1. Introduction
ScrollTell (“ScrollTell”, “we”, “our”, or “us”) is an independent business based in Egypt. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our visual landing-page builder service.
This policy applies to information collected through our website at scrolltell.com, our web application, and any related services (collectively, the “Service”).
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, do not use the Service. By accessing or using the Service, you agree to this Privacy Policy.
Global availability & EU/UK users. We offer the Service worldwide, including to users in the European Union/EEA and the United Kingdom. If you are in those regions, the GDPR / UK GDPR applies to your personal data and you have the rights described in Sections 4, 8, and 10. See Section 14 for how to contact us and your right to lodge a complaint with a supervisory authority.
2. Information We Collect
2.1 Personal Information You Provide
We collect information you voluntarily provide when you:
- Create an Account: Your name, email address, and (optionally) a profile picture, managed through Clerk, our authentication provider. Sign-in credentials such as passwords are handled by Clerk — we never receive or store them.
- Purchase Credits: When you buy credits, your payment is handled by our Merchant of Record, Polar, and its payment processor (Stripe). You provide your billing and card details to them, not to us — we never receive or store full card numbers. We receive only what we need to fulfil the order (your user id and the product/quantity purchased). See Section 5.1.
- Contact Us: Information in support requests, feedback forms, and communications with our team
- Participate in Surveys: Responses to optional surveys and research
2.2 Information Collected Automatically
When you use the Service, a limited amount of technical data is collected:
- Server & Log Data: Standard request logs from our hosting provider and application — your IP address, access times, browser/user-agent, and error logs — used for security, debugging, and reliability.
- Usage Analytics: First-party product-usage events tied to your account (which key milestones you reach), with non-PII metadata. We record a coarse, country-level region (the two-letter country code only). This country is provided to our application as a country code by our hosting/CDN edge (Cloudflare), which performs the lookup; our application does not read, geolocate, store, or otherwise process your IP address for these analytics, and we never resolve your city or precise location. We do not use device fingerprinting, collect screen resolution or unique device identifiers, track clicks/scrolling or navigation paths, or use third-party analytics trackers. See Section 9, and you can opt out in Account Settings.
2.3 Content You Create
We store the content you create and upload using the Service:
- Landing page projects, designs, and configurations
- Text, headlines, copy, and written content
- Images, videos, and media files you upload
- Exported code and project files
Your content belongs to you. We process it solely to provide the Service and do not use your content for advertising or sell it to third parties.
3. How We Use Your Information
3.1 Service Delivery
- Provide, operate, and maintain the Service
- Process transactions and send billing notifications
- Generate and deliver code exports
- Provide customer support and respond to inquiries
- Authenticate your identity and manage your account
3.2 Service Improvement
- Analyze usage patterns to improve features and user experience
- Develop new features, products, and services
- Conduct research, testing, and quality assurance
- Monitor and improve Service performance and stability
- Identify and fix bugs and technical issues
3.3 Communication
- Send essential service notifications (account, billing, security)
- Respond to your inquiries, feedback, and support requests
- Send product updates and feature announcements
- Send marketing communications (only with your consent)
- Notify you about changes to our Terms or Privacy Policy
You can opt out of marketing communications at any time using the unsubscribe link or by contacting us. Essential service communications cannot be opted out of.
3.4 Security and Compliance
- Protect against unauthorized access, fraud, and abuse
- Enforce our Terms of Service and policies
- Comply with legal obligations and respond to lawful requests
- Protect the rights, property, and safety of users and others
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), European Union (EU), or United Kingdom (UK), we process your personal data based on the following legal grounds:
- Performance of Contract: Processing necessary to provide the Service as described in our Terms of Service
- Legitimate Interests: Processing for our legitimate business interests, such as improving the Service, preventing fraud, and ensuring security, where these interests are not overridden by your rights
- Consent: Processing based on your explicit consent, such as for marketing communications and non-essential cookies
- Legal Obligation: Processing necessary to comply with applicable laws and regulations
You have the right to withdraw consent at any time where we rely on consent as a legal basis for processing.
5. Information Sharing
We do not sell your personal information. We may share your information only in the following circumstances:
5.1 Service Providers
We work with trusted third-party service providers who assist in operating the Service. These providers are contractually obligated to protect your data and may only use it for the purposes we specify:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Clerk | Authentication & user management | clerk.com/privacy |
| Polar (Merchant of Record) | Payments, tax, invoicing & payouts — the seller of record for purchases; uses Stripe as its payment processor | polar.sh/legal/privacy-policy |
| Cloudflare | DNS, CDN & edge security; provides a coarse country code used for regional eligibility (Section 2.2) | cloudflare.com/privacypolicy |
| Render | Application hosting & infrastructure | render.com/privacy |
| Supabase | Database & file storage | supabase.com/privacy |
| Anthropic | AI features — animation suggestions generated from your prompts (only when you use AI) | anthropic.com/legal/privacy |
Data processing agreements & infrastructure security. These providers process personal data on our behalf under data processing agreements (DPAs) and only as instructed. Our hosting and infrastructure provider, Render, maintains SOC 2 Type 2 and ISO 27001 certifications and complies with the GDPR; we operate under Render's GDPR Data Processing Agreement. Personal data handled by our infrastructure on our behalf — including standard request data such as your IP address in server logs (Section 2.2) — is processed under that agreement. These certifications are held by our service providers, not by ScrollTell itself; we remain responsible for our own application-level privacy and security practices. If we add or replace a provider that processes personal data, we will update the list above; for material changes we follow the notice process in Section 13.
5.2 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or part of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service before your information is transferred and becomes subject to a different privacy policy.
5.3 Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal processes (subpoenas, court orders, legal requests)
- Requests from government authorities
- Protection of our rights, privacy, safety, or property
- Emergency situations involving potential threats to individuals
We will attempt to notify you of legal demands for your data when legally permitted, unless prohibited by law or court order.
6. Data Retention
We retain your personal information for as long as necessary to:
- Provide the Service and fulfill the purposes described in this policy
- Comply with legal, accounting, or reporting obligations
- Resolve disputes and enforce our agreements
- Protect against fraudulent or abusive activity
Retention periods:
- Account data: Retained while your account is active, plus 30 days after deletion request
- Project data: Retained while your account is active, deleted 30 days after account closure
- Payment data: We do not store card details. Our Merchant of Record, Polar (and its payment processor, Stripe), retains transaction records under its own policy and legal/tax requirements. In our database, export and billing audit rows are deleted together with your account; we keep only a minimized, non-identifying record of the deletion (no personal or payment data)
- Support communications: If you email us, those messages are retained by our email provider; we do not apply a separate retention schedule
- Usage-analytics events: Kept until you opt out (which erases them) or delete your account, whichever comes first
When you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes.
7. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption in transit: all data is transmitted over TLS
- Encryption at rest: your project content is encrypted with AES-256-GCM before it is stored
- Access controls: access is gated by authentication, and administrative access is restricted
- Rate-limiting & abuse controls on sensitive and cost-bearing routes
- Reputable infrastructure: we rely on established providers (Section 5.1) that maintain their own security certifications (e.g. our host, Render, holds SOC 2 Type 2 and ISO 27001)
- Encrypted backups with tested recovery procedures
As a small, independent operation we apply reasonable technical measures appropriate to the risk rather than the internal security teams of a large company. No method of transmission or storage is 100% secure and we cannot guarantee absolute security, but we will notify you promptly if a breach affects your data as required by applicable law.
8. Your Rights
Depending on your location, you may have certain rights regarding your personal data:
8.1 Right to Access and Portability
You can request a copy of your personal data in a structured, commonly used, machine-readable format. You can also request information about how we process your data.
8.2 Right to Correction
You can request correction of inaccurate or incomplete personal data. You can also update most account information directly through your account settings.
8.3 Right to Deletion
You can request deletion of your personal data. We will comply unless we have a legal obligation to retain the data or need it for legitimate purposes.
8.4 Right to Restriction
You can request that we restrict processing of your data in certain circumstances, such as while we verify the accuracy of your data or assess a deletion request.
8.5 Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds.
8.6 Right to Withdraw Consent
Where we rely on your consent as the legal basis for processing, you can withdraw that consent at any time — for example, by disabling usage analytics in Account Settings. Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it.
8.7 Automated Decision-Making
We do not use your personal data to make decisions based solely on automated processing — including profiling — that produce legal or similarly significant effects about you, within the meaning of Article 22 of the GDPR.
Our optional AI features (which suggest animation changes from your prompts) are assistive only: each suggestion is applied to your project as a single reversible change that you review and can keep or undo, and it reaches your exported code only if you choose to export. They do not make automated decisions that produce legal or similarly significant effects about you.
To exercise these rights, contact us at [email protected]. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing certain requests. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority (see Section 14).
10. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States, where data protection laws may differ from those in your jurisdiction.
When transferring data internationally, we ensure appropriate safeguards:
- Standard Contractual Clauses (SCCs): We use EU-approved SCCs for transfers to countries without adequacy decisions
- Data Processing Agreements: Contractual commitments with all service providers regarding data protection
- Adequacy Decisions: Where available, we rely on European Commission adequacy decisions
- Data Privacy Framework: We work with providers certified under the EU-U.S. Data Privacy Framework where applicable
11. Children's Privacy
The Service requires users to be at least 18 and is not intended for anyone under 18. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected].
If we become aware that we have collected personal information from someone under 18 without appropriate consent, we will take steps to delete that information promptly.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request information about the categories and specific pieces of personal information we collect, use, disclose, and sell
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale or sharing of personal information (we do not sell personal information)
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights
- Right to Limit: Limit the use and disclosure of sensitive personal information
We do not sell or share personal information for cross-context behavioral advertising.
To exercise your California rights, contact us at [email protected]. Because we operate exclusively online and have a direct relationship with you, email is our designated method for submitting requests. You may also use an authorized agent to submit a request on your behalf, subject to our verification of your identity and the agent's authority. We will respond within 45 days.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the “Last updated” date at the top of this page
- For material changes, we will notify you via email at least 30 days in advance
- We may also display a notice within the Service
- Your continued use after changes take effect constitutes acceptance
We encourage you to review this Privacy Policy periodically. If you do not agree with changes, please stop using the Service before the effective date.
14. Contact Us
If you have questions about this Privacy Policy or our data practices:
- All inquiries (privacy & support): [email protected]
ScrollTell is an independent business operated from Egypt. Payments and receipts are handled by our Merchant of Record, Polar Software, Inc., under its own privacy policy. We are the data controller for your account and project data as described in this policy; email us at [email protected] for any data request.
EU/UK users. If you are in the EU/EEA or the UK, the GDPR / UK GDPR gives you the rights described in Section 8 — email us at [email protected] to exercise any of them. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Acknowledgment
By using ScrollTell, you acknowledge that you have read and understood this Privacy Policy. For questions, contact us at [email protected].