CRATARA legal

Privacy Policy

This policy describes CRATARA privacy practices for the website, trials and business operations platform. It also explains the separate responsibilities of CRATARA and each customer organization.

Effective August 26, 2026

Notice at collection

At or before account creation, we collect identifiers and account information (such as name, work email, authentication identifiers and organization role), internet or device information needed for security, and any plan or invitation selection. We use this information to create and secure accounts, provide the requested service, prevent abuse, support users and communicate operational or security notices.

When you use CRATARA, we also process the warehouse and customer records described below. We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use Customer Content to train a general-purpose AI model.

Who is responsible for the data

For account administration, the public website and direct business communications, CRATARA determines why and how personal information is processed. For warehouse records that a customer organization enters or uploads ("Customer Content"), the customer generally determines the purpose and CRATARA processes the information to provide the service. The customer is responsible for lawful notices, permissions and instructions to its employees, contractors, clients, suppliers and other individuals whose information it places in CRATARA.

Categories of information

  • Account and organization data: names, work emails, authentication identifiers, memberships, roles, language, plan preference and acceptance records.
  • Operational data: customers, products, SKUs, barcodes, inventory, locations, shipments, work orders, quantities, service rates, exceptions and billing-capture records.
  • Proof of Work and audit data: employee identity, timestamps, scans, notes, changes, prior and resulting states, and linked photos.
  • Technical and security data: session information, IP address and request, device or browser information that may appear in infrastructure and security logs.
  • Support and communications: questions, issue descriptions, email correspondence and attachments you choose to provide.

CRATARA is not designed to collect Social Security numbers, government IDs, payment-card data, health data, biometric templates or other highly sensitive personal information. Do not place such information in free-text fields, notes or photos.

Sources and purposes

We receive information directly from users and customer administrators, from Google when a user selects Google sign-in, and automatically from the application and infrastructure during use. We process it to authenticate users; enforce organization and role boundaries; deliver inbound, inventory, Proof of Work, Revenue Protection and exception workflows; preserve auditability; provide support; diagnose reliability and security issues; comply with law; and protect CRATARA, customers and others from misuse.

Proof photos and workforce data

Proof of Work can identify the employee who performed an operation and can include damage photos. New photos selected through the supported browser workflow are re-encoded before upload to remove embedded device metadata such as GPS and camera details. The operational event still records the authenticated user and server timestamp. Users should photograph the goods or damage—not faces, identification documents, computer screens, home addresses or unrelated people.

Customer organizations must provide any workplace monitoring, employee privacy or camera notices required by applicable law and collective or employment agreements. CRATARA does not perform facial recognition or create biometric identifiers.

Disclosure and service providers

We disclose information only as needed to operate the service, follow customer instructions, complete a business transaction, comply with legal process, or protect rights and security. Current infrastructure providers include Supabase (authentication, database and storage), Vercel (application hosting and delivery), and Google (only when Google sign-in is selected). They may process technical and account data under their applicable agreements. See the Subprocessors page for current details.

Cookies and similar storage

CRATARA currently uses session cookies and local browser storage that are necessary for authentication, security, language choice and the in-product help introduction. It does not currently use advertising cookies or third-party analytics pixels. Details are in the Cookie Policy.

Retention and deletion

We retain account and Customer Content while needed to provide the service, follow customer instructions, maintain security and audit history, resolve disputes, and satisfy legal or accounting obligations. Proof, inventory movements and audit history may require longer retention because their purpose is to preserve operational traceability. Backups may retain residual copies until the normal backup cycle completes. Account owners should contact us before termination to arrange export and deletion requirements.

Privacy choices and requests

Depending on where you live and whether a privacy law applies, you may have rights to know, access, correct, delete, or obtain a copy of personal information, and to appeal or opt out of certain processing. CRATARA does not discriminate for exercising a privacy right. If your information was supplied by your employer or another customer organization, contact that organization first; we will assist it as appropriate.

Submit a request to asielhernandezmartinez@gmail.com. We may need to verify identity and authority before responding. An authorized agent must provide evidence of authorization.

Security, children and international use

CRATARA uses authenticated access, organization-scoped database and storage rules, role controls, secure connections, restrictive browser security headers and operational logging. No service can guarantee absolute security. Report suspected unauthorized access promptly to the contact below.

CRATARA is a business service for adults and is not directed to children. Users must be at least 18. We do not knowingly collect personal information from children under 13. If you believe a child provided information, contact us for review and deletion.

Information may be processed in the United States and other locations where service providers operate. Customer organizations are responsible for determining whether their use requires additional transfer safeguards.

Changes and contact

We may update this policy as practices or laws change. We will not materially expand use of previously collected Customer Content without appropriate notice and, where required, consent. The effective date identifies the current version.

Privacy and security questions: asielhernandezmartinez@gmail.com.