Privacy Policy
What we collect, why we collect it, and how to ask us to delete it. GDPR + CCPA compliant.
Last updated: April 8, 2026
Overview
SlapMyWeb respects your privacy. This policy explains what data we collect, how we use it, and your rights under GDPR and CCPA.
Data we collect
- Account data: email, name, hashed password, plan, signup IP
- Scan data: URLs you submit, scan results, screenshots, cached HTML
- Billing data: handled by Stripe — we never see your card number
- Usage data: anonymous analytics (page views, feature usage), error logs
- Communications: support emails, contact-form submissions
How we use it
- To run audits and deliver scan results to you
- To process billing and send transactional emails
- To improve the Service (anonymized usage analytics)
- To respond to support requests
- To detect abuse and enforce our Terms
Data retention
We keep your account data for as long as your account is active. Scan data is retained according to your plan (7 days on Free, unlimited on Pro and Agency). You can delete your account and all associated data at any time from Settings → Danger zone.
Your rights (GDPR/CCPA)
- Access: request a copy of your data
- Rectification: correct inaccurate data
- Erasure: delete your data (“right to be forgotten”)
- Portability: export your data in JSON
- Opt-out: stop marketing emails (transactional emails will continue)
Security
Passwords are bcrypt-hashed, sessions use signed JWTs, all traffic is HTTPS-only with HSTS, and we keep daily database backups. We follow OWASP best practices and patch dependencies regularly. Found a security issue? Email [email protected].
Contact
Privacy questions or data requests: [email protected]. We respond within 30 days as required by GDPR.