// Legal
Privacy Policy
Last updated: 6 June 2026
Crow (we, us, or our) operates the website at yourcrow.com, the Crow web application, and the site-wide CrowCode script (crow.js) (collectively, the Service). This policy explains what data we collect, how we use it, and your rights regarding it.
By using any part of the Service you agree to the practices described here. If you do not agree, please do not use the Service.
1. Information We Collect
Account data. When you register for Crow, we collect your name, email address, and a hashed password. We never store your password in plain text.
Usage data. We collect information about how you interact with the web application (pages created, suggestions generated, and similar product activity) to operate and improve the Service.
Session data. We use a server-side session cookie to keep you logged in. This cookie contains no personal information and expires when you log out or after a period of inactivity.
CrowCode data. If you install CrowCode (crow.js) once across your website, the script collects, on your behalf, an anonymous visitor identifier stored in localStorage, page URL and referrer, experiment and variant assignments, configured conversion events, and privacy-bounded Heatmap click and scroll coordinates. Optional behavioural diagnostics require the diagnostic consent setting and do not capture form values or page text. This data is sent to Crow's servers and stored against your account so you can understand behaviour and measure experiments. Crow acts as a data processor for this visitor data. You remain the data controller and are responsible for obtaining any consent your visitors require.
Newsletter. If you subscribe to our newsletter, we store your email address for the purpose of sending you product updates and CRO content. You can unsubscribe at any time.
Communications. If you contact us directly, we may retain your message and contact details to respond and keep records.
3. How We Use Your Information
- To create and manage your account.
- To provide the core Service: CRO analysis, suggestions, A/B experiments, analytics, and CMS integrations.
- To store and display CrowCode data, including visitor events, experiment assignments, conversion events, and Heatmap signals, within your Crow account.
- To send transactional emails (account confirmations, password resets).
- To send the newsletter you subscribed to (you can opt out at any time).
- To detect and prevent fraud, abuse, and security incidents.
- To improve and develop the Service based on aggregated, anonymised usage patterns.
4. Data Sharing
We do not sell, rent, or trade your personal data. We may share it only in the following limited circumstances:
- Service providers: third parties we use to operate the Service (hosting, email delivery, error monitoring). They are bound by data processing agreements and may only use data to perform services for us.
- Legal requirements: if required to do so by law, court order, or governmental authority.
- Business transfers: in the event of a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
5. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes.
CrowCode event data, including visitor events, experiment assignments, conversion events, and Heatmap events, is retained according to the controls shown in the Service and deleted within 30 days of account deletion. You can delete supported experiment and diagnostic data from within the app.
6. Security
We use industry-standard measures to protect your data: HTTPS everywhere, bcrypt-hashed passwords, and server-side sessions. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your location, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Data portability: receive your data in a structured, machine-readable format.
To exercise any of these rights, email us at support@yourcrow.com. We will respond within 30 days.
8. Cookies
The Crow web application uses one first-party session cookie, strictly necessary for authentication. We do not use advertising cookies or third-party tracking cookies on the main application.
The marketing site (yourcrow.com) may use lightweight analytics to understand aggregate traffic. No personally identifiable information is collected through these analytics.
9. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify registered users by email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
11. Contact
If you have questions about this policy or your data, please contact us at: