Last updated: May 1, 2025

Privacy Policy for Service Users

Private Captcha (“Service”) is a solution by Intmaker OÜ (“we”, “us”, “our”) to protect our customer’s websites against automated programs and scripts (“bots”) in a privacy-friendly way. This solution includes client-side protection (“widget”) that customers integrate into their websites and server-side validation services.

When providing protection solution, we act as a processor under Art. 4(8) GDPR. Our customer, who acts as the controller under Art. 4(7) GDPR, is responsible for complying with the privacy obligations for the websites, where the Service is used. For our Service users, we act as a data controller under Art. 4(7) GDPR.

This privacy policy only applies to the Service users and visitors of websites on the domain and all subdomains of Private Captcha.

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

Data we collect

Registration data

When you register an account with us, we collect and process personal data from you as your registration data. This information includes your email and your name. You can delete your user account with us from account settings in the Service portal. The legal basis for this data processing is Article 6(1)(f) (legitimate interests) of the GDPR.

Payment data

We do not collect or store your payment data. Instead, you disclose this information to our payment provider of choice Paddle and this is subject to Paddle’s Privacy Policy.

Email addresses

We use the email address you used when creating an account only for Service functionality, such as logging in or critical account updates. We do not send marketing emails without your permission. Emails are sent using Transaction Email service provided by Scaleway SAS and this is a subject to their privacy policy.

Usage data

Website usage data

On our websites, we use the open-source web analytics software Plausible, self-hosted on our servers. Plausible does not use cookies or store any personally identifiable information. We do not sell, rent, or otherwise make this data available to third parties, except as necessary to make Plausible work, as required by law, or to protect our rights and property.

Server usage data

Whenever you visit or use our Service portal, we automatically collect the standard data provided by your web browser. This may include your IP address, type and version of the browser you use, time and date of the visit, page visited and other technical data. This data is used for monitoring the Service security and performance, and addressing technical issues. The legal basis for this data process is Article 6(1)(f) (legitimate interests) of the GDPR.

Cookies and other tracking data

We use only strictly necessary functional cookies on our Service portal that are required to provide you access to your account. We do not use other types of cookies (such as tracking, performance or personalization cookies).

Web pages with integration to our payment provider of choice Paddle may use additional cookies which is a subject to Paddle’s Privacy Policy.

We collect and process data only if we have a legal basis for doing so. The legal basis depends on the Personal Data we collect and the specific context in which we collect it.

  • if the processing is necessary for the fulfilment of a contract to which you are a party or for the implementation of pre-contractual measures;
  • if processing is based on legitimate interests and these interests are not overridden by your data protection interests;
  • if you give us your consent to process personal data for a specific reason;
  • if such processing is required to comply with a legal obligation.

If the data processing by us is based on your consent, you have the right to withdraw your consent at any time. We don’t keep personal data for longer than is necessary to provide our service or than required by law. We strive to protect stored data using commercially reasonable efforts to prevent unauthorized access, misuse or modification, however, we cannot guarantee its absolute security.

Data handling

How we use the data and for what purpose

We save and use your personal data only to process your orders and to provide and maintain our Service. The latter involves, but is not limited to, security, diagnostics, customer support, monitoring, and administrative purposes.

With whom the data is disclosed

We do not sell, rent, or otherwise make this data available to third parties, except as necessary to provide the Service or as required by law. These service providers are required to comply with GDPR by the contracts we have with them. We may also disclose any retained data if required by law or to protect our rights and property.

Subprocessors:

Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Data controller is: Intmaker OÜ Address: Pärnu mnt 139b, 11317, Tallinn, Estonia Email: inquiries@privatecaptcha.com

Protect your forms and APIs from abuse

Independent, privacy-first, self-hostable CAPTCHA service made in EU