Privacy policy
What we collect, why we collect it, and what you can do about it. We do not sell personal data and we do not run advertising trackers.
Last updated
1. The short version
- We collect what we need to run accounts, sales and payouts.
- We do not sell your data or share it with advertisers.
- There are no third-party advertising or social trackers.
- Analytics are aggregated and cookieless; we cannot use them to identify you.
- You can export or delete your data from account settings at any time.
2. Who is responsible
CramShare B.V., registered in Amsterdam, is the data controller for the personal data described here. For any privacy request, use contact and select the relevant topic; privacy requests are routed to our data protection contact.
3. What we collect
You give us:
- Account details — name, email, password hash.
- Institution and course details, if you add them to improve your search results.
- Documents you upload, including their metadata and any content inside them.
- Reviews, support messages and anything else you send us.
We generate:
- Purchase and payout records, which we are legally required to retain.
- Security logs — IP address, browser and timestamps for sign-in events and abuse prevention.
- Aggregated usage counts such as how often a document is opened. These are not linked back to individual accounts.
- Payout details, if you sell — a PayPal address, bank account or UPI ID, and the name on the account. Used only to pay you, never shown to buyers or other sellers, and shown back to you masked rather than in full.
We deliberately do not collect payment card details. Those are entered with our payment provider and never reach CramShare servers.
4. Why we process it, and our legal basis
- To provide the service — accounts, downloads, sales. Basis: performance of a contract.
- To pay sellers and meet tax obligations — payout and invoice records. Basis: contract and legal obligation.
- To keep the marketplace safe — fraud detection, review of uploads, abuse investigation. Basis: legitimate interests.
- To improve the product — aggregated, cookieless analytics. Basis: legitimate interests.
- To email you about your account — receipts, payout statements, security notices. Basis: contract. Marketing email is separate and opt-in only.
5. How long we keep it
- Account data: until you delete your account.
- Documents you published: removed from sale immediately on unpublishing; deleted 90 days later.
- Purchase and payout records: seven years, because tax law requires it. This is the one category deleting your account does not clear.
- Security logs: 12 months.
- Support conversations: 24 months.
6. Who else processes it
We use a small number of processors, each under a data processing agreement and each limited to what they need:
- A cloud hosting and database provider, hosted in the EU.
- A payment provider, for card processing and payouts.
- An email provider, for transactional messages.
We do not share personal data with advertisers, data brokers or any third party for their own purposes. Where a processor operates outside the EEA, transfers are covered by Standard Contractual Clauses.
7. Cookies
We set one essential cookie to keep you signed in, and one to remember your consent choices. Neither is used for tracking and neither requires consent under the ePrivacy Directive.
We do not use advertising, retargeting or social media cookies. If that ever changes, we will ask for consent before setting them, with refusing as easy as accepting.
8. Your rights
Under GDPR you can request access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. Most of these are self-service in account settings; the rest we handle within 30 days.
If you are unhappy with how we have handled a request, you may complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
9. Security
Data is encrypted in transit and at rest. Access to production data is restricted to staff who need it and is logged. Passwords are stored hashed and salted, never in a form we can read. If a breach affecting your data occurs, we will notify you and the relevant authority within the timeframes the law requires.
10. Changes
We will post changes here and, for anything material, email you at least 30 days before it takes effect. The date at the top of this page always reflects the current version.