Data & removal
Effective
runsonwhat shows which software tools companies use, with the public evidence behind every match. This page explains what we collect about companies, where it comes from, why we think that’s fair, and how to get a company removed. For data about you as a visitor, see the Privacy Policy.
What we collect about companies
DNS records
Public TXT, SPF, MX, NS, DMARC, CAA and A records, a short list of common DKIM selectors, and where common subdomains point (CNAME).
Certificate logs
Certificate Transparency logs, which publicly record every HTTPS certificate. We read them ourselves and through Merklemap, plus crt.sh, CertSpotter, HackerTarget and RapidDNS for live lookups.
Website code
The homepage, response headers, the scripts it loads, its tag-manager container and public Segment settings: the same files any browser downloads.
Public config files
robots.txt, security.txt, llms.txt, ads.txt and app-ads.txt, and OpenID discovery documents on the site and its sign-in hosts.
Subprocessor lists
A company's own subprocessor or DPA page, and only when its homepage links to it. We don't guess URLs.
Company profile facts
Name, industry, size, country and city, founding year, a short description, and links to official profiles such as LinkedIn. From Wikidata, the Y Combinator directory, People Data Labs' free company dataset, and the company's own homepage and schema.org markup.
From these we work out which tools a company appears to use, when we first saw each one, and when one seems to have been dropped. We find company domains in public lists: website rankings (Tranco, Cisco Umbrella, Majestic, Chrome UX Report), the Y Combinator directory, Show HN launches, Wikidata, People Data Labs’ free dataset, links on homepages we scan, and new certificates.
What we don’t collect
- Personal data about people at these companies. We don’t collect employee names, email addresses, phone numbers or personal profiles.
- Anything from LinkedIn itself. We don’t scrape LinkedIn; a company’s LinkedIn link comes from the sources above.
- Anything behind a login or not meant to be public. We never sign in, submit forms or guess passwords, and we don’t store copies of the pages we read.
How we collect it
Our batch crawler identifies itself as runsonwhat-bot/1.0, obeys robots.txt (a blocked site gets public DNS lookups only), follows only links from the homepage, and visits each site about once a month. DNS records are rechecked weekly, without touching the website. The bot page has the details.
When someone types a domain into Look up a site, we fetch that site once on their behalf, the way a browser would. That result is shown to them and kept in memory for about 30 minutes; it isn’t added to our database.
Why we think this is fair
This is business-to-business information: which products an organization has chosen, drawn from records the company itself publishes so that browsers, mail servers and vendors can work. Information about a company is generally not personal data. Where it could relate to a person, for example a sole trader whose business uses their own name, we rely on our legitimate interest in describing the software market (GDPR Art. 6(1)(f)). We think the impact is low: the data is already public, it’s about business tools, we show the evidence for every match, and removal is one email. If you object, we’ll stop.
Accuracy
Matches are inferred automatically, so some will be wrong or out of date: a DNS record can outlive the tool, or a script can be loaded but unused. Every match links to its evidence so you can check it. If you see a mistake, email hello@runsonwhat.com with the domain and the tool, and we’ll fix it.
Getting a company removed
Email hello@runsonwhat.com with the domain. Please write from an address at that domain, or otherwise show you can speak for the company. We will:
- stop scanning the domain, for good;
- remove it from every company list on the site;
- delete the tool matches and other data we hold about it, keeping only the domain name on a do-not-scan list so it isn’t added again.
We usually do this within a few days and reply when it’s done. One thing removal can’t stop: anyone can still type the domain into the live lookup, which reads public records at that moment and doesn’t store the result.
To stop only the website reads, add this to your robots.txt. Our crawler will then read public DNS records only. This doesn’t delete data we already have; email us for that.
User-agent: runsonwhat Disallow: /
Deleting your account
If you signed in to runsonwhat and want your account gone, email hello@runsonwhat.com from the address you sign in with. We delete it within 30 days and confirm by email. The Privacy Policy explains what that removes.
Contact
Anything else about our data: hello@runsonwhat.com.