Privacy Policy
This notice explains how CrowdSafe Group, LLC handles account, service, support and event data in CrowdSafeData.
Effective August 16, 2026 · Version 1.11. Scope and roles
This Policy covers CrowdSafeData websites, accounts, subscriptions and support. For account, billing, security and website information, CrowdSafe generally acts as a business or controller. For event or venue data uploaded by a customer, CrowdSafe generally acts as a service provider or processor under the customer’s instructions.
2. Information we collect
- Account identity, including sign-in email and optional display name supplied through the authentication service.
- Organization, membership, role, subscription, billing-status and invitation records.
- Authorized event, access, crowd, location, concession and operational data uploaded by customers.
- Mappings, findings, importance settings, reports, source fingerprints and audit activity.
- Support communications, service diagnostics and security events.
- Privacy-preserving website and product telemetry, including event type, date, coarse country, device class, referral channel and pseudonymous visitor or account tokens.
3. How we use information
We use information to provide and secure the service; isolate organizations; process authorized analytical instructions; manage subscriptions and support; maintain audit and recovery records; detect abuse; improve reliability; and comply with law. We do not sell personal information or use customer event data for cross-context behavioral advertising.
4. Legal bases
Where applicable, processing is based on performance of a contract, legitimate interests in providing and securing a professional service, compliance with law, consent where requested, and the customer’s documented instructions for customer-controlled data.
5. Sharing and subprocessors
Information may be processed by infrastructure, authentication, storage, security, billing and support providers necessary to operate CrowdSafeData; professional advisers bound by confidentiality; and authorities where legally required. OpenAI Sites and Cloudflare services support site delivery, the hosted runtime and protected storage. Google Firebase provides authentication. PayPal or Stripe processes billing only when the applicable method is activated. Customer data is not disclosed to unrelated advertisers.
6. International transfers
CrowdSafeData is operated from the United States and may process information in other locations used by service providers. Where required, the parties may use approved transfer mechanisms, including the European Commission’s Standard Contractual Clauses, together with appropriate supplementary measures.
7. Website and product analytics
We measure acquisition, authentication, uploads, completed analyses, findings use, failures and apparent crawler or scanner traffic to operate the beta and improve reliability. Daily visitor tokens are created with a one-way keyed hash and rotate each day; account activity uses a separate pseudonymous token. The analytics store does not retain raw IP addresses, full user-agent strings, email addresses, uploaded filenames, uploaded records or free-form URLs. Telemetry is used in aggregate for product operations, not advertising profiles.
8. Retention and deletion
Data is kept only for operational, contractual, security and legal purposes under the published Retention Policy and organization settings. Raw pseudonymous product telemetry is scheduled for deletion after 90 days; aggregate operational reports may be retained without the underlying visitor or account tokens. Customers should export needed results before deletion or termination. Backups expire on a separate controlled schedule.
9. Security
Controls include authenticated access, organization scoping, role checks, protected object storage, server-side source fingerprints, audit events, security headers, bounded uploads and recovery snapshots. Customers should not upload unnecessary direct identifiers and must promptly report suspected unauthorized access.
10. Privacy choices and rights
Depending on location, individuals may request access, correction, deletion, portability, restriction or objection, and may appeal or complain to a regulator. CrowdSafe does not sell or share personal information for targeted advertising. Account users can submit a privacy request through Support; DPA and Standard Contractual Clause requests use the same documented request path. Requests about customer-uploaded event data should normally be directed to the customer controlling that data. We verify only the information reasonably necessary to process a request.
11. Children and changes
The service is intended for organizations and professional users, not children. We do not knowingly collect children’s personal information through public registration. We may update this Policy prospectively and will identify the effective date and material changes.