Privacy Policy

Effective: 2026-05-01 · KVKK + GDPR aligned · Plain English · Read in under 5 minutes.

1. Who we are

Createrun is operated by Createrun (the "Company"). This policy covers personal data we process when you use the createrun.com marketing site, the Createrun platform under our managed cloud, or contact us for sales / support. On-prem deployments are governed by the customer's own privacy practices — Createrun is the Data Processor in that case, not the Data Controller.

2. What we collect

  • Marketing site analytics— Google Analytics 4 (anonymised IP, page views, sessions). Used to understand traffic patterns. No PII.
  • Form submissions(Get a Demo, Contact, Partner program) — name, company, email, phone, use-case description. Used to respond to your request.
  • Account data on managed cloud— email, name, organisation, authentication tokens (hashed). Required to provide the service.
  • Server logs— IP, user agent, request paths. Retained 90 days for security investigation. Anonymised / purged after.

3. What we do with it

  • Respond to inbound inquiries.
  • Provide and improve the service for managed cloud customers.
  • Send transactional emails (account, billing, security alerts) — never marketing without explicit opt-in.
  • Investigate security incidents.
  • Comply with legal obligations (KVKK, GDPR, tax, etc.).

4. What we don't do

  • We don't sell personal data. Period.
  • We don't share it with third parties for marketing.
  • We don't ingest customer business data (the data your CRApps process) into our analytics. On-prem deploys never reach our network.

5. Your rights (KVKK / GDPR)

  • Right to access — request a copy of your data.
  • Right to rectification — fix incorrect data.
  • Right to erasure — request deletion (subject to retention obligations).
  • Right to portability — receive your data in machine-readable form.
  • Right to object — opt out of processing.
  • Right to lodge a complaint — to your supervisory authority (KVK Kurulu in Turkey, your national DPA in the EU).

Exercise any of these by emailingprivacy@createrun.com. We respond within 30 days.

6. Sub-processors

For the managed cloud, we use:

  • Google Analytics— site analytics
  • Stripe— payment processing for paid CRApps
  • Email infrastructure provider— transactional email delivery

Each is bound by an appropriate data processing agreement. The full list is in ourData Processing Agreement.

7. Data retention

  • Form submissions: 24 months (or until deletion request).
  • Account data: lifetime of account + 30 days.
  • Server logs: 90 days.
  • Backups: 90 days, encrypted at rest.

8. Security

See/securityfor full architecture. Briefly: TLS in transit; AES-256 / DPAPI at rest; OAuth2/OIDC tokens; encrypted Configuration Store secrets; SPKI-pinned downloads; signed installer manifests.

9. Cookies

Strictly necessary cookies only (session, CSRF). Optional: Google Analytics (you can opt out via the cookie banner). No third-party advertising cookies.

10. Children

Createrun is not intended for use by individuals under 16. We do not knowingly collect data from children.

11. Changes

We update this policy as our practices evolve. Material changes will be announced 30 days in advance via email (for managed cloud customers) and on thechangelog.

12. Contact

Privacy questions:privacy@createrun.com
Security disclosures:security@createrun.com
Data Protection Officer (DPO) — appointed; contact viadpo@createrun.com.

Related:Terms of Service·Data Processing Agreement·Security & Trust