Skip to content

What does Crate do with my data?

Crate collects the account details you give us, the store data you create, and the technical data needed to run and secure the service. For your own account Crate is the controller. For the buyer data in your store Crate is a processor acting on your instructions, under the data processing addendum. Crate does not sell personal information and does not share it for cross-context behavioral advertising, as California law defines those terms. Personal information goes only to the service providers that run Crate, to the partners you connect, and where the law requires. Anybody, anywhere, can ask for access, correction, deletion or a portable copy, and Crate answers within 30 days. A jurisdiction annex names the law, the regulator and the complaint route where you live.

Who we are

Crate is a commerce platform that businesses use to sell on their own store, on social channels and in messaging apps, and to manage products, orders, customers and payments from one dashboard.

This policy explains what personal information Crate handles, why, who it goes to, how long it is kept and what you can ask us to do about it. It covers the Crate marketing site, the Crate dashboard and the storefronts Crate hosts for merchants.

The two roles Crate plays, and why it matters to you

Crate handles two different kinds of personal information and the rules differ for each. For a merchant's own account data, meaning your name, your login, your billing details and how you use the dashboard, Crate decides why and how it is processed. Crate is the controller and this policy governs it.

For the data inside a merchant's store, meaning their buyers' names, addresses and order histories, the merchant decides and Crate acts on their instructions. Crate is a processor and the merchant is the controller. If you bought something from a store running on Crate, the store owner is who you ask first and their own privacy policy applies to what they do with your order.

Read the data processing addendum

What we collect

Identifiers and contact details, meaning the name, business name, email address and phone number you give us when you create an account or contact us.

Commercial information, meaning your plan, your billing records, and the products, orders and customers you create inside Crate.

Internet and device activity, meaning log data, IP address, browser and device type, pages viewed and actions taken, collected to run, secure and improve the service.

Payment information, meaning the payment provider's reference for a transaction, the amount, the currency and the result. Card numbers are captured by the payment provider and never reach Crate in a form Crate could store.

Communications, meaning the support messages, emails and forms you send us and our replies.

Crate does not collect biometric information or precise geolocation, and does not ask you for information about your race, religion, health, sexual orientation, union membership or immigration status.

How we use it

To provide the service, which includes creating and running your store, processing orders and payments, and sending the transactional email a sale requires.

To bill you, to prevent fraud and abuse, to keep the platform secure, and to investigate a problem you or another merchant reports.

To support you, which sometimes means a support engineer viewing your store with time-limited access that is logged and visible in your own activity log.

To improve the product, using aggregated and de-identified usage data wherever the question can be answered that way.

To send product and marketing email where you have opted in. Every one of those carries an unsubscribe link that works on the first click, and unsubscribing never affects the transactional email your account needs.

Selling and sharing

Crate does not sell personal information and does not share it for cross-context behavioral advertising, as the California Consumer Privacy Act defines those terms. Crate has not done so in the preceding twelve months.

Crate does not use merchant or buyer personal information to train third party models, and does not sell store data to anybody.

The right to opt out exists whether or not there is anything to opt out of, so the mechanism is published and it works. Crate also honors Global Privacy Control, in every country rather than only where a law demands it.

Sensitive personal information, as California defines it, is a category Crate almost entirely avoids: no government identifiers, no precise geolocation, no racial or ethnic origin, no religious belief, no union membership, no health, sex life or sexual orientation, and Crate does not read the contents of your mail or messages. The one category Crate does hold is your account log-in and password, used to sign you in and keep the account secure, which are uses the statute permits without an opt out and which Crate never uses to infer anything about you.

Who we share it with

Service providers that run parts of Crate, which are hosting and database infrastructure, object storage for product and media files, and email delivery. Each is bound by written terms and may use the data only to deliver its service to us. Every one of them is named on the subprocessor page, with what it does and the country it does it in.

The payment providers and delivery partners a merchant chooses to connect, and only the data those services need to take a payment or move a parcel.

A buyer or an acquirer, if Crate is ever part of a merger or a sale, under confidentiality and with notice posted here before your data becomes subject to a different policy.

Law enforcement or a court, where the law requires it. We check that a demand is valid, we give it no more than it actually asks for, and we tell the affected customer unless we are legally prohibited from doing so.

See the named list of subprocessors

Your privacy rights

Wherever you live, you can ask us to confirm whether we process personal information about you and to give you access to it, to correct it if it is wrong, to delete it, or to hand you a portable copy in a machine readable format. You can also ask us to stop using it for targeted advertising, and that is a request Crate can honor immediately because Crate does not do it.

Crate honors the same requests from everybody, in every country. Splitting the product into people with rights and people without them is not a line we want to draw. Which law names your rights, which regulator supervises them and where you complain if our answer is wrong does depend on where you live, and the jurisdiction annexes at the foot of this page set that out, with the one crate believes is yours placed first.

Exercising a right never costs you anything and never degrades the service you get. We respond within 30 days, everywhere, and will tell you inside those 30 days if we need a single extension and why. Thirty days is not the deadline any one of these laws sets. It is shorter than California allows and it clears the month the European, British and Nigerian rules give us, and one number we can always keep is easier to operate than five numbers keyed on a guess about where you live.

An authorized agent may make a request for you if they give us written proof that you authorized them. If we refuse a request we will tell you why, and you can appeal by replying to that message. An appeal is decided by somebody who was not involved in the original decision, within 30 days. Several US state laws require that appeal and Crate gives it to everybody rather than checking your address first. If we refuse the appeal we will name the regulator you can take it to, which is the one for the place you live and is listed in the annex for your jurisdiction.

If your personal information sits inside a merchant's store rather than in your own Crate account, send the request to that merchant. Crate will pass it on and help them act on it, but Crate cannot decide it for them.

How to make a request

Email [email protected] from the address on the account, or use the contact form, and say which right you are exercising. We verify identity in proportion to the request: a copy of your own data needs more proof than an unsubscribe.

Those are two designated methods, which is the minimum California requires, and neither of them asks you to create an account to use it.

Merchants can also access, correct and export most of their own data directly from the Crate dashboard without asking anybody.

Cookies and tracking

Crate uses cookies to keep you signed in, to remember a cart, to measure how the site is used, and, where you have consented, for marketing. The cookie notice lists every cookie by name and purpose, and your choices can be changed at any time from that page.

Crate honors Global Privacy Control. A browser sending that signal is treated as an opt out of any sale or sharing of personal information, for that browser, and for the account as well if you are signed in.

Read the cookie notice

How long we keep it

Account and store data is kept while your account is open, because that is what makes the service work. After you close an account, the personal information Crate processes for you is deleted within 90 days.

Per category, because a single global period is not a retention disclosure. Account and contact details, and the products, orders and customers you create, are kept while the account is open and deleted within 90 days of closing it. Billing and invoice records are kept for as long as tax law requires, which is commonly six or seven years and is the one period Crate cannot shorten. Support conversations are kept for two years so a later problem can be traced back. Server and security logs are kept for 90 days. Marketing consent records are kept for as long as the consent stands plus two years, because a consent nobody can evidence is a consent that did not happen.

The exception is a record the law requires us to keep, such as an invoice or a tax record, and in that case only the record the law names is kept and only for as long as it requires.

Crate does not currently keep an off-site backup, so a deletion reaches every copy of your data at once. When off-site backups are in place this paragraph will say how long a deletion takes to reach them, and the security page tracks that work in the open.

How we protect it

Data is encrypted in transit with TLS. Payment provider keys, outbound mail credentials, sending-domain signing keys and integration tokens are encrypted at the application layer with AES-256-GCM, and passwords are hashed, so a stolen database copy does not hand over usable credentials. The underlying disk is not encrypted at the volume level today, and the security page says so rather than leaving you to assume otherwise.

Every record belongs to a store and every query is scoped to a store before it runs, so one merchant cannot reach another merchant's data. Access to production data is limited to staff whose work requires it, requires multi-factor authentication, and is logged.

Read the security page

If there is a breach

There has not been a breach of Crate. This section says what happens if there is one, because a commitment written after the event is worth nothing and a policy that does not name the commitment is not answering the question.

Two different obligations sit behind one event, and Crate keeps both. Where the data breached is a merchant's own account data, Crate is the controller and Crate notifies the regulator and the people affected itself. Where the data breached is a merchant's buyer data, the merchant is the controller and Crate is the processor, so Crate tells the merchant and the merchant decides what goes to their regulator and their customers. The data processing addendum commits Crate to telling a merchant within 72 hours of becoming aware, which is stricter than European law requires of a processor.

As controller, Crate reports a breach to the supervisory authority within 72 hours of becoming aware of it wherever a 72 hour deadline exists, which covers the European Economic Area, the United Kingdom and Nigeria. Where the law sets no clock, which is the position in most of the United States, Crate reports in the most expedient time possible and without unreasonable delay, which is the standard those statutes actually use. Canada is reported as soon as feasible where there is a real risk of significant harm. Crate does not wait for the slowest deadline that applies to it.

Crate tells you directly, without undue delay, where a breach is likely to put you at high risk. That notice says what happened, when, which categories of information were involved, what Crate has done about it, what you can do, and who to contact for more. It goes out in plain language rather than a legal notice you have to decode, and it is not delayed while the wording is polished.

Crate keeps a record of every breach, including one small enough that no regulator has to hear about it, with what happened, its effects and what was done. Canadian law makes that record mandatory and requires it to be kept for two years, so two years is the floor Crate applies to every breach record everywhere rather than only to Canadian ones.

If a breach affects more than 500 residents of California, a sample copy of the notice also goes to the California Attorney General, which that state requires and which Crate does whether or not it is asked.

Read the security page

Where the data is

Crate runs on infrastructure in the United Kingdom and personal information is processed there. Email delivery is processed in France and payment processing happens wherever the provider a merchant connects operates. If you are outside those places, using Crate means your information is transferred to and processed in them, where privacy law may differ from your own.

Where a transfer needs a legal mechanism, Crate relies on the standard contractual clauses or the equivalent mechanism recognized in your jurisdiction, incorporated by reference into the signed data processing addendum.

Children

Crate is a business tool, is not directed at children and does not knowingly collect the personal information of a minor as the law of your own country defines one. That threshold is under 18 in Nigeria, under 13 in the United States for federal purposes with a further opt in required between 13 and 16 in California, and between 13 and 16 across the European Economic Area depending on the member state. Crate does not sell or share the personal information of anybody under 16 in any circumstances, and does not sell or share the personal information of anybody else either. If you believe a child has given us information, email [email protected] and we will delete it.

Changes to this policy

We update this policy as the product changes and post the new date at the top of this page. Where a change materially reduces your rights we will tell account holders by email before it takes effect, rather than relying on you to notice a date.

Contact

Email [email protected] with anything about this policy, including a request under any of the rights above.

The registered name and address of the company responsible for this personal information are being finalized and will be published here before Crate leaves free trial. Until then, [email protected] reaches the people who are actually accountable for it.

By jurisdiction

Your rights where you live

Everything above applies to everybody. Crate honors access, correction, deletion and a portable copy for every person who asks, in every country, and answers within 30 days worldwide. The annexes below do not add or remove a right. They name the law, the regulator, the deadline and the complaint route that apply where you live, so you can check our answer against your own rules rather than take our word for it.

Crate has put the United States annex first because that is the market this site is currently showing you. It is a guess from your connection and it changes nothing. Every annex below is on this page for every visitor, and you can read and rely on whichever one is actually yours.

United States

Where we think you are

You live in California, or in one of the other states that has passed a comprehensive privacy law.

The law
The California Consumer Privacy Act as amended by the California Privacy Rights Act, plus the comprehensive privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Nebraska, New Hampshire and New Jersey.
The regulator
The California Privacy Protection Agency and the California Attorney General, or the attorney general of the state you live in.
California Privacy Protection Agency
Our answer time
30 days, which is shorter than the 45 days California allows, and it is the same 30 days crate promises everywhere else.
If you are not satisfied
Reply to our answer and an appeal is decided by somebody who was not part of the first decision. If that answer is still wrong, complain to the California Privacy Protection Agency, the California Attorney General or your own state attorney general. None of them charges you and none of them needs our permission.

California does not work through lawful bases the way European law does. What does the same job is the notice at collection, which is the What we collect and How we use it sections above, read together with the retention period stated in each. Those sections are the notice, they are on this page before you give us anything, and there is no second version of them behind a form.

You can ask us to confirm whether we hold personal information about you, to hand you the specific pieces we hold and not only the categories, to correct anything that is wrong, to delete it, and to give you a portable copy in a format another service can read. You can ask us to stop using it for targeted advertising, which is a request we can honor the moment it arrives because crate does not do targeted advertising at all.

Crate does not sell personal information and does not share it for cross-context behavioral advertising, using those two terms exactly as the CCPA defines them, which is broader than an exchange for money. Crate has not done either in the preceding twelve months and has no plan to start. The opt-out right still exists whether or not there is anything to opt out of, so the mechanism to exercise it is published and works, and Global Privacy Control is honored on every crate page in every country.

Sensitive personal information, as California defines it, is a category crate almost entirely avoids. Crate does not collect government identifiers, precise geolocation, racial or ethnic origin, religious belief, union membership, health, sex life or sexual orientation, and does not read the contents of your mail or messages. Crate does hold your account log-in and password, which California counts as sensitive personal information. It is used to sign you in and to keep the account secure, which are uses the statute permits without an opt-out, and it is never used to infer anything about you. The right to limit is published anyway, on the same page as the opt-out.

Exercising a right never costs you money, never slows your store down and never changes the price you pay. Crate offers no financial incentive in exchange for personal information, so there is no incentive notice to give you. An authorized agent can act for you if they show us written permission signed by you, and we may still ask you to confirm it directly, which is what the regulations allow and what protects you from somebody else claiming to be your agent.

The United States has no single breach notification law and no single deadline. Every state has its own statute, California's is Civil Code section 1798.82, and what they share is a standard rather than a clock: notice in the most expedient time possible and without unreasonable delay. Crate works to that standard, tells you directly where a breach is likely to put you at high risk, and sends a sample copy of the notice to the California Attorney General where more than 500 California residents are affected. The commitment itself is in the breach section above and it is the same one everywhere; this paragraph names the law behind it in your state.

Several states, Virginia, Colorado, Connecticut, Texas, Oregon, Montana and others, require an internal appeal when a request is refused. Crate gives that appeal to everybody rather than checking your address first, and tells you the regulator to go to if the appeal fails.

If your personal information is inside a store built on crate rather than in a crate account of your own, the merchant is the business that decides what happens to it and crate is their service provider. Send the request to the merchant. Crate will pass it on and help them carry it out, and crate will not use that data for its own purposes, which is the restriction the service provider terms in our data processing addendum put on us.

Exercise the opt-out and the limit right

European Economic Area

You live in the European Union, or in Iceland, Liechtenstein or Norway.

The law
The General Data Protection Regulation, Regulation 2016/679, together with the ePrivacy rules as implemented in your own country and, for a sale to a consumer, the Consumer Rights Directive 2011/83.
The regulator
The supervisory authority of the country you live in, the country you work in, or the country where the problem happened. You may choose any of the three.
Find your national supervisory authority
Our answer time
30 days. The Regulation allows one month, extendable by two more for a genuinely complex request, and requires us to tell you inside the first month if we are taking longer and why. Crate promises the shorter number and keeps it for everybody.
If you are not satisfied
Write to [email protected] first and we will answer within 30 days. You do not have to come to us first: you may lodge a complaint directly with your supervisory authority, and you keep the right to a judicial remedy either way. Neither costs you anything and neither needs our permission.

The lawful basis for each thing crate does

Article 6 wants a lawful basis for each separate purpose, named where the data is collected rather than described in general. This is that list, in full, and there is nothing crate does with your personal data that is not on it.

Creating and running your account and your store
Contract Article 6(1)(b). Without this processing there is no service to give you, so there is nothing here to consent to or object to.
Charging you for your plan
Contract Article 6(1)(b). The card details themselves are held by the payment provider you connected rather than by crate.
Keeping the invoice after you have paid it
Legal obligation Article 6(1)(c). Tax and company law fix how long a financial record is kept, which is why an erasure request does not reach an invoice.
Transactional email your account needs, such as a receipt, a password reset or a security alert
Contract Article 6(1)(b). This is the service rather than marketing, and it is the reason you cannot unsubscribe from it without closing the account.
Keeping the platform secure, preventing fraud and investigating abuse
Legitimate interests Article 6(1)(f). The interest is running a platform that is not used to defraud people. A balancing test is written down for it, you can object, and your interests win where they are the weightier.
Answering your support messages and improving the product
Legitimate interests Article 6(1)(f). Same balancing test, same right to object. Crate does not need a support conversation to be consented to before it can answer you.
Marketing email to somebody who is not yet a customer
Consent Article 6(1)(a), asked for before the first message and withdrawable in one click from every message afterwards.
Anything stored on or read from your device beyond what the site strictly needs
Consent under the ePrivacy rules This is not an Article 6 basis and cannot be swapped for one. It comes from the ePrivacy rules as your own country implements them, it covers local storage and pixels and not only cookies, and it is why crate sets nothing non-essential until you say yes.
Special category data, meaning the Article 9 list
No basis, because there is no processing Crate does not ask you for health, biometric, genetic, racial, political, religious, trade union or sexual data and does not want it. There is no row here to fill in because there is nothing to base.

Where a basis is legitimate interests you can object at any time and crate has to stop unless it can show compelling grounds that override yours. Where a basis is consent you can withdraw it at any time, through the same control that gave it, and withdrawing it does not make anything crate did before the withdrawal unlawful.

The practical consequence of that last pair of rows is the one visitors notice. Crate asks before it stores anything on your device that the site does not strictly need, it asks the same way in every country rather than only where the law is strictest, refusing is exactly as easy as accepting and sits on the same layer, and the choice can be changed again at any time from the cookie policy. Nothing is pre-ticked, continuing to scroll is not consent, and crate runs no advertising cookies at all.

Special category data is the Article 9 list: health, biometrics, genetics, racial or ethnic origin, political opinion, religious or philosophical belief, trade union membership, sex life and sexual orientation. Crate does not ask you for any of it and does not want it. Where a merchant chooses to put such data into a customer record inside their own store, that merchant is the controller of it and the Article 9 condition is theirs to hold, not ours. The data processing addendum says the same thing in contract language rather than leaving it to be inferred.

You can ask crate to confirm whether it holds personal data about you and to give you a copy of it, to correct it, to erase it, to restrict what we do with it while a dispute is open, to hand you a portable copy in a structured and machine readable form, and to object to anything we do on the basis of legitimate interests. Where processing rests on consent you can withdraw it at any time, and withdrawing it is as easy as giving it was, through the same control. Making a request is free, it never degrades the service you get, and we ask for proof of identity only in proportion to what is being asked for: a copy of your own data needs more than an unsubscribe does.

Crate does not make decisions about you by automated means alone that produce legal or similarly significant effects, so the Article 22 right has nothing to bite on here. Fraud and risk signals can flag an account and a person reviews the flag before anything is restricted. If that ever changes, this paragraph changes before the change ships rather than after somebody notices.

Where personal data leaves the European Economic Area, Chapter V has to carry it. Crate uses the 2021 standard contractual clauses, Module Two where a merchant sends their shoppers' data to crate as its processor, and Module Three where crate passes that data to a subprocessor that runs part of the platform. A transfer impact assessment is available on request alongside the clauses, which is what the Schrems II judgment requires to sit beside them rather than instead of them. The Swiss Addendum is available for a buyer who needs it. Where a recipient in the United States is certified under the EU-US Data Privacy Framework, crate relies on that certification only after checking it against the live list, and never as a blanket answer for transfers to the United States.

Where the data physically sits, and how that was established. The application, the database, the job queue and uploaded files run on OVH infrastructure in the United Kingdom. Onward processing happens in France for transactional email, in Nigeria for merchants who connect Paystack, and in the United States for authoritative DNS and certificate issuance. That position comes from the provider's own published allocation record for the address block the host sits in, which names it VPS-UK2 and registers it to Great Britain, read together with the provider hostname, rather than from a third party geolocation database. It has not yet been confirmed against the provider's control panel, and it is stated here at that strength rather than a stronger one. The subprocessor page names all five parties and the country each one operates in.

That means a transfer from the European Economic Area to crate is a transfer to the United Kingdom, and the instrument depends on the state of the European Commission's adequacy decision for the United Kingdom on the day you read this. Where that decision is in force it carries the transfer and no further instrument is needed. Crate does not assert its current status on this page, because an adequacy decision has an expiry and a policy page that quotes one from memory is how a policy becomes wrong without anybody editing it, so check the Commission's own register. The standard contractual clauses described above stand behind it either way, and crate will sign them on request whether or not adequacy is in force. Whether the clauses or the adequacy decision is the right instrument for your own transfer is a question for your counsel, and it is one of the open legal questions this document does not answer for you.

Article 37 requires a data protection officer where the core activity is large scale regular and systematic monitoring of people, or large scale processing of special category data. Neither describes crate: monitoring people is not what the product does, and crate does not ask for special category data. Crate has therefore not appointed a data protection officer and will not imply one by giving somebody the title. Privacy questions go to [email protected] and reach the people who are actually accountable for the answer.

Article 27 is the separate question and the honest answer is that it is open. A controller or processor with no establishment in the Union that offers services to people in the Union has to appoint a representative here, and whether that applies to crate depends on where the operating company ends up established, which is not settled. No representative has been appointed today. When one is, the name and postal address are published on this page and in the data processing addendum, because a representative you cannot write to is not a representative, and crate will not market to merchants in the European Economic Area on the footing that one exists before it does.

If there is a personal data breach, crate notifies the relevant supervisory authority within 72 hours of becoming aware unless the breach is unlikely to result in a risk to anybody, and tells you directly and without undue delay where the risk to you is high, in plain language, with what happened, what it means for you and what to do about it. Where the data is inside a merchant's store crate is the processor, and crate tells that merchant within 72 hours with what is known at the time rather than waiting for a complete picture. Article 33(2) asks only for notice without undue delay, so that is a tighter promise than the law requires and it is deliberately the same 72 hours the data processing addendum makes, because two numbers for one event is two answers. Every breach is written down whether or not it is reportable, which is what Article 33(5) requires a supervisory authority to be able to inspect. There has not been one to record.

Article 8 sets the age at which a child can consent for themselves to an online service at 16 by default, and member states may lower it to 13, 14 or 15, which several have. Crate is a business tool, is not directed at children and does not knowingly open an account for anybody below the age its country sets. If you believe a child's data has reached us, email [email protected] and it will be deleted.

One last thing, because it is asked often and the answer surprises people. The 14 day right of withdrawal in the Consumer Rights Directive does not apply to your subscription to crate. A merchant buying a tool for their business is a trader and not a consumer, and crate would rather say that plainly than imply a right it is not giving you. The 14 days belong to the other contract on this platform, the one between a merchant and their shopper, and the guide below sets out what a merchant owes there, what crate does about it today and what it does not do yet.

Read the EU and UK consumer rights guide for merchants

United Kingdom

You live in England, Scotland, Wales or Northern Ireland.

The law
The UK General Data Protection Regulation and the Data Protection Act 2018, together with the Privacy and Electronic Communications Regulations for cookies and marketing email, and the Consumer Contracts Regulations 2013 and Consumer Rights Act 2015 for a sale to a consumer.
The regulator
The Information Commissioner's Office.
Information Commissioner's Office
Our answer time
30 days. UK law allows one month, extendable by two more for a genuinely complex request, with notice of the delay and its reasons inside the first month. Crate promises the shorter number and keeps it for everybody.
If you are not satisfied
Write to [email protected] first and we will answer within 30 days. You do not have to: you may complain directly to the Information Commissioner's Office, which is free, and you keep the right to a judicial remedy either way.

The lawful basis for each thing crate does

UK GDPR Article 6 wants a lawful basis for each separate purpose. The list is the same as the European one because the processing is the same processing, and it is written out here so this annex stands on its own.

Creating and running your account and your store
Contract Article 6(1)(b) of the UK GDPR. Without it there is no service to give you.
Charging you for your plan
Contract Article 6(1)(b). Card details sit with the payment provider you connected rather than with crate.
Keeping the invoice after you have paid it
Legal obligation Article 6(1)(c). How long a financial record is kept is fixed by tax and company law rather than by us.
Transactional email your account needs, such as a receipt, a password reset or a security alert
Contract Article 6(1)(b). It is the service and not marketing, which is why it cannot be unsubscribed from without closing the account.
Keeping the platform secure, preventing fraud and investigating abuse
Legitimate interests Article 6(1)(f), with a legitimate interests assessment written down for it. You can object and your interests win where they are the weightier.
Answering your support messages and improving the product
Legitimate interests Article 6(1)(f), same assessment and the same right to object.
Marketing email to somebody who is not yet a customer
Consent Article 6(1)(a). The Regulations would allow a soft opt-in to an existing customer about similar goods and services. Crate does not use it and asks first anyway.
Anything stored on or read from your device beyond what the site strictly needs
Consent under PECR regulation 6 The Privacy and Electronic Communications Regulations govern this, not Article 6, and the two cannot be swapped. It covers local storage and pixels as well as cookies.
Special category data, meaning the Article 9 list
No basis, because there is no processing Crate does not ask for it and does not want it. There is nothing here to base.

Where a basis is legitimate interests you can object and crate has to stop unless it can show compelling grounds that override yours. Where a basis is consent you can withdraw it as easily as you gave it, and the withdrawal does not make what happened before it unlawful.

UK data protection law is close enough to the European text that the substance is the same: the same rights, the same 30 day answer, the same absence of automated decisions with legal effect, and the same refusal to ask you for special category data. The paragraphs below name the places the two genuinely differ, which are the cookie and marketing rules, the transfer instruments, the representative question and the age threshold.

Cookies and marketing email are governed by the Privacy and Electronic Communications Regulations rather than by the UK GDPR alone. Storing or reading anything on your device beyond what the site strictly needs takes your prior consent, and the same rule covers local storage and pixels rather than only cookies. Crate's position is that nothing non-essential is set until you say yes, everywhere, which is stricter than the soft opt-in the Regulations would allow for marketing email to an existing customer.

You can ask crate to confirm whether it holds personal data about you and to give you a copy, to correct it, to erase it, to restrict processing while a dispute is open, to give you a portable copy, and to object to anything resting on our legitimate interests. Where processing rests on consent you can withdraw it as easily as you gave it. Requests are free and never cost you the service.

Transfers out of the United Kingdom run on the International Data Transfer Agreement or on the UK Addendum bolted onto the EU standard contractual clauses, and crate will sign whichever instrument your own counsel prefers rather than insisting on one. A transfer risk assessment is available on request alongside either. The United Kingdom recognises the European Economic Area as adequate, so a transfer into the EEA needs no extra instrument, and it operates its own extension of the Data Privacy Framework for certified recipients in the United States, which crate relies on only after checking the live certification list.

Where the data physically sits. The application, the database, the job queue and uploaded files run on OVH infrastructure in the United Kingdom, so for a British merchant the main processing does not leave the country at all. The transfers that do leave are the onward ones: France for transactional email, Nigeria for merchants who connect Paystack, and the United States for authoritative DNS and certificate issuance, each named on the subprocessor page with the country it operates in. That position was established from the provider's own published allocation record for the address block, which names it VPS-UK2 and registers it to Great Britain, rather than from a geolocation database, and it has not yet been confirmed against the provider's control panel. It is stated at that strength and no stronger.

Crate has not appointed a data protection officer, for the reason set out in the European annex: the Article 37 triggers do not describe what this product does. Crate has not appointed a UK Article 27 representative either, and that appointment is separate from any European one rather than covered by it. Whether crate needs one depends on where the operating company ends up established, which is not settled. When a representative is appointed the name and postal address are published here. Crate does not currently pay the ICO data protection fee, because that fee falls on organisations established in the United Kingdom and crate is not, and if that changes the registration number is published here rather than merely mentioned.

If there is a personal data breach, crate notifies the Information Commissioner's Office within 72 hours of becoming aware unless the breach is unlikely to result in a risk to anybody, and tells you directly and without undue delay where the risk to you is high. Where the data is inside a merchant's store crate is the processor and tells that merchant within 72 hours. Every breach is recorded whether or not it is reportable. There has not been one to record.

The United Kingdom sets the age at which a child can consent for themselves to an online service at 13. The Age Appropriate Design Code applies to services likely to be accessed by children, and crate is a business administration tool rather than a service children use, so it is out of scope. Crate does not knowingly open an account for anybody under 13, and [email protected] will delete a child's data if any reaches us.

The 14 day cancellation right in the Consumer Contracts Regulations 2013 does not apply to your subscription to crate, because a business buying a tool for its business is not a consumer. It applies to the contract between a merchant and their shopper, alongside the Consumer Rights Act 2015 and its 30 day short term right to reject goods that are not of satisfactory quality. The guide below sets out what a merchant owes on that contract, and what crate does and does not do about it today.

Read the EU and UK consumer rights guide for merchants

Canada

You live in Canada. Quebec has extra rules and they are set out at the end of this annex.

The law
The Personal Information Protection and Electronic Documents Act, plus Quebec's Law 25 if you are in Quebec, and Canada's Anti-Spam Legislation for marketing email.
The regulator
The Office of the Privacy Commissioner of Canada, or the Commission d'acces a l'information du Quebec if you are in Quebec.
Office of the Privacy Commissioner of Canada
Our answer time
30 days, which matches the access deadline Canadian law sets. If a request is complex we will tell you inside those 30 days that we need longer and why, rather than going quiet.
If you are not satisfied
Write to us first and we will answer. If you are still not satisfied, complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'acces a l'information du Quebec if you are in Quebec. Both are free.

Canadian law is built on consent rather than on a list of lawful bases, and the kind of consent it expects rises with how sensitive the information is. Crate relies on your express consent when you create an account and agree to the terms, and on consent you can obviously infer for the things a commerce platform plainly has to do with the data to work at all, such as showing you your own orders. Marketing email is separate, express and opt-in, and it is never bundled into signing up.

You can withdraw consent at any time, subject to what the law and our contract with you still require. Withdrawing consent for marketing email costs you nothing and takes one click. Withdrawing consent for the processing that runs your store means the store cannot run, so we will tell you plainly what stops working before we act on it rather than after.

You can ask what personal information we hold about you, what we have used it for and who we have given it to, and you can challenge its accuracy and have it corrected. If we refuse any part of a request we will tell you which part and why, in writing, and tell you how to challenge that decision with us and then with the Commissioner. One named person is accountable for personal information at crate and [email protected] reaches them.

Crate processes personal information outside Canada. That means it is subject to the law of the country where it is processed, and the courts, law enforcement and national security authorities of that country may be able to compel access to it, whatever crate's contracts say. Canadian law does not prohibit that, but it does require us to tell you it happens, so this paragraph exists and is not buried. Every party that processes data for us is bound by written terms requiring comparable protection.

If a breach of our safeguards creates a real risk of significant harm to you, crate reports it to the Office of the Privacy Commissioner as soon as feasible and tells you as soon as feasible, along with anyone else who could act to reduce the harm. Canadian law is also the reason the breach section above commits to a record of every breach kept for two years, reportable or not. That requirement is Canadian, the record crate keeps is not: one register covering every breach anywhere is easier to keep honestly than a Canadian one and a separate everything-else one. There has not been a breach to record.

Marketing email to a Canadian address runs on express consent under Canada's Anti-Spam Legislation. Every message identifies crate, gives a way to reach us, and carries an unsubscribe link that works on the first click. Canadian law allows ten business days to act on an unsubscribe. Crate acts on it immediately, and the transactional email your account actually needs is not affected.

Quebec adds four things and they are worth reading even if the rest of this annex is familiar. Consent must be asked for separately from everything else, in clear language, rather than folded into a terms checkbox. Privacy settings must default to the most protective option, which is why nothing non-essential is switched on for you. You have a right to a portable copy of the information you gave us. And before any personal information leaves Quebec, an assessment has to conclude that it will get adequate protection where it is going.

Canada sets no single age at which a person can consent for themselves, and the Privacy Commissioner treats a child's information as sensitive whatever their age. Quebec is specific: the personal information of a person under 14 cannot be collected without a parent or guardian, except where the collection is clearly for that person's benefit. Crate is a business tool, is not directed at children and does not knowingly open an account for a minor, which is the position the children section above states and which this annex does not change.

Quebec also gives you a right to know when a decision about you is made only by automated means, and to have a person look at it. Crate does not make decisions about you by automated means alone that carry a legal or similarly significant effect. Fraud and abuse signals can flag an account, and a person reviews the flag before anything is restricted.

Nigeria

You live in Nigeria, or your personal information is processed in Nigeria.

The law
The Nigeria Data Protection Act 2023, and the Federal Competition and Consumer Protection Act 2018 for the consumer side of a sale.
The regulator
The Nigeria Data Protection Commission.
Nigeria Data Protection Commission
Our answer time
30 days, which sits inside the one month the Act allows. If we need an extension we will tell you inside the first 30 days and say why.
If you are not satisfied
Complain to us first at [email protected] and we will answer within 30 days. If our answer is wrong you can lodge a complaint with the Nigeria Data Protection Commission, and nothing in this policy stops you going to court instead or as well.

The Nigeria Data Protection Act works from lawful bases in much the same shape as European law, so this annex reads like the European one on purpose. Running your account and billing you is necessary to perform our contract with you. Keeping the platform secure, preventing fraud and abuse, answering support and improving the product are our legitimate interests, and where an interest of ours is weighed against yours, yours wins if it is the weightier. Marketing email is consent, asked for separately.

Where crate relies on your consent, that consent has to be freely given, specific, informed and unambiguous, and it has to be as easy to withdraw as it was to give. It is. Nothing non-essential is switched on until you say so, and the same control that switches it on switches it off again.

You can ask for confirmation that we process your data, for access to it, for a correction, for erasure, for processing to be restricted while a dispute is open, and for a portable copy. You can object to processing that rests on our legitimate interests, and you can object to a decision made about you by automated means alone. Crate does not make such decisions with a legal or similarly significant effect.

Personal information is processed outside Nigeria. The Act permits that where the destination gives adequate protection or where one of the bases it lists applies, including performance of the contract you have with us. Every processor crate uses is bound by written terms carrying the same obligations crate owes you, and the data processing addendum sets those terms out in full.

A child in Nigeria is anyone under 18, which is the widest definition of the jurisdictions this policy covers, and processing a child's data needs verified consent from a parent or guardian. Crate is a business tool, it is not directed at children, and it does not knowingly open an account for a minor. If you believe a child's data has reached us, email [email protected] and it will be deleted.

If there is a breach that is likely to put your rights at risk, crate reports it to the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and tells you without undue delay where the risk to you is high. That 72 hour commitment is the same one the data processing addendum makes to merchants and it is deliberately the same number, because two commitments about one event is two answers.

Whether crate meets the Commission's thresholds to be a data controller of major importance, and therefore has to register with the Commission and appoint a data protection officer, is being determined and is not yet settled. Crate will register and publish the registration here if it does. Until then this page names no registration number and no data protection officer, because publishing one that does not exist would point your complaint at somebody who cannot answer it.