CrewsForge — Privacy Policy
Last updated: 21.03.2026
Effective date: 22.03.2026
This Privacy Policy explains how Ryomen Corporation, a Wyoming corporation ("CrewsForge", "we", "us"), collects, uses, shares, and protects personal data when you use [crewsforge.com] and the CrewsForge application (the "Platform").
Read this together with our Terms of Service and Cookie Policy.
1. Who We Are and How to Reach Us
Controller: Ryomen Corporation, 30 N Gould St #66355, Sheridan, WY 82801, USA
- Privacy enquiries and rights requests: support@crewsforge.com
- Security issues: support@crewsforge.com
Our operations team is located in the United States, and Platform infrastructure is hosted in [REGION — e.g. the European Union]. See Section 9 on international transfers.
2. Who This Policy Covers
This Policy applies to:
- Founders — Users who scope, fund, and receive project work;
- Teams — Users who perform project work, including their individual members;
- Visitors — anyone browsing the public website;
- Contacts — people whose details reach us through referrals, partners, or business correspondence.
A note on project content. When a Founder or a Team uploads documents, briefs, or deliverables containing personal data about other people (their own customers, employees, or contractors), that User determines the purpose of that data and is independently responsible for it. We process it on their behalf as part of running the Platform. That User must have a lawful basis for uploading it and must not upload categories of data the Platform is not designed to hold — in particular health data, biometric data, payment card numbers, or government identifiers outside the verification flow described in Section 4.4.
3. Data We Collect
3.1 Data you give us
| Category | Examples |
|---|---|
| Account data | Name, email, password hash, role, language, timezone |
| Profile data | Company name, website, portfolio, skills, rates, team composition, biography, avatar |
| Project data | Briefs, requirements, roadmaps, Milestones, Acceptance Criteria, deliverables, uploaded documents |
| Communications | On-Platform messages, support tickets, dispute submissions and evidence |
| AI Consultant inputs | Prompts, questions, and documents you upload to the AI Consultant |
| Verification data | Identity documents, business registration, beneficial ownership, tax identifiers, sanctions-screening results — collected primarily by our payment processor (Section 4.4) |
| Payout data | Bank or payout account details, held by our payment processor |
| Marketing data | Newsletter subscriptions, event registrations, survey responses |
3.2 Data collected automatically
| Category | Examples |
|---|---|
| Device and connection | IP address, browser, operating system, device type, language |
| Usage | Pages viewed, features used, funnel steps completed, timestamps, referring URL |
| Security | Login attempts, session tokens, fraud and abuse signals |
| Diagnostics | Error reports, performance traces, application logs |
| Cookies | See the Cookie Policy |
3.3 Data from third parties
- Payment processor (Stripe) — verification status, payout status, chargeback and dispute notifications.
- Lead-generation and referral partners — contact details, where the partner has a lawful basis to share them.
- Public sources — company registries, professional networks, and public websites, used to validate Team information.
- Sanctions and watchlist providers — screening results required by law.
3.4 What we do not collect
We do not collect special-category data (racial or ethnic origin, political opinions, religion, trade union membership, genetic or biometric data, health, sex life or sexual orientation) and ask that you do not provide it. We do not knowingly collect data from anyone under 18 (Section 12).
4. Why We Use Your Data, and Our Legal Basis
Legal bases below refer to the GDPR / UK GDPR. Where other laws apply, we rely on the equivalent basis.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and administer your account | Account, profile | Contract (Art. 6(1)(b)) |
| Operate Projects, Milestones, and Acceptance Criteria | Project, communications | Contract |
| Match Founders with Teams (manual review by our Operators) | Profile, project | Contract; legitimate interests |
| Provide the AI Consultant | AI inputs, project | Contract |
| Process payments and hold Milestone funds | Payment, payout, account | Contract; legal obligation |
| Identity verification, KYC, AML, sanctions screening | Verification | Legal obligation (Art. 6(1)(c)) |
| Resolve disputes between Users | Project, communications, evidence | Contract; legitimate interests in a functioning dispute mechanism |
| Prevent fraud, abuse, and security incidents | Device, security, usage | Legitimate interests (Art. 6(1)(f)) |
| Improve and debug the Platform | Usage, diagnostics | Legitimate interests; consent where cookie-based |
| Send service and transactional messages | Account, project | Contract |
| Send marketing emails | Marketing, account | Consent, or legitimate interests for existing customers where permitted |
| Comply with tax, accounting, and legal obligations | Payment, account | Legal obligation |
| Establish, exercise, or defend legal claims | As relevant | Legitimate interests; legal claims (Art. 9(2)(f) where applicable) |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You may object at any time (Section 10).
5. The AI Consultant
5.1 How it works. The AI Consultant processes your prompts and uploaded documents to produce roadmaps, technology recommendations, role breakdowns, and budget estimate ranges.
5.2 Third-party model providers. We deliver AI features using third-party providers, currently [PROVIDER(S)]. Your inputs and the resulting outputs are transmitted to and processed by those providers under enterprise agreements that include confidentiality and security commitments.
5.3 Training. [We have contracted with our model providers so that your inputs and outputs are not used to train their general-purpose models.] [If we ever wish to use your content to improve our own systems, we will ask for your consent first.]
5.4 Retention by providers. Providers may retain inputs for a limited period for abuse monitoring, typically up to [30] days, after which they are deleted. Retention on our own systems is described in Section 8.
5.5 No automated decisions with legal effect. AI output is advisory. It does not determine whether you are accepted onto the Platform, whether a Team is matched to a Project, or how a dispute is decided — see Section 11.
5.6 What not to upload. Do not submit personal data you are not entitled to disclose, and do not submit payment card numbers, passwords, health data, or identity documents to the AI Consultant.
6. Who We Share Data With
We do not sell personal data. We share it only as follows.
6.1 With other Users. Founders and Teams see each other's profile and project data as necessary to evaluate, negotiate, and perform a Project. A Team's profile and reputation are visible to Founders considering it. Dispute submissions are shared with the other party.
6.2 With service providers (processors), under written agreements limiting them to our instructions:
| Provider | Function | Location |
|---|---|---|
| Stripe, Inc. | Payments, payouts, KYC, fraud | USA / EU |
| [Cloud / VPS provider] | Hosting, storage | [REGION] |
| [Email provider] | Transactional and marketing email | [REGION] |
| [AI model provider(s)] | AI Consultant | [REGION] |
| [Analytics provider] | Product analytics | [REGION] |
| [Error monitoring provider] | Diagnostics | [REGION] |
| [Support tooling] | Customer support | [REGION] |
6.3 With independent controllers. Stripe acts as an independent controller for payment processing, KYC, and fraud prevention, and processes your data under its own privacy policy.
6.4 With professional advisors — lawyers, accountants, auditors, and insurers, bound by confidentiality.
6.5 For legal reasons. We may disclose data where required by law, court order, or a valid request from a competent authority, or where necessary to protect our rights, your safety, or the safety of others. [Where legally permitted, we will notify you before disclosing.]
6.6 On a corporate transaction. If we are involved in a merger, acquisition, financing, or sale of assets, data may be transferred, subject to the protections in this Policy.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, hashed passwords, role-based access control, least-privilege access for staff, audit logging, network segmentation, monitoring and alerting, dependency scanning, and regular backups.
No system is perfectly secure. If a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and notify you without undue delay where the risk is high.
Report vulnerabilities to support@crewsforge.com. We will not pursue good-faith security research conducted under our responsible disclosure guidelines.
8. How Long We Keep Data
| Data | Retention |
|---|---|
| Account and profile | While the account is active, then [24] months |
| Project, Milestone, and deliverable records | [7] years from Project closure — evidentiary and contractual |
| Financial and tax records | [7] years — legal obligation |
| KYC and verification records | [5] years after the relationship ends — AML obligation |
| Dispute records and decisions | [7] years |
| On-Platform messages | While the account is active, then [24] months |
| AI Consultant inputs and outputs | [12] months, unless part of a Project record |
| Security and access logs | [12] months |
| Diagnostic logs | [90] days |
| Marketing data | Until you unsubscribe, then [24] months for suppression |
| Cookies | See the Cookie Policy |
Where data must be kept for one purpose but not another, we restrict access and stop active use. Anonymised and aggregated data may be kept indefinitely.
9. International Transfers
CrewsForge is established in the United States, and our providers operate in the EU, UK, US, and elsewhere. Your data will therefore be transferred across borders.
Where personal data is transferred out of the EEA or UK, we rely on:
- the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by transfer risk assessments and technical measures; or
- an adequacy decision, where one covers the recipient; or
- the EU–US Data Privacy Framework, where the recipient is certified.
You may request a copy of the safeguards we use by writing to support@crewsforge.com.
10. Your Rights
Subject to your location and to legal limits, you may:
- Access the personal data we hold about you, and obtain a copy;
- Rectify inaccurate or incomplete data;
- Erase data, where we no longer have a basis to keep it;
- Restrict processing while a dispute about accuracy or legitimacy is resolved;
- Object to processing based on legitimate interests, and to direct marketing at any time and absolutely;
- Port data you gave us, in a structured machine-readable format;
- Withdraw consent where processing is based on it, without affecting prior processing;
- Not be subject to solely automated decisions with legal or similarly significant effects (Section 11);
- Complain to your supervisory authority — in the EEA, your national DPA; in the UK, the ICO.
Californian residents (CCPA/CPRA) additionally have the right to know the categories collected, disclosed, and sold or shared; to delete; to correct; to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights. We do not sell personal information and do not share it for cross-context behavioural advertising. Requests may be made by an authorised agent.
How to exercise. Write to support@crewsforge.com. We will respond within 30 days (extendable by 60 days for complex requests, with notice). We may ask you to verify your identity. Requests are free unless manifestly unfounded or excessive.
Limits. Erasure may be refused where we must retain data for financial, tax, AML, or dispute-evidence reasons, or to establish or defend legal claims. In that case we restrict the data rather than delete it.
11. Automated Decision-Making and Profiling
Team matching on CrewsForge is performed manually by our Operators. We do not use algorithmic matching, and no algorithm decides whether a Team is shown a Project.
We use automated processing in two limited areas:
- Fraud and security screening, including checks performed by our payment processor. A high-risk signal may lead to a hold, additional verification, or suspension. A human reviews any decision that materially affects your account before it becomes final.
- AI Consultant output, which is advisory only and produces no decision about you.
If you believe an automated process has affected you unfairly, contact support@crewsforge.com — you may obtain human review, express your view, and contest the outcome.
12. Children
The Platform is for business use by adults. It is not directed at anyone under 18, and we do not knowingly collect their data. If you believe a minor has given us personal data, contact support@crewsforge.com and we will delete it.
13. Marketing
We send marketing email only where you have consented, or where you are an existing customer and the law permits messages about similar services. Every marketing email carries an unsubscribe link, and unsubscribing takes effect promptly.
Transactional messages — Milestone approvals, payment notifications, dispute updates, security alerts — are part of the service and cannot be unsubscribed from while your account is active.
14. Changes to This Policy
We may update this Policy. The "Last updated" date reflects the current version. For material changes we will notify you by email or through the Platform at least [30] days before they take effect. Where a change requires consent, we will ask for it.
Previous versions are available on request.
15. Contact
Ryomen Corporation
30 N Gould St #66355
Sheridan, WY 82801, USA
General: support@crewsforge.com
This document is a drafting template prepared for CrewsForge and is not legal advice. It must be completed from an actual data-mapping exercise and reviewed by qualified counsel in each jurisdiction where the Platform is offered before publication.