Privacy policy
1. Introduction
Crocadilo, a SaaS platform for creating Digital Business Cards and Digital WhatsApp Stores, operated by CVC International Ltd (UK-based), is committed to protecting the privacy and security of the data handled within the application. The platform is GDPR compliant. Users of the platform retain full ownership of their data
2. Data Collected:
The Crocadilo platform collects and processes data related to user account creation, service usage, financial history, and prospect engagement:
Data Storage Location
While the specific geographical data center location is not detailed in the provided documentation, the parent company, CVC International Ltd, is UK-based. The platform adheres to GDPR compliance standards
Registration Data
To access the SaaS portal (backend.crocadilo.com), the following data is collected upon sign-up and login:
• Email and Password.
• Credentials verified through Google Sign-In for a faster login experience.
• Verification data (e.g., CAPTCHA response)
Registration Data
Data related to user subscriptions and physical products is logged and tracked:
• Earnings (if applicable).
• Transactions (financial history associated with the account).
• My Orders (tracking purchases of hardware, such as NFC Cards or Wearables)
Support Data
Data is collected concerning user configuration and service interactions:
• Consultation Data: Setup of the AI Digital Agent is a managed service that requires consultation with a Crocadilo Account Manager.
• Service Configuration: Email addresses provided by the user to receive service booking confirmations and inquiry routing
Leads, Engagement, and Logging Data (Inquiry and Appointment)
The platform automatically logs customer interactions and lead data to the backend portal/Dashboard,:
• Visitor Log: Tracks which prospects or individuals view the user's digital card.
• Inquiry Log: Provides a centralized view of messages and leads captured through the card.
• Newsletter Data: Visitor email addresses captured via the Newsletter Popup.
• Appointment Manager: Collects and displays a calendar view of client bookings. Auto-confirmation emails are sent to both the prospect and the card owner upon booking
Contact Form
When a prospect uses the standard Contact Form feature:
• The form captures the prospect's Name, Message, and Email.
• This data is emailed directly to the card owner for manual response. The card owner must configure the routing email address.
Google Analytics
We use Google Analytics on our site for anonymous reporting of site usage. So, no personalized data is stored.
The platform also allows users to manage their own analytics tracking:
• Users can integrate external tools like Google Analytics (GA4) and Tag Manager by adding custom JavaScript code to their card
If you would like to opt-out of Google Analytics monitoring your behavior on our website please use this link: Google Analytics Opt-out.
Cases for using the personal data
Collected data is used to provide service, track performance, and automate sales processes:
• Performance Tracking: Data is used to display key metrics such as View counts, earnings, and current week sales.
• Service Delivery: Data (like contact information and configured business hours) is used to enable Appointment Booking (generating available slots and sending auto-confirmation emails).
• Automated Sales: Data is leveraged by the AI Digital Agent to log leads and inquiries automatically, and to trigger automated email sequences for follow-up.
• SEO: Configuration data (Meta Title, Meta Description, Keywords) is used to optimize the digital card's appearance in search results.
3. Embedded Content
Pages on this site may include embedded content, like YouTube videos, for example. Embedded content from other websites behaves in the exact same way as if you visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website. Below you can find a list of the services we use:
The Facebook page plugin is used to display our Facebook timeline on our site. Facebook has its own cookie and privacy policies over which we have no control. There is no installation of cookies from Facebook and your IP is not sent to a Facebook server until you consent to it. See their privacy policy here: Facebook Privacy Policy.
We use the Twitter API to display our tweets timeline on our site. Twitter has its own cookie and privacy policies over which we have no control. Your IP is not sent to a Twitter server until you consent to it. See their privacy policy here: Twitter Privacy Policy.
Youtube
We use the Twitter API to display our tweets timeline on our site. Twitter has its own cookie and privacy policies over which we have no control. Your IP is not sent to a Twitter server until you consent to it. See their privacy policy here: YouTube Privacy Policy.
4. Cookies
This site uses cookies – small text files that are placed on your machine to help the site provide a better user experience. In general, cookies are used to retain user preferences, store information for things like shopping carts, and provide anonymised tracking data to third party applications like Google Analytics. Cookies generally exist to make your browsing experience better. However, you may prefer to disable cookies on this site and on others. The most effective way to do this is to disable cookies in your browser. We suggest consulting the help section of your browser.
Necessary Cookies (all site visitors)
cfduid: Is used for our CDN CloudFlare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. See more information on privacy here: CloudFlare Privacy Policy.
PHPSESSID: To identify your unique session on the website.
Necessary Cookies (Additional for Logged in Customers)
wp-auth: Used by WordPress to authenticate logged-in visitors, password authentication and user verification.
wordpress_logged_in_{hash}: Used by WordPress to authenticate logged-in visitors, password authentication and user verification.
wordpress_test_cookie: Used by WordPress to ensure cookies are working correctly.
wp-settings-[UID]: WordPress sets a few wp-settings-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface.
wp-settings-[UID]:WordPress also sets a few wp-settings-{time}-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface.
5. Who Has Access To Your Data
If you are not a registered client for our site, there is no personal information we can retain or view regarding yourself.
If you are a client with a registered account, your personal information can be accessed by:
• Our system administrators.
• Our supporters when they (in order to provide support) need to get the information about the client
6. Third Party Access to Your Data
The platform facilitates the flow of data to and from third parties based on the user's configuration, but the user controls these integrations:
• External Links: Users link to external services such as PayPal or Stripe via Payment Links and embed videos from YouTube.
• Analytics: Users can inject custom JavaScript for Google Analytics (GA4) and Tag Manager.
• CRM Integration: The AI Digital Agent is capable of integrating with CRMs for lead management.
• Login Services: Users utilize their Google credentials for fast sign-in.
7. How Long We Retain Your Data For
When you submit a support ticket or a comment, its metadata is retained until (if) you tell us to remove it. We use this data so that we can recognize you and approve your comments automatically instead of holding them for moderation.
If you register on our website, we also store the personal information you provide in your user profile. You can see, edit, or delete your personal information at any time (except changing your username). Website administrators can also see and edit that information.
8. Security Measures
We use the SSL/HTTPS protocol throughout our site. This encrypts our user communications with the servers so that personally identifiable information is not captured/hijacked by third parties without authorization.
In case of a data breach, system administrators will immediately take all needed steps to ensure system integrity, will contact affected users and will attempt to reset passwords if needed.
9. Your data rights
Crocadilo ensures users have primary control and ownership over their data:
• Data Ownership: Users retain full ownership of data collected through their cards.
• Right to Delete: Users can delete their accounts and information at any time.
• Data Management: Users manage their inquiries, appointments, and general logs via the backend portal/Dashboard,.
GDPR Rights
Your privacy is critically important to us. Going forward with the GDPR we aim to support the GDPR standard. ThemeREX permits residents of the European Union to use its Service. Therefore, it is the intent of Crocadilo to comply with the European General Data Protection Regulation. For more details please see here: EU GDPR Information Portal.
10. Third Party Websites
Crocadilo may post links to third party websites on this website. These third party websites are not screened for privacy or security compliance by Crocadilo and you release us from any liability for the conduct of these third party websites.
All social media sharing links, either displayed as text links or social media icons do not connect you to any of the associated third parties unless you explicitly click on them.
Please be aware that this Privacy Policy, and any other policies in place, in addition to any amendments, does not create rights enforceable by third parties or require disclosure of any personal information relating to members of the Service or Site. Crocadilo bears no responsibility for the information collected or used by any advertiser or third party website. Please review the privacy policy and terms of service for each site you visit through third party links.
11. Release of Your Data for Legal Purposes
At times it may become necessary or desirable to Crocadilo, for legal purposes, to release your information in response to a request from a government agency or a private litigant. You agree that we may disclose your information to a third party where we believe, in good faith, that it is desirable to do so for the purposes of a civil action, criminal investigation, or other legal matter. In the event that we receive a subpoena affecting your privacy, we may elect to notify you to give you an opportunity to file a motion to quash the subpoena, or we may attempt to quash it ourselves, but we are not obligated to do either. We may also proactively report you, and release your information to, third parties where we believe that it is prudent to do so for legal reasons, such as our belief that you have engaged in fraudulent activities. You release us from any damages that may arise from or relate to the release of your information to a request from law enforcement agencies or private litigants.
Any passing on of personal data for legal purposes will only be done in compliance with laws of the country you reside in.
Last updated: 15 Dec, 2025