Skip to main content
LEGAL · PRIVACY

Privacy Policy

Version 1.1 · Effective 2026-09-10 · Last updated 2026-09-10 · Operator: Auren LLC


1. Who we are

CROSSPAD is a product operated by Auren LLC, a limited liability company organized under the laws of the State of Wyoming, United States ("Auren LLC", "we", "us", "our"). CROSSPAD is an automated PCB migration service that converts Altium design files to KiCad and delivers a validated, sealed Delivery Bundle.

For the personal data described in this policy, Auren LLC is the controller — the entity that decides why and how it is used.

  • Postal address: Auren LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States
  • Data-protection contact: Grégoire Bourdin, Managing Member, Auren LLC
  • Privacy requests: privacy@orkoottrae.resend.app
  • Support: support@orkoottrae.resend.app
  • Legal notices: legal@orkoottrae.resend.app
  • EU/UK representative: Auren LLC has not appointed a representative in the EU or the UK under Article 27 GDPR / UK GDPR at this time; contact the privacy address above.

2. What this policy covers

This policy explains how we handle personal data — information relating to an identified or identifiable person — when you visit https://crosspad.co, create an Account, place an Order, contact support or receive our emails. It applies to everyone who uses CROSSPAD, including people acting for an employer or client; your organization may have its own notice for you, but this policy still explains what Auren LLC does.

Customer Files are treated differently. Source Files, Decisions and anything else you upload or enter are Customer Files. We treat them as confidential business data, not as personal data about you. They are governed by the Terms of Service (ownership, limited processing license, confidentiality), the Security, File Retention and Deletion Policy (handling, storage, deletion) and the Data Processing Addendum (for Customers subject to EU or UK data-protection law).

Customer Files may incidentally contain personal data — an engineer's name in a title block, for example. We do not extract, index or use such data for any purpose of our own; where it is present we process it only as your processor, under your instructions, as set out in the Data Processing Addendum.

3. Personal data we collect

The table lists every category we process at launch and, for people in the EU, EEA and UK, the legal basis under the GDPR and UK GDPR. Contract = needed to perform the Terms of Service with you. Legitimate interests = needed for our legitimate interests, balanced against your rights. Consent = you agreed and may withdraw at any time. Legal obligation = required by law.

CategoryExamplesSourcePurposeLegal basis
Account dataEmail address (verified by one-time code), profile choice (independent engineer / hardware team / company migration), verification timestamp, business name given at checkoutYouCreate and run your Account; sign you in; send service emailsContract
Sign-in security dataHashed one-time code (never the code itself), attempt counter, expiry, session identifierGenerated by our systemsVerify you control the email; keep you signed in; detect abuse of the sign-in flowContract; Legitimate interests (security)
Order and payment referencesOrder Reference (CP-xxxxx), amount, currency, tax, Stripe customer ID, Stripe session and payment reference IDs, payment and refund statusYou; StripeFulfil your Order; receipts; refunds and Remediation; accounting and tax recordsContract; Legal obligation
Payment card dataCard number, expiry, CVC, billing addressYou, on Stripe's hosted checkout pagePaymentProcessed by Stripe only. We never receive or store card details
Consent and evidence recordsPolicy versions accepted and when; IP address and user agent captured when you accept terms, check out, apply a Decision, acknowledge a warning or download; a stored copy of the checkout page you sawYour device; our systemsProve what you agreed to; prevent fraud; respond to chargebacks; defend legal claimsLegitimate interests; Legal obligation where card-network or tax rules require records
Order activityDecisions applied, warnings acknowledged, Delivery and download events, bundle hash, Defect Reports, Remediation historyYou; our systemsPerform the migration; produce decision receipts and the report; run the Remediation ServiceContract
Support communicationsYour messages, email address, Order Reference, our repliesYouAnswer questions; run Remediation; handle complaintsContract; Legitimate interests
Marketing preferenceOpt-in record, date, unsubscribe recordYouSend product updates only if you asked; prove your choiceConsent
Technical logsIP address, request path, timestamp, browser information in server and edge logsYour device, via our hostKeep the Platform available; investigate errors, abuse and incidentsLegitimate interests
Cookiecp_session (section 5)Our websiteKeep you signed inContract (strictly necessary)

We do not collect precise location, biometric, government-identifier or special-category data, and ask you not to send them.

4. How we use personal data

We use personal data only for the purposes in section 3. In plain terms, we use it to:

  1. Run your Account and Orders — verify your email, sign you in, run the Analysis, take payment through Stripe, process the migration, deliver the Delivery Bundle, run the Remediation Service and handle refunds under the Refund and Remediation Policy.
  2. Send service emails — sign-in codes, order confirmations, Delivery notifications, Remediation and Customer Request messages, and notices of changes to our terms. These are part of the service and are sent whether or not you opted in to marketing.
  3. Send optional product updates — only if you ticked the separate, unticked marketing box. Every marketing email has an unsubscribe link, honored immediately.
  4. Keep evidence and defend disputes — Order records, consent records and the IP address and user agent captured at consent, checkout and download let us prove what was agreed and delivered if a chargeback or legal claim arises. This data is used only for security, fraud prevention and dispute evidence.
  5. Protect the Platform — detect abuse of the sign-in flow, block jurisdictions we cannot lawfully serve, investigate incidents.
  6. Comply with the law — tax and accounting rules, lawful requests from authorities, sanctions and export-control rules.

We do not sell personal data, share it for advertising, build profiles, track you across other sites, use personal data or Customer Files to train machine-learning models, or make automated decisions with legal effects about you (section 12).

5. Cookies

At launch CROSSPAD sets one cookie, cp_session, which keeps you signed in after you verify your email. It is strictly necessary, so no consent banner is shown. We set no analytics, advertising or third-party cookies. Stripe's hosted checkout page sets its own cookies under Stripe's policy. Details are in the Cookie Policy at /cookies.

6. Who receives personal data

6.1 Service providers (subprocessors)

Each provider acts on our instructions under a written contract, except where noted.

ProviderRoleData involvedLocation
Vercel, Inc.Hosting, serverless compute, edge logsTechnical logs; all data passing through the applicationUnited States
Neon, Inc.Postgres database (encrypted at rest per Neon's statement)Account, sign-in, Order, consent and support dataUnited States
Resend, Inc.Transactional emailEmail address and content of service emailsUnited States
Stripe, Inc.Payments, tax, receipts, fraud screeningEmail, payment and billing details, Order Reference, amount, IP at checkoutUnited States (Stripe's own transfer safeguards)
Vercel Blob (Vercel, Inc.)Object storage for Customer Files and Delivery Bundles, with provider-managed encryption at restCustomer Files, Delivery BundlesUnited States
Processing worker hostIsolated processing environment; the processing worker host configured for the applicable deploymentCustomer Files and processing logs during the job onlyUnited States
Analytics, monitoring, support-desk or AI componentsNone at launch

Stripe as an independent controller. Stripe also uses payment data for its own purposes — payment fraud prevention, financial-regulation compliance and running its network — and is an independent controller for those purposes. See https://stripe.com/privacy.

The current subprocessor list is kept in this section at /privacy#subprocessors, mirrored at /security, and is updated before any new provider handles personal data.

6.2 Other recipients

We may share personal data with professional advisers under confidentiality; with card networks, issuers and Stripe when responding to a dispute, limited to the relevant evidence; with courts, regulators and authorities where legally required or necessary to establish, exercise or defend legal claims; and with a successor in a merger, acquisition or asset sale, in which case this policy continues to apply and we tell you before a different policy applies. We do not share personal data with data brokers or advertising networks.

7. International transfers

Auren LLC is established in the United States and processes personal data there; subprocessor locations are in section 6.1. If you are in the EU, EEA, UK or Switzerland, your data is transferred to the United States, which has no general adequacy decision. We rely on:

  • Standard Contractual Clauses (Commission Decision (EU) 2021/914) with our subprocessors and, for Customers under the Data Processing Addendum, with the Customer;
  • the UK International Data Transfer Addendum for UK transfers.

Auren LLC is not certified under the EU-US Data Privacy Framework or its UK Extension and does not rely on it, or on any subprocessor's certification under it; transfers to our subprocessors rely on the Standard Contractual Clauses and the UK Addendum.

You can request a copy of the safeguards (commercial details removed) at the privacy email in section 1.

8. How long we keep personal data

We keep personal data only as long as needed for the purposes in section 3 and the legal, tax and dispute-defense periods below. This is the same schedule used in the Security, File Retention and Deletion Policy and the Data Processing Addendum.

RecordRetention
Source FilesDeleted 30 days after Delivery or Order closure; earlier on request after Customer Acceptance; immediately if the Order is cancelled before Commencement
Delivery BundlesDownload Period (90 days), then deleted; bundle hash retained
Orders, payments, consents, Decisions, delivery metadata, event log, dispute packets7 years from Order closure
Support communications3 years
IP address and user agent captured at consent, checkout and downloadWith the Order record; used only for security, fraud and dispute evidence
Server and edge logs90 days
Analysis-only uploads that never become an OrderDeleted 7 days after upload
Unverified Accounts, expired one-time codes and sessionsPurged after 30 days / on expiry
Marketing consent and unsubscribe recordsUntil withdrawn, plus 3 years as proof
Account data after deletion requestPersonal identifiers removed within 30 days; Order records retained (anonymized where possible) for the periods above

When a period ends we delete the data or anonymize it so it no longer identifies you.

9. Security

We protect personal data with these controls at launch:

  • TLS for connections to crosspad.co and to our providers.
  • Hosted payment page: card details are entered on Stripe's page and never pass through our systems.
  • Hashed one-time codes: sign-in codes are stored only as keyed hashes, expire after 10 minutes and lock after 5 failed attempts.
  • Access controls: staff access to systems holding personal data is limited to people who need it for their role and is logged.
  • Cookie protections: cp_session is httpOnly, Secure and SameSite=Lax.

How Customer Files are isolated, processed and deleted is described in the Security, File Retention and Deletion Policy at /security, which lists only controls that are implemented. No method of transmission or storage removes all risk; please protect your email account, which is the key to your Account.

10. Your rights

10.1 Everyone

Wherever you are, you can ask what personal data we hold and get a copy; ask us to correct it; ask us to delete your Account (section 8 lists what we must keep); unsubscribe from marketing at any time; and raise a question or complaint with us.

10.2 EU, EEA and UK

If the GDPR or UK GDPR applies to you, you also have the right to restrict processing in certain cases; to data portability for data you gave us that we process by automated means under contract or consent; to object to processing based on legitimate interests, and at any time to direct marketing; to withdraw consent without affecting earlier processing; and to lodge a complaint with a supervisory authority, in particular where you live, work or believe an infringement occurred. UK: Information Commissioner's Office (https://ico.org.uk). EU authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en.

10.3 US state privacy rights

Depending on your state and on whether a state privacy law (for example California's CCPA/CPRA or the laws of Colorado, Connecticut, Virginia, Utah, Texas or Oregon) applies to Auren LLC, you may have rights to know, access, correct, delete and port your personal data, to opt out of sale, sharing and targeted advertising, and not to be discriminated against for exercising them. We do not sell or share personal data and do not use it for targeted advertising, so no opt-out is needed. Other rights can be exercised under section 10.4; where the law allows, an authorized agent may act for you with proof of authority.

10.4 How to exercise your rights

Write to privacy@orkoottrae.resend.app, preferably from your Account email.

  • Verification: we confirm you control the Account email, usually by one-time code, and may ask for more detail if the request is unclear.
  • Timing: we respond within 30 days of a verified request. Complex or repeated requests may take up to 60 further days (EU/UK) or 45 days (US states, where applicable); we tell you why within the first 30 days.
  • Cost: free, unless requests are clearly unfounded or excessive, in which case we may charge a reasonable fee or decline and explain why.
  • Limits: we may keep data we are legally required to keep or need for dispute defense (section 8), and will tell you what we kept and why.

11. Children

CROSSPAD is a business and professional service. You must be at least 18 to create an Account or place an Order. We do not knowingly collect personal data from anyone under 18; if you believe we have, contact us and we will delete it.

12. Automated decision-making

We make no decisions about you by automated means that produce legal or similarly significant effects. The migration verdicts (Ready, Decisions required, Blocked) and the validation categories in your report are automated assessments of your files, not of you, and only determine whether a particular file can be ordered. Stripe may apply automated fraud screening to payments as an independent controller.

13. Changes to this policy

Each version carries a version number, effective date and last-updated date; prior versions are available on request. For a material change — a new purpose, data category, subprocessor handling personal data, or change to your rights — we notify you by email and on the website at least 14 days before it takes effect, unless the law requires less. Minor changes take effect when posted.

14. Contact

  • Privacy requests: privacy@orkoottrae.resend.app
  • Support: support@orkoottrae.resend.app
  • Legal notices: legal@orkoottrae.resend.app
  • Post: Auren LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States
  • Data-protection contact: Grégoire Bourdin, Managing Member, Auren LLC
  • EU/UK representative: Auren LLC has not appointed a representative in the EU or the UK under Article 27 GDPR / UK GDPR at this time; contact the privacy address above.

Related documents: Terms of Service (/terms) · Cookie Policy (/cookies) · Security, File Retention and Deletion Policy (/security) · Refund and Remediation Policy (/refund-policy) · Data Processing Addendum (/dpa).

SHA-256 f352bd7d54fcc8e9e4f64bdc4af02c56269236b5d4549cd2d99c593c1d7ac287

Version 1.1, effective 2026-09-10. Prior versions available on request at legal@orkoottrae.resend.app.