1. Who We Are

CrocoDealer is an independent software and technology project operated by Ruslan Korolev, an individual located in Botswana.

This Privacy Policy explains how CrocoDealer ("CrocoDealer", "we", "us" or "our") collects, uses, stores, shares and protects personal information in connection with crocodealer.com, CrocoDealer software, APIs, centralized authentication services, hosting infrastructure, SaaS products and related services (collectively, the "Service").

Contact for privacy matters: privacy@crocodealer.com.

2. CrocoDealer's Different Data-Processing Roles

CrocoDealer may process personal data in different legal roles depending on why the data is processed.

2.1 CrocoDealer as Controller

CrocoDealer generally acts as a controller for personal data used for its own purposes, including:

  • CrocoDealer account administration;
  • centralized authentication and identity infrastructure;
  • security and fraud prevention;
  • billing and subscription administration;
  • technical support;
  • service telemetry and operational logs;
  • legal compliance;
  • communications with customers and users;
  • management and improvement of the CrocoDealer platform.

2.2 CrocoDealer as Processor

When a customer uses CrocoDealer to host or process personal data for the customer's own business, website, store, marketplace or other Customer Project, CrocoDealer may act as a data processor on behalf of that customer.

In those circumstances, the customer generally determines the purposes of processing and is responsible for providing required notices, establishing a lawful basis and issuing lawful processing instructions to CrocoDealer.

CrocoDealer processes such data according to applicable law, the customer's documented instructions, these Terms and any additional data-processing agreement between the parties.

3. Centralized Authentication Across CrocoDealer-Powered Projects

CrocoDealer may provide a centralized identity and authentication service used by multiple websites, applications or Customer Projects built on CrocoDealer technology.

This means that technical account identifiers, authentication records, security information and login-related information may be processed centrally by CrocoDealer even where a user interacts with a particular Customer Project rather than directly with crocodealer.com.

Where supported, users may authenticate through third-party identity providers such as Google. CrocoDealer may receive information made available by the provider according to the permissions and authentication flow shown to the user, such as an account identifier, name, profile image and email address.

A Customer Project's own privacy policy may provide additional information about how that project uses information obtained through CrocoDealer services.

4. Information We May Collect

4.1 Account and Identity Information

  • name and display name;
  • email address;
  • telephone number where provided;
  • account and internal user identifiers;
  • authentication-provider identifiers;
  • profile image where provided by the user or authentication provider;
  • country, region, language and account preferences;
  • roles, permissions and organization membership.

4.2 Customer and Business Information

  • business or project name;
  • contact information;
  • subscription and plan information;
  • billing and transaction references;
  • support requests and communications;
  • configuration and integration information;
  • authorized personnel and user roles.

4.3 Customer Project Data

Depending on the customer's use of the Service, CrocoDealer may technically process data such as:

  • product and catalog records;
  • customer and CRM records;
  • orders and sales records;
  • warehouse, inventory and stock information;
  • messages and communications;
  • uploaded files and images;
  • user profiles and account information;
  • reports and operational records;
  • other information submitted to a Customer Project.

Where this information is processed solely on behalf of a customer, CrocoDealer processes it in its role as processor rather than using it for unrelated independent purposes.

4.4 Technical and Usage Information

  • IP address;
  • browser and device information;
  • operating system;
  • language and locale;
  • dates and times of access;
  • session and authentication events;
  • API requests and technical logs;
  • error reports and diagnostics;
  • security events and fraud indicators;
  • approximate location derived from network information;
  • feature and service usage information;
  • cookies and similar identifiers.

5. Why We Process Personal Information

CrocoDealer may process personal information to:

  • provide, host and maintain the Service;
  • authenticate users;
  • operate centralized user accounts;
  • provide SaaS functionality to Customer Projects;
  • store and process Customer Project data on customer instructions;
  • manage subscriptions and paid service periods;
  • provide APIs, integrations and messaging;
  • provide product, CRM, warehouse, inventory, order and reporting functionality;
  • provide technical support;
  • diagnose errors and maintain reliability;
  • protect accounts and systems;
  • detect fraud, abuse and security threats;
  • enforce CrocoDealer Terms of Service;
  • respond to lawful legal requests;
  • establish, exercise or defend legal claims;
  • meet legal and regulatory obligations;
  • improve, secure and develop CrocoDealer technology.

6. Legal Bases

Where applicable law requires a legal basis for processing, CrocoDealer may rely on one or more of:

  • Contract: processing necessary to provide an account, paid SaaS service or other requested functionality.
  • Legitimate interests: operating, protecting, securing, improving and administering the Service, where those interests are not overridden by applicable rights.
  • Legal obligation: processing necessary to comply with applicable law or binding legal requirements.
  • Consent: where consent is required for a particular optional feature, communication, cookie or other processing activity.
  • Customer instructions: where CrocoDealer acts as processor on behalf of a customer that is responsible for establishing an appropriate legal basis.

7. Customer Ownership and Data Access

CrocoDealer does not claim ownership of customer-created content, business records or personal data merely because the information is stored or processed using the Service.

Customers retain their rights in Customer Data, subject to third-party rights and applicable law. CrocoDealer retains ownership of its software, technology, database architecture, APIs, algorithms, internal systems, source code and other platform intellectual property.

A customer's right to receive its data does not include a right to inspect, obtain or copy CrocoDealer source code, internal databases as technological structures, server configuration, algorithms, proprietary schemas, deployment systems or trade secrets.

8. Data Export

Subject to applicable law and the CrocoDealer Terms of Service, customers may request an export of available Customer Data in a commonly used machine-readable format supported by CrocoDealer, such as CSV, JSON or another reasonable export format.

Individual data subjects may also have statutory rights to obtain copies or portability of personal data in circumstances defined by applicable data-protection law.

Data export does not require CrocoDealer to provide software, source code, internal systems or proprietary technical structures.

9. Cookies and Similar Technologies

CrocoDealer and CrocoDealer-powered projects may use cookies, local storage and similar technologies for:

  • authentication and session management;
  • security and fraud prevention;
  • language and preference settings;
  • service functionality;
  • performance monitoring;
  • analytics where permitted.

Where applicable law requires consent for non-essential technologies, appropriate consent mechanisms should be used before those technologies are activated.

10. Service Providers and Subprocessors

CrocoDealer does not sell personal data.

CrocoDealer may use carefully selected service providers and subprocessors where reasonably necessary to operate the Service. These may include providers of:

  • cloud and server infrastructure;
  • content delivery and network services;
  • email and communications delivery;
  • identity and authentication services;
  • security and anti-abuse services;
  • monitoring and error diagnostics;
  • backup and storage services;
  • payment or billing infrastructure where applicable;
  • other technical services necessary to provide requested functionality.

Such providers may process only the information reasonably necessary for their role, subject to applicable contractual and legal protections.

CrocoDealer does not provide customer databases to unrelated third parties for their own advertising, resale or independent commercial exploitation.

11. Law Enforcement, Courts and Authorities

CrocoDealer does not provide police, governments or other authorities with unrestricted or routine access to Customer Data.

CrocoDealer may preserve or disclose personal information where required or permitted by applicable law, including in connection with a legitimate investigation, valid court order, warrant, subpoena, regulatory requirement or other lawful process from a competent authority.

Where legally and practically appropriate, CrocoDealer may:

  • verify the authority of the requester;
  • require appropriate legal process;
  • request clarification or a narrower request;
  • disclose only information responsive to the lawful request;
  • challenge invalid, unlawful or excessively broad requests;
  • notify affected customers or users where legally permitted.

12. International Data Processing and Transfers

CrocoDealer is designed to support international services and may use infrastructure, customers, service providers and users located in different countries.

Personal data may therefore be processed in countries other than the country in which the data subject or customer is located.

CrocoDealer will seek to conduct international transfers in accordance with applicable data-protection law, including using legally recognized transfer mechanisms or safeguards where required.

Where Botswana law requires a copy of personal data transferred from Botswana to remain in Botswana for the relevant processing period, CrocoDealer will apply that requirement to processing within the scope of that law.

13. Data Security

CrocoDealer uses reasonable technical and organizational measures intended to provide a level of security appropriate to the nature and risks of the relevant processing.

Measures may include, as appropriate:

  • access controls and permissions;
  • authentication controls;
  • encryption or pseudonymization where appropriate;
  • system monitoring and logging;
  • backup and recovery measures;
  • security testing and maintenance;
  • confidentiality obligations for authorized personnel.

No internet-connected service can guarantee absolute security, and CrocoDealer does not represent that breaches, cyberattacks, unauthorized access or data loss can never occur.

14. Personal Data Breaches

If CrocoDealer becomes aware of a personal-data breach, it will assess the incident, take reasonable containment and remediation steps, and provide notifications or assistance required by applicable law.

Where CrocoDealer acts as processor for a customer, CrocoDealer will provide information reasonably necessary for the customer to meet applicable breach-response obligations, subject to applicable law and the circumstances of the incident.

15. Data Retention

CrocoDealer retains personal information only for as long as reasonably necessary for the purposes for which it is processed and as required or permitted by applicable law.

Retention may depend on:

  • whether an account or paid Service remains active;
  • customer instructions;
  • contractual obligations;
  • fraud and security requirements;
  • backup cycles;
  • technical recovery requirements;
  • pending disputes or legal claims;
  • applicable limitation periods;
  • legal or regulatory requirements.

Information no longer required may be deleted, anonymized or otherwise handled according to applicable law.

16. Data After Customer Termination

When a customer stops using CrocoDealer, Customer Data may remain available for a limited period to permit export, recovery, backup rotation, security review, legal compliance or dispute resolution.

CrocoDealer is not required to retain a complete operational copy of a terminated Customer Project indefinitely.

Customers should request and securely store any required export before applicable retention periods expire.

17. Data Subject Rights

Depending on applicable law and CrocoDealer's role in the relevant processing, individuals may have rights to:

  • obtain information about processing;
  • request access to personal data;
  • obtain a copy of personal data;
  • request correction of inaccurate data;
  • request deletion where legally applicable;
  • request restriction of processing;
  • object to certain processing;
  • request data portability where legally applicable;
  • withdraw consent where processing is based on consent;
  • complain to an applicable supervisory authority.

Requests concerning CrocoDealer-controlled account or authentication information may be sent to privacy@crocodealer.com.

Where CrocoDealer processes personal data solely on behalf of a Customer Project, a request may need to be handled by that customer as controller. CrocoDealer may forward or refer the request to the relevant customer and will provide legally required assistance.

18. Verification of Privacy Requests

CrocoDealer may take reasonable steps to verify the identity and authority of a person submitting a privacy request before disclosing, changing, exporting or deleting personal information.

This is intended to protect users against unauthorized requests and account takeover.

19. Sensitive and Highly Regulated Data

Customers should not use CrocoDealer to process sensitive, criminal-offence, biometric, health or other highly regulated personal data unless the relevant CrocoDealer service is appropriate for that processing and the customer has established a lawful basis and any safeguards required by applicable law.

CrocoDealer may restrict processing that creates legal, security or compliance risks not reasonably supported by the Service.

20. Aggregated and Anonymized Information

CrocoDealer may create aggregated or anonymized statistics that do not identify an individual and do not reveal confidential Customer Data.

CrocoDealer may use such information for analytics, capacity planning, security, benchmarking, service improvement, research and development and general business operations.

21. Third-Party Services

CrocoDealer-powered services may integrate with independent third-party services. Information sent directly by a user or customer to an independent third party may be governed by that third party's own privacy policy and terms.

CrocoDealer is not responsible for independent processing performed by third parties outside CrocoDealer's control.

22. Children

CrocoDealer's commercial SaaS services are not intended to be independently contracted for by children. Customer Projects that permit use by minors are responsible for implementing age, consent and parental-control requirements applicable to their own services, while CrocoDealer will comply with obligations that apply directly to CrocoDealer's own processing.

23. Automated Security and Operational Systems

CrocoDealer may use automated systems to detect spam, fraud, suspicious authentication, unusual API activity, malicious behavior, infrastructure attacks, duplicate activity and other security or operational signals.

Where applicable law gives an individual rights regarding automated decisions that produce legal or similarly significant effects, CrocoDealer will respect those rights in processing for which CrocoDealer is the responsible controller.

24. Changes to This Privacy Policy

CrocoDealer may update this Privacy Policy to reflect changes in technology, infrastructure, law, Service features or data-processing practices.

The latest version will be published with its effective date. Additional notice will be provided where required by law.

25. Contact

CrocoDealer

Operator / Data Controller for CrocoDealer-controlled processing: Ruslan Korolev

Country: Botswana

Service address: P.O. BOX 47604, Phakalane, Gaborone, Botswana

Privacy: privacy@crocodealer.com

Legal: legal@crocodealer.com

Abuse / take-down notices: abuse@crocodealer.com

Support: support@crocodealer.com