Data Collected and Stored by CrowdHandler
CrowdHandler is committed to data privacy and transparency. We only collect and retain information required to provide our queueing and access management services to clients.
Anonymous Session Data
When a user accesses a client’s application, the client application sends CrowdHandler an API request with an anonymous session token, IP address, user agent string, language preference and the URL the user is requesting. We use this information to check the user’s position in any queues and either grant access, redirect the user to a waiting room or block access as configured by the client.
IP Addresses
IP addresses are considered personal data in some jurisdictions, but CrowdHandler does not connect them to identifying information. We use IP addresses for security monitoring and to help our clients block repeat offenders. Clients can request to have IP addresses obscured if needed for their compliance requirements.
Billing Information
CrowdHandler does not directly collect or store any billing information or payment data. We use Stripe as a PCI-compliant third-party payment processor to handle all client invoices and payments.
Client Account Information
For administration of their account, clients provide an email and password to create an account in the CrowdHandler portal. Passwords are hashed and salted for security. Account data is stored in AWS Cognito, not on CrowdHandler’s servers. We only use this information to confirm a client’s identity for account login and management.
User Emails
We utilize MailChimp to distribute account management emails like invoices, notifications or newsletters to the email addresses provided by clients. MailChimp observes all GDPR principles around data privacy and consent. Clients can opt-out of marketing emails at any time.
Beyond the above data, CrowdHandler does not collect or store any other customer or personal information. Where clients utilize our DNS implementation, additional data may be transmitted to facilitate routing, but we have no direct access to the data payloads or origin responses.
CrowdHandler’s data privacy policy is strict, retaining only what is required to operate our service and provide value to clients. However, we maintain a shared responsibility model - while we govern data within our infrastructure and application, clients are responsible for compliance with regulations like GDPR when collecting and using data within their own systems and sending data to CrowdHandler’s APIs. Our role is to be transparent so we can work with clients to meet all compliance requirements together.