Privacy Policy &
Data Protection Standards
Our transparent commitment to protecting developer accounts, API telemetry, and rendering data.
Zero Data Brokering
We never sell, lease, or monetize your personal credentials, captured logs, or API queries to advertising networks.
Ephemeral Sandboxing
Target websites are rendered inside single-use isolated containers. No session cookies persist across workers.
256-Bit TLS 1.3 Security
All API requests, dashboard sessions, and database layers are protected with modern encryption and OWASP standards.
Full User Sovereignty
You retain complete ownership of your data with 1-click export and GDPR "Right to be Forgotten" account purging.
01 Information We Collect
PRNT Technologies Inc. collects minimal necessary data required to provision screenshot capture services, manage developer API authentication, and process transaction invoices.
-
Account Credentials: Full name, verified email address, hashed passwords (using bcrypt with work factor 12), and role permissions.
-
API Usage Telemetry: Requested target URLs, capture timestamps, HTTP status codes, output dimensions, and bandwidth consumption for rate limiting.
-
Payment & Billing Data: Processed directly through PCI-DSS Level 1 compliant payment gateways. We never receive or store raw credit card numbers.
02 Ephemeral Screenshot Processing Architecture
When your application requests a screenshot of a target URL, the rendering lifecycle follows strict ephemeral sandboxing:
-
Stateless Chromium Workers: Each capture executes inside an unprivileged Docker sandbox with strict seccomp filters and memory limits.
-
Zero Target State Persistence: Any cookies, localStorage objects, or session states created by the target webpage during rendering are immediately destroyed upon worker teardown.
-
Configurable CDN Storage: Rendered image assets are cached on encrypted edge CDN nodes according to your retention preferences (from instant pass-through to 30 days).
04 Data Retention Schedule & Automatic Purging
PRNT enforces automated lifecycle rules to ensure data is retained only for the duration required by operational necessity or legal compliance:
| Data Category | Retention Period | Purge Mechanism |
|---|---|---|
| Rendered Screenshots | 1 to 30 Days (Per Plan Configuration) | Automated Daily Cron |
| API Capture Logs | 90 Days | Rolling FIFO Deletion |
| Security Audit Trails | 365 Days (OWASP Best Practice) | Encrypted Archive |
| Financial Invoices | 7 Years (Statutory Tax Compliance) | PCI Vault |
05 Your Rights Under GDPR, KVKK & CCPA
Regardless of your geographical residency, PRNT extends worldwide privacy rights to all registered developers and visitors:
-
Right to Access & Portability: Export your complete API usage history, account profile, and billing ledger in structured JSON/CSV formats.
-
Right to Erasure (Right to be Forgotten): Permanently delete your account and all associated cryptographic API keys with immediate effect.
-
Right to Restrict Processing: Revoke active API keys at any time to halt all programmatic rendering and data storage immediately.
06 Technical Security & Infrastructure Hardening
We implement rigorous organizational and technical safeguards designed to preserve data integrity and prevent unauthorized access:
-
Encryption in Transit & Rest: Strict Transport Security (HSTS) with TLS 1.3 for all endpoints. Sensitive database columns and cache stores are encrypted via AES-256.
-
SQL Injection & XSS Immunity: Zero dynamic query string concatenations. 100% of database interactions execute through parameterized PDO prepared statements.
-
Brute-Force & DDoS Mitigation: Multi-layered IP sliding window rate limiters and automatic blocking of suspicious patterns.
07 Data Protection Officer (DPO) Contact
For any inquiries regarding this Privacy Policy, data subject access requests (DSAR), or security disclosures, our dedicated Data Protection Officer is available:
PRNT Global Privacy Office
Direct Email: privacy@prnt.tr • Response Time: Within 24-48 Business Hours