Privacy Policy
Effective: 2026-07-11 · Version: 0.2.0
This Privacy Policy explains what personal data Crumpert collects, why we collect it, and what your rights are. It applies to the crumpert.com website and our iOS and Android apps alike. It's written to satisfy the UK GDPR, the EU GDPR, and the California Consumer Privacy Act (CCPA) at once, and follows the ICO's "fair processing" guidance.
1. Who we are
Crumpert Limited (company number 17307057, England and Wales; registered office 16 Pennant Apartments, Devan Grove, London N4 2UZ) ("we", "us") is the data controller for personal data you provide to us through the Service.
- Contact: privacy@crumpert.com
- UK ICO registration: ZC196250 (registered 12 July 2026)
- EU representative (Art. 27 GDPR): pending — see §11
2. Data we collect
When you create an account
- Email address (required)
- Name and avatar (from Google if you sign in with Google; otherwise optional)
- An IP address and basic device info at sign-in time (for fraud prevention and audit logs)
When you publish (creators)
- Handle, display name, specialty, bio, plan prices and trial settings, compliance acknowledgement
- Posts, comments, trade entries, and community-chat messages you create
- Verified track-record data (call entry/exit prices captured from market data, timestamps, computed returns)
- Stripe Connect account ID and payout-related metadata
- Aggregate audience analytics (subscriber counts split paid/trial, profile-view counts deduplicated per viewer per day)
- Tax forms (W-9 / W-8BEN) handled directly by Stripe; we receive only a status flag
When you read
- Subscriptions (free and paid) and billing status; payment itself is handled by Stripe (see §4)
- Likes, reposts, comments, and community-chat messages
- Direct messages you exchange with creators (stored so both sides can read the thread; not end-to-end encrypted)
- Pages you visit while signed in (for the "Live Feed" and personalised recommendations)
- Strictly-necessary session cookies
- Your recent searches are stored on your device only — they never reach our servers
In the mobile apps
- A push-notification device token if you enable notifications (used only to deliver notifications to your device; deleted when you sign out or the platform reports the token dead)
- The app loads the same website, so the categories above are identical in the apps; we collect no additional device identifiers, advertising IDs, or location data
When you contact us
- The contents of your emails or messages, and any attachments
We do not collect
- Card details (handled by Stripe)
- Sensitive data (health, biometric, political opinion) — please don't post any
- Children's data — the Service is for users 18+
3. Why we use it (lawful bases under UK/EU GDPR)
| Purpose | Lawful basis |
|---|---|
| Provide the Service (auth, posts, comments, messages, subscriptions) | Contract |
| Stripe payments and payouts | Contract |
| Send transactional emails (sign-in link, receipts, new-post and comment notifications) | Contract |
| Send push notifications you've enabled (new posts from creators you subscribe to) | Contract |
| Send marketing emails (only if you opt in) | Consent |
| Fraud prevention, security, abuse detection | Legitimate interest |
| Aggregate creator analytics (view counts, subscriber growth) | Legitimate interest |
| Comply with legal obligations (tax, takedown notices) | Legal obligation |
| Anonymous analytics if you accept cookies | Consent |
You can withdraw consent at any time (see §6).
4. Who we share data with
We use the following processors under data processing agreements. Each handles your data only on our instructions.
| Processor | What for | Where |
|---|---|---|
| Neon | Postgres database | EU (Frankfurt or Dublin) |
| Vercel | App hosting, serverless functions | EU (London or Frankfurt) |
| Cloudflare R2 | Image hosting | Cloudflare's global network |
| Resend | Transactional + magic-link email | US (sub-processed; standard contractual clauses) |
| Sign-in (only if you choose Google OAuth) | US | |
| Stripe | Subscription payments and creator payouts | US / EU (Stripe routes to local entity) |
| Apple (APNs) | Delivering push notifications to iOS devices (receives your device token) | US |
| Sentry | Error monitoring (no PII by default; we scrub user data from error reports) | US (standard contractual clauses) |
| Alpaca / Stooq | Stock price lookups (we send ticker symbols, not user data) | US |
We do not sell your personal data. We don't share it with anyone except processors, regulators when legally required, and acquirers in the event of a corporate sale (you'll be notified).
5. International transfers
Crumpert is based in the UK. Some of our processors are in the US. We rely on the UK Addendum to the EU Standard Contractual Clauses (or the EU SCCs directly) plus supplementary measures (Stripe and Resend operate under SCCs; Sentry has an EU data residency plan available if you require it).
6. Your rights
You can exercise any of these by emailing privacy@crumpert.com. We respond within 30 days.
- Access: a copy of the personal data we hold about you
- Rectification: fix inaccuracies
- Erasure: delete your account and personal data (subject to retention obligations — see §8)
- Restriction: stop processing while a complaint is being resolved
- Portability: receive your posts and account data in JSON
- Object: to processing based on legitimate interest, or to direct marketing at any time
- Withdraw consent: for non-essential cookies or marketing emails
If you live in the UK, you can complain to the ICO. If you live in the EU, complain to your local data protection authority. If you live in California, you also have rights under CCPA — same email address.
7. Cookies and similar technologies
We use the minimum cookies necessary:
- Auth session cookie (strictly necessary; can't be disabled without breaking sign-in)
- Cookie-consent state — stored in
localStorage, not a cookie, but tracked similarly
If we add analytics or advertising cookies later, they'll be off by default and only set after explicit consent via the banner.
8. Retention
- Account data: kept while your account is active. Deleted within 30 days of account closure, except where we need to retain it longer for legal obligations (e.g. financial records: 6 years for HMRC).
- Posts and comments: kept while published. Deletion is propagated to processors within 30 days.
- Sign-in logs and audit trails: 12 months.
- Push-notification device tokens: until you sign out, disable notifications, or the platform reports the token invalid.
- Error reports (Sentry): 90 days.
9. Security
We use TLS in transit, encryption-at-rest on the database, principle-of-least-privilege access controls, and audit logging. No system is perfectly secure; if you become aware of a vulnerability please email security@crumpert.com.
10. Children
Crumpert is not for users under 18. We don't knowingly collect data from anyone under 18. If you believe a minor has signed up, email privacy@crumpert.com and we'll delete the account.
11. Regulatory registrations
- UK ICO registration: Crumpert Limited is registered with the Information Commissioner's Office under reference ZC196250 (registered 12 July 2026; renewed annually). You can verify this on the ICO register.
Still to be completed:
- EU Article 27 representative: required because the UK is outside the EU. Appoint a provider (rep.eu, EDPO) — €500–700/year.
12. Changes
We may update this Policy. Material changes are notified by email or in-product banner at least 14 days before they take effect.