Privacy Policy
Effective June 30, 2026
This Privacy Policy explains how Shotpane(“we”, “us”) collects, uses, and protects information in connection with the Shotpanewebsite, API, and MCP server (together, the “Service”). Shotpane is a developer API that renders a public web URL you supply into a screenshot, PDF, or social/OG image. By using the Service, you agree to this Policy.
1. Scope
This Policy applies to information we process when you visit our marketing site, generate or use an API key, or call our API. It does not apply to the websites you choose to render, which are operated by third parties and governed by their own policies.
2. Information we collect
We collect only what we need to operate the Service:
- Account email. The email address you provide to create an API key.
- API key & usage data. Your issued API key and the metadata we use to authenticate requests and enforce quotas: your plan, your monthly request count, and the current billing period.
- Request metadata. When you call the API we keep a lightweight usage record: the key used, the kind of render (screenshot or PDF), the hostname of the URL you submitted, and a timestamp. We do not store the full submitted URL or any query string.
- Billing data (paid plans only). If you upgrade to a paid plan, payment is handled by Stripe. We store a Stripe customer identifier to associate your subscription with your key. We do not collect or store your card number. Stripe does.
Importantly, the URL you submit is fetched and rendered solely to produce your output. The rendered screenshot, PDF, or OG image is returned to you and is not retained beyond the transient processing needed to fulfill your request.
3. How we use information
We use the information above to:
- issue and authenticate API keys and identify your account;
- meter usage, enforce plan quotas and rate limits, and prevent abuse;
- process payments and manage subscriptions for paid plans;
- provide support and respond to your requests;
- maintain, debug, and secure the Service, and comply with our legal obligations.
4. Cookies & tracking
Our marketing site uses only essential cookies necessary for the site to function. We do not use advertising cookies, and we do not run third-party advertising or cross-site tracking. API access is authenticated by your API key rather than by cookies.
5. Third-party services & sub-processors
We rely on a small number of service providers to operate the Service. Each processes data only as needed to provide its function:
- Stripe: payment processing and subscription management for paid plans.
- Convex: database that stores your account email, API key, and usage/quota metadata.
- Cloudflare: browser-rendering infrastructure used to capture the URLs you submit.
- Vercel: hosting and delivery of the website and API.
These providers act as our sub-processors and are bound by their own terms and privacy commitments. The Service also depends on the availability of the third-party pages you choose to render.
6. How we share information
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share information only with the sub-processors listed above to provide the Service, or where required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the Service.
7. Data retention
We retain your account email, API key, and usage metadata for as long as your account is active and as needed to provide the Service. Lightweight request records are kept for analytics and abuse prevention and may be pruned over time. As noted above, rendered output is not retained after your request is fulfilled. When you ask us to delete your account, we delete the associated data except where we must retain limited records to comply with legal, tax, or accounting obligations.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to opt out of certain processing, for example under the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA). Because we do not sell personal data or use it for cross-context behavioral advertising, there is no such activity to opt out of. To exercise any right, email us at support@shotpane.com and we will respond as required by applicable law. We will not discriminate against you for exercising your rights.
9. Security
We use reasonable technical and organizational measures to protect the information we hold, including access controls and reliance on reputable infrastructure providers. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. Keep your API key confidential and notify us promptly of any unauthorized use.
10. Children’s privacy
The Service is a developer tool intended for businesses and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
11. International users
We are based in, and process information in, the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States and other locations where our sub-processors operate, which may have different data-protection laws than your jurisdiction.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, provide notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
13. Contact
Questions about this Policy or your data? support@shotpane.com.