Privacy Policy
Last updated: July 15, 2026
1. INTRODUCTION
OpenSERP ("we", "us", "our") operates the website openserp.org and the OpenSERP API. The Service is operated by TATLAB LTD, a company registered in England and Wales (company number 17289453), with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom. TATLAB LTD is the data controller for personal data processed through the Service. This Privacy Policy explains how we collect, use, and protect your information.
2. DATA WE COLLECT
2.1 Account Data
- Email address (provided at registration)
- Hashed password (we never store plaintext passwords)
2.2 Billing Data
- Transaction records (amounts, dates, payment references)
- Stripe and NOWPayments collect the payment information needed to process your chosen method. We do not directly receive or store full card numbers or security codes. We retain provider transaction records and webhook data, which may include checkout details and cryptocurrency payment addresses
2.3 Usage Data
- API request records: timestamp, endpoint, account or API key identifiers, response status, credits used, and limited request parameters such as query text or an extraction URL
- Purpose: billing calculation, rate limiting, abuse prevention
- We do not store search-result response bodies in these billing and operational records
2.4 Technical Data
- IP address (used for rate limiting, security, and network logs)
- Browser user agent (when accessing the website)
- Cloudflare Web Analytics / Browser Insights performance metrics, such as page load timing and Core Web Vitals
- Microsoft Clarity product-analytics data (aggregate usage, heatmaps, and session replay) in the signed-in dashboard only. For EU/EEA/UK visitors this runs only on opt-in; elsewhere it is enabled by default and can be turned off at any time, and we honour "Do Not Track" as an opt-out. Clarity masks all text and input fields, so account content such as API keys, balances, and search query text is not captured, and sessions are identified only by a one-way hashed account identifier, never your email or raw account id
2.5 Waitlist Data
If you join the OpenSERP Cloud waitlist, we may email you about early access, onboarding, product availability, and related launch updates.
- Email address and optional use case description (if you signed up for early access)
- UTM parameters and referrer, when present, to understand how people found the waitlist
- Cloudflare Turnstile verification data used to prevent automated or abusive submissions
3. HOW WE USE YOUR DATA
- To provide and maintain the Service
- To process payments and maintain your account balance
- To enforce rate limits and prevent abuse
- To communicate service updates and important notices
- To manage the OpenSERP Cloud waitlist, early-access onboarding, and launch planning
- To understand aggregate public website performance
- To comply with legal obligations
We rely on performance of our contract to provide accounts, API access and billing; legitimate interests to secure, operate and improve the Service and communicate necessary service information; legal obligations for tax, accounting and regulatory records; and consent where we specifically ask for it. Where we rely on legitimate interests, we consider the impact on your rights and use only data reasonably necessary for the stated purpose.
4. DATA SHARING
We do NOT sell, rent, or trade your personal data. We share data only with:
- Hosting, security and performance providers, including Cloudflare, to operate and protect the Service
- Analytics providers, specifically Microsoft (Clarity), used only in the signed-in dashboard and only with your consent, to help us understand and improve product usage
- Payment providers, including Stripe and NOWPayments, to process and reconcile top-ups
- Email delivery providers to send account, billing, security and requested product messages
- Service providers needed to fulfil API requests, which receive only the request data needed to perform the requested operation
- Professional advisers and public authorities where reasonably necessary or required by valid legal process
5. DATA RETENTION
- Account data: retained while your account is active, then deleted or anonymized unless a longer period is needed for legal claims, security, or compliance
- API usage records, including limited request parameters: retained for up to 12 months for billing accuracy, support, security, and dispute resolution
- Billing and transaction records: retained for up to 6 years, or longer where tax, accounting, fraud prevention, or legal-claim requirements apply
- Waitlist data: retained until the waitlist program ends, unless you request deletion earlier
- Unsubscribe records: retained as long as needed to respect your communication preference
6. COOKIES AND TRACKING
- We use only essential cookies required for the Service to function (authentication session)
- We use Cloudflare Turnstile for bot protection, which may set its own cookies
- We use Cloudflare Web Analytics / Browser Insights for performance measurement
- We use Microsoft Clarity for product analytics in the signed-in dashboard only - opt-in for EU/EEA/UK visitors, on by default with an opt-out elsewhere, and "Do Not Track" is honoured
- We do NOT use advertising cookies
- See our Cookie Policy for details
7. YOUR RIGHTS (UK GDPR, EU GDPR & SIMILAR LAWS)
If UK data protection law, EU/EEA data protection law, or similar law applies to you, you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Port your data to another service
- Restrict or object to certain processing
- Withdraw consent at any time
To exercise any of these rights, contact us at [email protected] . We normally respond within one month, subject to any extension permitted by law.
You may also make a data protection complaint to us at [email protected]. We will acknowledge it within 30 days, investigate as appropriate, and tell you the outcome without undue delay. You also have the right to complain to the UK Information Commissioner's Office or, where applicable, your local data protection authority.
8. DATA SECURITY
We implement appropriate technical and organizational measures to protect your data, including encrypted connections (HTTPS/TLS), hashed passwords, and secure API key storage.
9. INTERNATIONAL TRANSFERS
Some providers may process data outside the United Kingdom or your country. Where applicable, we rely on UK adequacy regulations or approved contractual safeguards and supplementary measures. Contact us if you want information about the safeguard used for a particular transfer.
10. CHILDREN
The Service is not intended for use by anyone under the age of 16. We do not knowingly collect data from children.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on our website.
12. CONTACT
For privacy-related questions or requests:
- Controller: TATLAB LTD, company number 17289453
- Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
- Email: [email protected]
- Or use the contact information on our website