protection-profile identifier, a customer-scoped keyed HMAC-derived matching value, rule status, creation time, last-match time and expiry time. The raw IP address and HMAC secret are not stored in the rule record. The matching value is internal to PageShield and is not included in customer-facing or switching exports; any exported rule identifier is a separate non-secret record identifier. | Suppress notifications for a matching source only for the Customer that created the rule. Redirect functionality remains active. The rule expires ninety (90) days after creation or the most recent match, unless removed earlier by the Customer; it is not used to create a cross-customer IP-reputation database. |
| Server logs and security data | IP addresses, request metadata, timestamps, authentication and rate-limit events, error information, webhook delivery status and retry records, security signals and incident records. These are separate from the raw IP address used transiently for Detection Event enrichment; PageShield does not intentionally write that raw IP to the Detection Event record or feature-specific application logs. | Secure and operate the Service, apply rate limits, investigate incidents and troubleshoot failures. Routine logs are retained for thirty (30) days; isolated incident or legal records may be retained for the longer limited periods described in Section 12. |
| Service Usage Data | Technical, operational, diagnostic and statistical information generated through operation, security, performance and use of the Service, including feature use, request volumes, errors and Plan-limit measurements. It excludes Customer Personal Data, Detection Event records and Heartbeat records when PageShield processes them on the Customer's behalf, but may include limited request or security metadata processed by PageShield as controller. | Operate, secure, maintain, troubleshoot and administer the Service, measure and enforce Plan limits, and understand and improve Service performance. It is treated as personal data until aggregated or irreversibly anonymised. |
| Switching, export and retrieval request data | Account identification, request type, requested scope, destination-provider or on-premises details, authorised-representative details, transfer instructions, acknowledgements, communications, delivery records and security-verification information. | Verify authority, produce and secure exports, administer deletion and document compliance. Request and confirmation records are retained for up to three (3) years after closure; temporary packages follow the shorter package-retention period. |
| Deletion ledger data | A keyed cryptographic hash (HMAC or equivalent) of the deleted Account email address and the deletion date, stored separately from the main database. | Prevent a backup restoration from reintroducing a deleted Account and automatically reapply deletion. Each pseudonymised ledger entry is automatically deleted thirty (30) days after Account deletion. |
| Dashboard localStorage | Authentication/session token and a basic interface preference, such as a selected light or dark theme. | Maintain dashboard sign-in and session continuity and remember the selected interface preference. |
| Protection Snippet localStorage | A localStorage entry used on a Customer page to limit Heartbeat frequency. | Limit Heartbeats so that, under normal technical conditions, they are designed not to be sent more than once per hour for the same browser/device. This is not used for advertising, profiling or cross-site tracking. |
The categories of personal data, their sources and the purposes for which they are processed are set out in Table 1 below. The exact fields processed in a particular case depend on the features used, the Customer configuration and the information contained in the relevant request or communication.
PageShield does not require Customers to submit sensitive personal data, payment-card data, authentication credentials, health data, children's data, special-category data or other high-risk information through URLs, referrers, configuration fields, webhooks, switching instructions or support requests. Customers should minimise such data and avoid including it in locations that may be transmitted to PageShield or a destination selected by the Customer.
When the Protection Snippet runs on the Customer's authorised original domain, it may send a limited Heartbeat. Under normal technical conditions, the Heartbeat is designed to be sent no more than once per hour for the same browser/device. It may include the Customer or protection-profile identifier, hostname and timestamp and is used to confirm that protection is active and functioning.
The Heartbeat is not intended to identify a visitor, create an advertising profile, perform cross-site tracking or fingerprint a device. As with most web requests, related server logs may still contain an IP address, user-agent string and other request metadata.
When the Protection Snippet appears to run on a domain other than the configured Protected Domain, the Service may receive a Detection Event containing the hostname, URL, referrer if available, user-agent string, timestamp, redirect status and related technical metadata. The request's raw IP address is used transiently in memory to perform local location and ASN lookups, generate a short-lived daily deduplication identifier and, where the Customer has created a rule, compare a customer-scoped notification-suppression identifier. The raw IP address used for this Detection Event flow is not retained as part of the Detection Event, written to the application database, or recorded in application or infrastructure logs generated for that flow. Separate routine logs for other Service activities, such as Account authentication, dashboard security or incident response, are described in Sections 4 and 12.
The location and ASN lookups are performed locally against the MaxMind GeoLite2 City and GeoLite2 ASN databases stored on PageShield infrastructure. The raw IP address is not transmitted to MaxMind or any other third party for a live lookup, and no additional external geolocation, ASN or IP-intelligence API or database is used for the functions described in this Section. Where a pixel fallback is used, it may generate the same or a more limited subset of Detection Event metadata, depending on the technical conditions. The enrichment, classification, deduplication and suppression functions are performed server-side and do not add cookies or localStorage entries and do not actively collect additional browser or device attributes commonly used for fingerprinting beyond the request metadata described above.
PageShield derives an approximate country and city from the raw IP address through the locally hosted GeoLite2 City database and obtains the ASN through the locally hosted GeoLite2 ASN database. The ASN is checked against a locally stored, manually maintained list of ASNs known to belong to cloud or hosting providers, including providers such as AWS, Google Cloud, Microsoft Azure, DigitalOcean, OVH and Hetzner. The list is not dynamically populated from an external service and may be reviewed and updated by PageShield from time to time. Solely for the classification heuristic, an ASN found on that list is treated as a data-centre signal, while an ASN not found on the list is treated as a non-data-centre or residential-ISP signal. This signal is not a verified statement about the network or person. The ASN, list-match result and data-centre/residential signal are used transiently and are not retained. The only retained technical label is bot, human or unknown.
The classification is produced separately for each Detection Event from the user-agent string and the transient network signal described above. The technical reasons, ASN and data-centre/residential signal are not stored with the event, and PageShield does not build a persistent visitor or source profile for this feature. The result is informative, may be inaccurate, and may influence only the suppression of notifications where the Customer has expressly enabled that option; it does not automatically change, disable or otherwise affect redirect behaviour.
For short-term event deduplication, PageShield generates a pseudonymous identifier using a secret or salt that rotates daily. The identifier is used only within the applicable daily window, is not used to create a persistent cross-day or cross-customer profile, and is deleted or rendered unusable when the daily secret or salt rotates.
A Customer may create a rule instructing PageShield not to send notifications for future Detection Events associated with the same source IP address. PageShield does not retain the raw IP address for that rule. It creates a customer-scoped keyed HMAC-based pseudonymous identifier, stores the rule separately for that Customer and compares future transiently received IP addresses only within that Customer scope.
A notification-suppression rule affects notifications only. It does not prevent a Detection Event from being recorded where otherwise applicable and does not disable or alter redirect functionality. The Customer may remove the rule at any time. The identifier and rule expire ninety (90) days after creation or the most recent matching occurrence, whichever is later. PageShield does not reuse the identifier for another Customer and does not maintain a global IP-reputation list. A matching occurrence therefore restarts the ninety-day period, so a rule may remain active for longer than ninety days while matching continues.
Where product CSV export is available for the applicable Plan and the relevant functionality has been enabled and generated retained records, the export package includes, for retained Detection Events, the approximate country, approximate city and bot/human/unknown Classification Result, and includes customer-facing Notification Suppression Rule records with the rule scope and available lifecycle metadata. These records may be provided in the Detection Event CSV or in a separate rules CSV within the export package. The export does not include the raw source IP address, transient ASN, internal data-centre/residential signal, internal ASN list, HMAC key or secret, HMAC-derived matching value, rotating daily salt, or internal classification and matching logic. Any customer-facing rule identifier included in an export is a separate non-secret record identifier and is not the HMAC-derived value used to recognise a future source. Statutory switching exports are governed additionally by the EU Data Act Addendum.
A Detection Event, approximate country or city, network signal and bot/human/unknown result are technical estimates. They do not establish a visitor's identity, residence, precise location, intent or legal status and do not by themselves establish that a page or request is unlawful, infringing, automated, malicious or unauthorised. Events and classifications may be incomplete, duplicated, delayed or inaccurate and may arise from staging, previews, proxies, VPNs, shared networks, caches, content delivery systems, authorised mirrors or other legitimate configurations.
The Service is not designed to collect names, checkout details, card details, order content, form submissions or other transaction data from visitors. Customers must not intentionally place unnecessary personal data, sensitive information or confidential information in protected URLs, Redirect Destinations, webhook URLs, referrers, configuration fields or switching instructions. Information contained in a URL or referrer may be transmitted automatically by a browser or platform even when PageShield did not request that information.
Webhook alerts are available only on Pro and Business. The alert payload is limited to a generic message directing the Customer to review the dashboard. It does not include the full URL, referrer, user-agent string, IP address or protection-profile name. PageShield processes the Customer-configured webhook destination, delivery status, timestamps and limited error information required to attempt delivery and troubleshoot failures. If delivery fails, the Service retries after approximately five (5) seconds, thirty (30) seconds and two (2) minutes, then records the failure in an error log retained for thirty (30) days without affecting other Service functions.
The table below describes the legal bases that PageShield relies on when it acts as an independent controller. Where PageShield acts only as a processor, the Customer determines the legal basis for the underlying processing and PageShield processes the relevant data under the DPA and the Customer's documented instructions. The GDPR legal bases described below do not determine whether separate ePrivacy, terminal-equipment, localStorage or electronic-communications requirements apply.
| Processing activity | PageShield role | Legal basis or relevant interest |
|---|---|---|
| Account creation, authentication and dashboard access | Controller | Performance of a contract or steps taken at the individual's request before entering a contract; legitimate interests in providing and securing business-user access where the Account user acts for an organisation. |
| Subscription and Plan administration | Controller | Performance of a contract; legitimate interests in administering business subscriptions; compliance with legal obligations for records that CRAFTAC must retain. |
| Support and Service communications | Controller | Performance of a contract; legitimate interests in support, troubleshooting, security and maintaining proportionate records; legal obligation where applicable. Records are retained for up to two (2) years after closure, subject to earlier deletion where no longer necessary and longer retention only where law or a live claim requires it. |
| Customer-configured Heartbeats, Detection Events, local geolocation and ASN lookup, bot/human/unknown classification, daily deduplication, notification suppression, alerts, webhooks and redirects | Processor where performed on the Customer's instructions | The Customer determines and documents the applicable legal basis, necessity, proportionality and transparency arrangements for the relevant visitor processing. The DPA governs PageShield's processing on behalf of the Customer. |
| Dashboard exports, Account deletion and deletion-restoration safeguards | Controller for administration, verification, security, deletion-ledger and compliance records; processor for Customer Personal Data included in a Customer-requested export | Performance of a contract; legitimate interests in validating authority, protecting exports, preventing restoration of deleted Accounts and documenting requests; legal obligation where the request exercises a statutory right. Request records are retained for up to three (3) years. Each export link expires after seven (7) days. At least one retrievable package or the ability to regenerate it remains available throughout any applicable EU Data Act retrieval period, and remaining temporary packages are deleted no later than fourteen (14) days after that period closes, unless law or a live claim requires longer retention. Deletion-ledger entries are retained for thirty (30) days. |
| Security, abuse prevention, rate limiting, reliability and incident investigation | Controller for PageShield's own purposes | Legitimate interests in securing the Service, preventing misuse, protecting Customers and visitors, maintaining reliability and investigating incidents. |
| Dashboard localStorage and related authentication data | Controller | Performance of a contract and legitimate interests in authentication, Account administration and session continuity. The theme preference supports a user-selected interface setting. Separate terminal-equipment rules apply independently of Article 6 GDPR. |
| Protection Snippet localStorage and Heartbeat throttling on Customer pages | Processor for Customer-configured localStorage and Heartbeat processing; PageShield may separately act as controller for server-side security, abuse-prevention or legal-protection processing | The Customer determines the GDPR legal basis and any consent, notice or exception required under ePrivacy, electronic-communications or terminal-equipment rules for the Customer-controlled implementation. An Article 6 GDPR legal basis does not replace a separate requirement under those rules. |
| Limited technical data used by PageShield for its own security or legal protection | Controller | Legitimate interests in fraud prevention, security, service integrity and establishing, exercising or defending legal claims. |
| Compliance with law and binding requests | Controller | Compliance with legal obligations and, where applicable, legitimate interests in responding to lawful requests and protecting legal rights. |
| Service performance analysis and product improvement using limited Service Usage Data | Controller | Legitimate interests in diagnosing failures, understanding Service performance, prioritising improvements and administering Plans, subject to necessity, balancing, data minimisation and aggregation or irreversible anonymisation where reasonably possible. Customer Personal Data processed on a Customer's behalf is not used for an independent product-improvement purpose without a documented instruction or another lawful basis. |
Our legitimate interests include providing a secure and reliable technical service, preventing fraud and unauthorised use, administering business relationships, resolving support issues, securing and documenting switching processes, understanding and improving Service performance, and protecting legal rights. When relying on legitimate interests, we consider whether the interest is lawful, specific and current, whether the processing is necessary, and whether the interests, rights or freedoms of the relevant individuals override that interest. Relevant safeguards include data minimisation, limited access, validation of authorised recipients, secure transfer methods and aggregation or irreversible anonymisation where reasonably possible.
If PageShield later introduces optional marketing communications, analytics or non-essential tracking, we will identify and use an appropriate legal basis and provide any choices, notices or consents required before or when that processing begins.
to create and administer Accounts, authenticate users and manage access;
to provide, operate, maintain, secure and support the Service;
to configure and operate Heartbeats, Detection Events, local approximate geolocation, per-event bot/human/unknown classification, daily deduplication, customer-scoped notification suppression, dashboard history, alerts, webhooks and optional redirects;
to receive and use limited subscription metadata from Lemon Squeezy and administer paid access;
to respond to requests, troubleshoot issues and communicate about the Service;
to validate, secure, perform and document Customer export, switching, retrieval and deletion requests;
to communicate with destination providers or other third parties expressly authorised by the Customer;
to enforce Plan limits, prevent abuse, investigate suspected violations and protect the Service and third parties;
to comply with legal obligations and establish, exercise or defend legal claims;
to notify Customers about material Service, document, Account, switching or security matters; and
to analyse, troubleshoot and improve the Service using limited Service Usage Data and, where possible, aggregated or irreversibly anonymised information. Information remains personal data for as long as an individual can reasonably be identified from it.
PageShield does not use the personal data described in this Policy to make decisions based solely on automated processing that produce legal effects or similarly significant effects for an individual. Clone detection, location enrichment, daily deduplication, bot/human/unknown classification, notification suppression and redirect functions operate on technical request data and Customer configurations. The classification is informational, is not used to determine a person's legal status or eligibility, and does not automatically change redirection.
To the extent that assigning a per-event bot/human/unknown Classification Result constitutes profiling under applicable data-protection law, it is limited to an automated technical categorisation of the individual Detection Event. PageShield does not use that categorisation to infer broader personal characteristics, build a persistent behavioural profile, combine the result across Customers or make a decision producing legal or similarly significant effects for an individual.
Paid subscription transactions are processed by Lemon Squeezy as Merchant of Record. Lemon Squeezy receives and processes payment method information, invoices, tax information, refund and chargeback information and related purchase records under its own legal terms and privacy documentation. For those checkout and payment activities, Lemon Squeezy generally determines its own processing purposes and responsibilities.
PageShield does not receive or store full payment-card details. We receive limited subscription and transaction metadata, such as Plan, subscription status, renewal or cancellation status, customer or subscription identifiers, transaction references and related webhook metadata, so that we can activate, suspend, resume or terminate access to paid features and maintain appropriate records. PageShield keeps this local subscription metadata while the Account exists and removes it as part of complete Account deletion, except to the extent that a limited record must be retained for a legal, accounting, tax, fraud-prevention, dispute or defence-of-rights purpose. Lemon Squeezy retains its own transaction records under its own legal obligations and privacy documentation.
The dashboard stores an authentication or session token only to the extent strictly necessary to provide sign-in and session continuity expressly requested by the user. A basic interface preference, such as light or dark theme, is stored only after the user has received the relevant notice and given any consent required by applicable terminal-equipment law. Refusing or withdrawing consent for the preference leaves the default theme in place and does not prevent use of the core Service. These entries are not used for advertising. The authentication or session token remains only until it expires, is replaced, is removed through logout or is cleared by the user. The interface preference remains until it is changed, consent is withdrawn or storage is cleared. PageShield does not use third-party advertising cookies in the Service.
If a user blocks or clears strictly necessary localStorage, authentication or session continuity may not operate as intended. Blocking or refusing non-essential preference storage affects only the relevant preference.
The Protection Snippet does not use cookies and is not intended for advertising tracking or cross-site profiling. It does not actively collect additional browser or device attributes commonly used for fingerprinting, such as canvas, WebGL, installed-font, hardware or similar high-entropy signals, and it does not create a persistent cross-site visitor identifier. It uses localStorage on a Customer page only to limit the frequency of Heartbeats so that, under normal technical conditions, a Heartbeat is designed not to be sent more than once per hour for the same browser/device. The localStorage entry may remain until it is overwritten, expires or is cleared by the user/browser, or removed by the script where such removal is implemented; its purpose is only to determine whether the throttling interval has elapsed.
If localStorage is cleared, unavailable or blocked, or if a visitor changes browser, device or browsing mode, Heartbeat throttling may differ from its normal design.
Where Romanian Law No. 506/2004 or equivalent terminal-equipment rules apply, the Customer must determine before deployment whether Heartbeat-throttling localStorage requires consent or falls within a valid statutory exception. Where consent is required, the Customer must not enable the relevant non-exempt storage or access before valid affirmative consent has been obtained and must enable withdrawal as easily as consent was given.
The Customer is responsible for providing the required notice, obtaining and recording any legally required consent, configuring and testing its chosen consent-management implementation, and ensuring that refusal or withdrawal is respected. PageShield provides information reasonably necessary to describe the Protection Snippet and localStorage behaviour. Unless current technical documentation expressly states otherwise, PageShield does not warrant compatibility with a particular consent-management platform or represent that installation or activation alone establishes compliance. Refusal or withdrawal may affect Heartbeat throttling but is not used for advertising, profiling or cross-site tracking.
The geolocation, ASN lookup, bot/human/unknown classification, daily deduplication and notification-suppression comparison are performed server-side from information received with the Detection Event request. These functions do not add cookies or localStorage entries and do not actively collect additional browser or device attributes commonly used for fingerprinting. This technical design does not by itself determine whether the initial Protection Snippet request or transmission falls within Article 5(3) of the ePrivacy Directive, Romanian Law No. 506/2004 or an equivalent rule, or whether consent or an exception applies. The Customer must make and document that assessment for its implementation, without limiting any obligation that applies directly to PageShield.
Where the Customer relies on the exception for storage or access that is strictly necessary to transmit a communication or to provide an information-society service expressly requested by the user, the Customer must document the factual and legal basis for that exception before enabling the relevant operation. A storage operation is not exempt merely because it is technical, limited, security-related or non-advertising. Nothing in this Section transfers or excludes any obligation that applies directly to PageShield under applicable law.
We disclose personal data only where necessary for the purposes described in this Policy, on the Customer's documented instructions, with the relevant individual's permission, or where required or permitted by law. We do not sell personal data or disclose visitor technical metadata for behavioural advertising. PageShield maintains a live Subprocessor register at https://pageshield.io/legal/subprocessors.html. Where a provider processes personal data on PageShield's behalf, PageShield applies the contractual and data-processing arrangements required by law; providers that determine their own purposes remain responsible for those purposes under their own privacy documentation.
| Recipient or category | Purpose and current status |
|---|---|
| Lemon Squeezy | Merchant of Record and seller of record for the payment transaction. Lemon Squeezy receives payment and purchase data through its own checkout and generally determines its own purposes for checkout, tax, fraud, refund and chargeback processing. It provides PageShield with limited subscription, transaction-reference and status metadata. |
| Hetzner | Hosting and server-infrastructure provider. The main hosting environment, active database and database backups used by PageShield are located in Germany. |
| Cloudflare | Authoritative DNS and basic DNS-layer protection. Cloudflare is not configured as an application reverse proxy and does not receive application, API, Protection Snippet, detection or switching payloads through the Service flow. It may process limited Account, zone and DNS-operational data under its own applicable documentation. PageShield reassesses the relevant role before any configuration change that materially changes processing. |
| Google Workspace | Transactional email delivery for Account and billing notifications, support correspondence and statutory notices, including withdrawal confirmations. Google Workspace is not intended to receive Heartbeat records, Detection Event history, raw Detection Event IP addresses, location/classification fields or Customer protection configurations. Processing locations and transfers are governed by Google's applicable documentation and data-processing terms. |
| MaxMind | Supplier of the downloadable GeoLite2 City and GeoLite2 ASN databases used locally on PageShield infrastructure. Under the described architecture, MaxMind does not receive raw Detection Event IP addresses, Detection Events, Classification Results or Notification Suppression Rule data through live lookup requests and is not a recipient of Customer Personal Data for this processing. |
| Customer-configured webhook destinations | Customer-directed recipients. Webhook alerts are available only on Pro and Business and contain a generic teaser directing the Customer to the dashboard. The payload does not include the full URL, referrer, user-agent string, IP address or profile name. Delivery and error records are retained for thirty (30) days. The Customer is responsible for the destination and applicable privacy information. |
| Customer-authorised switching destinations and representatives | Destination providers, on-premises transfer contacts or authorised third parties identified by the Customer for an export or switching process. PageShield transmits data only within the validated scope of the request and may require information reasonably necessary to protect the transfer. Such recipients are not PageShield subprocessors merely because they receive a Customer-directed export. |
| Future or additional operational providers | Email delivery, support, uptime monitoring, error monitoring, logging, backup, security or similar functions only if and when activated. PageShield identifies relevant providers in the live register at https://pageshield.io/legal/subprocessors.html and provides the notice required by the DPA before a new Subprocessor begins processing Customer Personal Data. |
| Professional advisers, authorities and legal recipients | Legal, accounting, security or other professional assistance and disclosures required or permitted by law or necessary to establish, exercise or defend legal claims. |
| Business-transfer recipients | Potential or actual purchasers, investors, advisers or successors in connection with a merger, financing, reorganisation, sale of assets or similar transaction, subject to appropriate confidentiality and legal safeguards. |
CRAFTAC SRL is established in Romania. The main hosting environment, active database and database backups are hosted with Hetzner in Germany. Lemon Squeezy may process payment and transaction data in the United States and other jurisdictions under its own arrangements. Cloudflare provides authoritative DNS and basic DNS-layer protection. It is not configured as an application reverse proxy and does not receive application payloads through the PageShield Service flow; it may process limited Account, zone and DNS-operational data under its applicable documentation. Customer-selected webhook endpoints, Redirect Destinations, destination providers, authorised representatives and on-premises environments may be located in jurisdictions selected by the Customer.
Where PageShield transfers personal data outside the European Economic Area to a provider acting on its behalf and a transfer safeguard is required, PageShield puts the applicable mechanism in place before the transfer begins. Depending on the circumstances, this may include an adequacy decision, the European Commission's standard contractual clauses, a transfer impact assessment and supplementary measures. Where a recipient, such as a Merchant of Record, independently determines its own purposes, its own privacy documentation and transfer arrangements also apply. You may contact us for a copy or meaningful summary of the applicable safeguard where required by law, subject to lawful confidentiality and security redactions.
A Customer may instruct PageShield to export data to a destination provider, authorised representative or on-premises environment outside the EEA. Any personal-data transfer performed by PageShield remains subject to the DPA and applicable data-protection law. The EU Data Act does not replace or reduce the requirements governing lawful personal-data disclosure and international transfers. The Customer is responsible for selecting an authorised destination, providing lawful instructions and assessing requirements that apply to the Customer or destination recipient.
Customers operating outside the EEA remain responsible for assessing the local privacy, data-protection, electronic-communications and international-transfer requirements applicable to their own websites, visitors, Redirect Destinations, webhooks, switching destinations and use of the Service.
We retain personal data only for as long as necessary for the purposes described in this Policy. Where a fixed period is not stated, the period is determined using criteria including the nature and volume of the data, Account status, the functionality requested by the Customer, security and troubleshooting needs, switching and retrieval requirements, legal and accounting obligations, disputes and the establishment, exercise or defence of legal claims.
Plan-based dashboard history works as follows: Starter provides read-only access to up to seven (7) days of Detection Event history and no commercial CSV export; Pro provides access to up to ninety (90) days; Business has no separate Plan-based dashboard history window while the Business Subscription remains active. These visibility rules are separate from retention. Raw Heartbeat records are retained for thirty (30) days. Complete retained Detection Event metadata, including approximate country and city and the bot/human/unknown result, is retained for ninety (90) days. The raw IP address, ASN and internal ASN-list match signal used for event enrichment are not retained as Detection Event fields. After ninety (90) days, fields and combinations of fields reasonably capable of identifying, singling out or linking an individual — including approximate country, city and the Classification Result — are deleted or irreversibly anonymised, with no conditional extension.
The daily deduplication identifier is retained only for the applicable daily window and is deleted or rendered unusable when the daily secret or salt rotates. A customer-scoped notification-suppression identifier and its rule are retained for ninety (90) days from creation or from the most recent matching occurrence, whichever is later, unless the Customer removes the rule earlier. Routine server, application, IP, webhook-delivery and error logs are retained for thirty (30) days. Records isolated because they are necessary for a documented security incident, fraud investigation, dispute or legal claim may be retained for up to twelve (12) months after the incident is closed, or for the applicable legal limitation period where a claim or binding legal obligation requires longer retention. These retention periods are separate from Plan-based dashboard visibility and do not guarantee that any record will remain available until the end of a maximum period.
| Data | Current retention approach | |
|---|---|---|
| Account and authentication data | Retained while the Account exists. Verified Account deletion removes active-database records immediately, subject to limited records required by law, security or legal claims, the fourteen (14)-day backup cycle and the thirty (30)-day deletion ledger. | |
| Subscription metadata | Retained while the Account exists and for up to three (3) years after Account closure or the final transaction, whichever is later, for contract administration, refunds, fraud prevention, disputes and legal claims. Lemon Squeezy applies its own retention rules to transaction records it controls. | |
| Dashboard history availability | Starter: read-only access to up to 7 days and no CSV export. Pro: access to up to 90 days. Business: no separate Plan-based visibility window while the Business Subscription remains active. These visibility rules remain subject to the 30-day Heartbeat and 90-day complete Detection Event retention periods. | |
| Heartbeat, Detection Event and related Customer records | Raw Heartbeat records: 30 days. Complete retained Detection Event metadata, including approximate country/city and bot/human/unknown classification: 90 days. The raw IP address, ASN and internal ASN-list match result used for enrichment are not retained as Detection Event fields. After 90 days, fields and combinations of fields reasonably capable of identifying, singling out or linking an individual are deleted or irreversibly anonymised, with no conditional extension. The daily deduplication identifier is retained only for its daily window. | |
| Notification-suppression rules | A customer-scoped HMAC-derived matching value and related rule metadata are retained for 90 days from creation or the most recent matching occurrence, whichever is later, unless the Customer removes the rule earlier. A matching occurrence restarts the 90-day period, so the rule may remain active for longer than 90 days while matching continues. The matching value is not used for another Customer or a global IP-reputation list and is not included in customer-facing or switching exports. | |
| Server logs, IP logs and security records | Routine server, application, IP, webhook delivery/error and security logs: 30 days. A limited subset isolated for a documented incident, fraud investigation or dispute: up to 12 months after closure. Records necessary for a live claim or binding legal obligation may be retained for the applicable legal period. | |
| Service Usage Data | Identifiable or account-linked Service Usage Data is retained for up to twelve (12) months. Aggregated or irreversibly anonymised statistics may be retained for longer because they are no longer personal data. | |
| Switching, export and retrieval request records | Request, identity/authority verification, confirmation and compliance records: up to three (3) years after closure of the request. Data contained in a temporary package follows the shorter package-retention period. Records needed for a live dispute or binding legal obligation may be retained longer. | |
| Temporary export or transfer packages | Each secure download link expires after seven (7) days. During an applicable retrieval period, PageShield keeps at least one retrievable package available or maintains the ability to regenerate it after verification. Superseded and intermediate copies are deleted promptly, and all remaining temporary packages are automatically deleted no later than fourteen (14) days after the retrieval period closes, unless a binding legal obligation or live claim requires longer retention. | |
| Support and communication data | Up to two (2) years after the support request or correspondence is closed. Unnecessary attachments, screenshots and diagnostic data are deleted earlier where practicable. Longer retention applies only where required for a live dispute, legal claim or binding obligation. | |
| Backups | Database backups are stored within the Hetzner-hosted environment in Germany and are automatically rotated and deleted on a fourteen (14)-day cycle. Deleted data may therefore remain in a protected backup for up to fourteen (14) days and is not returned to ordinary active processing. | |
| Deletion ledger | A keyed cryptographic hash (HMAC or equivalent) of the deleted Account email address and the deletion date are stored separately and used solely to reapply deletion after backup restoration. The hash is pseudonymised personal data. Each entry is automatically deleted thirty (30) days after Account deletion. | |
Cancelling a Subscription does not delete the Account or associated data. Self-service Account deletion is available in Settings and requires the user to type the exact Account email address as explicit confirmation. Once confirmed, deletion from the active database is immediate and synchronous. Customer Personal Data processed on behalf of a Customer is returned or deleted as provided in the DPA, including the Customer's applicable choice at the end of processing services.
Database backups are automatically rotated so that backup copies older than fourteen (14) days are deleted. Data removed from the active database may therefore remain in an existing backup for up to fourteen (14) days, unless a longer period is required by law. Backups are not used for ordinary active processing and may be restored only for recovery, continuity, security or legal purposes.
To prevent a backup restoration from reintroducing an Account that was previously deleted, PageShield maintains a deletion ledger stored separately from the main database and outside the ordinary database-restoration set. The ledger contains only a keyed cryptographic hash (HMAC or equivalent) of the Account email address and the deletion date. The hash is treated as pseudonymised personal data and is used solely to identify and automatically re-delete an Account that reappears after a restoration. Access is restricted and logged, and the ledger is not used for marketing, profiling or recreation of the Account. Each ledger entry is automatically deleted thirty (30) days after the corresponding Account deletion, a period that exceeds the fourteen (14)-day backup-rotation cycle and provides an operational restoration margin.
Where the EU Data Act Addendum applies, its retrieval and erasure provisions supplement this Section for Exportable Data and Portable Digital Assets. Personal data return and deletion remain subject to the DPA and applicable data-protection law. Data that PageShield processes as an independent controller may be retained only for the separate lawful purposes described in this Policy and not for the continued provision of a terminated Service.
PageShield may retain a minimal record where necessary to document a rights or switching request, prevent fraud or repeat trial abuse, comply with law, resolve a dispute or establish, exercise or defend legal claims. Such a record is limited to what is necessary, is not used for marketing and is retained only while the relevant purpose or legal requirement continues. Data that has been irreversibly anonymised is no longer personal data and may be retained and used without applying the periods above.
We implement technical and organisational measures designed to provide a level of security appropriate to the risks of the processing, taking into account the nature, scope, context and purposes of processing, the state of the art and implementation costs. Measures include HTTPS/TLS for data in transit, password hashing, access controls, local GeoLite2 City and GeoLite2 ASN lookups without live disclosure of IP addresses to MaxMind or another lookup provider, non-retention of raw IP/ASN enrichment fields and internal network-type signals, daily rotation of the deduplication secret or salt, keyed HMAC identifiers for notification-suppression rules, logical customer scoping, restricted secret access, automated retention and deletion or irreversible-anonymisation jobs, fourteen (14)-day backup rotation, webhook payload minimisation and measures intended to limit access to persons who require it for operational, support, security or legal purposes.
For Customer-directed exports and switching processes, PageShield uses authenticated delivery, access-controlled links where appropriate, structured machine-readable export files, destination validation, expiry controls and transfer logging. Where applicable law requires an open interface, PageShield makes a documented authenticated export API or equivalent open machine-to-machine interface available on an equal basis to Customers and authorised destination providers, subject to authentication and proportionate security controls. The currently supported formats, packaging methods and interfaces are identified in the EU Data Act Addendum and public switching documentation. Customers and authorised recipients must protect credentials, tokens, export files and transfer instructions and use secure transfer methods.
No online service can be guaranteed to be completely secure. This statement does not limit PageShield's obligations under applicable law. Customers are responsible for securing their own credentials, Accounts, protected pages, Redirect Destinations, webhook endpoints, integrations and destination infrastructure and for limiting the data placed in URLs, configurations and switching instructions.
Depending on the applicable law and the circumstances, you may have the right to request access to and a copy of your personal data, rectification, erasure, restriction of processing, data portability and information about recipients, including the actual identity of recipients where applicable law requires it. You may object to processing based on legitimate interests and may withdraw consent at any time where consent is the legal basis, without affecting processing carried out before withdrawal.
PageShield does not use the personal data described in this Policy to make decisions based solely on automated processing that produce legal effects or similarly significant effects for individuals. The bot/human/unknown result is an informative, per-event technical classification and may affect notifications only where configured by the Customer. To the extent that this categorisation constitutes profiling, the limitations described in Section 7 apply.
Requests may be sent to support@pageshield.io. We may request information reasonably necessary to verify identity, authority and the scope of the request. Because raw Detection Event IP addresses are not retained, an IP address alone may not allow PageShield to locate a historical Detection Event. Where possible, a visitor should provide the relevant hostname or URL and an approximate date and time, together with any other information reasonably available to them. PageShield will not require disproportionate additional information solely to identify a record, and we do not collect additional personal data solely in order to identify a person who would not otherwise be identifiable.
Requests and the first copy provided under a right of access are normally free of charge. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, PageShield may charge a reasonable fee or refuse to act only to the extent permitted by applicable law. We will respond within the period required by applicable law; under the GDPR, this is normally one month and may be extended by up to two additional months for complex or numerous requests where legally permitted and properly notified. If we do not act on a request, we will provide the reasons and information about available complaint or judicial remedies as required by law.
Data-protection rights are subject to the conditions and exceptions set out in applicable law. For example, the right to erasure may not apply where continued processing is necessary to comply with a legal obligation or to establish, exercise or defend legal claims, and an objection based on legitimate interests may be rejected only where the applicable legal test is met. If you are a visitor of a Customer's page and the Customer is the relevant controller, we may direct you to the Customer or assist that Customer in accordance with the DPA and applicable law.
You may lodge a complaint with the supervisory authority in the country of your habitual residence, place of work or the alleged infringement. CRAFTAC SRL's supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 28-30 General Gheorghe Magheru Boulevard, District 1, 010336 Bucharest, Romania; email: anspdcp@dataprotection.ro; website: www.dataprotection.ro.
The Starter free tier does not include product CSV export, even where the Account previously had a paid Subscription. This product restriction does not limit a statutory access or data-portability request, a DPA return right or a switching/export right under the EU Data Act Addendum. A product CSV export may not include all personal data or information required for a statutory request. Account deletion may be performed through Settings or requested through support where appropriate.
Where Chapter VI of Regulation (EU) 2023/2854 applies to PageShield, the relevant Service or the Customer relationship, the PageShield EU Data Act Addendum governs contractual switching, portability, transition, retrieval and deletion within its stated scope. PageShield makes the related public switching and infrastructure-jurisdiction information available at https://pageshield.io/eu-data-act-addendum.html and in any linked technical switching documentation. Those rights are distinct from GDPR data-subject rights: neither type of request automatically initiates the other. Where an export contains personal data, the GDPR, the DPA and applicable international-transfer rules continue to apply.
The EU Data Act Addendum does not by itself create a lawful basis for disclosing personal data to a destination provider or representative. The Customer must identify the destination, provide lawful instructions and protect credentials and export files; PageShield may verify or pause a request to prevent unauthorised disclosure, comply with law or address a material security concern. Export categories, exclusions, methods, periods and erasure are described in the Addendum and PageShield documentation. Customer Personal Data remains governed by the DPA, while PageShield-controlled switching records are governed by this Privacy Policy.
Redirect Destinations, webhook endpoints, Customer websites, destination providers, authorised switching representatives, on-premises infrastructure and other third-party services are selected or controlled by the Customer and may process personal data under their own privacy notices and contractual arrangements. PageShield is not responsible for the privacy practices of a Customer, a cloned page, a third-party destination or an integration that PageShield does not control, without limiting any responsibility PageShield retains for its own processing or for an authorised transmission under applicable law or the DPA.
After delivery to a Customer-selected destination, the Customer and recipient are responsible for access, import, further use, security, retention and deletion in that environment, except to the extent PageShield remains legally responsible for the transfer or expressly agrees otherwise in writing.
The Service is intended and optimised primarily for business and professional use, is not directed to children and may be used to create an Account only by a person who is at least 18 years old or has reached the age of legal majority in the applicable jurisdiction. We do not knowingly collect personal data directly from children through Account registration. The Service does not ordinarily determine the age of visitors to Customer pages, so limited technical metadata may be received if a child visits such a page without PageShield knowing the visitor is a child.
Customers must not intentionally use the Service to collect or transmit children's data or deploy it on a service directed to children unless they have established and implemented all legal bases, notices, parental authorisations and safeguards required by applicable law. If you believe that a child's personal data has been submitted to PageShield improperly, contact us so that we can assess and take appropriate action.
We may update this Privacy Policy to reflect changes in the Service, providers, export or switching functionality, legal requirements or processing practices. If a change is material, we will make reasonable efforts to notify active Account users by email, dashboard notice or another appropriate electronic method before the change takes effect where required or reasonably practicable. The version in force and its effective date will be published with the Service.
Before using personal data for a new purpose that requires additional information under applicable law, PageShield will provide that information before the further processing begins. Where the new activity requires consent or another specific action, publication of an updated Privacy Policy will not by itself replace that consent or action.
For privacy questions, data-protection rights requests or concerns, contact support@pageshield.io. EU Data Act switching requests should use the subject line "EU Data Act Switching Request" so that they can be routed and documented appropriately. If PageShield later provides a dedicated privacy contact, this section will be updated.
CRAFTAC SRL | Romanian Trade Register no. J22/725/2024 | CUI 49662167 | Address: Str. Bisericii 9, Bl. 65, Sc. A, Et. 4, Ap. 15, Cod 707085, Sat Lunca Cetatuii, Judetul Iasi, Romania | Email: support@pageshield.io