Privacy Policy
Last updated: 2026-07-27
This policy describes what Crail actually collects and does today. It is provided for transparency and is not a substitute for legal advice — if you need a compliance-grade policy for a specific jurisdiction, have it reviewed by counsel before relying on it.
What we collect
Crail's pages are static and don't run visitor analytics or advertising trackers. The only personal information we collect is what you submit directly through a form on the site — contact requests, vendor-listing requests, review submissions, or "request info" leads — each tagged with aformType so we know what it's for. Submissions are stored server-side and are not sold or shared with third parties except the vendor a lead was intended for.
Review submissions
If you submit a review, we collect what you enter (role, company size, use case, ratings, pros/cons) and your work email for verification purposes only — your email is never published. See ourmethodology for how verification works.
Third-party content we link to
Vendor pages may reference publicly-posted discussion from Reddit, Hacker News, or similar forums, always with a link back to the original post. We don't collect data from those platforms about you — we only read and excerpt content that is already public. See ourtakedown policy if you want something like this removed.
Vendor and company data
Vendor listings (pricing, features, compliance posture, etc.) are compiled from each vendor's own public pricing pages, documentation, and GitHub repositories, or submitted directly by the vendor. This is business information about products, not personal information about individuals.
Contact
Questions about this policy, or requests to access/delete information you've submitted, can be sent via our contact form.