Privacy Policy
Effective June 30, 2026
1. Who we are
CrusaderBase is operated by Not Beer Inc. ("we", "us"). We provide AI agents that help consumer-packaged-goods brands run operational workflows — including creator and influencer sample programs that integrate with Instagram, and agents that connect to the other business systems you already use (email, accounting, e-commerce, payments, retail/EDI, and warehouse platforms) to work on your behalf under your approval.
2. Information we collect
We collect information from these sources:
- Account information. Name and email address you provide when creating an account, supplied through our identity provider (Clerk).
- Brand configuration. Product catalog, brand voice, message templates, warehouse and 3PL configuration, and approval-policy settings you enter when configuring an agent.
- Instagram data (with your consent). When you connect an Instagram Business or Creator account, we access: messages in conversations involving that account, public profile fields of accounts you message, mentions of your account, and media you choose to track. We use the Instagram Graph API and comply with Meta's Platform Terms.
- Connected service data (with your consent). When you connect another business system — such as your email, accounting, e-commerce, payment, retail/EDI, warehouse, or market- data provider — we access only the data needed to operate the agent you enabled. What we access from each provider is described in "Connected services and third-party integrations" below.
3. Connected services and third-party integrations
CrusaderBase is built to connect to the systems you already use. With your explicit authorization, the agents you enable may integrate with third-party services. These today include, and may over time expand to include, categories such as:
- Email and calendar (e.g. Google / Gmail, Microsoft 365)
- Accounting and finance (e.g. QuickBooks / Intuit, Bill.com)
- E-commerce and subscriptions (e.g. Shopify, Recharge)
- Payments (e.g. Stripe)
- Retail and distribution (e.g. EDI networks such as SPS Commerce and ConnectPointz; distributor portals such as KeHE and UNFI)
- Warehouse and logistics / 3PLs (e.g. UNIS, ShipStation, ShipBob, ShipHero)
- Syndicated market data (e.g. SPINS, Circana)
- Social and messaging (e.g. Meta / Instagram)
For every integration, the same commitments apply: we request the minimum access needed for the feature you enabled; credentials are stored encrypted (AWS Secrets Manager) and scoped to your tenant; data from one connected service is used only to operate your agents and is isolated from other customers by database row-level security; we do not sell your data and do not use it to train machine-learning models for any party other than you; you may disconnect an integration or request deletion at any time; and we honor each provider's platform terms and data policies. Where a provider imposes specific obligations — for example Google's Limited Use requirements (Section 4) or Meta's Platform Terms — those obligations control for that provider's data.
4. Google user data and Limited Use
When you connect a Google (Gmail) account, we request only the scopes needed to operate the agents you enable: sending email from your account after your in-app approval (gmail.send); where you enable an agent that processes inbound mail, reading and organizing the relevant messages (gmail.readonly, gmail.modify); and your account email address (userinfo.email).
CrusaderBase's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide or improve the user-facing features you have enabled; is never sold; is never transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with equivalent privacy protections; is never used for advertising; and is not used to develop, improve, or train generalized artificial-intelligence or machine-learning models. Humans do not read Google user data except with your consent for support, for security purposes, to comply with applicable law, or on data that has been aggregated and anonymized.
5. How we use information
- To operate the agents you have enabled — for example, reading inbound DMs to extract shipping addresses, queueing shipments for your approval, sending tracking updates and follow-ups.
- To submit shipments and tracking requests to your configured 3PL partners on your behalf.
- To produce dashboards, audit logs, and inspector traces so you can review what the agent has done and why.
- To monitor service health, prevent abuse, and meet legal obligations.
We do not sell personal information. We do not use your Instagram data, message content, connected-service data, or creator data to train machine-learning models for any party other than you.
6. How we share information
We share information only with service providers necessary to deliver the service, under contracts that limit their use of your data:
- Clerk — identity and session management.
- Supabase (Postgres, file storage, realtime) — primary data store, hosted in the United States.
- Amazon Web Services — application hosting, secrets management, file storage.
- Vercel — frontend hosting and edge delivery.
- Meta Platforms — Instagram Graph API used to read and send messages on your authorized account.
- Google — Gmail API used to send, and (where you enable it) read and organize, messages on your authorized account.
- Your configured integrations and 3PLs (e.g. UNIS, ShipStation, and the services listed in Section 3) — only the data necessary to perform the actions you have approved.
We may disclose information when required by law, to protect our rights, or in connection with a corporate transaction (subject to equivalent privacy protections).
7. Data retention and deletion
We retain operational data for as long as your account is active and as needed to provide the service. Audit logs and inspector traces are retained for a minimum of 12 months to support compliance and dispute resolution.
You may request deletion of your data at any time by emailing dillon@enjoynotbeer.com. Instagram users whose data we hold (for example, creators who have messaged your connected account) may request removal through the same address or through Meta's data-deletion callback mechanism, which is implemented at /api/data-deletion. Data obtained from a connected service is deleted when you disconnect that integration or delete your account, subject to the retention period above and any legal obligation to retain records.
8. Security
We use TLS for data in transit, encryption at rest for stored data, role-based access control for our staff, and AWS Secrets Manager for credential storage with rotation. We are building toward SOC 2 Type II readiness and will pursue formal audit when our customer base requires it.
9. Your rights
Depending on your jurisdiction (including the EU/UK under GDPR and California under CCPA/CPRA) you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. To exercise any of these rights, contact dillon@enjoynotbeer.com.
10. Children
CrusaderBase is not directed to children under 16 and we do not knowingly collect personal information from them. The service is intended for use by businesses.
11. Changes
We may update this policy. Material changes will be communicated by email or in-app notice. Continued use after the effective date of an update constitutes acceptance.
12. Contact
Questions about this policy or your data: dillon@enjoynotbeer.com.