CrateHQ Privacy Policy
Last Updated: May 16, 2026
This Privacy Policy explains how CrateHQ ("we", "us", "our") collects, uses, discloses, and protects information when you use our wholesale ordering platform (the "Service").
CrateHQ is operated by Vinay Padmanabhi, doing business as CrateHQ.
1. Information We Collect
A. Information you provide to us
- Account information: name, email address, business name, business address, phone number
- Payment information: payment details for your CrateHQ subscription are collected and processed by Stripe; we do not store full payment card details. CrateHQ does not process payments on behalf of you or your customers.
- Communications: messages you send to us via email or in-product
- Customer Data: information about your wholesale customers and their orders that you upload or that flows through the Service
B. Information from third-party services you connect
- Shopify: store data, products, customers, orders (only data you authorize via OAuth)
- Square: store data, products, customers, orders (only data you authorize via OAuth)
- QuickBooks: invoice and customer data, accounts receivable information (OAuth)
- ShipStation: shipment and tracking data (OAuth or API credentials you provide)
We only access third-party data you authorize.
C. Information we collect automatically
- Usage data: pages visited, features used, time spent, actions taken
- Device information: browser type, operating system, IP address, device identifiers
- Cookies and similar technologies: for session management, preferences, and analytics
2. How We Use Information
We use information to:
- Provide, maintain, and improve the Service
- Bill subscription fees and manage subscriptions
- Communicate with you about the Service, including support, billing, and product updates
- Develop new features and analyze usage patterns
- Detect, prevent, and address fraud, security issues, and policy violations
- Comply with legal obligations
- Enforce our Terms of Service
3. How We Share Information
We share information with:
- Service providers who help us operate the Service (hosting, payment processing via Stripe, analytics, customer support tools, email delivery). These providers are bound by confidentiality obligations.
- Third-party integrations you connect (Shopify, Square, QuickBooks, ShipStation) as necessary to provide the Service.
- Legal authorities when required by law, subpoena, or court order, or when necessary to protect our rights or the safety of others.
- Business transfers in connection with a merger, acquisition, sale of assets, or bankruptcy. We will notify you of any such transfer.
We do not sell personal information.
4. Data Retention
- Account information is retained for as long as your account is active and as needed to provide the Service.
- After account termination, we retain Customer Data for 30 days to allow export, then delete it within a reasonable period unless retention is required by law.
- We may retain aggregated, de-identified data indefinitely for analytics and Service improvement.
- Backup copies may persist for up to 90 days after deletion before being overwritten in the ordinary course.
5. Security and Incident Notification
We use commercially reasonable administrative, technical, and organizational measures to protect your information, including encryption in transit (TLS), access controls, authentication, and regular security review. No system is completely secure, and we cannot guarantee absolute security.
If we confirm a security incident involving unauthorized access to your information, we will notify you without undue delay and provide reasonable information and cooperation regarding the incident.
6. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your information (subject to legal retention requirements)
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent (where processing is based on consent)
To exercise these rights, contact us at vinay@cratehq.ai. We will respond within the timeframes required by applicable law.
7. California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (as amended):
- Right to know: what personal information we collect, use, and share
- Right to delete: request deletion of personal information (subject to exceptions)
- Right to correct: request correction of inaccurate personal information
- Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising
- Right to limit use of sensitive personal information: we do not use sensitive personal information for purposes requiring this right
- Right to non-discrimination: we will not discriminate against you for exercising privacy rights
To exercise these rights, contact us at vinay@cratehq.ai.
8. European Economic Area, United Kingdom, and Switzerland Residents (GDPR)
If you are in the EEA, UK, or Switzerland, you have additional rights under data protection laws:
- Lawful basis for processing: we process data based on contractual necessity, legitimate interests, or your consent
- Right to lodge a complaint with a supervisory authority in your jurisdiction
- Right to data portability in a machine-readable format
We may transfer data outside the EEA to the United States. When we do, we use appropriate safeguards such as Standard Contractual Clauses.
9. Children's Privacy
The Service is not intended for use by children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us immediately.
10. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your login session
- Remember your preferences
- Analyze usage patterns and Service performance
You can control cookies through your browser settings. Disabling cookies may impact Service functionality.
We do not currently respond to "Do Not Track" signals from browsers.
11. International Data Transfers
We process data in the United States. By using the Service, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-product notification. The "Last Updated" date at the top reflects the most recent revision.
13. Contact
For privacy questions, requests, or to exercise your rights:
Vinay Padmanabhi, doing business as CrateHQ Email: vinay@cratehq.ai