Privacy Policy
Last updated: 12 September 2026
This policy covers the FalconScrape website (falconscrape.com), the FalconScrape for Google Sheets™ add-on, and the API behind it (api.falconscrape.com). The data controller is PIOTR VASSEV IT SOLUTIONS, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in Poland, Leśna 69D, 42-622, Nowe Chechło, Poland ("we"). Contact: support@falconscrape.com.
What the Google Sheets add-on accesses
The add-on runs when you use its formulas, open its sidebar, or choose one of its menu actions. It accesses:
- Formula inputs — the arguments you supply, including values from cell ranges passed to a formula. These inputs, such as a search phrase, country code or listing URL, are sent to api.falconscrape.com to fetch the requested public web data.
- Your Google identity and email address (
openidanduserinfo.emailscopes) — when you choose Activate with Google, the add-on sends a Google ID token to our API. We verify it with Google and use the verified email address to create or identify your FalconScrape account and associate its credits and billing status. Marketplace installation may also display name and profile-picture access as part of Google's default identity consent; FalconScrape uses your verified email address for account identification. - The current spreadsheet (
spreadsheets.currentonlyscope) — formulas return results into that spreadsheet. Refresh all looks up and creates or updates theFALCON_REFRESHnamed range and its timestamp in a hidden_falconsheet within the same spreadsheet. Formulas that reference this marker can then recalculate. - External service connections (
script.external_requestscope) — the add-on calls api.falconscrape.com for activation, account status, formula requests and billing actions when available. Our backend uses the service providers listed below to process these requests. - Sidebar and dialog content (
script.container.uiscope) — the add-on displays its activation/account sidebar and dialogs inside Google Sheets. The sidebar lets you activate or sign out, view your account and credits, and access billing controls when available.
The add-on does not request access to Gmail or contacts, search your Drive, or read unrelated spreadsheet cells. Its spreadsheet access is limited to formula inputs and the refresh controls described above. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we store
| Data | Purpose | Retention |
|---|---|---|
| Email address, plan, credit balance | Account and billing | Until account deletion, subject to the billing-record exception below |
| Full payment-event payloads | Process payments and investigate failures | Normally removed by daily cleanup after 30 days from successful processing; unresolved events and investigation holds are retained for resolution |
| Payment identifiers, purchase/refund records and minimal event receipts | Maintain credits, prevent duplicate grants and meet financial obligations | While needed for active entitlements and reconciliation, and for applicable financial-record periods described below |
| Access token (hashed in our backend) | Authenticate formula calls | Until revoked |
| Usage records: which formula, how many rows, response time, whether cached | Metering, abuse prevention, product analytics | 24 months |
| Formula arguments and returned results | Serve cached results so recalculations do not consume credits | Up to 24 hours |
We do not upload or store a copy of your spreadsheet. Formula inputs and fetched results may be cached as described above; the refresh marker remains in your spreadsheet.
The add-on stores your FalconScrape access token in Google's Apps Script user properties so it can authenticate later requests. Sign out clears that stored token; it does not delete your FalconScrape account or revoke Google's permissions. You can manage Google access separately in your Google Account connections.
We send service emails about your account, such as a notice a few days before your trial ends. Each one carries a one-click opt-out link; opting out stops all account emails from us. For paid purchases, Stripe/Link sends transaction communications separately from these service emails; our service-email opt-out does not control those messages.
Beta access requests
If you request beta access on our website, we store your email address, request date, invitation status and email-delivery records in Neon. Vercel hosts the form and API; Resend receives your email address and message content to send your confirmation and beta invitation. These records are separate from activated add-on accounts: requesting access does not start a trial or subscribe you to a newsletter.
We use this information with your consent to handle your beta request. Withdraw using the link in either email or contact support@falconscrape.com to request deletion. Withdrawn addresses remain suppressed from beta invitations until deletion. Beta request and related delivery records are deleted within 180 days of signup (with daily cleanup). For abuse prevention, we temporarily store a keyed hash derived from your IP address and request counts in Neon, with expired counters removed by daily cleanup; we do not store your raw IP address in the signup table.
Public web data returned by formulas
Formulas return information that is publicly displayed on third-party websites (marketplaces, job boards, directories). Some records may contain names of sellers or authors shown publicly on those sites. You are responsible for your own lawful use of that data; we act as a processor of your requests and do not build profiles of the individuals who appear in results.
How we share Google user data
We share Google user data, including your verified email address and any cell values you explicitly pass as formula inputs, only as needed to provide the features described in this policy. The following providers receive or process data for those purposes:
- Google — sign-in and add-on runtime. Google runs the add-on, processes the spreadsheet actions you request, and stores the add-on's access token in Apps Script user properties and temporary formula results in Apps Script cache. Our backend sends your Google ID token to Google's verification service to validate your sign-in.
- Vercel — website and API hosting. Our API running on Vercel processes your Google ID token during activation, your verified email address, FalconScrape access token, formula inputs and results, and account requests. Operational logs may contain request metadata, errors and service-email delivery information.
- Neon — account database. Neon stores your verified email address, the hash of your FalconScrape access token, plan and credit information, usage and billing records, and service-email preferences and delivery records. We do not store your Google ID token in the account database.
- Upstash — caching and abuse prevention. Upstash processes temporary formula results, hashes derived from formula inputs for cache keys, and internal account identifiers for rate limiting. We do not send your Google ID token or account email address to Upstash as identity fields.
- Apify — public web data extraction. Apify receives the search terms, listing URLs and other supported formula arguments needed to fetch the requested results. The relevant third-party source websites receive the search or listing requests needed to retrieve that data. We do not attach your Google ID token, FalconScrape access token or account email address to those extraction requests. If you put personal information in a formula argument, that information may be included in the request.
- Resend — service-email delivery. Resend receives your email address and the content of service emails, such as your trial end date, remaining credits and account opt-out link, to deliver those messages. It does not receive your Google ID token or spreadsheet contents from us.
Stripe/Link — paid checkout and billing when available for your account. When you choose a paid checkout or billing-management action, we send Stripe your verified account email address, an internal account identifier and the purchase or subscription information needed for that action. This includes the selected plan or credit pack, billing interval, price reference and identifiers linking the purchase to your account. Our billing integration does not send Stripe your Google ID token, FalconScrape access token, spreadsheet contents, formula inputs or returned scraping results.
You enter payment and billing details on Stripe/Link-hosted pages. We do not collect full card numbers or security codes in the add-on or our API. We receive payment and subscription updates to grant credits, manage account status and reconcile purchases and refunds. These updates are stored in Neon and may contain billing contact details, address, tax information and limited payment-method details, such as card brand and last four digits, in addition to transaction identifiers, amounts and status. Our backend stores payment-event payloads, not only transaction IDs.
Stripe/Link also processes data for its own payment-service purposes under the Link Privacy Policy and Stripe Privacy Policy. For those services, Stripe and FalconScrape act as independent controllers. Information about Stripe's processing and privacy requests is available through those policies.
We use billing data to perform the paid service contract, reconcile and secure payments, and meet applicable recordkeeping obligations. Financial records required under Polish tax rules are generally kept until the relevant tax liability becomes time-barred: normally five years from the end of the calendar year in which payment of that tax was due. Suspension, interruption or other applicable rules can extend this period. We retain necessary records for unresolved disputes or legal claims and keep the minimal identifiers needed to reconcile valid purchases and avoid duplicate credits. Full payment-event payloads have the shorter operational retention shown above; they are not our accounting archive. Contact us about records held by FalconScrape; contact Stripe/Link through its privacy channels about records it controls.
Website analytics: Vercel Analytics processes website visit and page-view information without analytics cookies. We do not send your Google ID token, account email address or spreadsheet contents to it as analytics events.
We do not sell Google user data, share it for advertising or data brokering, or use it to develop, improve or train generalized artificial intelligence or machine-learning models. We do not transfer or disclose Google user data for purposes other than providing the features described here, except where required by applicable law. Providers may process data outside your country, including in the United States and the European Union.
How we protect Google user data
We use the following technical safeguards to protect Google user data and other sensitive information handled by the add-on:
- Encryption in transit. The add-on communicates with our API over HTTPS. Our backend also uses HTTPS for Google identity verification and requests to the data-extraction and email-delivery services.
- Verified sign-in. Before issuing an account token, our backend verifies the Google ID token with Google and checks that it was issued for an accepted application client, has not expired, and contains a verified email address.
- Protected account tokens. FalconScrape generates random access tokens and stores only their SHA-256 hashes in the account database. The token used by the add-on is kept in Apps Script user properties rather than in spreadsheet cells or formula arguments. Signing out clears the add-on's stored token; activating again rotates the account token.
- Authenticated access. Account and formula API requests require a valid FalconScrape token. Administrative API requests require a separate secret credential. Backend service credentials are read from server-side environment configuration rather than included in the spreadsheet or add-on code.
- Limited data collection. We process only the formula inputs and spreadsheet controls described above, rather than uploading the whole spreadsheet. Temporary result caches have expiration times, and account deletion can be requested as described below.
These safeguards reduce the risk of unauthorized access or disclosure; no method of transmission or storage can guarantee absolute security.
Your rights
You can access, correct, export, or delete your account data by emailing support@falconscrape.com. EU/EEA residents have the rights set out in the GDPR, including the right to complain to the Polish supervisory authority (UODO). We do not sell personal data.
Account closure and retained records
To close your account, email support@falconscrape.com. We verify the request and confirm whether you want immediate service termination or only to stop subscription renewal. Immediate closure ends access and removes unused plan and pack credits; it does not automatically issue a refund or limit your refund rights. We stop verified subscription renewal and check outstanding payments, refunds and disputes before confirming completion. A request may remain pending while those checks are resolved.
On completed closure, we revoke account access, replace the email in the application account with an internal reference, remove account usage and matching beta-signup records, and remove raw billing-event payloads once pending issues and holds are resolved. We retain limited billing identifiers, purchase/refund records and the closure record for the purposes above. Those retained identifiers are pseudonymous, not anonymous. A new registration does not restore the old subscription or credits.
We keep encrypted recovery copies of the account database locally and in private Google Drive storage. These copies can include account, usage and billing records described above; recovery keys are stored separately. Routine database backups are retained for seven days, with longer retention only where needed for an investigation or recovery checkpoint. Financial archives and deletion-request records follow their separate retention purposes. Older copies may also remain in restricted database recovery history until they expire or are removed. Restored data must be reconciled with completed deletion requests before being used again. Deleting a FalconScrape account does not delete data independently held by Stripe/Link, Google or records subject to legal retention.
Cookies
The website uses no advertising or tracking cookies. A single local-storage key remembers your light/dark theme preference. Stripe/Link-hosted checkout and billing pages are separate services whose storage and privacy practices are described in their policies.
Changes
We will post updates on this page and change the date above. Material changes to the add-on's data use will be announced in the add-on sidebar.