This policy explains how Krusade LLC (“Krusade”, “we”, “us”) collects, uses, shares, and protects personal information. It applies to krusade.com and to every software product and service Krusade operates (each, a “Service”), including any Service that lets you sign in with a Google Account.
Krusade is a holding company; individual Services are operated under their own names and at their own web addresses. Where a Service publishes a supplementary privacy notice of its own, that notice applies in addition to this one, and this policy governs if the two conflict.
Information we collect
We collect only what a Service needs in order to work.
- Account information. Your name, email address, and — where you sign in with a third-party provider — the account identifier that provider gives us.
- Content you provide. Whatever you create, upload, or connect to a Service in the course of using it.
- Payment information. For paid Services, our payment processor handles your card details. We receive the billing status, the last four digits, and the card brand — never the full card number.
- Usage and device data. IP address, browser and device type, pages or features used, and timestamps. We use this to keep the Services running, diagnose faults, and detect abuse.
- Correspondence. Messages you send us, and our replies.
We do not buy personal information from data brokers, and we do not build advertising profiles.
Google user data
Some Services let you sign in with Google or connect a Google Account. When you do, Google shows you exactly which permissions are being requested, and nothing is accessed until you grant them.
Krusade LLC’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in relation to data received from Google APIs:
- We use it only to provide or improve the user-facing features that you granted the permission for.
- We do not use it for advertising, and we do not serve advertisements of any kind against it.
- We do not sell it, and we do not transfer it for advertising.
- We do not allow humans to read it, except: with your explicit consent for a specific case (for example, when you ask us to investigate a support issue); where it is necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data is aggregated and de-identified.
- We transfer it to third parties only as needed to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition — and never for any other purpose.
You can review and revoke a Service’s access to your Google Account at any time at myaccount.google.com/permissions. Revoking access stops any further data being retrieved; to have data we already hold deleted, see Retention and deletion.
How we use information
- To provide, maintain, and secure the Services.
- To authenticate you and keep your account safe.
- To take payment for paid Services.
- To respond to your questions and provide support you have asked for.
- To send service messages about outages, security, billing, or material changes to a Service. These are not marketing, and you cannot opt out of them while you hold an account.
- To diagnose faults and understand which features are used, so we can improve them.
- To comply with legal obligations and to enforce our terms.
We send marketing email only if you have asked us to, and every such message carries an unsubscribe link.
Legal bases
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service you signed up for); legitimate interests (keeping the Services secure, preventing abuse, and improving them); consent (optional integrations and marketing email, which you may withdraw at any time); and legal obligation (tax, accounting, and lawful requests).
How we share information
We do not sell personal information. We share it only in these circumstances:
- Service providers who process data on our behalf and under contract — hosting and infrastructure, database hosting, email delivery, payment processing, error monitoring, and analytics. They may use it only to perform services for us.
- Legal requirements — where we are required to by law, or where disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers — if a Service or Krusade itself is acquired, information may transfer with it. We will give notice before your information becomes subject to a different privacy policy.
Retention and deletion
We keep personal information for as long as your account is active, and afterwards only as long as we need it for the purposes described here or to meet a legal obligation.
You can delete your account from within a Service where that option is offered, or by emailing contact@krusade.com from the address on the account. We action deletion requests within 30 days. Residual copies in encrypted backups are purged on our normal backup rotation, within 90 days. We may retain a minimal record of the transaction — invoices and similar — where tax or accounting law requires it.
Security
We encrypt data in transit with TLS, restrict access to production systems to the people who need it, and store credentials using industry-standard hashing. No system is perfectly secure, and we cannot guarantee absolute security; if we become aware of a breach affecting your personal information, we will notify you and any regulator as required by law.
Your rights
Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, object to or restrict how we use it, export it in a portable format, and withdraw consent. If you are in California, you also have the right not to be discriminated against for exercising these rights — and, as stated above, we do not sell or share personal information for cross-context behavioural advertising.
To exercise any of these, email contact@krusade.com. We will respond within the time the applicable law allows. You may also complain to your local data protection authority.
Cookies
We use cookies and similar local storage to keep you signed in and to remember preferences such as your light or dark theme. Where a Service uses analytics, it is configured to measure usage in aggregate rather than to track you across other sites. You can clear or block cookies in your browser, though signing in will not work without them.
International transfers
Krusade is based in the United States, and information is processed there. If you access a Service from outside the United States, you understand that your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Children
The Services are not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us personal information, email us and we will delete it.
Changes to this policy
We may update this policy. When we do, we will change the date at the top of this page, and for material changes we will give notice through the affected Service or by email before the change takes effect.
Contact
Krusade LLC — contact@krusade.com