Privacy Policy
Last updated: 26 May 2026
This Privacy Policy explains how LLC “CR Visual Lab” (“CR Maps”, “we”) collects, uses, and protects personal data when you use the CR Maps platform (cr-maps.com, app.cr-maps.com, and our interactive maps). We are committed to handling personal data in line with the General Data Protection Regulation (GDPR) and applicable Ukrainian data-protection law.
1. Our two roles: Controller and Processor
When we provide accounts and run our website/application, and process the personal data of our Customers (account holders) and website visitors, we act as the data controller.
When our Customers use CR Maps to collect Lead Data from their own visitors through embedded maps, the Customer is the data controller and we act as a data processor on the Customer’s behalf and instructions, governed by our Data Processing Agreement. If you are an end visitor who submitted an enquiry through a developer’s or agency’s map, please direct privacy requests to that company; we will assist them as their processor.
2. Personal data we collect
- (a) Account & contact data — when you register or contact us: name, email, company, phone (optional), and login credentials. If you sign in with Google, we also receive basic profile information (such as your name and email address) from your Google account.
- (b) Usage & technical data — IP address, browser/device info, pages viewed, and log data, collected to operate and secure the Service.
- (c) Customer Content & Lead Data — data our Customers upload and the enquiries collected through their maps (e.g., a buyer’s name, email, phone, message). We process this on the Customer’s behalf.
- (d) Communications — messages you send us via forms or email.
3. How we use personal data (purposes)
- to provide, operate, maintain and secure the Service;
- to create and manage accounts and authenticate users;
- to respond to enquiries and provide support;
- to improve the Service and develop new features;
- to comply with legal obligations and enforce our Terms.
4. Legal bases (GDPR Art. 6)
We rely on: performance of a contract (providing the Service to you); our legitimate interests (operating and securing the Service, communicating with you); your consent (where required, e.g., certain communications); and compliance with a legal obligation. For Lead Data processed as a processor, the legal basis is determined by the relevant Customer (controller).
5. Cookies
We use only essential cookies necessary for the Service to function — for example, to keep you signed in and to maintain your session. We do not use third-party advertising or analytics cookies. Because we use only strictly necessary cookies, a cookie-consent banner is not required; you can control cookies through your browser settings, though disabling essential cookies may break parts of the Service.
6. Sharing and subprocessors
We do not sell personal data. We share it only with:
- service providers (subprocessors) who help us run the Service, such as Google (sign-in / authentication) and our hosting and email-delivery providers, under appropriate confidentiality and data-protection terms;
- authorities or third parties where required by law or to protect our rights;
- a successor in the event of a merger, acquisition, or asset sale.
CR Maps’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google sign-in only to authenticate you and to obtain your basic profile information (name and email). We do not use Google user data for advertising, and we do not sell it or transfer it to others except as needed to provide the Service, for security or legal reasons, or with your consent.
7. International transfers
Where a subprocessor is located outside Ukraine or the European Economic Area, we ensure appropriate safeguards are in place (such as the European Commission’s Standard Contractual Clauses) before transferring personal data.
8. Data retention
We keep account and contact data for as long as your account is active and as needed to provide the Service, then for a reasonable period to meet legal, accounting or dispute-resolution needs. Lead Data is retained according to the relevant Customer’s instructions. We delete or anonymise personal data when it is no longer needed.
9. Data security
We apply technical and organisational measures to protect personal data, including access controls, encryption in transit, and limiting access to authorised personnel bound by confidentiality. No method of transmission or storage is completely secure, but we work to protect your data and to respond appropriately to any incident.
10. Your rights
Subject to applicable law (including the GDPR), you may have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority (in the EU, your local data-protection authority; in Ukraine, the Ukrainian Parliament Commissioner for Human Rights). To exercise your rights, contact us at info@createrender.com. If your request relates to Lead Data collected through a Customer’s map, we will refer you to, or assist, the relevant Customer (controller).
11. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from children under 16.
12. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, notify you.
13. Contact
For any questions about this Policy or your personal data, contact us at info@createrender.com.