Your information

Privacy Notice

How Capturewell collects, uses, shares, retains, and protects personal information.

Effective
22 July 2026
Version
2026-07-22

1. Who we are and when this notice applies

SPACEMANCODES LTD , trading as Capturewell, is responsible for personal information used to operate Capturewell accounts, billing, security, support, and service analytics. In that context we act as a controller under UK data protection law.

When a customer instructs us to capture a webpage containing personal data, we generally process that data on the customer’s behalf. The customer is the controller and Capturewell is its processor. Our Data Processing Addendum applies to that processing.

This notice applies to visitors, account holders, API users, people who contact us, and people whose personal data is included in material processed by the Service. A customer using Capturewell remains responsible for its own privacy information and lawful basis for each capture.

2. Information we process

Category Examples Main reason
Account and identity Name, email address, password hash, verification status, avatar, passkey records, two-factor settings, and recovery information. Create and secure your account and communicate about the Service.
Captures and configuration Target URLs, rendered page content, capture files and thumbnails, options, dimensions, status, errors, templates, schedules, watermarks, Recipes, and execution results. Perform your instructions, deliver output, calculate credits, and diagnose failures.
API and integrations API-key name, prefix and hash, last-used time, encrypted webhook URLs and signing secrets, encrypted customer-storage URLs, delivery status, and technical response data. Authenticate requests, provide integrations, prevent abuse, and troubleshoot delivery.
Billing Stripe customer and transaction IDs, pack, price, credits, tax and invoice details, payment status, payment-method type and last four digits, Auto Recharge settings, refunds, and disputes. We do not receive your complete card number. Process purchases, issue documents, operate Auto Recharge, prevent fraud, and meet accounting and tax duties.
Device, network, and usage IP address, request time, route, URL and referrer, user agent, browser, operating system, language, coarse location, security events, session data, and product actions. Deliver and secure the Service, enforce limits, investigate incidents, and improve aggregate product usage.
Communications Feedback, support requests, complaint details, contact information, and our replies. Respond, support the contract, improve the Service, and handle legal requests or complaints.

3. Where information comes from

We receive information directly from you, your browser or API client, people authorised to use your account, Stripe, and systems involved in delivering or securing the Service. At your instruction, the renderer also receives content from the public webpage you ask us to capture.

A target page may contain personal information about people who have no relationship with Capturewell. We use that information only to provide the customer-requested capture and related support, security, and legal functions. Customers must not use the Service to collect personal data unlawfully.

4. Purposes and lawful bases

  • Contract: to register users, provide captures and integrations, manage credits and payments, support accounts, and enforce the Terms.
  • Legal obligation: to keep required financial records, respond to lawful requests, protect legal rights, and meet data-protection and consumer-law duties.
  • Legitimate interests: to secure the Service, prevent fraud and abuse, keep proportionate operational records, understand aggregate usage, improve reliability, and establish or defend legal claims. We assess these interests against affected people’s rights.
  • Consent: where required for optional storage or access technologies, marketing, or another clearly identified purpose. You can withdraw consent without affecting earlier lawful use.

When we act as a processor, the customer, rather than Capturewell, chooses the lawful basis for Customer Content. We process it under the customer’s documented instructions and the DPA.

5. AI-assisted Recipes

Recipes are optional. When enabled and used, we may send the configured AI provider your Recipe instructions plus bounded accessible names, nearby headings and context, visible target text, semantic state, and aggregate action effects. This is used to plan a short, constrained sequence of browser actions for your capture.

We configure provider-side response storage off. We do not send the screenshot, raw page HTML, cookies, form or input values, request headers, URL query strings, or raw account IDs as part of Recipe planning. The provider may still process limited service and security metadata under its agreement with us. Do not place sensitive personal data in a Recipe instruction.

Recipes do not make legal or similarly significant decisions about people. Their output controls only bounded preparation of a requested webpage capture.

6. Who receives information

We use the following providers and recipients where needed:

  • application, database, cache, network, browser-rendering, and private object-storage providers, including Amazon Web Services and Cloudflare where the corresponding production service is configured;
  • Stripe for checkout, payment methods, invoices, tax, fraud prevention, refunds, and disputes;
  • Pirsch Analytics for cookie-free, aggregate product analytics. Pirsch receives request information such as IP address and user agent to create a daily, non-reversible visitor hash; it does not store the IP address;
  • OpenAI when you use an enabled AI-assisted Recipe, subject to the limits described above;
  • the transactional email provider configured to send account, security, billing, and support messages; and
  • professional advisers, insurers, auditors, authorities, courts, counterparties to a business transaction, or others where reasonably necessary and lawful.

We do not sell personal information. We do not use Customer Content to train general-purpose AI models, and we do not share it for advertising. Your chosen webhook endpoint or storage provider receives output only when you instruct us to send it there.

7. International transfers

Some providers operate outside the UK. Where UK personal data is transferred to a country without an applicable UK adequacy regulation, we use an approved safeguard such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary measures where appropriate.

Contact us if you want information about the safeguard used for a particular provider, subject to necessary confidentiality protections.

8. How long we keep information

  • Capture files, thumbnails, and retained clean originals are normally deleted after the expiry time shown in the Service, currently 24 hours. Short-lived working files are deleted sooner or during the next cleanup cycle.
  • Capture status, URL, options, dimensions, errors, credit usage, and delivery metadata can remain in your account until you delete the capture or close the account. Expiry of the file does not automatically erase this metadata.
  • API keys, templates, schedules, Recipes, watermarks, webhook configuration, preferences, and account details remain until you delete them, replace them, or close the account.
  • Billing, fraud, tax, complaint, and legal-claim records are kept for the period reasonably required by law or to establish, exercise, or defend rights. Stripe may retain its own records under its legal duties.
  • Security and operational logs are retained for a limited period appropriate to investigation and reliability needs. Pirsch retains analytics according to our configured analytics account; reports are aggregate and the input IP address is not stored.

Closing an account initiates deletion of account data and private capture storage after pending billing is safely stopped. Limited encrypted backups may persist until overwritten, and we may retain specific records where law or an active legal claim requires it. Customer-owned storage is not controlled by us and must be deleted by the customer.

9. Cookies, device storage, and analytics

Capturewell does not use advertising cookies. We use limited first-party storage to provide security and remember choices you request:

Technology Purpose Typical duration
Session and CSRF cookies Keep you signed in, preserve the requested session, and protect forms and authenticated requests. Usually 10080 minutes after inactivity. A longer authentication cookie is used only if you select “Remember me”.
Appearance cookie and local storage Remember light, dark, or system theme after you choose it. Cookie: up to one year. Local storage: until changed or cleared in your browser.
Sidebar cookie Remember whether an authenticated user collapsed the application sidebar. Up to seven days.
Service-worker cache Store public application assets and an offline page on your device. It does not cache private capture files or authenticated page responses. Until replaced by an application update or cleared in your browser.
Pirsch Analytics Measure aggregate product actions and service usage without setting an analytics cookie or reading browser storage. No browser identifier.

Security and session cookies are necessary for the Service you request. Appearance storage is created when you choose a preference and can be changed in Appearance settings or removed using browser controls. You can remove cached application assets through your browser’s site-data settings. If we introduce non-exempt analytics, advertising, or similar technologies, we will request consent before enabling them where required.

10. Security

We use measures designed for the nature of the data and risk, including encrypted transport, private object storage, time-limited signed file URLs, credential hashing, encryption of webhook and delivery secrets, access controls, public-network validation, rate limits, isolated rendering, and retention limits. No system is perfectly secure, so keep your credentials private and report a suspected incident promptly.

11. Your rights

Depending on the circumstances, UK data protection law gives you rights to be informed, access your personal data, correct it, erase it, restrict its use, receive portable data, object to processing, withdraw consent, and not be subject to certain solely automated significant decisions. These rights are not absolute and may depend on our role and lawful basis.

Use account settings for routine updates and deletion, or email us for another request. We may need to verify your identity. If your request concerns data a Capturewell customer submitted, we may direct you to that customer or assist it in responding because it controls that data.

12. Data protection complaints

You can make a data protection complaint by emailing us with the subject “Data protection complaint”. Explain what happened, the information involved, and what outcome you seek. We will acknowledge a complaint within 30 days, investigate without undue delay, keep you appropriately informed, and tell you the outcome.

You may also complain to the UK Information Commissioner’s Office. We would appreciate the opportunity to address your concern first, but you do not have to contact us before approaching the ICO.

13. Children and changes to this notice

Capturewell is a developer service for adults and organisations and is not directed to children. Do not create an account if you are under 18. Customers must take particular care before instructing us to process children’s personal data.

We update this notice when our processing or the law changes. We will post the new version here and bring material changes to account holders’ attention before they take effect where required.

Contact

SPACEMANCODES LTD

Company number: 12193639 · Registered in England and Wales

3 Station Road, Parson Drove, Wisbech, England, PE13 4HA

[email protected]