İçeriğe geç

Privacy Policy

Bu sayfa yalnızca İngilizce olarak mevcuttur.

Last revised on September 24, 2026. Previous versions of this document are available on GitHub.


Welcome, and thank you for your interest in Crowdin (“Crowdin”, “we”, or “us”), our web site at https://crowdin.com (the “Site”), and all related web sites, downloadable software, mobile applications (including tablet applications), and other services provided by us and on which a link to this Privacy Policy is displayed, and all other communications with individuals though from written or oral means, such as email or phone (collectively, together with the Site, our “Service”).

This Privacy Policy (“Policy”) describes the information that we gather on or through the Service, how we use and disclose such information, and the steps we take to protect such information. By visiting the Site, or by purchasing or using the Service, you accept the privacy practices described in this Policy.

This Policy is incorporated into, and is subject to, the Crowdin Terms of Service. Capitalized terms used but not defined in this Policy have the meaning given to them in the Crowdin Terms of Service.

Authorized Useran individual who is registered, invited, or permitted by a Client to access a workspace and/or use the Services. Authorized Users may include, without limitation, in-house localization managers, developers, external or outsourced freelance translators, proofreaders, and language service providers (LSPs).
Clienta customer of Crowdin.
Client Datapersonal data, reports, addresses, and other files, folders or documents in electronic form that an Authorized User of the Service stores within the Service.
Data Protection Lawsall applicable international, national, federal, state, regional, and local laws, statutes, regulations, directives, regulatory requirements, and rules relating to data protection, data privacy, data security, or the processing of Personal Data, as amended, updated, or superseded from time to time, including, without limitation: (i) Regulation (EU) 2016/679 (EU General Data Protection Regulation - EU GDPR); (ii) the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018; (iii) the Swiss Federal Act on Data Protection (FADP); (iv) applicable US federal and state privacy statutes (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act - CCPA/CPRA, and comprehensive state data privacy laws); and (v) any other applicable data protection and privacy legislation worldwide in any jurisdiction where the Service is provided, accessed, or where Personal Data is processed.
Personal Dataany information relating to an identified or identifiable natural person.
Public Areathe area of the Site that can be accessed both by Authorized Users and Visitors, without needing to log in.
Restricted Areathe area of the Site that can be accessed only by Authorized Users, and where access requires logging in.
Restricted Transfera transfer of Personal Data under this Policy that would be prohibited by applicable Data Protection Laws (such as the EU GDPR, UK GDPR, or Swiss FADP) in the absence of an adequacy decision issued by the competent authorities, or in the absence of the appropriate legal transfer mechanisms implemented under Section 13 of this Policy.
Visitoran individual other than an Authorized User, who uses the public area, but has no access to the restricted areas of the Site or Service.

We collect different types of information from or through the Service. The legal bases for Crowdin’s processing of personal data are primarily that the processing is necessary for providing the Service in accordance with Crowdin’s Terms of Service and that the processing is carried out in Crowdin’s legitimate interests, which are further explained in the section “How We Use the Information We Collect” of this Policy. We may also process data upon your consent, asking for it as appropriate.

When you use the Service, as an Authorized User or as a Visitor, you may provide, and we may collect Personal Data. Examples of Personal Data include name, email address, mailing address, and credit card or other billing information. Personal Data also includes other information, such as geographic area or preferences, when any such information is linked to information that identifies a specific individual. You may provide us with Personal Data in various ways on the Service. For example, when you register for an Account, use the Service, post Client Data, interact with other users of the Service through communication or messaging capabilities, or send us customer service-related requests.

A Client or Authorized User may store or upload into the Service Client Data. Crowdin has no direct relationship with the individuals whose Personal Data it hosts as part of Client Data. Each Client is responsible for providing notice to its customers and third persons concerning the purpose for which Client collects their Personal Data and how this Personal Data is processed in or through the Service as part of Client Data.

When an Authorized User or Visitor uses the Service, we may automatically record certain information from the Authorized User’s or Visitor’s device by using various types of technology, including cookies, “clear gifs” or “web beacons.” This “automatically collected” information may include IP address or other device address or ID, web browser and/or device type, the web pages or sites visited just before or just after using the Service, the pages or other content the Authorized User or Visitor views or interacts with on the Service, and the dates and times of the visit, access, or use of the Service. We also may use these technologies to collect information regarding a Visitor or Authorized User’s interaction with email messages, such as whether the Visitor or Authorized User opens, clicks on, or forwards a message. This information is gathered from all Authorized Users and Visitors. Our use of cookies and other tracking technologies is discussed more below, and in more detail in our Cookie Statement here. Separately, we may automatically collect technical and infrastructure performance data strictly to ensure system stability, monitor infrastructure observability, and facilitate application error alerting (such as identifying software bugs or crashes). This technical diagnostic data is processed separately from behavioral marketing analytics, used exclusively to maintain platform uptime, performance, and security, and accessed strictly by authorized technical personnel on a need-to-know basis.

You may be given the option to access or register for the Service through the use of your user name and passwords for certain services provided by third parties (each, an “Integrated Service”), such as through the use of your Google account, or otherwise have the option to authorize an Integrated Service to provide Personal Data or other information to us. By authorizing us to connect with an Integrated Service, you authorize us to access and store your name, email address(es), timezones, gender, current city, profile picture URL, and other information that the Integrated Service makes available to us, and to use and disclose it in accordance with this Policy. You should check your privacy settings on each Integrated Service to understand what information that Integrated Service makes available to us, and make changes as appropriate. Please review each Integrated Service’s terms of use and privacy policies carefully before using their services and connecting to our Service.

We may obtain information, including Personal Data, from third parties and sources other than the Service, such as our partners, advertisers and Integrated Services. If we combine or associate information from other sources with Personal Data that we collect through the Service, we will treat the combined information as Personal Data in accordance with this Policy.

We use the information that we collect in a variety of ways in providing the Service and operating our business, including the following:

We use the information – other than Client Data - to operate, maintain, enhance and provide all features of the Service, to provide the services and information that you request, to respond to comments and questions and to provide support to users of the Service. We process Client Data solely in accordance with the directions provided by the applicable Client or Authorized User. If you choose to utilize AI Features within the Service, Crowdin may process data strictly to generate the requested localization outputs, subject to confidentiality obligations and data protection safeguards.

We use the information to understand and analyze the usage trends and preferences of our Visitors and Authorized Users, to improve the Service, and to develop new products, services, features, and functionalities. Should this purpose require Crowdin to process Client Data, then the data will only be used in anonymized or aggregated form. Crowdin may anonymize and aggregate Personal Data contained within the Service so that it no longer identifies any specific individual or Client. We reserve the right to use such anonymized and aggregated data for our legitimate business purposes, including platform analytics, security enhancements, and system optimization aimed at enhancing platform performance (such as optimizing automated translation routing or generating translation quality evaluation (QE) metrics).

We may use a Visitor’s or Authorized User’s email address or other information – other than Client Data – to contact that Visitor or Authorized User (i) for administrative purposes such as customer service, to address intellectual property infringement, right of privacy violations or defamation issues related to the Client Data or Personal Data posted on the Service or (ii) with updates on promotions and events, relating to products and services offered by us and by third parties we work with. You have the ability to opt-out of receiving any promotional communications as described below under “Your Choices.”

We use automatically collected information and other information collected on the Service through cookies and similar technologies to: (i) personalize our Service, such as remembering an Authorized User’s or Visitor’s information so that the Authorized User or Visitor will not have to re-enter it during a visit or on subsequent visits; (ii) provide customized advertisements, content, and information; (iii) monitor and analyze the effectiveness of Service and third-party marketing activities; (iv) monitor aggregate site usage metrics such as total number of visitors and pages viewed; and (v) track your entries, submissions, and status in any promotions or other activities on the Service. You can obtain more information about cookies by visiting http://www.allaboutcookies.org. For further information about the types of cookies and tracking technologies we use, why, and how you can control them, please see our Cookie Statement here.

We use Google Analytics to measure and evaluate access to and traffic on the Public Area of the Site, and create user navigation reports for our Site administrators. Google operates independently from us and has its own privacy policy, which we strongly suggest you review. Google may use the information collected through Google Analytics to evaluate Authorized Users’ and Visitors’ activity on our Site. For more information, see Google Analytics Privacy and Data Sharing.

We take measures to protect the technical information collected by our use of Google Analytics. The data collected will only be used on a need to know basis to resolve technical issues, administer the Site and identify visitor preferences; but in this case, the data will be in non-identifiable form. We do not use any of this information to identify Visitors or Authorized Users.

Except as described in this Policy, we will not intentionally disclose the Personal Data or Client Data that we collect or store on the Service to third parties without the consent of the applicable Visitor, Authorized User or Client. We may disclose information to third parties if you consent to us doing so, as well as in the following circumstances:

Any information that you voluntarily choose to include in a Public Area of the Service, such as a public profile page, will be available to any Visitor or Authorized User who has access to that content.

We may display information related to your account such as your name, username, languages you prefer, the translation projects made publicly available which you are participating in and activities you performed in such project. Please consider carefully what information you disclose in your profile page and your desired level of anonymity, that you can regulate from profile settings. You can review and revise your profile information at any time.

We work with third party service providers who provide website, application development, hosting, maintenance, and other services for us. These third parties may have access to, or process Personal Data or Client Data as part of providing those services for us. We limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions, and our contracts with them require them to maintain the confidentiality of such information.

We may make certain automatically-collected, aggregated, or otherwise non-personally-identifiable information available to third parties for various purposes, including (i) compliance with various reporting obligations; (ii) for business or marketing purposes; or (iii) to assist such parties in understanding our Clients’, Authorized Users’ and Visitors’ interests, habits, and usage patterns for certain programs, content, services, and/or functionality available through the Service.

We may disclose Personal Data or other information if required to do so by law or in response to a facially valid court order, judicial or other government subpoena or warrant. With respect to any demands or requests from public authorities or law enforcement agencies for Client Data, any such disclosure is strictly governed by the specific procedures and safeguards set forth in Section 14 of this Policy.

We also reserve the right to disclose Personal Data or other information (excluding Client Data, which remains subject to Section 14) that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the Service and any facilities or equipment used to make the Service available, or (v) protect our property or other legal rights, enforce our contracts, or protect the rights, property, or safety of others.

To the extent legally permitted by applicable law or court order, Crowdin commits to inform its relevant Client before disclosing any Client Data to public authorities or law enforcement agencies, providing the Client with a reasonable opportunity to object to such disclosure, pursuant to Section 14 of this Policy.

Information about Authorized Users and Visitors, including Personal Data, may be disclosed and otherwise transferred to an acquirer, successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets and only if the recipient of the Authorized User or Visitor Data commits to a Privacy Policy that has terms substantially consistent with this Privacy Policy.

Client Data may be physically or electronically transferred to an acquirer, or successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets, for the sole purpose of continuing the operation of the Service, and only if the recipient of the Client Data commits to a Privacy Policy that has terms substantially consistent with this Privacy Policy.

We respect your privacy rights and provide you with reasonable access to the Personal Data that you may have provided through your use of the Services. If you wish to access or amend any other Personal Data we hold about you, or to request that we delete or transfer any information about you that we have obtained from an Integrated Service, you may contact us as set forth in the “How to Contact Us” section. At your request, we will have any reference to you deleted or blocked in our database.

You may update, correct, or delete your Account information and preferences at any time by accessing your Account settings page on the Service. Please note that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain all information you submit for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so.

For your protection, we require identity verification before responding to any Data Subject requests. If Crowdin no longer requires or processes Personal Data about you to provide the Service, we are under no obligation to maintain, acquire, or additionally process supplementary information to re-identify you solely for the purpose of responding to a regulatory data request.

You may decline to share certain Personal Data with us, in which case we may not be able to provide to you some of the features and functionality of the Service.

At any time, you may object to the processing of your Personal Data, on legitimate grounds, except if otherwise permitted by applicable law. If you believe your right to privacy granted by applicable data protection laws has been infringed upon, please contact us at privacy@crowdin.com. You also have a right to lodge a complaint with data protection authorities.

This provision does not apply to Personal Data that is part of Client Data. In this case, the management of the Client Data is subject to the Client’s own Privacy Policy, and any request for access, correction or deletion should be made to the Client responsible for the uploading and storage of such data into the Service.

You may opt out from the collection of navigation information about your visit to the Site by Google Analytics by using the Google Analytics Opt-out feature.

If you receive commercial emails from us, you may unsubscribe at any time by following the instructions contained within the email or by sending an email to the address provided in the “How to Contact Us” section.

Authorized Users are able to view and modify settings relating to the nature and frequency of promotional communications that they receive from us by accessing the “Settings” tab on the account.

Please be aware that if you opt-out of receiving commercial email from us or otherwise modify the nature or frequency of promotional communications you receive from us, it may take up to ten (10) business days for us to process your request. Additionally, even after you opt-out from receiving commercial messages from us, you will continue to receive administrative messages from us regarding the Service.

Crowdin has no direct relationship with the Client’s customers or third party whose Personal Data it may process on behalf of a Client. An individual who seeks access, or who seeks to correct, amend, delete inaccurate data or withdraw consent for further contact should direct his or her query to the Client or Authorized User they deal with directly. If the Client requests Crowdin to remove the data, we will respond to its request within thirty (30) days. We will delete, amend or block access to any Personal Data that we are storing only if we receive a written request to do so from the Client who is responsible for such Personal Data, unless we have a legal right to retain such Personal Data. We reserve the right to retain a copy of such data for archiving purposes, or to defend our rights in litigation. Any such request regarding Client Data should be addressed as indicated in the “How to Contact Us” section, and include sufficient information for Crowdin to identify the Client or its customer or third party and the information to delete or amend.

Subject to applicable Data Protection Laws (including Regulation (EU) 2016/679 - GDPR), if Crowdin acts as the Data Controller of your Personal Data, you have the following rights:

  • Right of Access (Art. 15 GDPR): The right to obtain confirmation as to whether your Personal Data is being processed and request a copy of your data.
  • Right to Rectification (Art. 16 GDPR): The right to request the correction or completion of inaccurate or incomplete Personal Data.
  • Right to Erasure / “Right to be Forgotten” (Art. 17 GDPR): The right to request the deletion of your Personal Data, subject to applicable statutory retention obligations.
  • Right to Restriction of Processing (Art. 18 GDPR): The right to restrict the processing of your Personal Data under certain conditions (e.g., if you contest data accuracy or object to processing).
  • Right to Data Portability (Art. 20 GDPR): The right to receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
  • Right to Object (Art. 21 GDPR): The right to object at any time to the processing of your Personal Data based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
  • Right to Lodge a Complaint with a Supervisory Authority: If you believe that our processing of your Personal Data infringes applicable Data Protection Laws, you have the right to lodge a complaint with a competent supervisory authority.

To exercise any of these rights, please submit a written request to privacy@crowdin.com. For your protection, we may require identity verification before fulfilling your request.

Crowdin’s lead supervisory authority in the EU is: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon - AKI), address: Tatari 39, 10134 Tallinn, Estonia, website: www.aki.ee, email: info@aki.ee. You also retain the right to lodge a complaint with the data protection supervisory authority in the EU/EEA member state of your habitual residence or place of work.

The Service may contain features or links to web sites and services provided by third parties. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Service. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Service. We encourage you to learn about third parties’ privacy and security policies before providing them with information.

The Service also provides access to external integrations, custom machine translation engines, and third-party applications available for installation via the Crowdin Store, as well as the ability to connect third-party AI providers using your own API keys (BYOK Mode). When you choose to enable, connect, or install these third-party services, your data may be transferred to these external providers pursuant to your direct instructions. Crowdin acts strictly as a technical conduit for such transfers. We are not responsible for the privacy, data processing, or security practices of these third-party providers, and such entities do not constitute Crowdin’s subprocessors within the meaning of any Data Processing Addendum. We encourage you to review the privacy and security policies of any third-party services before integrating them with your Crowdin workspace.

Interest based advertising is the collection of data from different sources and across different platforms in order to predict an individual’s preferences or interest and to deliver to that individual, or his/her computer, smart phone or tablet, advertising based on his/her assumed preference or interest inferred from the collection of data pertaining to that individual or others who may have a similar profile or similar interests.

We work with a variety of third parties to attempt to understand the profiles of the individuals who are most likely to be interested in the Crowdin products or services so that we can send them promotional emails, or serve our advertisements to them on the websites and mobile apps of other entities.

These third parties include: (i) advertising networks, which collect information about a person’s interests when that person views or interacts with one of their advertisements; (ii) attribution partners, which measure the effectiveness of certain advertisements; and (iii) business partners, which collect information when a person views or interacts with one of their advertisements.

In collaboration with these third parties, we collect information about our customers, prospects and other individuals over time and across different platforms when they use these platforms or interact with them. Individuals may submit information directly on our Sites or on platforms run by third parties, or by interacting with us, our advertisements, or emails they receive from us or from third parties. We may use special tools that are commonly used for this purpose, such as cookies, pixels, and similar technologies. We may have access to databases of information collected by our business partners.

The information we or third party collect enables us to learn what purchases the person made, what ads or content the person sees, on which ads or links the person clicks, and other actions that the person takes on our Sites, or in response to our emails, or when visiting or using third parties’ platforms.

We, or the third parties with which we work, use the information collected as described above to understand the various activities and behaviors of our customers, Site visitors and others. We, or these third parties, do this for many reasons, including: to recognize new or past visitors to our Sites; to present more personalized content; to provide more useful and relevant ads - for example, if we know what ads you are shown we can try not to show you the same ones repeatedly; to identify visitors across devices, sales channels, third party websites and Sites, or to display or send personalized or targeted ads and other custom content that is more focused on a person’s perceived interest in products or services similar to those that we offer.

Our interest-based ads may be served to you in emails or on third-party platforms. We may serve these ads about our products or services or send commercial communications directly ourselves or through these third parties. Crowdin does not provide any personal information to the third party sites that display interest-based ads promoting Crowdin.

Except as described in this Policy and permitted under applicable law (including pursuant to user consent provided via our cookie management tools), Crowdin does not sell, rent, or disclose Client Data or raw account credentials to third-party advertising platforms. To the extent device identifiers or online activity data are processed for interest-based advertising, such processing is conducted strictly in accordance with applicable data protection laws, cookie consent requirements, and our Cookie Statement here.

We allow third parties with which we have a separate agreement to use cookies and other technologies to collect information about your use of the Site. These third parties include (i) business partners, which collect information when you view or interact with one of their advertisements on the Site; and (ii) advertising networks, which collect information about your interests when you view or interact with one of their advertisements.

The information gathered by these third parties is used to make predictions about your interests or preferences so that they can display advertisements or promotional material on this Site and on other sites across the Internet tailored to your apparent interests.

The business partners and advertising networks that serve interest-based advertisements on the Services have limited access to a small amount of information about your profile and your device, which is necessary to serve you advertisements that are tailored to your apparent interests. It is possible that they may reuse this small amount of information on other sites or services.

We do not sell or share direct personal identifiers (such as your name, raw email address, or Client Data) with these third parties for their independent marketing purposes. However, subject to applicable consent requirements and your privacy settings, these third parties may automatically collect or receive technical device identifiers (such as IP address, MAC address, browser type, or cookie IDs) and online activity data to provide tailored advertisements, performance analytics, and measurement services. You may manage, restrict, or revoke your consent for non-essential tracking technologies at any time via our Cookie Settings or as described in our Cookie Statement here.

  • strictly necessary/essential cookies - These cookies are essential in order to enable you to move around the website and use its features, such as accessing secure areas of the website. Without these cookies services you have asked for cannot be provided. These cookies don’t collect information that identifies a visitor.
  • functionality cookies - These cookies allow the website to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. For instance, a website may be able to provide you with local weather reports or traffic news by storing in a cookie the region in which you are currently located. These cookies can also be used to remember changes you have made to text size, fonts and other parts of web pages that you can customise. They may also be used to provide services you have asked for such as watching a video or commenting on a blog. The information these cookies collect may be anonymised and they cannot track your browsing activity on other websites.
  • behaviourally targeted advertising cookies - These cookies are used to deliver adverts more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaigns. They are usually placed by advertising networks with the website operator’s permission. They remember that you have visited a website and this information is shared with other organisations such as advertisers. Quite often targeting or advertising cookies will be linked to site functionality provided by the other organisation.

For more information about these and a full list of the cookies we use, what they do, and how to disable the non-necessary ones, please refer to our full Cookie Statement.

Protecting the privacy of young children is especially important. Except as explicitly set forth below regarding educational programs (such as the GitHub Student Developer Pack), our Service is not directed to individuals under the age of 18, and we do not knowingly collect Personal Data from persons under the age of 18 without obtaining verifiable parental consent. If you are under 18 years of age (and not operating an authorized Special Educational Account pursuant to Section 2.1 of our Terms of Service), please do not use or access the Service at any time or in any manner.

Notwithstanding the foregoing, pursuant to Section 2.1 of the Crowdin Terms of Service, individuals who are at least 13 years old and verified members of the GitHub Student Developer Pack may access and use Special Educational Accounts, provided they have obtained permission from a parent or legal guardian who has reviewed and accepted these terms on their behalf.

If we learn that Personal Data has been collected on the Service from persons under 18 years of age without required verifiable parental or guardian consent, we will take appropriate steps to delete this information. If you are a parent or guardian and discover that your child under 18 years of age (or under 13 years of age in any circumstance) has obtained an Account on the Service without your authorization, you may alert us at privacy@crowdin.com and request that we delete that child’s Personal Data from our systems.

The Service is not intended to be used by unauthorized minors, and is not intended to be used to post content to share publicly or with friends. To the extent that a minor has posted such content on the Service, the minor (or their parent/guardian) has the right to have this content deleted or removed using the deletion or removal options detailed in this Privacy Policy. If you have any questions regarding this topic, please contact us as indicated in the “How to Contact Us” section. Please be aware that, although we offer this deletion capability, the removal of content may not ensure complete or comprehensive removal of that content or information.

We follow generally accepted industry standards to protect the information submitted to us, both during transmission and once we receive it. We maintain appropriate administrative, technical and physical safeguards to protect Personal Data against accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse, and any other unlawful form of processing of the Personal Data in our possession. This includes, for example, firewalls, password protection and other access and authentication controls. We use SSL technology to encrypt data during transmission through public internet, and we also employ application-layer security features to further anonymize Personal Data.

However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. We cannot ensure or warrant the security of any information you transmit to us or store on the Service, and you do so at your own risk. We also cannot guarantee that such information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. If you believe your Personal Data has been compromised, please contact us as set forth in the “How to Contact Us” section.

If we learn of a security systems breach, we will inform you and the authorities of the occurrence of the breach in accordance with applicable law.

We maintain separate retention policies for data processed on behalf of our Clients (Client Data) and data processed for our own legitimate business operations (Administrative and Account Data). We only retain this information for as long as an Authorized User’s account is active or as otherwise needed to fulfill the purposes for which it was initially collected, unless otherwise required by law. We will retain and use information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements as follows:

  • the Client Data of closed accounts is deleted from active production databases within sixty (60) days of the date of closure
  • automated system backups are kept for up to an additional two (2) months until they are logically overwritten in the ordinary course of business, during which time such backup data is rendered strictly isolated, inaccessible, and protected from any further processing operations
  • billing information and related corporate transaction records are retained for a period of 7 years as of their provision to Crowdin in accordance with the Estonian accounting and taxation laws
  • information on legal transactions between Client and Crowdin and executed contractual agreements is retained for a period of 10 years as of their provision to Crowdin in accordance with the general limitation period set for civil claims in the Estonian General Part of the Civil Code Act

Although we may allow you to adjust your privacy settings to limit access to certain Personal Data, please be aware that no security measures are perfect or impenetrable. We are not responsible for circumvention of any privacy settings or security measures on the Service. Additionally, we cannot control the actions of other users with whom you may choose to share your information. Further, even after information posted on the Service is removed, caching and archiving services may have saved that information, and other users or third parties may have copied or stored the information available on the Service. We cannot and do not guarantee that information you post on or transmit to the Service will not be viewed by unauthorized persons.

To provide our services, we use data centers located in the United States and Ireland. The geographical region for storing your data may depend on the service options. If you are a resident of the European Economic Area (EEA), the United Kingdom, or Switzerland, please note that we transfer your Personal Data outside of these regions to the United States and other countries for storage, hosting and processing. We ensure such transfers are lawful and that your data is adequately protected. Whenever such an international transfer constitutes a Restricted Transfer, the primary safeguards we rely on for international data transfers are:

  • Adequacy Regulations: We may transfer Personal Data to countries that have been deemed to provide an adequate level of data protection by the relevant authorities, such as the European Commission, the UK Secretary of State, or the Swiss Federal Council.
  • Data Privacy Frameworks (DPF): When we transfer Personal Data to our third-party service providers located in the United States, we rely on their active self-certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, as applicable and set forth by the U.S. Department of Commerce. In the event that the DPF is suspended, invalidated, or inapplicable to a specific transfer scenario, the fallback contractual mechanisms described below shall automatically apply.
  • Standard Contractual Clauses and Agreements: For transfers to countries without an adequacy decision or to service providers not certified under the Data Privacy Framework, we rely on Standard Contractual Clauses (SCCs) issued by the European Commission, which are supplemented by the UK’s International Data Transfer Addendum (UK Addendum) when required for UK data transfers. For Restricted Transfers subject to the Swiss Federal Act on Data Protection (FADP), the EU SCCs apply with the necessary modifications required under Swiss law, designating the Swiss Federal Data Protection and Information Commissioner (FDPIC) as the competent supervisory authority. These clauses contractually oblige the data importer to process and protect your data with a level of security equivalent to that required by the GDPR and other applicable laws.

You can find more information about the countries we transfer data to in our Terms of Service and Subprocessors List.

Crowdin complies with lawful legal processes and government demands in accordance with applicable legislation. We do not voluntarily disclose personal data or localization content unless we believe in good faith that we are legally compelled to do so by a facially valid order issued by a competent judicial, administrative, or government body.

Our handling of public authority demands is governed strictly by the following provisions:

  • Where permitted by the requesting authority and applicable law, we will notify you via email of the existence of a data demand or request the authority to contact you directly. Crowdin is under no contractual or legal obligation to contest, appeal, or seek waivers for any non-disclosure orders or “gag orders” imposed by public authorities.
  • Crowdin discloses data only to the extent we believe is required to fulfill our strict legal obligations. We aim to disclose only the minimum amount of information necessary to satisfy the valid scope of the demand. Crowdin shall bear no liability whatsoever to you, your users, or any third party for any disclosures of data made in good faith compliance with any legal process or governmental demand.
  • Crowdin is a passive infrastructure provider and has no obligation to actively oppose, challenge, or initiate any legal proceedings against any government or public authority demands. Any motions, appeals, or legal actions to protect, quash, or modify a disclosure demand must be initiated and executed exclusively and independently by the Client. Crowdin has no duty to participate in, appear for, or fund any such legal defenses.
  • Crowdin does not purposefully maintain, authorize, or build cryptographic “backdoors” or specialized access points within our software, databases, or platform infrastructure for the purpose of facilitating unauthorized government surveillance or mass data interception.

Crowdin does not own, control or direct the use of any of the Client Data stored or processed by a Client or Authorized User via the Service. Only the Client or Authorized Users are entitled to access, retrieve and direct the use of such Client Data. Crowdin is largely unaware of what Client Data is actually being stored or made available by a Client or Authorized User to the Service and does not directly access such Client Data except as authorized by the Client, or as necessary to provide Services to the Client and its Authorized Users.

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679), the UK GDPR, and the Swiss Federal Act on Data Protection (FADP), the Parties acknowledge that the Client acts as the Data Controller and Crowdin acts strictly as a Data Processor with respect to the Personal Data contained within the localization content and translation files uploaded by the Client into the platform. In this capacity, Crowdin processes such data solely based on the documented final instructions of the Client.

Conversely, Crowdin acts as an independent Data Controller with respect to account administration data, billing details, business contact information, and platform usage metrics generated by authorized users for the purpose of managing the business relationship, facilitating transactions, providing customer support, and maintaining platform security. The Parties agree that they act independently as separate, individual Controllers for these respective activities, and nothing shall be construed to establish a joint controllership between Crowdin and the Client.

Crowdin acts strictly as a Data Processor on behalf of its Clients and Authorized Users with respect to any Client Data containing Personal Data that is subject to the requirements of the GDPR. Except as provided in this Privacy Policy, Crowdin does not independently transfer, disclose, or otherwise make available Client Data containing Personal Data stored in connection with the Services to third parties, except to authorized third-party subprocessors who process such data on Crowdin’s behalf to facilitate the provision of the Services. All such processing and transfer activities are initiated or explicitly authorized solely by the applicable Client or Authorized User.

The Client or the Authorized User is the data controller under the Regulation for any Client Data containing Personal Data, meaning that such party controls the manner such Personal Data is collected and used as well as the determination of the purposes and means of the processing of such Personal Data.

Crowdin is not responsible for the content of the Personal Data contained in the Client Data or other information stored on its servers (or its subcontractors’ servers) at the discretion of the Client or Authorized User nor is Crowdin responsible for the manner in which the Client or Authorized User collects, handles disclosure, distributes or otherwise processes such information.

To the extent that Crowdin processes Personal Data subject to US state privacy laws (including the California Consumer Privacy Act, “CCPA”, and applicable state privacy statutes), the Client acknowledges that Crowdin acts strictly as a “Service Provider” or “Processor” regarding the Client’s uploaded content. Crowdin is contractually prohibited from, and shall not: (a) sell or share such Personal Data for cross-context behavioral advertising; (b) retain, use, or disclose such Personal Data for any purpose other than providing the Services; or (c) combine such Personal Data with other data, except as expressly permitted under applicable laws.

For the purposes of applicable Data Protection Laws (including the GDPR), the Data Controller for Personal Data processed under this Policy (excluding Client Data processed on behalf of Clients) is: Crowdin OÜ, registry code: 14479905, registered address: Liivalaia 36, Kesklinna linnaosa, Tallinn, Harju maakond, 10132, Republic of Estonia, email: privacy@crowdin.com.

The Service may include certain artificial intelligence or machine learning systems, features, or tools (“AI Features”). Account administrators maintain complete operational control over whether to enable or disable these AI Features within their workspace. The Client shall use commercially reasonable efforts to ensure that no unnecessary Personal Data is included in such requests, adhering to the principle of data minimization under applicable Data Protection Laws.

For all AI Features operated directly within the Service (“Managed Mode”), except as otherwise explicitly authorized by the Client or disclosed by Crowdin for specific specialized models, Crowdin uses commercially reasonable efforts to ensure that its selected third-party AI sub-processors are contractually prohibited from using any Personal Data or confidential information contained within the Client Data, inputs, prompts, or source texts to train, tune, or improve generalized, publicly available, or third-party artificial intelligence and machine learning models. For the avoidance of doubt, Crowdin itself does not and shall not use any such data, inputs, prompts, or source texts to train, fine-tune, or otherwise improve any artificial intelligence or machine learning models.

When the Client utilizes AI Features by integrating its own third-party AI service provider accounts or API keys (Bring Your Own Key - “BYOK Mode”), the Client acknowledges that Crowdin acts strictly as a technical conduit for the transmission of data. The Client maintains sole responsibility for executing appropriate data processing agreements, managing data privacy, configuring opt-out settings, and ensuring compliance directly with such third-party AI providers. Crowdin shall not be liable for the data processing, security, or privacy practices of any third-party providers connected via BYOK Mode.

Please revisit this page periodically to stay aware of any changes to this Policy, which we may update from time to time. If we modify the Policy, we will make it available through the Service, and indicate the date of the latest revision, and will comply with applicable law. Your continued use of the Service after the revised Policy has become effective indicates that you have read, understood and agreed to the current version of the Policy.

Crowdin’s use and transfer to any other app of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Crowdin confirms that the Google Workspace APIs accessed through our services (including the Crowdin platform and any applications developed by Crowdin and available for installation at store.crowdin.com) are used solely to provide the requested functionality. We do not share Google user data with any third parties except our sub-processors, who are contractually bound to process such data on our behalf and in accordance with applicable data protection laws. We do not use this data to develop, improve, or train generalized artificial intelligence (AI) or machine learning (ML) models.

Furthermore, data received via Google Workspace APIs is strictly prohibited from being used, transferred, disclosed, or processed to develop, improve, or train generalized, non-personalized, or foundational artificial intelligence (AI) or machine learning (ML) models.

Please contact us with any questions or comments about this Policy, your Personal Data, our use and disclosure practices, your consent choices, or if you have any concerns or complaints about this Policy or your Personal Data, by email at privacy@crowdin.com.


Your Crowdin Team.

Bu sayfa faydalı oldu mu?