Legal & Privacy

Privacy Policy.

This Privacy Policy explains how CRV Verified collects, uses, discloses, retains, and protects information associated with its website, applications, certification services, and public registry.

Last Updated August 17, 2026
CRV Privacy Framework

Transparency in how information is handled.

CRV collects information needed to operate its verification framework, review applications, maintain registry integrity, and communicate with applicants and the public.

01
Policy Scope

Scope of This Privacy Policy

This policy applies to information collected through the CRV website, certification applications, registry services, contact forms, payment-related interactions, compliance reviews, and communications with CRV.

It does not govern the privacy practices of independently operated certified businesses, third-party websites, laboratories, payment processors, or external services that maintain their own privacy policies.

02
Data Categories

Information We Collect

Information You Provide

  • Name, email address, telephone number, and contact details.
  • Business name, entity information, address, website, domain, and ownership information.
  • Application responses and category-specific certification information.
  • Policies, licenses, reports, certificates, COAs, batch records, photographs, and other supporting evidence.
  • Communications, complaints, clarification responses, and compliance-related submissions.
  • Billing details and transaction information, excluding complete payment-card numbers processed by payment providers.

Information Collected Automatically

  • Internet Protocol address and approximate location derived from it.
  • Browser, device, operating-system, and language information.
  • Pages visited, referring pages, timestamps, and website interactions.
  • Cookie identifiers, security logs, and diagnostic information.
Do not submit patient files, medical records, diagnostic information, or identifiable consumer health information unless CRV expressly requests it through an authorized process.
03
Processing Purposes

How We Use Information

CRV may use information to:

  • Receive, evaluate, and administer certification applications.
  • Verify business identity and review submitted evidence.
  • Make and document certification decisions.
  • Create and maintain public registry records.
  • Administer verification codes and badge authorization.
  • Monitor certification standing and investigate material concerns.
  • Process payments and maintain transaction records.
  • Respond to inquiries and provide applicant support.
  • Protect the website, registry, applicants, and CRV from fraud or misuse.
  • Comply with legal obligations and enforce CRV policies.
  • Analyze and improve CRV services and website performance.
04
Public Information

CRV Public Registry

Approved businesses receive a publicly accessible verification record. Depending on the certification category and standing, published information may include:

  • Business or operating name.
  • Website or verified domain.
  • CRV verification code.
  • Certification category and level.
  • Current registry standing.
  • Certification or review dates.
  • Public status notices or relevant registry annotations.

Confidential application materials and complete supporting documentation are not intended for public display unless CRV provides notice, receives appropriate authorization, or disclosure is otherwise permitted or required by law.

05
Financial Processing

Payment Information

Payments may be processed through third-party payment providers. These providers collect and process payment-card and billing information under their own terms and privacy policies.

CRV may receive limited transaction information such as payer identity, billing contact information, transaction amount, payment status, provider reference, and payment date. CRV does not intend to store complete payment-card numbers on its servers.

06
Third Parties

How Information May Be Disclosed

CRV may disclose limited information to:

  • Website hosting, security, storage, email, analytics, and technical service providers.
  • Payment processors and financial-service providers.
  • Professional advisers such as attorneys, accountants, and consultants.
  • Testing organizations, laboratories, or information sources when verification is necessary and authorized.
  • Government authorities or other parties when legally required or reasonably necessary to protect rights and safety.
  • A successor organization in connection with a merger, acquisition, restructuring, or transfer of assets.

CRV does not sell personal information for monetary consideration. If CRV’s practices materially change, this policy and any legally required privacy controls will be updated.

07
Website Technology

Cookies & Similar Technologies

CRV may use cookies and similar technologies for essential website operation, security, preference storage, performance measurement, form functionality, and analytics.

Browser controls may allow users to block or delete cookies. Disabling essential cookies may affect website functionality. Where required, CRV will request consent or provide additional controls for nonessential technologies.

08
Data Lifecycle

Information Retention

CRV retains information for as long as reasonably necessary to process applications, administer certification, maintain registry integrity, comply with legal and accounting obligations, resolve disputes, document enforcement decisions, and protect against fraud or misuse.

Retention periods may vary according to the type of information, certification status, contractual requirements, legal obligations, and the need to preserve an accurate historical record.

09
Safeguards

Data Security

CRV uses reasonable administrative, technical, and organizational safeguards intended to protect information from unauthorized access, alteration, disclosure, misuse, or destruction.

No website, storage environment, transmission method, or security system can be guaranteed to be completely secure. Users should avoid transmitting information that CRV has not requested.

10
Individual Requests

Your Privacy Rights

Subject to applicable law and relevant exceptions, individuals may have the right to request:

  • Confirmation of whether CRV processes their personal information.
  • Access to categories or copies of personal information.
  • Correction of inaccurate personal information.
  • Deletion of eligible personal information.
  • Information about applicable disclosures or processing purposes.
  • Restriction of or objection to certain processing.
  • Non-discriminatory treatment for exercising applicable privacy rights.

Requests may be submitted to [email protected]. CRV may request information reasonably necessary to verify identity and prevent unauthorized access or deletion.

11
Age Limitation

Children’s Privacy

CRV services are intended for businesses and adults acting in a professional capacity. They are not directed to children, and CRV does not knowingly seek to collect personal information from children under 13.

If you believe a child has submitted personal information to CRV, contact us so the information can be evaluated and removed where appropriate.

12
Policy Updates

Changes to This Policy

CRV may update this Privacy Policy to reflect changes in its services, technology, legal obligations, or information practices.

The revised policy will display an updated date. Where required by applicable law, CRV will provide additional notice or obtain consent before materially different practices apply.

13
Privacy Contact

Contact CRV

For privacy questions, requests, or concerns, contact:

CRV
Privacy Principle Collect what is needed. Protect what is entrusted.

CRV’s published policy should remain consistent with its actual data practices, service providers, and technical configuration.

Contact Support
Scroll to Top