01 Who we are
Crux Data (“Crux,” “we,” “our”) is a marketing agency based in the United States. This policy applies to the website cruxdata.io and to the marketing services we provide to our clients. The data controller for the purposes of GDPR is Crux Data.
Contact for privacy matters: privacy@cruxdata.io (or preston@cruxdata.io).
02 Information we collect
2.1 Information you provide directly
When you fill out a form on our site — the contact form, the plan signup form, or the interactive custom plan builder — we collect what you enter. That typically includes your name, business email address, business website URL, any notes or messages, and (on plan forms) the services or plan you selected.
2.2 Information collected automatically
When you browse cruxdata.io, the following may be collected automatically by our hosting platform, analytics tools, and advertising pixels:
- Your IP address, browser type and version, operating system, device type, screen size, and general location (city/region level).
- Pages you visited, time and date of visits, referrer URL, and how you arrived on our site (search, ad click, direct, referral).
- Cookie identifiers used for analytics and advertising measurement.
- A small amount of data your browser stores locally (your theme preference).
2.3 Categories under U.S. state privacy laws
The categories above map to the following CCPA/CPRA categories: identifiers (name, email, IP, cookie IDs), internet or other electronic network activity information (pages viewed, referrer, ad interactions), commercial information (services you inquired about), and inferences (drawn from analytics). We do not collect sensitive personal information as defined by CPRA.
03 Why we use it
We use personal information to:
- Respond to your inquiries and provide services — the primary reason we collect anything.
- Send the proposal, information, or plan details you asked for.
- Deliver and improve the marketing services we have been hired for.
- Measure how the website performs and how our own marketing is working (analytics).
- Measure the effectiveness of advertising when we run ads to promote our services.
- Comply with legal obligations, respond to lawful requests, and protect our rights.
We do not sell personal information for money. We do share limited data with advertising partners (see Section 4) in ways that certain state laws define as “sharing” for cross-context behavioral advertising — you can opt out below. We do not use your data to train AI models.
Legal bases (GDPR). For visitors in the EU/EEA/UK, we rely on the following bases under GDPR Article 6(1): performance of a contract (fulfilling your inquiry), our legitimate interest (basic analytics and site security), and your consent (advertising cookies).
04 Who we share it with
We share information only with the service providers who help us run our business, and only as needed. We do not sell personal information for monetary consideration. Under California’s CPRA and similar U.S. state laws, our use of Google Ads and Google Analytics constitutes “sharing” for cross-context behavioral advertising, which you can opt out of.
| Recipient | Purpose | Data shared |
|---|---|---|
| Squarespace (or our hosting provider) | Website hosting, basic traffic analytics, site security | IP, request logs, cookies |
| Formspree | Processing contact and signup form submissions and delivering them to our inbox | Form contents (name, email, message, plan) |
| Google (Analytics 4) | Website performance analytics | Pageview data, cookie ID, IP (truncated), referrer |
| Google (Ads) | Measuring the performance of ads we run to promote Crux Data | Pageview data, cookie ID, conversion events |
| Our email & CRM tools | Responding to inquiries and managing client communication | Name, email, business context you shared |
We may also disclose information when required by law, in response to lawful requests from public authorities, to protect our rights or the safety of others, or in connection with a business transfer (merger, acquisition, or asset sale). In any such transfer we would require the recipient to honor this policy.
05 Cookies and tracking technologies
Cookies are small text files that a website stores on your device. Similar technologies include pixels, local storage, and SDKs. We use three categories:
- Strictly necessary — used to make the site work (session, security). No consent required, and you cannot opt out of these without breaking basic site function.
- Analytics — used to understand how visitors use the site (Google Analytics 4). Under GDPR/UK GDPR we obtain your consent before setting these. Under U.S. laws you can opt out.
- Advertising — used to measure ad effectiveness and, where applicable, reach you with relevant ads (Google Ads pixel). Under GDPR/UK GDPR we obtain your consent. Under CCPA/CPRA this is “sharing” and you can opt out at any time via the “Your Privacy Choices” link in our footer.
Global Privacy Control (GPC). We recognize and honor the Global Privacy Control browser signal. If your browser sends a GPC signal, we treat it as a valid opt-out of the sale or sharing of personal information for that browser and device.
Do Not Track (DNT). Our site does not currently respond to the older DNT header. We do respond to Global Privacy Control, which is the successor mechanism recognized by California, Colorado, Connecticut, and other U.S. state regulators.
You can also disable cookies in your browser settings. Some site functionality may not work as expected if you do.
You can opt out of Google Analytics site-wide at tools.google.com/dlpage/gaoptout.
06 How long we keep information
We keep specific timeframes, not vague “as long as necessary” language:
- Contact and inquiry form submissions: 24 months after last interaction, unless we enter into a client relationship (in which case we keep the record for the duration of the engagement plus 7 years for tax/records purposes).
- Google Analytics data: 14 months (the GA4 default retention we set).
- Google Ads conversion data: as configured in Google Ads (typically 13 months).
- Email correspondence: retained for the duration of the business relationship plus 3 years for records purposes.
- Backups and archives: may retain data slightly longer as part of routine backup rotation. We overwrite backups on a rolling schedule.
You can ask us to delete your information at any time (see Section 7).
07 Your rights and choices
Depending on where you live, you have some or all of the following rights over your personal information:
- Right to know / access — what personal information we have about you, where we got it, and who we shared it with.
- Right to correct — ask us to fix inaccurate information.
- Right to delete — ask us to delete your personal information (subject to legal retention obligations).
- Right to portability — get a copy of your information in a usable format.
- Right to opt out of sale / sharing — we do not sell for money, but we do share for cross-context behavioral advertising via Google Ads. You can opt out via the “Your Privacy Choices” link in our footer, by sending a Global Privacy Control signal, or by emailing privacy@cruxdata.io.
- Right to opt out of targeted advertising — separate from the sale/sharing opt-out under some state laws.
- Right to limit use of sensitive personal information — we don’t collect sensitive personal information as defined by CPRA, so this is a no-op for us.
- Right to non-discrimination — we will not deny you service, charge you more, or provide you a lower level of service because you exercised any of these rights.
- Right to appeal — if we deny your request under Virginia, Colorado, Connecticut, or similar state law, you can appeal by replying to our denial. If your appeal is denied, you may contact your state Attorney General.
How to exercise a right. Email privacy@cruxdata.io with the subject line “Privacy Request” and tell us what you want. We may need to verify your identity before we can act on a request. We will respond within 45 days (as required by CCPA) and typically much sooner. For GDPR/UK requests, we respond within 30 days. There is no fee for exercising your rights.
Authorized agents. California residents may designate an authorized agent to make a request on their behalf. We will ask the agent for signed proof of authorization before processing.
EU/EEA/UK residents. If you are unhappy with how we have handled your data, you have the right to lodge a complaint with your local supervisory authority. A list is available at edpb.europa.eu/about-edpb/members. UK residents can contact the ICO at ico.org.uk.
08 International data transfers
Crux Data is based in the United States and our service providers are primarily U.S.-based. If you are in the EU/EEA/UK, your personal information will be transferred to and processed in the United States. Where our service providers offer them, we rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses as the transfer mechanism.
09 Children
cruxdata.io is intended for a business audience. We do not knowingly collect information from anyone under the age of 16. If you believe a child under 16 has provided us with personal information, please contact us and we will delete it.
10 Security
We use reasonable administrative and technical safeguards to protect the information we collect, including HTTPS/TLS for site transport, access controls on our tools, and vendor selection with security in mind. No internet transmission or storage is ever 100% secure, so we cannot guarantee absolute security, but we take it seriously and will notify affected individuals promptly if we experience a data breach as required by applicable law.
11 Marketing email & CAN-SPAM
If we send you marketing email (which we do only if you opt in or have an existing business relationship with us), every message will (a) accurately identify the sender, (b) use a non-deceptive subject line, (c) identify itself as an advertisement where applicable, (d) include our physical postal address, and (e) provide a clear, one-click way to unsubscribe. Unsubscribe requests are honored within 10 business days.
12 Third-party links
Our site may contain links to third-party sites we do not control (social profiles, external tools, articles). We are not responsible for the privacy practices of those sites. Please read their privacy policies before providing information.
13 Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Effective” and “Last updated” dates at the top of this page and, if the changes are significant, notify active clients directly.
14 State-specific notices (informational)
The rights and controls described above satisfy the applicable requirements of the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), Iowa Consumer Data Protection Act (ICDPA), Texas Data Privacy and Security Act (TDPSA), Oregon Consumer Privacy Act (OCPA), Delaware Personal Data Privacy Act (DPDPA), and the New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Montana, Rhode Island, Indiana, Kentucky, and Nebraska privacy acts, to the extent they apply to us.
Certain of these laws only apply above numeric revenue or data-volume thresholds. Crux Data is a small business and may not meet the applicability thresholds of every listed statute, but we honor the substantive consumer rights (access, delete, correct, opt-out) for all U.S. residents regardless.
California: we do not sell personal information for money. We do “share” personal information for cross-context behavioral advertising via Google Ads. Opt out via the “Your Privacy Choices” link in our footer, via Global Privacy Control, or by emailing us.
Nevada: Nevada residents can opt out of the future sale of covered personal information by emailing privacy@cruxdata.io.
15 Contact
Privacy questions, data-subject requests, and opt-outs:
privacy@cruxdata.io
Alternate: preston@cruxdata.io
We will acknowledge receipt within 5 business days and respond substantively within 30 days (GDPR) or 45 days (CCPA) as applicable.