Privacy Policy
This Privacy Policy applies to all visitors and clients of CranUp and covers our obligations under the UK GDPR, EU GDPR, US applicable privacy laws (including CCPA/CPRA where applicable), and the Indian Information Technology Act 2000 and Digital Personal Data Protection Act 2023 (DPDPA). Please read this carefully.
1. Who We Are
CranUp (“we”, “us”, “our”) is a full-service digital marketing and technology agency. We provide social media marketing, graphic design, performance marketing, ecommerce development, ERP development, and custom software services to businesses across the United States, United Kingdom, India, and the Middle East.
For the purposes of UK/EU data protection law, CranUp is the Data Controller in respect of the personal data we hold about you.
Contact details:
- Email: hello@cranup.com
- Website: www.cranup.com
2. What Information We Collect
2.1 Information you provide to us
- Full name, job title, and company name
- Email address and telephone number
- Billing and payment information (processed securely via third-party payment processors)
- Project briefs, creative assets, and materials you share with us
- Communications and correspondence (email, chat, calls)
2.2 Information collected automatically
- IP address and approximate location (country/city)
- Browser type, operating system, and device information
- Pages visited, time on site, and referral source
- Cookies and similar tracking technologies (see Section 6)
2.3 Information from third parties
- Social media profile data when you connect accounts to our services
- Analytics data from advertising platforms (Google Ads, Meta, LinkedIn)
- Business information from public sources for prospect outreach
3. How We Use Your Information
We use personal data for the following purposes:
- To provide, manage, and deliver our services to you under our client agreement
- To process payments and issue invoices
- To communicate with you about projects, updates, and support
- To send marketing communications (only where you have opted in or we have a legitimate interest)
- To analyse website traffic and improve our services
- To comply with legal and regulatory obligations
- To protect against fraud and ensure the security of our systems
4. Legal Basis for Processing (UK/EU GDPR)
Under UK GDPR and EU GDPR, we rely on the following legal bases:
- Contract: Processing necessary to perform our services contract with you.
- Legitimate Interests: For marketing to existing clients, improving our services, and fraud prevention, where our interests are not overridden by your rights.
- Legal Obligation: Where processing is required by applicable law.
- Consent: For marketing to non-clients and for cookies requiring consent. You may withdraw consent at any time.
5. Data Sharing
We do not sell your personal data. We may share it with:
- Service providers who process data on our behalf (hosting, payment processing, analytics, project management tools) under strict data processing agreements
- Advertising platforms (Google, Meta, LinkedIn) for campaign management purposes, on your behalf as a client
- Legal and regulatory authorities where required by law
- Professional advisers (lawyers, accountants) under duties of confidentiality
All third-party processors are required to maintain appropriate security measures and may only process your data for specified purposes.
6. Cookies
Our website uses cookies to:
- Ensure the website functions correctly (strictly necessary cookies)
- Analyse website traffic and performance (analytics cookies)
- Enable advertising and remarketing features (marketing cookies)
You can manage your cookie preferences at any time via our cookie consent tool or your browser settings. Disabling certain cookies may affect website functionality.
7. International Data Transfers
As a global agency, your data may be transferred to and processed in countries outside your country of residence, including the UK, US, and India. Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place:
- UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs)
- Adequacy decisions made by relevant authorities
- Other lawful transfer mechanisms as required
For Indian residents: your data may be stored and processed outside India. We take steps to ensure equivalent protection in line with the DPDPA 2023.
8. Data Retention
We retain personal data only for as long as necessary:
- Client data: for the duration of the engagement plus 7 years (for tax and legal compliance)
- Prospect and marketing data: up to 2 years from last interaction, or until you opt out
- Website analytics data: up to 26 months
- Cookie data: as specified in our cookie notice (typically 1–24 months depending on the cookie)
9. Your Rights
9.1 UK/EU residents (UK GDPR / EU GDPR)
You have the right to:
- Access your personal data (Subject Access Request)
- Rectify inaccurate or incomplete data
- Erasure (“right to be forgotten”) in certain circumstances
- Restriction of processing in certain circumstances
- Data portability
- Object to processing based on legitimate interests or for direct marketing
- Not be subject to solely automated decision-making with significant legal effects
To exercise these rights, contact us at hello@cranup.com. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk (UK) or your local supervisory authority (EU).
9.2 California residents (CCPA/CPRA)
California residents have the right to:
- Know what personal information we collect and how it is used
- Delete personal information we hold (subject to exemptions)
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell your data)
- Non-discrimination for exercising your rights
To submit a request, contact us at hello@cranup.com with the subject line “CCPA Request”.
9.3 Indian residents (DPDPA 2023 / IT Act 2000)
Indian residents have the right to:
- Access information about personal data processed
- Correction and erasure of personal data
- Grievance redressal
- Nominate a person to exercise rights on your behalf
To exercise your rights under DPDPA, contact our Data Protection Officer at hello@cranup.com.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Access controls and role-based permissions
- Regular security reviews and staff training
- Incident response procedures
No transmission over the internet is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.
11. Children’s Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
12. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies before providing any personal information.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this document and, where appropriate, notify you by email. Your continued use of our services after any changes constitutes acceptance of the updated policy.
14. Contact Us
For any questions, requests, or concerns about this Privacy Policy or how we handle your personal data, please contact us:
- Email: hello@cranup.com
- Website: www.cranup.com
We aim to respond to all requests within 30 days (UK/EU GDPR requirement) or as otherwise required by applicable law.