Policies · Privacy

Privacy Policy

Last updated: July 13, 2026 · Crestora Labs, a division of Crestora Property Group LLC
In short:
  • We collect only what we need to run your account, licences, and billing.
  • We don't sell your personal information. Payments go through Stripe — we never see your full card number.
  • Data is encrypted in transit and at rest; licences are bound to a device by a hashed fingerprint.
  • You can access, correct, export, or delete your data any time — email [email protected].
1

Scope

This Policy explains how Crestora Labs, a division of Crestora Property Group LLC ("we," "us," or "our"), handles personal information across our website, subscriptions, and software (the "Services"). We are a United States-based company, and this Policy is written to align with the GDPR, UK GDPR, and CCPA/CPRA. It does not cover third-party sites or services we don't control, even where linked from ours.

2

Information We Collect

Depending on how you use the Services, we collect:

  • Account & contact — your email and any name or organization you provide.
  • Subscription & payment — plan, seats, billing status, and transaction history. Payments are processed by Stripe; we do not store full card numbers and typically receive only the card's last four digits, brand, and a transaction identifier.
  • Licensing & activation — your account email and subscription/seat data, a hashed device fingerprint that binds a licence to an authorized device, and basic application, version, and operating-system details sent at activation and validation.
  • Support — the content of messages you send us.
  • Website & cookies — standard technical data (IP address, browser, device, referring pages) and cookies, as described in our Cookie Policy.
3

How We Use It

  • Provide, activate, secure, maintain, and improve the Services, including updates.
  • Process subscriptions, payments, renewals, and seat/licence entitlements.
  • Authenticate users, enforce device- or seat-bound licensing, and prevent fraud or abuse.
  • Provide support and send service-related messages (activation, receipts, renewals, security notices).
  • Meet legal obligations and enforce our Terms.
4

Legal Bases (GDPR)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to deliver the Services you subscribe to), legitimate interests (to secure and improve the Services and prevent abuse, balanced against your rights), consent (for certain cookies, analytics, and optional communications — you may withdraw it at any time), and legal obligation.

5

How We Share It

We do not sell your personal information. We share it only with service providers who help us operate the Services:

  • Stripe — payments and billing.
  • Microsoft 365 — business email and communications.
  • OVHcloud — hosting (data centers in Canada and the United States).
  • Cloudflare — CDN, DNS, and web application firewall (WAF) security.

We may also disclose information to professional advisors, in connection with a merger or asset sale, or where required by law or to protect rights and safety. Business customers may be covered by our Data Processing Agreement, which strictly governs shorter deletion timelines for customer-owned data.

6

Cookies

We and certain third parties use cookies on the Website; our desktop applications do not use browser cookies. See our Cookie Policy for details and controls.

7

Data Retention

We keep personal information only as long as needed for the purposes above and to meet our legal, tax, and accounting obligations. Retention periods are typically:

  • Account and subscription data — the customer relationship plus up to 3 years.
  • Payment and transaction records — up to 7 years (U.S. tax and accounting).
  • Device fingerprint and activation data — the subscription plus up to 2 years.
  • Support communications — up to 2 years, longer where needed for legal or security reasons.

When it is no longer needed, we delete or anonymize it.

8

Security

We use technical and organizational measures to protect personal information, including encryption in transit and at rest, access controls, device binding, and hashed device fingerprints. No system is completely secure, so we cannot guarantee absolute security. Please keep your account credentials confidential.

If a personal-data breach affects your information, we will notify you and the appropriate authorities where, and within the time, the law requires.

9

International Transfers

As a U.S.-based company using service providers in the United States, Canada, the EU, and elsewhere, personal information may be transferred across borders. Where it is, we rely on recognized safeguards such as the European Commission's Standard Contractual Clauses. See our Data Processing Agreement for details.

10

Your Rights

Subject to applicable law, you may access, correct, delete, restrict or object to processing, and export your personal information, withdraw consent, and lodge a complaint with a supervisory authority. California residents (CCPA/CPRA) have equivalent rights, and we do not sell or share personal information as those terms are defined there. To exercise any right, contact us below; we will verify your request and respond within the time the law requires, and you may use an authorized agent where permitted.

If we decline your request, you may appeal by contacting us using the details in Section 13; where the law of your state grants a right to appeal, we will respond within the period the law requires.

11

Children

The Services are not directed to children, and we do not knowingly collect information from anyone under 16 (or under 13 in the United States). If you believe a child has given us information, contact us and we will delete it.

12

Changes

We may update this Policy from time to time. For material changes we will update the "Last updated" date above and, where appropriate, provide notice. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

13

Contact Us

For questions or to exercise your rights, contact [email protected], or write to:

Crestora Labs
6300 N Wickham Rd
# 130 - 422
Melbourne, FL 32940
United States

EU Representative & Data Protection Officer

As a U.S. company that does not target individuals in the European Union, we are not required to appoint an Article 27 EU representative, and we have not appointed a Data Protection Officer. For privacy questions, email [email protected].

Still have questions?

We're happy to help — reach out any time.

Email [email protected]