Trust Center
Our security controls, subprocessors and documentation.
Last updated 9 September 2026
Compliance
| GDPR | Compliant as controller and processor |
| Penetration test | November 2024 â available on request |
Crobox is a product discovery and guided selling platform for ecommerce. We hold as little data as possible: we do not store personally identifiable information about shoppers. When tracking is enabled a shopper is represented by a randomly generated cookie identifier, not derived from anything about the person. Shoppers can opt out and request deletion via our API.
The only personal data we hold belongs to people who log in to the Crobox platform â a name, a username, and a bcrypt password hash.
All production infrastructure runs in the EU. See subprocessors for the full list, and security controls for the controls we commit to.
Contact
Security questions, questionnaires, or a vulnerability report:security@crobox.com(security.txt).