Baseline text pending counsel review
Privacy notice
Last updated 14 September 2026 · version 2026-09-14
This notice explains what CrownVouch stores, why, for how long, who it is shared with, and what rights you have. It covers this website, the CrownVouch application, review-request email sent on behalf of businesses, and the customer feedback pages those emails link to.
1. Who is responsible
- Operator
- Operator legal name not configured
- Contact
- [email protected]
- Postal address
- Operator postal address not configured
Privacy questions and requests: [email protected].
- Business accounts, billing and website enquiries. The operator decides why and how this data is used.
- Customers of a business that uses CrownVouch (the people who receive review requests). For your customers' data, the business decides how it is used and we act on its instructions under the data processing agreement. If you received a review request, the business that sent it is your first contact; we will help it answer you, or forward your request to it.
2. What we store and where it comes from
- Business and user account fields needed to operate the account: names, work email addresses, roles, timezone, business postal address and reply-to address, uploaded logo. Source: you.
- Customer name, email address, a source reference, and suppression state (opt-out, bounce, complaint or erasure). Source: the business, through its own system, a CSV upload, manual entry or the API.
- A transaction identifier and completion timestamp from the business's own system.
- The request lifecycle (scheduled, sent, delivered, submitted, Google handoff, skipped, failed) and the reason for each state.
- First-party private feedback: the rating, any comment, optional contact details a customer chooses to add on a reusable link, and the issue workflow that follows (assignee, deadline, notes, resolution summary). Source: the customer.
- Email provider event identifiers and minimum diagnostic metadata; a hashed IP address and browser identifier on feedback pages for abuse prevention.
- Subscription identifiers, partner attribution identifiers, and the version and time of each legal document you accepted.
- If you sign in with Google: your Google account identifier, email address and whether Google reports it as verified.
3. What we do not store
- Card details. Payments are handled on Polar's hosted pages.
- Full invoice or payment objects from a business's invoicing system.
- Complete webhook bodies after successful processing (failed events keep a short, encrypted diagnostic copy for 7 days).
- Customer postal addresses, payment amounts, line items or tax details.
- Google passwords or copied Google account credentials. We never ask for them.
- Special categories of data. Feedback forms ask for a rating and free text only; please do not include health, financial or similar details.
4. Why we use data
| Purpose | Why |
|---|---|
| Providing the service to a business: accounts, sign-in, sending review requests on its instruction, showing outcomes | Contract: to deliver the service the business signed up for; for customer data, the business's instructions under the DPA |
| Sending a review request and one reminder to a business's customer after a completed transaction | Contract with the business, which asked us to contact the customer about work it completed; every email has an unsubscribe, and the business is responsible for making sure it may contact each recipient |
| Recording private feedback and creating a follow-up issue | Your request: you chose to send feedback, and the business uses it to resolve problems |
| Security, abuse prevention, rate limiting, audit logging | Security: keeping the service and its data safe |
| Billing, tax records, legal acceptance records | Contract and legal requirement: charging for the service and keeping the records the law requires |
| Replying to website enquiries | Your request: you asked us to get in touch |
| Product emails about material changes to terms or the service | Legal requirement and contract: account holders must be told about changes; no marketing without separate consent |
We do not make automated decisions with legal or similarly significant effects. Ratings of 1 to 3 create an internal follow-up task for the business; they never change whether a customer can post a public review.
5. Website enquiries
The setup enquiry form asks for your name, business name, work email address and, optionally, whether you have a Google Business Profile. We also record an allowlisted acquisition source (for example “direct” or a partner code) so we know how you found us. A hidden field catches automated submissions.
Enquiry data is stored once per email address, is readable only by the operator, and is used only to reply to you. It is never imported into a review campaign and never used to enrol you in marketing email; marketing consent is a separate, explicit choice. Unconverted enquiries are deleted after 90 days.
6. Review-request email sent on behalf of businesses
When a business uses CrownVouch, request and reminder emails are sent by us on that business's behalf from an authenticated CrownVouch sending domain, with the business name as the display name and the business's postal address in the footer. A customer receives one request and at most one reminder for a completed transaction, and is not asked again by the same business within 90 days.
Every email has a one-step unsubscribe. Opt-outs, hard bounces and complaints are honoured promptly and suppress future review requests from that business. Marketing content is kept out of review-request email.
7. Customer feedback pages
The pages customers reach from an email use a single-use link that expires after 30 days by default. Those pages send no-store, noindex and no-referrer headers, and contain no third-party session replay, advertising or analytics scripts. The Google link and the private feedback form are independent; private feedback is sent to the business and is never published by us. Google-link activation is recorded as an observed signal only; we do not know whether a review was posted.
9. Retention
| Data | Default retention |
|---|---|
| Website setup enquiries (name, business, work email, profile status, source) | Deleted after 90 days if not converted, unless an ongoing requested conversation needs them |
| Failed webhook diagnostic payload | 7 days, encrypted and access-restricted |
| Integration event metadata | 90 days |
| Email delivery metadata (sent, delivered, bounced, complained) | 12 months |
| Public feedback link token | 30 days active by default (a business may choose 7 to 60), then irreversibly invalidated |
| Unsubscribe token | At least 60 days after the last related email |
| Customer feedback and resolved issues | 24 months |
| Audit logs | 12 months |
| Account sign-in sessions | Up to 14 days, removed 7 days after expiry |
| Legal acceptance records (which version you accepted, when) | For the life of the account plus the period needed to evidence acceptance |
| Suppression records (opt-outs, bounces, complaints, erasures) | Minimal hash and status retained as needed to prevent resending |
| Business data after a subscription ends | 30-day read and export window, then scheduled for deletion 30 days later |
These periods are enforced automatically by a daily maintenance job. When a subscription ends, sending stops and the business keeps read and export access for a 30-day wind-down, after which the business is scheduled for deletion.
11. Logging and analytics
Server logs redact customer email addresses and feedback links. Product analytics, where used, contain no names, email addresses, feedback text or review tokens. Uncertain traffic is labelled rather than attributed. We do not use session replay anywhere on customer-facing pages.
12. Your rights
Depending on the state you live in, you may have the right to:
- know what personal data we hold about you and receive a copy in a portable format;
- correct inaccurate data;
- have your data deleted;
- opt out of review-request email (use the unsubscribe link, which works immediately);
- not be discriminated against for exercising these rights.
If you think we have not handled your data properly, you can complain to the Federal Trade Commission or to your state attorney general.
How to exercise them. Account holders can download their data and delete their account from Account in the dashboard. Business owners can export all business data, and look up, export or erase an individual customer's data, from Settings → Privacy and data; each action is logged. Customers of a business can contact that business directly, or email [email protected]; we will act on the business's instructions or forward the request. We answer within 45 days and may ask you to verify your identity, for example by replying from the address the request concerns.
13. Notice for California and other US states
In the last 12 months we have collected the categories of personal information listed in section 2 (identifiers, commercial information about transactions, and internet activity limited to feedback-page security signals) for the purposes in section 4. We do not sell or share personal information, do not use or disclose sensitive personal information, and do not knowingly collect data from people under 16. Rights to know, delete, correct and to non-discrimination can be exercised as described in section 12; an authorised agent may act for you with written permission.
14. Children
The service is for businesses and is not directed at children. If you believe a child's data reached us, contact us and we will delete it.
15. Security
Every business's data is isolated by database row-level security, secrets and tokens are encrypted or hashed at rest, and access is limited to the roles a business assigns. The full list of technical and organisational measures is on the security page. If a personal-data breach affects you, we will inform the businesses concerned without undue delay and within 48 hours of confirming it, and regulators where state breach-notification laws require.
16. Changes to this notice
We will post changes here with a new version and date. Account holders are asked to acknowledge material changes on their next sign-in and are emailed at least 14 days in advance when the change affects how their data is used.