Legal

Privacy Notice

How NTV LTD uses personal information to run and secure Monocrawl.

Effective

1 September 2026

Version

2026-09-01

Controller

Monocrawl is a trading name of NTV LTD, a private limited company registered in England and Wales with company number 11364012, whose registered office is Amelia House, Crescent Road, Worthing, West Sussex, England, BN11 1QR

Privacy requests

01

Who controls your information

NTV LTD, trading as Monocrawl, is the controller of personal information used to create accounts, supply the service, bill customers, secure systems and handle enquiries. Its registered office is Amelia House, Crescent Road, Worthing, West Sussex, England, BN11 1QR; company number 11364012.

This Notice applies under the UK GDPR and Data Protection Act 2018 as amended, including relevant changes made by the Data (Use and Access) Act 2025.

02

Scope

This Notice covers visitors, account users, prospective and current customers, people who contact us, and security events involving the service. It does not govern a customer’s independent use of API results.

Personal information appearing in third-party or publicly accessible source data is addressed separately in the Public Data and Data Sources Notice. Depending on the processing, a customer may be an independent controller of its downstream use.

03

Information we handle

  • Account and identity information: name, email address, encrypted authentication records, OAuth identifiers if Google or GitHub sign-in is used, role, two-factor configuration, session and recovery metadata.
  • Service and security information: API-key hashes and labels, IP address, user agent, sign-in/session activity, rate-limit identifiers, request path and parameters, request ID, response status, timing, provider, credit use, cache status and diagnostic errors. We do not store the plaintext of an API key after it is issued.
  • Product content: saved Explorer history, jobs and job results, monitors and runs, cohorts, notifications, webhook endpoints and delivery records, and support or legal requests you submit.
  • Billing information: customer and payment references from Stripe, billing address and tax status where returned to us, pack or plan, amount, currency, tax, credits, invoice/payment status, receipts, subscription state, auto-recharge settings and checkout-consent evidence. Card numbers and CVC are entered into Stripe, not Monocrawl.
  • Communications: support, billing, cancellation, privacy, public-data, legal and security messages plus their request status.
  • Public-source query material: usernames, URLs, post IDs, search terms or other targets you ask an endpoint to retrieve. A target can itself be personal information.
04

Purposes and lawful bases

Contract and steps before a contract

We use account, request, billing, subscription, job, monitor, webhook and support information to open the account, authenticate you, execute requested calls, meter credits, take payment, provide receipts, deliver webhooks and provide support.

Legal obligations

We keep and disclose information where necessary for tax, accounting, company, consumer, payment, sanctions, law-enforcement or data-protection duties.

Legitimate interests

We use proportionate service and security information to prevent fraud and abuse, defend systems, investigate incidents, diagnose failures, enforce the Terms, understand reliability and improve the service. Our interests are providing a secure commercial API and protecting customers and upstream resources. We balance those interests against the impact on people and use less identifying information where practical.

Consent

Where we introduce optional marketing or non-essential storage requiring consent, consent will be requested separately and can be withdrawn. Current authentication and checkout storage does not rely on marketing consent.

05

Where information comes from

We receive information from you, your organisation, your browser or API client, Stripe, authentication providers you choose, security and infrastructure services, and the third-party source or upstream provider named or implied by the endpoint.

For public-source information about someone who is not a customer, categories typically include public profile identifiers, public posts or comments, public engagement figures and related metadata. Sources include official APIs, independent API providers and publicly accessible pages. Exact provenance varies by endpoint and response; see the Public Data Notice.

06

Recipients and providers

We disclose only what is reasonably needed to run the service. Current infrastructure categories are:

  • Supabase-hosted PostgreSQL on AWS eu-west-1 (Ireland) for the application database. The application uses the database connection directly; the Supabase Data API is disabled.
  • Vercel for web application hosting and request execution, configured to the London region for the application.
  • Stripe for Checkout, card/payment processing, invoices, tax calculation, subscriptions and fraud controls.
  • Upstash Redis when configured for distributed rate-limit and fair-use counters. Keys are service identifiers or pseudonymous IDs rather than plaintext API keys.
  • Google or GitHub only when you choose that OAuth sign-in method.
  • Endpoint upstreams and official APIs, which receive the query target and parameters needed to perform the request but do not receive your Monocrawl password or plaintext API key.
  • Public-data suppliers, by category: a contracted social-platform data supplier (public profiles, posts, comments, search and ad-library data across the major social networks); independent data vendors reached through a single API-marketplace account (retail and marketplace listings, professional-network data, short-video and photo-network data, business and software reviews, travel listings, company financial statements, forum data), each named in the private supplier register and in the technical metadata of the route it serves; a search-and-shopping data supplier (search results, shopping listings, app-store listings, business listings and web-page audits); and the official developer APIs of the platforms where we hold access (video sharing, code hosting, forums, music and live streaming, marketplaces, app stores, maps, company registries, prediction markets, decentralised social networks and technology news). Each receives only the query target and parameters needed for the request.
  • Large-language-model providers (currently two primary providers with two alternates available for failover) receive the deterministic payload of a request when the research briefing, a monitor’s relevance judgement, the schema-extraction option of the web tools or the assistant composes text; they never receive your account details or API key.
  • Infrastructure providers, by category: web hosting and scheduled-job execution; a managed PostgreSQL database; a managed cache and queue service; a payment processor for checkout, invoices, tax and fraud controls; a transactional email delivery service; and a bot-check service on public forms.
  • Professional advisers, insurers, auditors, authorities or a buyer of the business where necessary and subject to legal safeguards.

Outbound email delivery is not currently a dependency for the published contact route. Requests submitted at Contact are written to the internal request queue; if an email provider is enabled later, this Notice will identify the material provider before relying on it.

07

International transfers

The primary database region is Ireland and application execution is configured in London. Some suppliers are headquartered or provide support and onward processing outside the UK. Where UK personal information is transferred to a country without UK adequacy regulations, we require an applicable safeguard such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful transfer mechanism, together with risk assessment where required.

Calling an endpoint may send a target to an upstream in another country. Do not submit confidential information or unnecessary personal information as a query.

08

Retention and deletion

  • Authentication sessions expire after seven days under the current account configuration; a user or operator can revoke them sooner.
  • Account, keys, wallet, usage events, jobs, monitors, cohorts, webhook configuration and ordinary service history are kept while the account exists, or until an available deletion action removes the item. Self-serve account deletion cascades through those account-linked records.
  • Public response cache entries normally expire after five minutes under the current default, although endpoint or operational configuration may use a different documented cache duration.
  • Idempotency records expire after 24 hours and are deleted by worker housekeeping.
  • Open support, cancellation, privacy, legal and security requests are kept while handled and afterwards only as long as reasonably needed for follow-up, dispute evidence, safeguarding or legal compliance.
  • Payment, tax, invoice and checkout-consent evidence is kept for at least the applicable statutory period. Current deletion takes a pseudonymised snapshot of payment records through the end of the sixth year after the transaction year. Stripe references can still permit re-identification with access to Stripe, so this record is pseudonymised, not anonymous.

Deletion first disables auto-recharge and cancels an active Stripe subscription; if Stripe does not confirm cancellation, local erasure is aborted. Legal holds, disputes, fraud prevention or tax duties may require limited information to be kept longer.

09

Security

Controls include hashed API keys, encrypted transport, scoped authentication, optional two-factor authentication, revocable sessions, body-size limits, distributed rate limiting, signed webhooks, audit records, private-network blocking for customer-supplied fetch targets and restricted database access.

No internet service can guarantee absolute security. Use unique credentials, enable two-factor authentication, restrict and rotate keys, and report suspected incidents through the security category without sending secrets.

10

Your rights

Depending on the circumstances, you may ask for access, correction, erasure, restriction, portability, or an explanation of processing; object to processing based on legitimate interests; withdraw consent; and complain to a supervisory authority. Rights are not absolute and we may need identity evidence or retain information required by law.

For direct marketing, an objection is unconditional. For legitimate-interest processing, we will stop unless compelling legitimate grounds override your interests, rights and freedoms or the information is needed for legal claims. Public-data suppression requests are handled under the Public Data Notice.

We do not currently make solely automated decisions about customers that produce legal or similarly significant effects.

11

Cookies and local storage

Monocrawl uses authentication/session storage and security state needed to sign you in, plus preference and workflow storage such as sidebar state, referral attribution and local Explorer history. We do not currently deploy advertising or analytics cookies. Stripe may set its own security and checkout storage on Stripe-hosted pages.

The precise current inventory and durations appear in the Cookie Policy. If non-essential analytics or advertising storage is introduced, it will be held back until any required consent is obtained.

12

Contact and complaints

Submit a privacy request at our recorded contact route; choose “Privacy/data rights”. It accepts requests without an account and provides a reference. Postal requests may be sent to NTV LTD, Amelia House, Crescent Road, Worthing, West Sussex, England, BN11 1QR.

You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would appreciate the chance to address the issue first, but you do not have to contact us before the ICO.

This Notice may change as processors or features change. We will publish the new version and date, and give appropriate notice of a material change.