Privacy Policy

Last updated: 28 August 2026

1. Who we are

Crowdable is an ambassador management platform operated by Crowdable SIA, Ventspils nov., Tārgales pag., Tārgale, "Zelmeņi" - 4, LV-3621, registration number 40203708984. You can reach us about anything on this page at crowdable@crowdable.co.

2. Two different roles we play

This distinction determines who you should contact about your data.

  • We are the data controller for your Crowdable account itself - the details you give us when signing up, and the technical records we keep to run the service securely.
  • We are a data processor for everything a brand does inside its own workspace. When you join a brand as an ambassador, that brand decides what to collect from you and why. We only process it on their instructions. Requests about that data are best directed to the brand, though you are always welcome to contact us and we will route it.

That split is not perfectly clean, and we would rather say so. Some things we decide ourselves rather than on a brand's instruction - closing an account, enforcing our own rules, keeping the security records below, answering a lawful request from an authority. For those we are the controller, whatever data they happen to touch. Which side of the line a particular activity falls on is being settled with counsel; if you are a brand writing your own record of processing activities, ask us rather than copying the two bullets above as though they were the whole picture.

3. What we collect

Account information

Your name and email address, and - if you asked for an account through our waiting list - the brand you told us you were here for. Crowdable has no passwords: you sign in by opening a single-use link we email you, so there is no password for us to store, leak, or ask you to remember.

Profile information

Anything you choose to add to your profile: a photo, a short bio, and - if you connect them - your social media handles, profile URLs, and follower counts for those accounts. All of this is optional and you can remove it at any time from your profile settings.

Technical and security records

When you log in, we record the IP address and browser user-agent attached to your session. We use this to keep you signed in, to let you recognise and end unfamiliar sessions, and to detect abuse. A session expires after 30 days of not being used, and the record of it is deleted a week after that. The week is deliberate rather than an oversight: if you come back from a fortnight away and want to know whether someone else signed in as you, the answer has to still exist. After it, the address and the browser go with the row.

Until recently this said the record was kept until you deleted your account, because that was the truth - nothing swept them. Now something does.

Separately, we count sign-in and signup attempts against your email address and your IP address so that the front door cannot be hammered. Those counters hold the address itself and are deleted 48 hours after they stop being useful as counters, which is long enough that an overnight incident is still answerable the next morning.

Content you create

Campaign submissions, uploaded files and proof images, comments, reactions, and your participation history within a brand's programme.

One thing about uploads is worth knowing before you make one. Images are served from addresses that do not ask who you are - your profile photo, proof images, and a brand's own logos and campaign artwork are fetched by the browser directly from our storage, so anyone holding the address can open it whether or not they have an account. The addresses contain a random identifier and are not listed or guessable, but that is obscurity rather than a lock, so treat an uploaded image as something that could be seen by someone you did not send it to. Support ticket screenshots are the exception: those are served only through a short-lived link minted after we have checked you may see the thread.

Waiting list

New signups are reviewed before being granted access. We record whether and when an account was approved or declined so that the review queue works and so a declined applicant is not re-reviewed indefinitely.

4. Analytics

We use Cloudflare Web Analytics to understand which pages get visited and where visitors arrive from. We chose it for how little it keeps: it sets no cookies, stores nothing on your device, uses no cross-site identifiers and no fingerprinting, and builds no profile of you. It cannot follow you to other websites, and it counts visits rather than people.

This page used to tell you it collected no personal data at all. That was too strong, and we would rather correct it than leave it standing. Like any request your browser makes, the measurement request carries your IP address, and an IP address is personal data. Cloudflare discards it at the data centre nearest you without writing it to logs or databases - so it is received and thrown away rather than never received.

We rely on legitimate interests for this rather than consent: knowing which pages are read is how the site gets better, nothing is stored on your device, no identifier follows you, and the one piece of personal data involved is discarded on arrival. That is a judgement, not a certainty, and you are entitled to disagree with it - see section 10 for how to object. Standard tracker-blocking extensions block it and the site works normally.

5. Cookies

On the pages you sign in to, we use strictly necessary cookies only - the ones that keep you logged in and protect forms against cross-site request forgery. We do not use advertising, marketing, or cross-site tracking cookies anywhere. Blocking essential cookies will prevent you from signing in.

One exception, on our home page only: the "Book a demo" badge is Calendly's, and loading it causes Calendly's own network to set a short-lived cookie of its own for bot protection. It expires in about half an hour and is not ours to read. Until recently that widget loaded on every page of the site, which put that cookie on pages that had nothing to do with booking a call; it is now confined to the home page.

6. Why we are allowed to process this (legal bases)

  • Performance of a contract - account, profile, and campaign data, without which we cannot provide the service you signed up for.
  • Legitimate interests - security records, abuse prevention, and privacy-preserving analytics that help us improve the product. We have weighed these against your rights and consider the impact minimal given how little is collected.
  • Consent - optional profile details and connected social accounts, which you can withdraw at any time by removing them.
  • Legal obligation - where we must retain records to comply with tax, accounting, or other statutory requirements.

7. Who we share data with

We do not sell personal data, and we never have. We share it only with the infrastructure providers needed to run the service:

  • Vercel - application hosting and delivery.
  • Neon - managed database hosting (eu-central-1).
  • Amazon Web Services (S3) - storage for uploaded images and files (eu-north-1).
  • Resend - delivery of every email we send you, including your sign-in links. Receives your name, your email address and the contents of the message. It keeps a copy for 30 days, in the United States. This page previously said 24 hours; that was our error, and the real figure is thirty times longer. Resend offers no European storage option, so a sign-in link sits on US infrastructure for a month.
  • Your browser's push service - Google, Mozilla or Apple, depending on the browser you turned notifications on in. If you enable push notifications, the notification is handed to whichever of them your browser nominated in order to reach your device. Turning push off stops this.
  • Calendly - the "Book a demo" badge on our home page, and only there. Loading it tells Calendly your IP address and browser, and its network sets the cookie described in section 5. Until recently it loaded on every page of the site, signed-in ones included; that was broader than it needed to be and it has been fixed rather than merely disclosed.
  • Cloudflare - aggregate web analytics. Receives your IP address with the measurement request and discards it at the nearest data centre without storing it, as section 4 explains.

One name has left this list. The typeface the site is set in used to be fetched from its foundry's servers on every page, which handed them your IP address for nothing but a font. We now serve the file ourselves, so they no longer see you at all.

We may also disclose data where legally required, or to a successor entity in a merger or acquisition - in which case we will tell you before your data becomes subject to a different policy.

Separately, and by design: the brands whose programmes you join can see your profile, submissions, and participation within their own workspace. Brands cannot see your data in other brands' workspaces.

8. International transfers

The two places your data sits at rest are both in the EU: the database in Frankfurt and uploaded files in Stockholm. Where it is processed is another matter. The application itself runs on servers in Washington, D.C., so every page you load is assembled in the United States from data stored in Europe. An earlier version of this page said we keep your data in the EU and stopped there, which left out the part that does the work.

Email is the other one worth naming plainly: Resend stores message content in the United States, as section 7 says.

We have now been through each provider's agreement rather than assuming. Vercel, Resend, Cloudflare and Calendly are all certified under the EU-US Data Privacy Framework and also carry the European Commission's Standard Contractual Clauses; Amazon Web Services keeps your files in Stockholm and applies the Clauses if anything leaves the EEA. Two honest gaps: we have not yet established that a data processing agreement is in force with our database provider, and we have not confirmed that Cloudflare's has been accepted for our account. Both are being chased, and we would rather tell you they are open than imply they are closed.

Several of these are US companies whose support staff can reach systems from outside the EEA, which can be a transfer even where the storage is not. You can ask us for a copy of the safeguard a given provider relies on and we will send what we hold.

9. How long we keep it

  • Account and profile data - until your account is deleted. There is no button for that yet: write to us and a person does it. See section 10.
  • Session records, including IP and user-agent - 7 days after the session expires, which is itself 30 days after you last used it. A daily job removes them; they no longer wait for the account to be deleted.
  • Sign-in and signup rate-limit counters, including email and IP - 48 hours after they stop being useful as counters.
  • Emails we sent you, at Resend - 30 days, in the United States, and deleted within 90 days if we close our account there. That covers the message itself, so a sign-in link outlives the 30 minutes it works for by about a month.
  • Campaign submissions and content - retained by the brand for as long as their programme runs; removed when the brand deletes them or closes its workspace.
  • Delivery address and sizes, after a brand removes you - the brand's copy stops being usable at the moment they remove you, and an archived copy of it is kept alongside the record of the removal. That copy exists so a removal is answerable rather than silent - so we can tell you what was held and when it stopped being used - and it is not available to the brand's workspace. It goes when your account is erased, or when that brand closes its workspace, whichever comes first.
  • Analytics - retained by Cloudflare in aggregate form only, and not linked to you.

When your account is deleted, we remove your personal data within 30 days, except where we are legally required to keep specific records for longer. One honest limit on that: a submission you made to a brand is both your personal data and that brand's record of work done for it, and what happens to it when you leave is a question we are taking advice on rather than answering two different ways in two documents. Ask us and we will tell you where that stands and which brands still hold submissions of yours.

10. Your rights

Under the GDPR you have the right to access your data, to have inaccurate data corrected, to have it deleted, to restrict or object to how we process it, and to receive it in a portable format. You can also withdraw consent at any time, without affecting processing that already happened.

Write to crowdable@crowdable.co and we will respond within one month. Some of these you can do yourself in the product - editing your profile, removing a social account, deleting a photo. For the rest there is no self-serve button: getting a copy of everything, or having it all deleted, is done by hand by a person here. That is a real answer rather than an automated one, so tell us early if you are working to a deadline of your own.

If you think we have handled your data badly, you can complain to your local data protection authority - we would appreciate the chance to put it right first.

11. Security

Data is encrypted in transit with TLS. There are no passwords at all - you sign in by opening a single-use link we email you, so there is no password for us to store, to lose, or for you to reuse somewhere else. This page previously said passwords were stored as salted hashes, which was left over from an older version of the product and was not true of it; removing that sentence is the reason for this update.

Whether one brand can reach another brand's data is decided on the server rather than by what the screen chooses to show, and the sign-in and signup routes are rate-limited to make guessing expensive. Access to production systems is kept to the people who need it to run the service, though we should be straight with you about what that is and is not: we do not keep a log of who on our side looked at what, so it is a practice rather than something we could prove to you after the fact. We are building that log.

No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.

12. Children

Crowdable is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

If we make a material change, we will update the date at the top and notify account holders by email or in-app before it takes effect.

© 2026 Crowdable. Made around people.