Privacy Policy

Last updated: January 1, 2024

1. Introduction

Critter (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our software-as-a-service platform and related services (“Service”).

This policy applies to information we collect through our Service, website, and communications with you. By using our Service, you consent to the data practices described in this policy.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, phone number, time zone, locale
  • Billing Information: Billing address, payment information (provided by third-party payment processors)
  • Profile Information: User preferences, settings, and profile data
  • Customer Data: Any data, content, or information you upload or input into our Service
  • Communications: Messages, feedback, and support requests you send to us

2.2 Information We Collect Automatically

  • Usage Data: How you interact with our Service, features used, time spent
  • Device Information: IP address, browser type, operating system, device identifiers
  • Log Data: Server logs, error reports, performance metrics
  • Cookies: Session cookies, preference cookies, and analytics cookies

2.3 Information from Third Parties

We may receive information from business partners, service providers, or public sources to enhance our Service or verify information you provide.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Process transactions and manage your account
  • Communicate with you about your account and our Service
  • Provide customer support and respond to inquiries
  • Send important notices about changes to our terms or policies
  • Analyze usage patterns to improve user experience
  • Detect, prevent, and address security issues or fraud
  • Comply with legal obligations and enforce our terms
  • Send marketing communications (with your consent where required)

4. Legal Basis for Processing (GDPR)

For users in the European Union, we process your personal data based on:

  • Contract Performance: To provide our Service as agreed in our Terms of Service
  • Legitimate Interest: To improve our Service, ensure security, and communicate with you
  • Legal Compliance: To comply with applicable laws and regulations
  • Consent: For marketing communications and optional features (where applicable)

5. Information Sharing and Disclosure

5.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5.2 When We Share Information

We may share your information in the following circumstances:

  • Service Providers: Third-party vendors who help us operate our Service (hosting, analytics, payment processing)
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • Legal Requirements: When required by law, court order, or to protect our rights
  • Safety and Security: To protect the safety of our users or prevent fraud
  • With Your Consent: When you explicitly agree to share information

6. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption of data in transit and at rest using AES-256
  • Regular security audits and penetration testing
  • Multi-factor authentication for administrative access
  • Employee training on data protection and security practices
  • Incident response procedures for security breaches

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but will notify you of any material breaches as required by law.

7. Data Retention

We retain your information for as long as necessary to provide our Service and fulfill the purposes outlined
in this policy:

  • Account Data: Retained while your account is active and for 90 days after termination
  • Customer Data: Retained according to your subscription terms and deleted upon request
  • Usage Logs: Typically retained for 12 months for security and analytics purposes
  • Legal Requirements: Some data may be retained longer to comply with legal obligations

8. Your Privacy Rights

Depending on your location, you may have the following rights:

8.1 General Rights

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal requirements)
  • Portability: Request your data in a machine-readable format
  • Opt-out: Unsubscribe from marketing communications

8.2 GDPR Rights (EU Users)

  • Right to restrict processing
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with supervisory authorities

To exercise these rights, contact us at privacy@critter.com. We will respond within 30 days.

9. International Data Transfers

Our Service is hosted in the United States. If you are accessing our Service from outside the US, your information may be transferred to, stored, and processed in the US where our servers are located.

For EU users, we ensure adequate protection through Standard Contractual Clauses approved by the European Commission and other appropriate safeguards.

10. Cookies and Tracking

We use cookies and similar technologies to:

  • Remember your preferences and settings
  • Analyze how our Service is used
  • Provide security features
  • Improve user experience

You can control cookies through your browser settings. However, disabling cookies may affect the functionality of our Service.

11. Children’s Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending an email notification to your registered email address
  • Providing notice through our Service

Changes will be effective 30 days after notification for material changes, or immediately for non-material changes.

13. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Privacy Officer

Email: info@critter.com

Address: Crittersoft, Level 11, Legal House, 101 Lambton Quay, Wellington 6011, New Zealand