This Privacy Policy explains how crossrevaer collects, uses, and protects your personal data when you access or use our API infrastructure and related services.
Effective Date: January 1, 2025Last Updated: June 15, 2025
We collect information you provide directly: name, email address, company name, billing details, and API usage credentials.
We automatically collect technical data including IP addresses, browser type, device identifiers, log files, and API request metadata.
We may collect usage analytics such as feature interactions, page views, and session duration to improve our services.
2. How We Use Your Data
To provision, maintain, and improve the crossrevaer API infrastructure and related services.
To process payments, send transactional communications, enforce our Terms of Service, and fulfill legal obligations.
To detect fraud, prevent abuse, and ensure the security and integrity of our financial infrastructure.
3. Cookies & Tracking
We use strictly necessary cookies to authenticate sessions and maintain platform security.
With your consent, we use analytics cookies (e.g., via aggregated telemetry tools) to understand platform usage.
You may manage or withdraw cookie consent at any time via our Cookie Preferences panel or browser settings.
4. Third-Party Sharing
We share data with vetted sub-processors (payment processors, cloud infrastructure providers, fraud detection services) under strict data processing agreements.
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
We may disclose data to law enforcement or regulators when required by applicable law or court order.
5. Your Rights (GDPR & CCPA)
You have the right to access, correct, or delete personal data we hold about you, and to request data portability.
EU/EEA residents may object to or restrict processing and lodge a complaint with their supervisory authority.
California residents may opt out of the sale of personal information (we do not sell data) and request disclosure of collected categories under the CCPA.
6. Data Retention
We retain account and billing data for 7 years to comply with financial regulatory requirements.
API logs and usage data are retained for 90 days, after which they are securely deleted or anonymized.
You may request early deletion of your personal data subject to our legal retention obligations.
7. Security
We employ AES-256 encryption at rest and TLS 1.3 in transit across all crossrevaer infrastructure.
Access to personal data is restricted to authorized personnel on a strict need-to-know basis, enforced via role-based controls.
We conduct regular penetration testing and third-party security audits of our systems.
8. Children's Privacy
crossrevaer services are intended solely for businesses and individuals aged 18 or older.
We do not knowingly collect personal data from anyone under the age of 18. If we become aware of such collection, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in law, technology, or our practices.
Material changes will be communicated via email or prominent notice on the platform at least 30 days before taking effect.
Continued use of crossrevaer services after the effective date constitutes acceptance of the updated policy.
10. Contact & Data Controller
The data controller is crossrevaer Inc., responsible for decisions about how your personal data is processed.
For privacy inquiries, data subject requests, or to reach our Data Protection Officer, contact: [email protected].
Postal: crossrevaer Inc., 340 Pine Street, Suite 800, San Francisco, CA 94104, United States.
Questions about your data?
Contact our Data Protection Officer at [email protected]. We respond to all verified requests within 30 days as required by GDPR Article 12.
crossrevaer
Embed financial infrastructure via a single API key.