Crimptech
PrivacyTermsCookies

Privacy policy

In effect from 5 September 2026

Drafted 19 August 2026 against what this application does. It has not yet been reviewed by a lawyer.

Contents

  1. 1Who we are
  2. 2What we collect, and why
  3. 3Links, tokens and files
  4. 4The legal basis for each purpose
  5. 5Who else the data reaches
  6. 6Manufacturing partners
  7. 7What we do not send
  8. 8Where the data goes
  9. 9How long we keep it
  10. 10Data subject rights
  11. 11How to exercise them
  12. 12Changes to this policy

This policy covers the Crimptech application at app.crimptech.nl: the quote flow, the account area, the staff console and the shipment tracking pages.

The cookies and browser storage the application uses are listed separately in the cookie policy.

1Who we are

Crimptech is the controller for the personal data described here. The registered office is Letterhout 23, 1507 EG Zaandam, Netherlands.

Chamber of Commerce number 95555927. VAT number NL867179624B01.

Write to info@crimptech.nl about anything in this policy.

No data protection officer is appointed. Requests reach the address above and are answered by the partners in the firm.

2What we collect, and why

Eight categories. What each of the companies that runs this application receives is set out further down.

  • Contact enquiries. The requested service, correspondent's name, company where given, email address, phone number where given and message submitted through the marketing site's contact form. This information is stored so Crimptech can answer the enquiry and retain a record of the correspondence.
  • Account identity. The email address, its verification status and the account identifier issued by the sign-in provider. These support authentication, quote ownership and email verification requirements.
  • Account profile. Optional contact name, company name, phone number, delivery address and billing address. The name, company and delivery address prefill shipments created from a quote. Staff see these fields and the phone number alongside the quote. The billing address remains in the account profile and is not shown on a quote.
  • Quote content. Part specifications, request notes, requested certifications, any withdrawal reason, the staff decline reason displayed on the quote page, the quoted price, and uploaded .step, .stp, .dxf and .pdf files with their original filenames. Up to 50 parts and 100 files per quote. This is what a price and a production plan are made from.
  • Order and shipment records, written by our staff. The customer name and email address, the company name, the real origin and destination addresses, the carrier and its tracking number, the timeline entries published to the tracking page with their location and note, and any documents attached to a shipment. This is what fulfils and tracks the order.
  • Internal notes on a quote. Free text written by staff, with the name and email address of the staff member who wrote it. These are never shown to a customer.
  • Message records. For every email this application sends, the recipient address and the subject are stored, and so is the body of any message a staff member composed. This is how staff see what a customer has been told, and how the application avoids sending the same message twice.
  • Tracking page opens. A shipment reference and a timestamp, up to 500 per shipment. No IP address, user agent or referrer is stored with them.

3Links, tokens and files

A quote carries a claim token and a shipment carries a tracking token. Each is a random string that opens one record and nothing else, and each travels in a link. A tracking link works without an account, so anyone holding it can open that shipment page.

The tracking page shows a sanitized view: the shipment title, the current stage, an estimated delivery date, city and country level locations, the client company, and the documents staff have attached. The carrier, the raw tracking number and the real addresses stay internal.

Uploaded files are never served from a permanent public URL. A quote file is served only to the signed-in account that owns it or to staff, a shipment document only through the tracking link it belongs to, and no email we send carries a link to a file.

4The legal basis for each purpose

PurposeBasis
Quoting a part, and fulfilling an orderPerformance of a contract and pre-contractual steps requested by the customer
Holding an account and confirming the email address on itPerformance of a contract
Email correspondence about a quote or orderPerformance of a contract
Checking the upload form for automated abuseLegitimate interest: keeping a public upload endpoint usable
Counting opens of a tracking linkLegitimate interest: knowing whether a customer has seen an update
Keeping commercial and tax records for seven yearsLegal obligation

5Who else the data reaches

Five processors run this application. Each row says what reaches that company.

Technology processors operate the application. Manufacturing partners receive the production information described in the following section.

ProcessorWhat reaches it
ClerkAccount email address, password or third-party sign-in credential, session activity, IP address and browser user agent
ConvexThe database described above, and every file uploaded to a quote or a shipment
ResendRecipient address and message body, including the quote reference, part specifications and uploaded filenames
CloudflareIP address, user agent and browser signals collected by the upload abuse check. Cloudflare also stores production photographs, video and documents under the relevant order
VercelEvery request to the application, including IP address, URL and headers. A quote file passes through a Vercel function when it is served back to a browser

6Manufacturing partners

Manufacturing partners receive the files required for production.

A manufacturing partner receives the drawing or model, part specification and quantity. Customer contact details remain with Crimptech. Customer names, email addresses and company names are disclosed to a partner only when the customer requests an introduction.

Which partner makes a given part is decided per order, so this policy names the category rather than a list of companies. Write to info@crimptech.nl to request the identities of partners holding data for a specific order.

The terms of use state the confidentiality obligation we require of each of them.

7What we do not send

The abuse-check widget connects directly from the browser to Cloudflare. The application verification request sends the challenge result and secret key to Cloudflare without forwarding the browser IP address.

The fonts are served from this application. No page requests a font from a third party while it loads. Two things are loaded from elsewhere and both are named in the table above: the sign-in code from Clerk, and the abuse check widget on the upload form from Cloudflare.

The application runs no analytics, no tag manager, no advertising pixel and no error reporting service.

8Where the data goes

All five of those companies are headquartered in the United States. Personal data described in this policy therefore leaves the European Economic Area.

The transfer rests on the safeguards each of those processors publishes for its European customers. Those differ from company to company, and this policy does not set out the mechanism one by one.

9How long we keep it

A contact enquiry is kept while it is useful to the correspondence and then deleted. If it becomes part of an order record, the commercial retention period below applies.

An unsubmitted quote becomes eligible for deletion after 24 hours.

A quote submitted without an account becomes eligible after 7 days if it remains unclaimed.

A claimed quote with an unconfirmed email address becomes eligible after 7 days.

These windows run from the last change of state. Hourly cleanup starts eligible deletions, which continue in batches until the record and its files are removed.

Commercial retention applies once staff record a quote as won or link it to a shipment or production order. That protection survives later stage changes and removal of the link, and takes precedence over the shorter windows above.

The current policy retains submitted quotes and shipment and production records for seven years, through the end of the seventh full calendar year after the applicable event. For a protected quote, the event is its first recorded commercial event. For another submitted quote, it is submission or later confirmation of the email address. Linked records must finish their own retention and deletion before the quote can be removed.

A shipment period runs from its latest tracking update or creation, whichever is later. A production record uses its latest stage event, review, cancellation or creation. Daily cleanup starts eligible deletions and records failed work for staff recovery.

The account profile has no time-based expiry. Fields can be changed or cleared from the profile page. Removal can also be requested at info@crimptech.nl.

10Data subject rights

The GDPR provides the following rights concerning the personal data described in this policy.

  • Access: a copy of the personal data held about the data subject.
  • Rectification: correction of anything inaccurate.
  • Erasure: deletion of the data, subject to the limit in the next section.
  • Restriction: a pause on processing while a question about it is settled.
  • Portability: data provided by the data subject, in a machine-readable format.
  • Objection: to processing we base on a legitimate interest, which is the abuse check and the tracking link counter.
  • Complaint: to the Autoriteit Persoonsgegevens, the Dutch supervisory authority, at any time.

11How to exercise them

Email info@crimptech.nl. We answer within one month.

Deleting a sign-in account removes its profile and quotes that never became orders, including their uploaded files. Quotes that became orders and their shipment records remain until the stated retention period ends to meet commercial record-keeping obligations.

We honour an erasure request except where a record has to be kept to meet a legal obligation. The seven year retention period for commercial and tax records is that case, and it covers a quote that became an order along with any shipment records belonging to it. A quote that never became an order carries no such obligation.

12Changes to this policy

The date at the top of this page is the date this version took effect.

Changes are published here with a new effective date.

Crimptech

Letterhout 23, 1507 EG Zaandam

KvK 95555927 · BTW NL867179624B01

PrivacyTermsCookies
crimptech.nl