Privacy Policy

    This Privacy Policy (the “Policy”) describes how Croppo processes the personal data of users of the websites croppo.ro and cropwizz.com (the “Site”), in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable Romanian data protection law.

    1. Data controller

    The controller of personal data collected through the Site is the team operating the Croppo project, based in Romania (“Croppo”, “we”, “us”). For any request regarding the processing of personal data, please contact us at contact@croppo.ro.

    Note: Croppo is in a pre-launch phase. The full identification details of the legal entity will be published upon formal incorporation.

    2. Categories of data processed

    Through the waitlist sign-up form we collect the following categories of data:

    • Data you provide: email address, selected role (farmer or buyer/business), and, optionally, county and farm size (farmers only).
    • Technical data collected automatically for security purposes: the IP address of the device used to submit the form and the submission timestamp. These data are used exclusively to prevent abuse (rate limiting) and automated submissions.
    • Aggregated traffic statistics: our hosting platform collects aggregated and anonymous data (visitor count, pageviews, country, device type) which do not allow your identification.

    We do not collect personal data belonging to special categories (art. 9 GDPR) and we do not knowingly process data of persons under the age of 16.

    3. Purposes and legal bases of processing

    PurposeLegal basis (GDPR)
    Managing the waitlist and sending a confirmation emailArt. 6(1)(b), pre-contractual measures at the data subject's request
    Notifying you about the platform launch and service-related communicationsArt. 6(1)(a), consent given at sign-up
    Planning the regional roll-out (county, farm size)Art. 6(1)(f), legitimate interest in sizing operations
    Preventing fraud, automated sign-ups and limiting abuse (IP)Art. 6(1)(f), legitimate interest in Site security
    Complying with legal obligations (e.g. responding to authority requests)Art. 6(1)(c), legal obligation

    4. Recipients and processors

    Data is not sold and is not disclosed to third parties for commercial purposes. To operate the Site we rely on the following providers, acting as processors:

    • Lovable (Lovable AB, Sweden). Site hosting, database infrastructure (Lovable Cloud, built on Supabase) and serverless functions used to process the form.
    • Supabase Inc. (USA), database infrastructure, as a sub-processor of Lovable.
    • Resend, Inc. (USA), delivery of confirmation emails and internal team notifications.

    Data may be disclosed to competent public authorities, within the limits and conditions provided by law.

    5. International transfers

    Some of our providers (Supabase, Resend) are established in the United States of America. Transfers of data to these jurisdictions take place on the basis of the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), supplemented, where applicable, by certification under the EU–US Data Privacy Framework, providing a level of protection consistent with the requirements of the GDPR.

    6. Retention period

    • Sign-up data (email, role, county, farm size), retained until the withdrawal of consent or, at the latest, 24 months after the public launch of the platform, at which point inactive sign-ups are deleted or anonymised.
    • Technical rate-limiting data (IP address, timestamp), retained for a short period of up to 24 hours and then automatically deleted.
    • Transactional emails sent via Resend, retained in the provider's logs according to their own policy (typically up to 30 days for content and longer for metadata).

    7. Rights of the data subject

    Under the GDPR you have the following rights:

    • right of access (art. 15);
    • right to rectification (art. 16);
    • right to erasure / “right to be forgotten” (art. 17);
    • right to restriction of processing (art. 18);
    • right to data portability (art. 20);
    • right to object to processing based on legitimate interest (art. 21);
    • right to withdraw consent at any time, without affecting the lawfulness of prior processing (art. 7(3));
    • right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro.

    Requests may be sent to contact@croppo.ro and will be addressed within a maximum of 30 days.

    8. Data security

    We apply appropriate technical and organisational measures to protect the data, including: encrypted transmission via HTTPS/TLS, data isolation through database Row-Level Security policies, restriction of operational data access to authorised team members only, input validation and sanitisation, and rate-limiting mechanisms to prevent abuse.

    9. Cookies and similar technologies

    The Site does not use advertising, profiling or marketing cookies and does not integrate tools such as Google Analytics, Meta Pixel or similar. We may use cookies and local storage strictly necessary for the operation of the Site (e.g. language preference), which do not require consent under art. 4(5)(b) of Romanian Law no. 506/2004.

    10. Automated decision-making

    We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

    11. Changes to this Policy

    We reserve the right to update this Policy. The updated version will be published on this page together with the date of the latest revision. Material changes will be communicated, where possible, by email.

    Last updated: July 15, 2026