Legal

Privacy policy

What we collect, why, how long we keep it, and who else touches it. Short, because we collect little.

In effect since . Webshotter, France.

Who we are

Webshotter is the controller of the personal data described here. Write to privacy@webshotter.com about anything on this page.

When you send us a URL to render, we are your processor for whatever that page contains — the data processing addendum governs that relationship, and it applies automatically if you are a business customer.

What we collect

Your account

  • Name and email address, because an account needs both.
  • A password hash. We never store the password.
  • An avatar image, if you upload one.
  • Your appearance preference.
  • The IP address and browser user-agent recorded at sign-up, kept as evidence for abuse and fraud investigations.

What you ask us to render

  • The URL — or the HTML, if you send a document instead — and every parameter of the request.
  • The resulting image, only if you asked us to keep it. An API render with store: false streams straight to you and its file is deleted as soon as you have it.
  • A ledger row per render: which team, which key, which worker, how long each phase took, and whether it succeeded.
  • An API request log row per call: the endpoint, the status, your IP address, your user-agent and the request and response payloads.

A URL can itself be personal data — a share link, a document id, a customer's name in a path. Treat what you send us as data you are entrusting to us, because that is what it is.

What we do not collect

  • No advertising or analytics trackers, on any page of this site, signed in or out.
  • No cookies beyond the session cookie that keeps you signed in and the CSRF token that stops somebody else acting as you.
  • No payment card details — when billing launches, the processor holds those and we never see them.

Why we are allowed to

  • To perform our contract with you: everything needed to run your account and fulfil your renders.
  • Our legitimate interests: keeping the service secure and available, investigating abuse, and understanding aggregate load. Weighed against your interests, and the reason the logs are as short as they are.
  • Legal obligation: tax records, and responding to a valid legal request.

How long we keep it

The scheduler enforces these, nightly. They are read from the application's own configuration, so this list cannot drift from what actually runs.

  • Webshots you did not ask us to keep: deleted as soon as they are collected, and swept within 15 minutes if you never collect them.
  • Webshots you did ask us to keep: until you delete them, or until the render record is pruned at 90 days.
  • Render ledger rows: 90 days.
  • API request log: 30 days.
  • Queued request bodies: 60 minutes, and normally deleted the moment the render is fulfilled.
  • Your account: until you delete it. Deleting it deletes the teams you own and everything in them, immediately and without an undo.

How a render is isolated

Every capture gets its own browser context, destroyed afterwards. No cookie, no storage and no cache from one render reaches another — including your own. This is why you cannot render a page you are signed in to by "just being signed in": there is nothing to be signed in with.

Who else sees it

Only the infrastructure providers we run on, each listed with its purpose and location on the subprocessors page. We do not sell personal data, we do not share it for advertising, and we do not use your pages or webshots to train machine-learning models.

We disclose data to an authority only where we are legally required to, and we will tell you unless we are forbidden from doing so.

International transfers

Application and image hosting are in the EU. Two of our providers — error monitoring and transactional email — are in the United States, and those transfers rely on the European Commission's standard contractual clauses.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. Most of that is self-service: settings shows and edits your profile, and account deletion is a button. For anything else, write to privacy@webshotter.com — we answer within 30 days and we do not charge for it.

If we get it wrong you may complain to your local supervisory authority. We would rather you told us first.

Security

The specifics — how tokens are stored, what the SSRF policy refuses, where images live, and where to report a vulnerability — are on the security page rather than summarised here, because that is a page a reader can act on.

Children

The Service is not for anyone under 16, and we do not knowingly hold data about anyone who is. Tell us if we do and we will delete it.

Changes

When this policy changes materially we email account owners before the new version takes effect. The effective date is at the top of the page.

Questions a policy cannot answer

If something here is unclear, or your legal team needs it in another shape, write to us — a person reads that address.