At CrafyCAPTCHA (operated by Maximiliano Nicolás Alemandi, doing business as Crafy Holding, hereinafter "we", "our" or the "Company"), we respect your privacy and are committed to protecting the personal information of our clients and the end-users who interact with our Service. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website or use our platform, widget, and SDKs.
1. Our Role (Controller vs. Processor)
For the purposes of data protection laws such as the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):
- We are the "Data Controller" regarding the personal information of our direct Clients (the developers and businesses that register to use CrafyCAPTCHA).
- We are the "Data Processor" regarding the telemetric and behavioral data collected from End-Users who interact with the CrafyCAPTCHA widget on our Clients' websites. The Client is the Data Controller in this scenario and is responsible for obtaining any necessary consent from their users.
2. Legal Basis for Processing
Under the GDPR, we rely on the following legal bases to process personal data:
- For our Clients: Performance of a Contract (Art. 6(1)(b)) to provide our SaaS services.
- For End-Users: Legitimate Interests (Art. 6(1)(f) and Recital 49) of our Clients to ensure network and information security, prevent fraud, and mitigate automated bot attacks.
3. Information We Collect
3.1. Information from Our Clients (Developers and Administrators)
When you create an account, use our management API, or contact support, we collect:
- Contact and Account Data: Name, email address, and passwords (securely hashed).
- Billing Data: Billing address and payment details. Note: We act as a software provider; our Merchant of Record and payment processor, Armitage Labs OÜ (Creem) based in Estonia, acts as the Data Controller for your financial information. We do not store credit card numbers on our servers. Please refer to Creem's Privacy Policy for details on their data handling.
- Platform Usage Data: Dashboard access logs, administrative IP addresses, domain configurations,
public_token, and API consumption metrics.
3.2. Information from End-Users (Visitors of protected sites)
To determine if traffic originates from a legitimate human or an automated bot/script, our widget analyzes traffic. We adhere to the principles of Privacy by Design:
- Strict IP Pseudonymization: IP addresses are never stored in plain text. They are immediately subjected to irreversible cryptographic hashing (HMAC-SHA256 with a secret salt) at the edge before being written to our databases.
- Network and Device Data: Hashed IPs, User-Agent, browser language, and device/browser metadata (e.g., WebGL renderer, screen dimensions).
- Interaction Data (Behavioral Biometrics): Mouse movement patterns, clicks, keyboard events, and cryptographic puzzle resolution times. These behavioral events are processed entirely in memory (RAM) and are never persisted to our database.
- Tokens and Nonces: Temporary codes generated for session validation and prevention of replay attacks.
4. Use of Information
We use the collected information for the following purposes:
- Service Delivery: Evaluating fraud risk, validating CAPTCHA challenges, mitigating DDoS attacks, and delivering validation responses to the Client's backend.
- Maintenance and Improvement: Monitoring infrastructure availability and training our adaptive friction algorithms to reduce false positives securely.
- Account Management: Processing payments (via Creem), managing plan quotas (Rate Limiting), and sending critical notifications about security updates.
5. Data Sharing and Sub-processors
We do not sell or rent personal data. We only share information with trusted third-party sub-processors necessary for our infrastructure:
5.1. Critical Infrastructure Sub-processors
- Cloudflare, Inc. (USA): CDN/WAF services and dynamic injection of Turnstile scripts. Certified under the EU-US Data Privacy Framework (DPF).
- Hostinger (USA): Cloud hosting provider for our backend servers and databases. Data transfers are governed by Standard Contractual Clauses (SCCs).
- Redis.io (USA): External caching and rate-limiting provider. Data is pseudonymized (hashed) before being sent to Redis.
5.2. Local Processing (Zero Data Sharing)
Unlike other anti-bot services, CrafyCAPTCHA uses local databases for Geo-location (MaxMind GeoLite2) and Threat Intelligence (FireHOL). Your end-users' IPs are processed entirely within our own servers and are never sent to third-party APIs for enrichment.
5.3. Legal Requirements
We may disclose information if reasonably necessary to comply with a law, regulation, legal process, or enforceable governmental request.
5.4. Crafy Holding Services
We share information with other platforms of the Crafy Holding group to provide operational and support services.
6. Data Retention
- Client Data: Retained while your account is active. Upon cancellation, data is deleted or anonymized within 30 to 90 days, except for information required for accounting or legal obligations.
- End-User Validation Flows: Retained for a maximum of 12 hours (with periodic garbage collection).
- Pseudonymized IP Reputation: Hashed IPs are retained for a maximum of 80 days from the last seen date.
- Server Error Logs: Retained for a maximum of 24 hours. These logs do not contain IP addresses. They may contain limited technical metadata (such as browser User-Agent) for debugging purposes.
7. Data Security
We implement industry-standard security measures including TLS/HTTPS encryption for all data in transit, irreversible cryptographic pseudonymization of IP addresses, and strict access controls to our infrastructure to protect your data from unauthorized access, loss, or alteration.
8. Privacy Rights and GDPR Article 11 Exception
Depending on your jurisdiction, Clients of CrafyCAPTCHA have the right to access, correct, delete, or restrict the processing of their personal data. To exercise these rights, email our Data Protection Officer at [email protected].
Note for End-Users (GDPR Article 11): Because we strictly pseudonymize IP addresses using irreversible cryptographic hashing and do not track users across sites, we cannot link a hash back to a specific identifiable human being. Therefore, in accordance with Article 11 of the GDPR, the rights of Access, Rectification, and Erasure are not directly actionable by us, as we lack the information to re-identify the data subject. Please direct any privacy requests to the owner of the website you visited.
9. International Data Transfers
Our primary servers are located in the United States. When providing the Service, information may be transferred outside the Client's or End-User's country of origin. We ensure such transfers are conducted under adequate legal safeguards, including the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs). The Company is established in Argentina, which benefits from an adequacy decision by the European Commission for the purposes of international data transfers.
10. Crafy Account
If you choose to create an account on our Service, your account and certain associated personal data will be managed by Crafy Account (a service owned by Crafy Holding). By using our Service, you acknowledge and expressly consent that your information will be jointly governed by this Privacy Policy and the Crafy Account Privacy Policy.
11. Children's Privacy (COPPA)
Our Service is intended for businesses and developers and is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information without parental consent, please contact us, and we will take steps to remove that information.
12. California Privacy Rights (CCPA/CPRA)
If you are a resident of California, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
- Right to Know and Access: You have the right to request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions.
- Right to Correct: You have the right to request the correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information with third parties for cross-context behavioral advertising purposes. Therefore, an explicit opt-out mechanism is not necessary.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights as a Client, please contact our support team. We will verify your request by matching the identifying information you provide with the information we have on file.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data handling practices, please contact us:
- Customer Support & Privacy: https://captcha.crafy.net/support/ (or via email at [email protected])