Privacy Policy

Version 1.2 · Effective 2 September 2026 · Permanent link to this version

This policy explains what Embedded Video processes, in two very different roles: as the controller of data about you, our merchant customer, and as a processor of limited data about visitors to your store.

1. Merchant accounts (we are the controller)

To operate your account we process: your name and email address (held with our sign-in provider, Clerk), your subscription and billing history, the videos you upload, and records of acceptance of our terms (timestamp, document version, a hash of the exact text served, IP address and browser identification at the moment of acceptance).

For every upload we keep a technical record: file name, declared type, size, a SHA-256 hash of the file, what a technical probe of the file found, and the IP address the upload was made from. The IP address is kept for the life of the content plus twelve months and is then deleted automatically. The rest of the record is retained as evidence of what was uploaded, including after the video itself is deleted — this is what allows us to answer rights holders and authorities accurately.

2. Store visitors (we are your processor)

When a visitor views a page with the widget, we deliver video to their browser and, where analytics is enabled, receive a small usage beacon. That beacon contains: the video id, the page address (with any query string removed), coarse device class (mobile or desktop), and event counts (views, plays, expands, dismisses).

It contains no cookie, no visitor identifier, and no fingerprint; we do not store visitors' IP addresses with analytics data. Aggregated statistics are what your dashboard shows; the raw beacons are deleted within 90 days. Delivery logs used for billing are aggregated per store per day.

One thing is stored on the visitor's device, and only during an A/B test. If you are running two or more versions of a clip against each other, the widget remembers which version that browser was shown, so a visitor is not given a different one on every page. It is a single entry holding a video id and an expiry date. It is not an identifier: every visitor in the same arm of the same test holds the same value, it says nothing about who they are, and it cannot be used to recognise anyone. It is written inside our own frame, so your store — and any other site — cannot read it. It is removed when the test ends or the entry expires, and it is not written at all for visitors whose analytics you have switched off, who have not given consent where you have set the widget to wait for it, or whose browser sends Global Privacy Control. Outside an A/B test the widget writes nothing to the visitor's device.

The widget offers controls for consent-gated markets: an analytics=off mode, an analytics=consent mode that sends nothing until your consent tool says otherwise, and it honours the Global Privacy Control signal. As the operator of your store, choosing and operating the right mode for your audience is your responsibility as controller.

3. Where data lives and who touches it

The Service runs on Amazon Web Services in the EU (Ireland). Sign-in is provided by Clerk. We do not sell data, and we share it only with these processors, on our instructions.

4. Your rights

You can access, correct and delete your account data. Deleting a video removes it from delivery immediately and from storage promptly, subject to the retention of the upload record described in section 1. To exercise any right, or to ask us to act on a request from one of your store's visitors, write to abuse@crimsonwren.com — we respond within 30 days.

5. Changes

Material changes will be presented in the dashboard before they take effect. Every version of this policy stays permanently available at its own address.

Contact

[Legal entity name — to be completed], contactable at abuse@crimsonwren.com. See the imprint for the registered address.