Who controls your data
Daniel (Darko) Cox, trading as Haunt API, is the controller for account, website, billing, support, abuse-prevention and security information.
Business address: 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom. Email: support@hauntapi.com.
When a business customer submits personal data for extraction, Haunt normally acts as that customer’s processor. The Data Processing Addendum governs that work.
What we collect
- Account information. Name, business email, password hash, API-key hash and prefix, account status, plan, acceptance records and account timestamps.
- Service information. Endpoint, timestamp, response status, latency, credits, request ID, error class, provider path and limited redacted URL or prompt previews.
- Extraction input. URLs, prompts, optional headers or cookies supplied by the customer, and visible page content needed to produce the requested result.
- Billing information. Plan, currency, Stripe customer and subscription identifiers, invoices, refunds and payment-status events. Haunt does not receive or store complete card details.
- Support and security information. Messages, diagnostic details, login and rate-limit events, abuse signals, IP-derived security information and relevant server logs.
- Website statistics. Page path, referral and campaign category, device class, viewport, event name, a session identifier and a first-party visitor identifier that rotates after 24 hours.
Why we use it
| Purpose | Information | UK GDPR basis |
|---|---|---|
| Provide accounts, extraction, support and plan access | Account, service and extraction information | Contract |
| Take payment and keep tax records | Account and billing information | Contract and legal obligation |
| Protect accounts, prevent abuse and investigate failures | Security, service and limited request information | Legitimate interests in operating a secure and reliable business |
| Measure and improve the website | Short-lived website statistics | Legitimate interests; the PECR statistical-purpose exception is used for device storage |
| Answer legal requests and establish claims | Relevant account, billing, support and security records | Legal obligation and legitimate interests |
Haunt does not use customer extraction content to train general-purpose AI models or to build advertising profiles. Service improvement uses operational measurements and aggregated or anonymised information, not customer content for a new purpose.
Retention
- Fetched page content is processed in memory and is not stored as a page archive.
- Extracted results are not stored by default. Opt-in cache results expire at the requested duration, never longer than 24 hours.
- Encrypted submitted URLs and prompts may be retained for up to 60 days for support, abuse prevention and billing evidence.
- Individual website funnel events expire after 7 days. The browser visitor identifier rotates after 24 hours; longer-term reporting uses aggregated statistics.
- Account records remain while an account is active. After closure, limited billing, fraud, security and legal records remain only for the applicable statutory or claims period.
- Stripe webhook records expire after 90 days. Other operational request records follow the published 60-day request-history limit unless a shorter period applies.
Deletion from resilient backups follows the normal backup cycle. Until overwritten, backup data is isolated and used only for disaster recovery.
Who receives data
Haunt uses service providers for infrastructure, model inference, residential network access, transactional email, payment, authentication and fonts. The current providers, roles and processing locations are listed on the Subprocessors page.
Haunt may also disclose limited information to professional advisers, regulators, courts or law-enforcement bodies where legally required. Personal data is not sold.
International transfers
Some providers process data outside the UK. Haunt permits a restricted transfer only where UK adequacy regulations apply or appropriate safeguards are in place, such as the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another lawful mechanism.
Haunt assesses the protection available for relevant transfers. Contact us for a copy or summary of the applicable safeguard, subject to necessary redactions.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability, or an objection to processing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
You may object at any time to processing based on legitimate interests. Haunt will stop unless it can demonstrate compelling lawful grounds or the processing is needed for legal claims.
Use the footer control to disable optional website analytics in this browser. You can also visit a public page with ?haunt_ignore=1; use ?haunt_track=1 to enable analytics again.
Privacy requests go to support@hauntapi.com. You may complain to the Information Commissioner’s Office.
Other required information
Account details are required to create and secure an account. Without them, Haunt cannot provide authenticated service or billing. Information marked optional can be omitted.
Haunt may receive account and payment status from Stripe, identity details from Google or GitHub when you choose social sign-in, and public-page content from URLs submitted by customers.
Haunt does not make solely automated decisions that produce legal or similarly significant effects about website visitors or account holders.
Business service
Haunt is offered to businesses and people acting in a business capacity. It is not directed at children, and accounts may not be created by anyone under 18.
Customers remain responsible for the lawfulness of the pages, credentials and personal data they submit.
Changes and contact
Material changes will be posted here and, where they significantly affect active accounts, notified by email before they take effect. A privacy notice describes processing; silence or continued browsing is not treated as consent.
Questions or requests: support@hauntapi.com. Related detail is in the Cookie Policy, DPA, Subprocessor List and Security page.