PAGEFLOCK / PRIVACY NOTICE

Your data. Explained.

What pageflock collects, what it is used for and the choices you have. This notice covers the website, workspace and public API.

Updated 17 September 2026 · Version 1.3
01

Account and access information

We store your name, email, creation date, confirmation status and credit balance. Passwords use a salted scrypt hash. Session, verification, reset and API tokens are stored as hashes; API keys also have a label, short identifier and status. These records provide access, secure your account and support account emails.

02

Requests and collected content

Request history contains target URLs or search queries, the operation type, timestamps, status, duration, credits and limited errors. Page extraction, product data, YouTube metadata and search return content without saving response bodies in request history. Requests with Idempotency-Key retain a bounded retry receipt, including the response where storage limits allow, for up to 24 hours; the dashboard uses this to recover interrupted requests. Saved configurations retain the submitted URL or query and options until deleted. Web, news and video search send your query, country and language to the search service to obtain public search results; avoid sensitive personal information in queries. YouTube metadata sends the canonical video URL to YouTube’s public oEmbed endpoint. No customer cookies or login credentials are sent to YouTube. Collections store extracted text, links and metadata for later access. Avoid credentials and personal information in URL query strings. Target websites receive requests from pageflock’s servers, including the requested URL and technical request information.

03

Why we process data

Account and usage information supports authentication, recovery, collections and credit accounting. Security checks and short-lived rate-limit identifiers help prevent misuse. Where applicable, processing bases are performance of our service agreement, legitimate interests in operating and protecting the service, and legal obligations for required records. This website includes no advertising trackers. pageflock does not sell account data or use collected page content to train a model.

04

Visits and clicks, with your permission

Optional Google Analytics measures which parts of pageflock people visit and which partner, tool and navigation links they use. Analytics is based on your consent and stays off until you accept it. It uses a browser identifier rather than your pageflock account identity. Google receives the event information and technical connection/device information; it may process information outside your country. Your requested URLs, search queries, result data, form contents, account email, password and API keys are excluded from these events. Google Signals and advertising personalisation are disabled. Use Cookie preferences to withdraw consent at any time. The Cookie Policy describes the stored preferences and analytics cookies; Google’s privacy policy explains its processing. Reports distinguish pageflock from other websites by hostname. Analytics reporting retention is controlled by the configured Google Analytics property settings.

05

Who receives information

Service operation may involve hosting, email and payment providers. When web search is enabled, search queries and localisation parameters are processed on pageflock’s secure infrastructure and search partners without sharing or selling search queries to third-party ad brokers or advertising networks. YouTube receives video URLs and server request information when you use the metadata endpoint. If checkout is enabled, Stripe collects payment details on its hosted checkout; pageflock stores purchase references, amounts, credits and status, not card numbers. Information may also be disclosed when required by law or necessary to address abuse. Provider identities, processing locations and transfer arrangements belong in the operator disclosures below.

06

How long records remain

Collection pages, results and job records expire seven days after creation and are removed by maintenance once work is terminal. Finished collections can be deleted sooner. Completed request history is pruned after 30 days. Retry receipts become unavailable after 24 hours and are pruned by maintenance or subsequent request admission. Sessions expire after seven days, password-reset links after 30 minutes and confirmation links after 24 hours. Maintenance removes expired token and rate-limit records. Account and API-key records remain until account closure. Export collections before their expiry.

07

What account closure removes

Closure prevents new work and waits for in-flight requests and pending checkouts to finish or expire. It deletes the profile, keys, sessions, recovery tokens, request history, saved configurations, retry receipts and owned collections. Paid and expired checkout records remain without the account profile, including checkout identifiers, amounts, credits and dates. These are pseudonymous records: a payment provider may still associate its own records with you. Their retention period and infrastructure backup retention must be specified in the operator disclosures.

08

Your choices and privacy rights

Settings lets you update your name, change your password, export account information and close the account. Export includes profile, key metadata, purchases, saved configurations, retained retry responses, collection history and up to 5,000 recent request records; download page content from each collection separately. Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing. Contact the privacy address below, including if you do not have an account. Proportionate identity verification may be needed. You may complain to your local data protection authority.

09

Changes to this notice

The update date records the latest revision. Material changes to processing purposes or your rights will be communicated before taking effect where required. pageflock is intended for people legally able to enter a service agreement; do not submit children’s data or sensitive personal data.

OPERATOR & CONTACT

Who runs pageflock.

Legal operator
HYVE LABS LLC
Business address
Sharjah Media City (Shams), Sharjah, United Arab Emirates
Registration country
United Arab Emirates
Privacy requests
abdul@hyvelabs.tech

Providers, locations and transfers

pageflock is operated by HYVE LABS LLC and hosted on Google Cloud Platform (application, collection worker and PostgreSQL database in the EU region europe-west1; some Google services may process data in the United States). Payments are handled by Stripe on its hosted checkout; card details are collected and stored by Stripe, never by pageflock. Optional web, news and video search sends your query and country/language to Serper (serper.dev). Transactional email (verification and purchase receipts) is delivered through Resend. Optional, consent-based product analytics use Google Analytics. YouTube metadata requests use Google public oEmbed. These processors act under their own terms; where personal data is transferred internationally they rely on their own standard contractual clauses and safeguards.

Payment record retention

Paid and expired checkout records (checkout identifiers, amounts, credits and dates) are kept, separately from your account profile, for at least five years after the transaction to meet UAE tax and accounting obligations. Encrypted database backups are retained for up to 30 days before rotation. Account request history is pruned after 30 days and collection results after seven days.

Contact & account help
YOUR PRIVACY

Choose what works for you. You can reopen these settings from the footer at any time.