Crawlsonar

Privacy & Data Protection Policy

Last updated: 10 July 2026

This policy explains how Northstar Infinity Works Ltd(“we”, “us”, “our”), the operator of Crawlsonar (the “Service”), collects, uses and protects personal data. We are the data controller for the personal data described here. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Northstar Infinity Works Ltd is a company registered in England & Wales (company number 17326480), registered office C/O Elsg Ltd, Regus, Building 2, Marlins Meadow, Watford, England, WD18 8YA. You can contact us about privacy at [email protected].

Summary

  • The tools work without an account. We set no analytics or advertising cookies unless you accept them via our cookie banner.
  • Our own usage analytics are cookieless and do not record your IP address or any identifier. Google Analytics loads only after you consent.
  • A privacy-preserving bot-protection check (Cloudflare Turnstile) runs on a couple of interactive tools to prevent abuse.
  • If you paste email headers, they are analysed entirely in your browser and never sent to us.
  • We only hold your email address if you choose to give it to us to receive a report by email.
  • You can ask us to access or delete your data at any time.

The personal data we process, and why

Information you submit to scan

To run a check you enter a target — a domain, URL, IP address, email address (for email authentication checks we use only its domain), or raw email headers. Targets are usually not your personal data. We use them only to perform the requested scan and to generate the result you asked for. Lawful basis: performance of the service you request (legitimate interests / your request).

Email headers pasted into the Email Header Analyzer are processed entirely in your browser (client-side). They are not transmitted to or stored by us.

Your email address (only if you provide it)

If you ask us to email you a report as a PDF, or opt in to updates, we collect your email address together with the tool and target you scanned and a timestamp recording your consent. We use this to deliver the report you requested and, where you have opted in, to send you occasional product updates. Lawful basis: consent. You can withdraw consent or unsubscribe at any time; withdrawal does not affect processing carried out before it.

Your IP address

When you use the “What is my IP” tool we read your IP address from the connection in order to display it to you. We also process IP addresses transiently to apply rate limits and protect the Service from abuse. We do not store your IP address in our analytics or lead records. Lawful basis: legitimate interests (operating and securing the Service).

Usage analytics

We record aggregated, first-party events (for example, that a scan was started or a report viewed) to understand how the Service is used and improve it. These events are cookieless and contain no IP address, user agent or other identifier. Lawful basis: legitimate interests (improving the Service).

In addition, we use Google Analytics 4 (provided by Google) for traffic measurement. It is governed by Google Consent Mode v2, which keeps analytics storage fully disabled by default — so no Google Analytics cookie is set and no data is sent — until you acceptvia our cookie banner. If you decline or ignore the banner, Google Analytics does not run. You can change your choice at any time using “Cookie settings” in the footer. Lawful basis: consent.

Shared reports

If you create a shareable report link, we store the scan result for up to 30 days at an unguessable, non-indexed URL so it can be viewed. Shared reports contain only the public scan data of the target and no information about you (no IP, no request data).

Cookies & local storage

Our tools and our own analytics are cookieless. We use a small number of cookies / local storage entries in two categories:

  • Strictly necessary (no consent required): a small localStorage entry that remembers your cookie choice; a session cookie set only when a member of our own team signs in to the administration area; and any short-lived cookie/token that Cloudflare Turnstile may set purely to carry out its bot-protection check on the tools it guards.
  • Analytics (optional — only with your consent): if you accept via the banner, Google Analytics 4sets its analytics cookies. Google Consent Mode v2 blocks these until you accept, and you can withdraw at any time via “Cookie settings” in the footer.

Who we share data with

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract and only as needed to run the Service:

  • Our hosting provider, which stores report and lead data on our behalf.
  • Cloudflare, Inc., which provides content delivery, security, DNS lookups and Turnstile bot protection (see below) for the Service.
  • Google (Google Analytics 4), for traffic measurement — only if you consent via the cookie banner.
  • Where email delivery is enabled, an email delivery provider, to send the report you requested.

[Operator to insert the specific hosting and email providers used, and their locations, once selected.]

International transfers

Some of our providers may process data outside the UK. Where they do, we rely on an adequacy decision or on appropriate safeguards (such as the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses) to protect your data.

How long we keep data

  • Scan inputs and results: not stored beyond returning your result, except where you create a shared report (up to 30 days) or request a PDF by email.
  • Email addresses (leads): kept until you unsubscribe or ask us to delete them, or until no longer needed for the purpose you consented to.
  • Analytics events: aggregated, non-identifying, retained to inform product decisions.

How we protect your data

We apply security-by-design measures, including HTTPS in transit, protection against server-side request forgery on all outbound fetches, rate limiting, and access controls on our administration area. No method of transmission or storage is completely secure, but we take appropriate technical and organisational measures to protect personal data.

Bot protection (Cloudflare Turnstile)

To protect certain interactive tools — currently our inbox deliverability test and AI Visibility checker — from automated abuse, we use Cloudflare Turnstile, a privacy-preserving alternative to CAPTCHAs. When you use one of those tools, Turnstile runs a check in the background to confirm you are a human; in most cases you will not see anything or need to do anything.

To perform this check, Cloudflare — acting as our processor — may process information such as your IP address and signals about your browser, device and interaction with the page. Cloudflare states that Turnstile does not use this information to track you across sites or for advertising. It runs as a strictly-necessary security measure and is not gated by the analytics consent banner. Lawful basis: legitimate interests (preventing fraud and abuse and keeping the Service available).

For full details of what Cloudflare processes through Turnstile, see Cloudflare’s Turnstile Privacy Policy.

Your rights

Under the UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to our processing;
  • data portability;
  • withdraw consent at any time (where processing is based on consent).

To exercise any of these rights, email [email protected]. We will respond within one month. If you are not satisfied, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we would appreciate the chance to resolve your concern first.

Third-party sites you scan

When you scan a target, we make requests to that third-party site. We are not responsible for the content or privacy practices of sites you choose to scan. Only scan sites you own or are authorised to test. Automated reports are point-in-time and may contain inaccuracies; they are not a certification.

Children

The Service is a technical tool intended for professionals and is not directed at children under 16.

Changes to this policy

We may update this policy from time to time. We will change the “last updated” date above and, for significant changes, take reasonable steps to notify you.

Contact

Northstar Infinity Works Ltd, C/O Elsg Ltd, Regus, Building 2, Marlins Meadow, Watford, England, WD18 8YA. Privacy enquiries: [email protected].