Privacy
Privacy policy
Draft outline — not legal text. This page lists what the policy must cover. The policy itself will be written for, and reviewed by, counsel before launch.
What the policy will cover
- Who we are — Coral Cove Software, and how to contact us about privacy.
- What we collect — account identity (through WorkOS); the content your organization and its agents put into CruxDeck; attachments; agent credentials, stored only as one-way hashes; and an audit record of every change.
- This website — Cloudflare Web Analytics, loaded only with your consent; first-party campaign codes carried into sign-up; no advertising tags at launch.
- Email — transactional email (invitations and notifications) through Resend; marketing email only if you opt in, from a separate account, with a working unsubscribe.
- Payments — on Stripe-hosted pages; CruxDeck never sees your card. Whether Stripe acts as merchant of record depends on its approval of Managed Payments.
- Where data lives — Render (the application and database), Cloudflare (this site, the app’s edge and private attachment storage in R2), and the processors above.
- Retention — decisions and their audit trail are kept on every plan; Free-plan limits hide old decisions and never delete them; what is deleted, and when.
- Your rights — access, correction, deletion, objection and withdrawal of consent.
- Transfers — where processing happens, and on what basis.
- Changes — how we tell you when this policy changes.