Crowdstack and GDPR
CertReports found no public GDPR evidence for Crowdstack as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 15 Jun 2021
- Expires or valid through
- 17 Mar 2027
- Scope
- We collect personal data to enhance the customer's online experience, authenticate them when they sign in to a Crowdstack site, send notifications, fulfill requests for services, contact them, customize the content, and provide anonymous reporting for internal and external clients. We limit personal data collection to only what we need. This includes: email address, name, passwords, phone numbers, birth date, gender, and address information. For services that require payment, we collect credit card information, which is stored in encrypted form on secure servers, including PCI-compliant third-party vendors. If users register and grant access to a third party social network (e.g., Facebook) or integrated service (e.g., Google), we will collect the personal information directly associated with those accounts. This includes the name, email address and the unique identifier provided by the service. Other data we collect include browser data, analytic data (overall usage, traffic or our websites), visit information via server logs (IP address, cookie information, and page requests), email or written correspondence, and monetary transaction records. We do not share personal information with other individuals, organizations, or companies outside of our company and its related entities, unless we have consent or unless: we are working with trusted partners who agree to abide by the rules of our privacy policy or have signed a confidentiality agreement; we are required respond to via a legal process; it is necessary to share information to investigate, prevent, or take action regarding illegal activities, suspected fraud, or potential threats to the physical safety of any person; or we are transmitting data in order to fulfill a service. In this circumstance, information is conveyed in order to render service, however, and is not shared for any other purpose.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Crowdstack, Inc.: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 1836fd962a |
- Kind
- listing
- Issued or listed
- 20 Sep 2016
- Scope
- We collect information such as email address, name, passwords, phone numbers, birth date, gender, and address information, and we may collect credit card information. We also store browser cookies, we log IP address, and page request. We may store any email or written correspondence, and any data from monetary transctions. We use this information to enhance the online experience, authenticate the user, send notifications, fulfill requests for services, contact users, customize advertising or content, and to provide anonymous reporting for internal and external customers.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Social Strata, Inc.: Inactive | Live pagesha256 4a8a5ac25e |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Crowdstack GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.