Skip to main content
CR

Crowdstack

GDPR evidence

crowdstack.comLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Crowdstack and GDPR

CertReports found no public GDPR evidence for Crowdstack as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: SW-US Certification, EU-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
15 Jun 2021
Expires or valid through
17 Mar 2027
Scope
We collect personal data to enhance the customer's online experience, authenticate them when they sign in to a Crowdstack site, send notifications, fulfill requests for services, contact them, customize the content, and provide anonymous reporting for internal and external clients. We limit personal data collection to only what we need. This includes: email address, name, passwords, phone numbers, birth date, gender, and address information. For services that require payment, we collect credit card information, which is stored in encrypted form on secure servers, including PCI-compliant third-party vendors. If users register and grant access to a third party social network (e.g., Facebook) or integrated service (e.g., Google), we will collect the personal information directly associated with those accounts. This includes the name, email address and the unique identifier provided by the service. Other data we collect include browser data, analytic data (overall usage, traffic or our websites), visit information via server logs (IP address, cookie information, and page requests), email or written correspondence, and monetary transaction records. We do not share personal information with other individuals, organizations, or companies outside of our company and its related entities, unless we have consent or unless: we are working with trusted partners who agree to abide by the rules of our privacy policy or have signed a confidentiality agreement; we are required respond to via a legal process; it is necessary to share information to investigate, prevent, or take action regarding illegal activities, suspected fraud, or potential threats to the physical safety of any person; or we are transmitting data in order to fulfill a service. In this circumstance, information is conveyed in order to render service, however, and is not shared for any other purpose.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Crowdstack, Inc.: Active: SW-US Certification, EU-US Certification, UK Extension Certification
Live pagesha256 1836fd962a
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
20 Sep 2016
Scope
We collect information such as email address, name, passwords, phone numbers, birth date, gender, and address information, and we may collect credit card information. We also store browser cookies, we log IP address, and page request. We may store any email or written correspondence, and any data from monetary transctions. We use this information to enhance the online experience, authenticate the user, send notifications, fulfill requests for services, contact users, customize advertising or content, and to provide anonymous reporting for internal and external customers.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Social Strata, Inc.: Inactive
Live pagesha256 4a8a5ac25e
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Crowdstack GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.

No same-category vendor has GDPR evidence in the index yet.