Privacy
Last updated 5 October 2026 · Charthouse Ltd, company 12795844, England and Wales ·hello@crawlertoll.com
CrawlerToll is built so that as little data as possible reaches us. Article text never leaves the publisher's site in the clear, card details never touch our systems, and we hold no payment credentials. This page says exactly what each part handles.
This website
crawlertoll.com sets no cookies and runs no analytics. It is hosted on Vercel today, moving to Cloudflare Pages. The host keeps standard server logs (IP address, user agent, requested URL) for a short period for security and operations. If you click a purchase button on /pro, the Freemius checkout loads in your browser; Freemius is the merchant of record for Pro subscriptions and processes your name, email and payment under its own privacy policy. We receive your name, email, and license status from Freemius so we can support you.
The WordPress plugin
The plugin runs on the publisher's own server. The publisher, not Charthouse, is the controller for their site. Crawler recognition, RSL policy and plain 402 responses run entirely locally and send nothing anywhere. The Pro plugin optionally contacts Freemius for license validation and can keep decision logs in the publisher's own database, under a retention window the publisher sets.
The unlock service (registry.crawlertoll.com)
The sealed paywall uses a small hosted service operated by Charthouse Ltd. Charthouse is the controller for what it needs to run and secure the service: publisher accounts and settings, request logs, rate-limit counters and backups. Receipts and licences about a publisher's readers belong to the publisher, who is the controller; Charthouse processes them on the publisher's behalf. The service stores, per sealed post: the content key, the content id (the site's host name and post number), the price and pricing rules, and the publisher's wallet address. It never receives the article text, card numbers, or wallet private keys. When someone unlocks a post it records a receipt: content id, payment rail, the payment reference (a Stripe PaymentIntent id or a blockchain transaction hash), a buyer reference, the listed price, rate and amount, the time, and, for card and USDC purchases, the time the buyer agreed to lose the 14-day withdrawal right. The buyer reference is the payer wallet address on the USDC rail, or a random device, pass or meter id; it is an email hash only if email features are ever switched on. Publishers can read these receipts back. Readers are never identified by name, and a payer wallet address is public on-chain by design.
- Metered free articles (Pro): the reader's free-allowance identity is a random token in their browser. To limit abuse, the service keeps a salted, daily-rotating hash of the IP address for the metering window; the raw address is not stored.
- Email: email features are not switched on, so no email addresses or email hashes are processed today.
- In the reader's browser: after an unlock, the content key and access pass are kept in the browser's local storage so the reader is not charged twice; metered free reads keep a random identifier there and in a first-party cookie. Nothing identifies the reader by name.
- Unlock webhooks (Pro): if the publisher configures a webhook, unlock events are queued and delivered to the URL they chose, signed with their own secret. Each queued event carries the buyer reference. Delivered events are not deleted separately: they are kept with the receipts under the retention rule below.
- Cross-device transfer codes: a reader who moves a pass to another device gets a random one-time code, which is kept for 10 minutes.
The service runs on Cloudflare Workers, KV and D1 (Cloudflare, Inc. as processor). If it cannot be reached, sealed posts stay locked and no payment can start; there is no service-level agreement at launch. Single-use payment references expire automatically. One retention rule applies to receipts, content keys, pricing rules and the webhook queue: they are kept while the publisher's account exists, and deleted within 30 days of delisting or of a deletion request, except records the law requires us to keep. Nightly backups are encrypted, stored in the EU, and deleted after 30 days, so a deletion reaches every backup within 30 days.
What we process and why
Charthouse Ltd is the controller for the service's own running and security: publisher accounts and settings, request logs, rate-limit counters and backups. For receipts, licences and other records about a publisher's readers, the publisher is the controller and Charthouse acts as its processor. Readers should contact the publisher first, and we will help the publisher answer.
| Data | Why | Lawful basis | Kept for |
|---|---|---|---|
| Buyer reference on receipts and AI-training licences: the payer wallet address, or a random device, pass or meter id; an email hash only if email features are ever switched on | Release the key, recover a lost unlock, prove a licence | Contract (publisher's, as processor) | The retention rule above |
| Payment reference: a Stripe PaymentIntent id or a blockchain transaction hash | Same | Contract (publisher's, as processor) | Same |
| Listed price, rate and amount on receipts | Same | Contract (publisher's, as processor) | Same |
| The time a buyer agreed to lose the 14-day withdrawal right | Record that consent was given | Contract (publisher's, as processor) | Same |
| Webhook delivery queue to the publisher's own endpoint (carries the buyer reference) | Tell the publisher about each unlock | Contract (publisher's, as processor) | Kept with the receipts; delivered events are not deleted separately |
| Read-pack balances | Count reads | Contract (publisher's, as processor) | Until used up, and no longer than the retention rule |
| Cross-device transfer codes | Move a pass to another device | Contract (publisher's, as processor) | 10 minutes |
| Publisher accounts and settings: site, token hash, content keys, pricing rules | Run the service | Contract, with the publisher | The retention rule above |
| Request logs: IP address and user agent, in Cloudflare Workers logs | Security and abuse prevention | Legitimate interest | Cloudflare's log retention (a few days) |
| IP-keyed rate-limit counters (hashed or short-lived) | Abuse prevention | Legitimate interest | Minutes to hours |
| Nightly encrypted backups of the above, stored in the EU | Recover the service after a failure | Legitimate interest | 30 days |
| Email hashes | Only when email features are switched on, which they are not today | Consent | Not applicable |
The retention rule: these records are kept while the publisher's account exists, and deleted within 30 days of delisting or of a deletion request, except records the law requires us to keep.
Payments
- Cards, Apple Pay, Google Pay: run on the publisher's own Stripe account. The card form is Stripe's, loaded in the reader's browser; card data goes to Stripe only. The publisher's server and the unlock service see a PaymentIntent id, amount and status, nothing more. Stripe's privacy policy applies.
- USDC over x402: the reader's or agent's wallet signs an authorisation which a third-party facilitator settles on the Base blockchain into the publisher's wallet. The transaction, including both wallet addresses and the amount, is public on-chain by the nature of the network. The default facilitator is xpay (facilitator.xpay.sh); publishers can choose another.
Charthouse never holds a Stripe secret, a payment-platform account, or a facilitator key, and never takes a share of any payment.
Processors we use
- Cloudflare, Inc.: hosting, Workers, D1 and KV for the unlock service, and email routing.
- The site host: Vercel Inc. today, Cloudflare Pages after the move.
- The x402 facilitators that settle USDC payments (xpay.sh, and PayAI as the fallback facilitator).
- Public Base RPC providers used to check a wallet signature (mainnet.base.org, PublicNode, 1RPC), which receive the payer address and signature for licence checks.
- Freemius, Inc.: Pro billing, as merchant of record.
International transfers
Cloudflare and others process data outside the UK. We rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and on the UK-US data bridge where the provider is certified.
Readers on publishers' sites
The publisher is the seller and the controller for its readers. CrawlerToll processes their receipts, licences and payment references on the publisher's behalf, and helps the publisher answer any request. Readers should contact the publisher first. Publishers can paste the suggested privacy text shown in the plugin.
Who we are
Charthouse Ltd, a private limited company registered in England and Wales under company number 12795844, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, is the controller for this website and for the running and security of the unlock service, and the processor for publishers' reader records.
Your rights and contact
Under the UK GDPR and, where it applies, the EU GDPR you have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent where we rely on it. For receipts, licences or anything else about a purchase on a publisher's site, contact that publisher first; they are the controller, and we will help them answer. For this website or the running of the unlock service, email hello@crawlertoll.com. You may complain to the UK Information Commissioner's Office.