Privacy
Privacy Policy
This policy explains what personal information Cronwick LLC collects, why we collect it, who we share it with, and how you can ask us to act on it.
Last updated
Who we are
Cronwick LLC is a Wyoming limited liability company, in the United States. For privacy laws that use the term, we are the controller of personal information described in this policy. Contact us at contact@cronwick.com.
Scope
This policy covers cronwick.com and the software and SaaS we sell under the Cronwick name. It does not cover sites or services we do not control, including Stripe’s own websites. Those have their own policies.
Information we collect
We collect the following categories, depending on what you do:
- Identity and contact. Your name and email address when you write to us, create an account, or check out.
- Billing. Stripe processes the payment. We store a Stripe customer identifier, subscription or invoice status, the amount, the currency, the card brand, the last four digits, and a billing country. Your full card number and card security code are processed by Stripe and are not stored by Cronwick.
- Account and product data. If a product has an account, we store the login email and, if you set a password, a salted hash of that password. We cannot read the password back. We also store the content you submit and the usage records needed to run the product, such as a seat count or a feature you turned on.
- Correspondence. The messages you send to contact@cronwick.com, and our replies.
- Technical logs. IP address, user agent, date and time, the URL requested, and a status code. We use these for security and to keep the service working.
We do not seek government identification numbers, precise geolocation, biometric data, or information about your health. Please do not send us those.
How we use it
We use personal information to:
- provide the software or subscription you buy;
- take payment, issue receipts, and keep tax records;
- answer your messages and handle refunds and privacy requests;
- authenticate you and protect accounts;
- detect fraud, abuse, and security incidents;
- comply with law; and
- understand, in aggregate, whether the service is working, without selling that information or using it for advertising.
Legal bases
If the GDPR or UK GDPR applies, we rely on these bases:
- Contract. To provide the product you asked for and to bill for it, and to send transactional messages about that purchase.
- Legitimate interests. To keep logs for security, prevent fraud, and fix the service, where those interests are not overridden by your rights.
- Legal obligation. To keep records tax and accounting law requires.
- Consent. Only if we ever send optional marketing email. We do not send marketing unless you ask for it. You can withdraw consent at any time.
Stripe and other processors
Stripe, Inc. and its affiliates process payments for us. Stripe collects payment details directly under its own privacy policy: stripe.com/privacy. We use the limited billing data Stripe shares with us, as described above.
We also use infrastructure providers to host this website, our products, and the mailbox for contact@cronwick.com. They process personal information only on our instructions, for those purposes. We do not authorize them to use it for their own advertising.
How long we keep it
- Account data: for the life of the account, then deleted or de-identified within 30 days after a verified deletion request, except records we must keep.
- Billing and tax records: for seven years after the relevant transaction, or longer if the law requires.
- Security logs: about 90 days, unless we need a log for an incident.
- Support email: about 24 months after the last message in the thread.
We may keep a record of a request you made under this policy so we can show that we handled it.
International transfers
We are in the United States. If you are elsewhere, your information is processed in the United States, where privacy laws may differ from the laws where you live. Where the GDPR or UK GDPR requires a transfer tool, we use an appropriate safeguard, such as the Standard Contractual Clauses, with supplementary measures if needed.
If you are in the European Economic Area or the United Kingdom, you may contact us at contact@cronwick.com to exercise your rights. Where the law requires us to appoint a representative, we will publish that person’s contact details on this page.
Security
We serve this website over HTTPS. We limit access to personal information to people who need it to operate the company, and we expect our processors to protect it. No method of transmission or storage is perfectly secure. If we learn of a breach that the law requires us to report, we will notify the people and authorities the law names.
Children
The Services are not directed to anyone under 16. We do not knowingly collect personal information from anyone under 16. If you believe we have, email contact@cronwick.com and we will delete it.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, to withdraw consent, and to lodge a complaint with a supervisory authority. California residents also have the right to know, delete, and correct personal information, and the right not to be discriminated against for exercising those rights.
Send requests to contact@cronwick.com. We will verify the request by confirming you control the email address on the account or the receipt. You may use an authorized agent where the law allows. We may ask the agent for proof of permission and we may confirm the request with you directly.
We aim to respond within 30 days under the GDPR and UK GDPR, and within 45 days under the CCPA/CPRA. Where the law allows an extension, we will tell you why. We will not discriminate against you for making a request. If we deny a request, we will explain the reason and how to appeal, where an appeal is required.
You may complain to your local data protection authority. In the United Kingdom, that is the Information Commissioner’s Office. We would like the chance to help first.
Marketing
We do not send marketing email unless you ask us to. Transactional messages about a purchase, a renewal, a failed payment, or a change to these policies are part of providing the service, not marketing. You can tell us to stop marketing at any time by emailing contact@cronwick.com.
Sale, sharing, and tracking
We do not sell personal information, as “sell” is defined by the CCPA/CPRA. We do not share it for cross-context behavioral advertising. We do not use sensitive personal information for purposes that would require a “limit the use” link. We do not respond to browser “Do Not Track” signals because this site does not track you across other sites. If that changes, we will update this policy and ask first where the law requires it.
Changes
We may update this policy. The date at the top of the page will change. If a change is material, we will post a notice on this page and, if you are a customer, email the address on your account.
Contact
Privacy requests and questions go to contact@cronwick.com. We aim to reply within two business days. Cronwick LLC, a Wyoming limited liability company.