CrawlerToll

Privacy

Last updated 5 October 2026 · Charthouse Ltd, company 12795844, England and Wales ·hello@crawlertoll.com

CrawlerToll is built so that as little data as possible reaches us. Article text never leaves the publisher's site in the clear, card details never touch our systems, and we hold no payment credentials. This page says exactly what each part handles.

This website

crawlertoll.com sets no cookies and runs no analytics. It is hosted on Vercel today, moving to Cloudflare Pages. The host keeps standard server logs (IP address, user agent, requested URL) for a short period for security and operations. If you click a purchase button on /pro, the Freemius checkout loads in your browser; Freemius is the merchant of record for Pro subscriptions and processes your name, email and payment under its own privacy policy. We receive your name, email, and license status from Freemius so we can support you.

The WordPress plugin

The plugin runs on the publisher's own server. The publisher, not Charthouse, is the controller for their site. Crawler recognition, RSL policy and plain 402 responses run entirely locally and send nothing anywhere. The Pro plugin optionally contacts Freemius for license validation and can keep decision logs in the publisher's own database, under a retention window the publisher sets.

The unlock service (registry.crawlertoll.com)

The sealed paywall uses a small hosted service operated by Charthouse Ltd. Charthouse is the controller for what it needs to run and secure the service: publisher accounts and settings, request logs, rate-limit counters and backups. Receipts and licences about a publisher's readers belong to the publisher, who is the controller; Charthouse processes them on the publisher's behalf. The service stores, per sealed post: the content key, the content id (the site's host name and post number), the price and pricing rules, and the publisher's wallet address. It never receives the article text, card numbers, or wallet private keys. When someone unlocks a post it records a receipt: content id, payment rail, the payment reference (a Stripe PaymentIntent id or a blockchain transaction hash), a buyer reference, the listed price, rate and amount, the time, and, for card and USDC purchases, the time the buyer agreed to lose the 14-day withdrawal right. The buyer reference is the payer wallet address on the USDC rail, or a random device, pass or meter id; it is an email hash only if email features are ever switched on. Publishers can read these receipts back. Readers are never identified by name, and a payer wallet address is public on-chain by design.

The service runs on Cloudflare Workers, KV and D1 (Cloudflare, Inc. as processor). If it cannot be reached, sealed posts stay locked and no payment can start; there is no service-level agreement at launch. Single-use payment references expire automatically. One retention rule applies to receipts, content keys, pricing rules and the webhook queue: they are kept while the publisher's account exists, and deleted within 30 days of delisting or of a deletion request, except records the law requires us to keep. Nightly backups are encrypted, stored in the EU, and deleted after 30 days, so a deletion reaches every backup within 30 days.

What we process and why

Charthouse Ltd is the controller for the service's own running and security: publisher accounts and settings, request logs, rate-limit counters and backups. For receipts, licences and other records about a publisher's readers, the publisher is the controller and Charthouse acts as its processor. Readers should contact the publisher first, and we will help the publisher answer.

DataWhyLawful basisKept for
Buyer reference on receipts and AI-training licences: the payer wallet address, or a random device, pass or meter id; an email hash only if email features are ever switched onRelease the key, recover a lost unlock, prove a licenceContract (publisher's, as processor)The retention rule above
Payment reference: a Stripe PaymentIntent id or a blockchain transaction hashSameContract (publisher's, as processor)Same
Listed price, rate and amount on receiptsSameContract (publisher's, as processor)Same
The time a buyer agreed to lose the 14-day withdrawal rightRecord that consent was givenContract (publisher's, as processor)Same
Webhook delivery queue to the publisher's own endpoint (carries the buyer reference)Tell the publisher about each unlockContract (publisher's, as processor)Kept with the receipts; delivered events are not deleted separately
Read-pack balancesCount readsContract (publisher's, as processor)Until used up, and no longer than the retention rule
Cross-device transfer codesMove a pass to another deviceContract (publisher's, as processor)10 minutes
Publisher accounts and settings: site, token hash, content keys, pricing rulesRun the serviceContract, with the publisherThe retention rule above
Request logs: IP address and user agent, in Cloudflare Workers logsSecurity and abuse preventionLegitimate interestCloudflare's log retention (a few days)
IP-keyed rate-limit counters (hashed or short-lived)Abuse preventionLegitimate interestMinutes to hours
Nightly encrypted backups of the above, stored in the EURecover the service after a failureLegitimate interest30 days
Email hashesOnly when email features are switched on, which they are not todayConsentNot applicable

The retention rule: these records are kept while the publisher's account exists, and deleted within 30 days of delisting or of a deletion request, except records the law requires us to keep.

Payments

Charthouse never holds a Stripe secret, a payment-platform account, or a facilitator key, and never takes a share of any payment.

Processors we use

International transfers

Cloudflare and others process data outside the UK. We rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and on the UK-US data bridge where the provider is certified.

Readers on publishers' sites

The publisher is the seller and the controller for its readers. CrawlerToll processes their receipts, licences and payment references on the publisher's behalf, and helps the publisher answer any request. Readers should contact the publisher first. Publishers can paste the suggested privacy text shown in the plugin.

Who we are

Charthouse Ltd, a private limited company registered in England and Wales under company number 12795844, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, is the controller for this website and for the running and security of the unlock service, and the processor for publishers' reader records.

Your rights and contact

Under the UK GDPR and, where it applies, the EU GDPR you have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent where we rely on it. For receipts, licences or anything else about a purchase on a publisher's site, contact that publisher first; they are the controller, and we will help them answer. For this website or the running of the unlock service, email hello@crawlertoll.com. You may complain to the UK Information Commissioner's Office.