CruxOCM, Inc. Privacy Policy
Last updated: July 21, 2026
This Privacy Policy describes how CruxOCM, Inc. (“Crux”, “us,” “our”, or “we”) handles personal data for website visitors and individuals who subscribe to use our services (“clients”).
About this policy
This Privacy Policy will change periodically to comply with privacy law requirements. If the changes are significant, we will provide notice.
We recommend that you read this Privacy Policy to ensure you are fully informed about the types of personal data we collect, why and how we collect, use, and protect it, how it is disclosed, where it is stored, and to ensure you are fully informed about your rights relating to any of your data. Residents of California, Nevada, and Canada, please also refer to the specific sections directed to you in this Privacy Policy to learn more about your privacy rights.
Privacy practices
How we collect
Crux collects personal data from you directly when you express an interest in obtaining additional information about our services, request a strategy session via our contact form, subscribe to updates, contact Crux’s customer support team, comment on our blogs or in community forums, or when you interact with us in any form.
What we collect
- Personal information. When you contact us or register an account with us, we may collect personal information such as your first and last name, title, name of business, work email address, and message content. If you are seeking customer support, you may also be asked to create a login and password for your account.
- Business contacts. When you access and use our services, we may also collect information about the business contacts that you upload into your account.
- Technical data. We may collect the IP address of your device, browser type, and similar technical signals to operate and secure the website, detect abuse, manage traffic, and (with consent) understand aggregate analytics.
How we use your personal data
We use your personal data to:
- respond to your inquiries about our services,
- maintain a commercial relationship with you and communicate with you (including account verification and discussions pertaining to your needs and preferences),
- market features and products and provide you with newsletters, promotional materials and information about events, and other information that may be of interest to you, where permitted,
- generate analytics for the improvement of the website and services,
- administer, maintain, manage and improve our website, services and products, and internal operations, including answering support questions and resolving technical issues,
- manage the services platform (including support systems and security),
- analyze, research and improve our products, business, services, and websites,
- test changes in our services and develop new features and products,
- comply with our legal obligations to establish, exercise, or defend legal claims, and to monitor and report compliance issues,
- prevent, investigate and respond to fraud, unauthorized access to or use of our services, breaches of terms and policies, or other wrongful behavior, and
- disclose as permitted or required by law, or as otherwise specified at the time of collection.
Cookies, consent, and related technologies
We use a first-party cookie preference control on this website. Categories include:
- Strictly necessary — required to operate the site (security, load balancing, remembering your cookie choices).
- Analytics — cookieless Umami analytics, loaded only with your consent. We do not use Google Analytics or Lead Forensics on this site.
- Marketing — optional category for future marketing tags; not used to sell personal information.
You can revisit choices anytime via Cookie settings in the site footer. Where required, we honor Global Privacy Control (GPC) signals for applicable opt-out of sale/share. For general cookie education, see allaboutcookies.org.
All marketing messages we send contain an “unsubscribe” link. You may opt out of marketing communications by following that link or contacting us at the address below. Transactional or business-relationship messages may continue after you opt out of marketing.
Service providers and processors
We use carefully selected vendors to operate this website and deliver services. Depending on the feature you use, processors may include:
- Amazon SES — transactional email for contact-form delivery (US-hosted).
- Cloudflare Turnstile — bot protection on contact forms.
- Google Cloud / GKE — hosting for this marketing website.
- Umami — cookieless, consent-gated analytics.
- Zendesk — optional Help Center / support launcher (US-hosted).
- HubSpot — may be used in a future gated lead-capture mode; not the default path on this site today.
Product and platform services for clients may also use Amazon Web Services (AWS) and related subprocessors under customer agreements.
Circumstances in which we share personal data
We do not rent, trade, or sell personal information. We share personal data only to provide services you requested, when we have your permission, or under the following circumstances:
- with service providers who process data on our behalf (email, hosting, security, support, analytics), under contractual obligations,
- with third-party contractors such as developers, support administrators, designers, data analysts, and network technicians to maintain and improve the services,
- if required by law or necessary to protect our rights or comply with a legal process,
- if we believe disclosure is required to investigate, prevent, or take action regarding illegal activities, suspected fraud, or a potential threat to the physical safety of a person,
- in connection with a merger, acquisition, or sale of assets — you will be notified of any change in ownership or control of personal information, and
- with our legal, financial, and other professional advisors.
How long we keep personal data
For website contact requests, we retain personal data for up to 24 months unless a longer period is required by law or needed to resolve a dispute. For clients with accounts, we retain personal data for as long as the account is open, unless a longer retention period is required by law. Analytics data is retained in aggregate form according to our analytics configuration.
Your rights
You have the following rights with respect to your personal information:
- Right to Access — You may request access to the personal data we have relating to you. We will reply within 30 days either to provide your information, confirm we do not have it, or explain if we cannot provide access (for example, if doing so would violate another individual’s privacy).
- Right to Correct — If you find your information is inaccurate, you may have it corrected.
- Right to Withdraw Consent — If consent was a basis of collection and you no longer consent to us retaining and using your personal data, you may request deletion. We will do so unless legal requirements impose retention periods.
How we protect personal data
To keep your personal data safe, we use appropriate security safeguards. These include physical measures (e.g., restricting access to offices and alarm systems), up-to-date technological tools (e.g., passwords, encryption, firewalls and security patches), and organizational controls (e.g., security clearances, limiting access, staff training, and agreements). We apply these measures based on the sensitivity of the information and the current state of technology. No data security measures can guarantee 100% security.
We will never initiate a request for personal information by email or pop-up window. If you receive a request that appears to originate from Crux, please do not respond and notify us using the contact information under “Questions?” below. To report a product or website security incident, see our Security page.
Transfer of personal data
If you are located outside the United States, please be aware that information we collect about you may be transferred to and processed in the United States or other jurisdictions outside your own (including by SES, Zendesk, and other US-hosted processors). By interacting with our websites and using our services, you consent to such transfers and acknowledge that data protection laws in those countries may differ from the laws in your country of residence.
Notice to California residents
As a supplement to other information in this Privacy Policy, we provide the following notice to residents of California (“California consumers”) in accordance with the California Consumer Privacy Act (“CCPA”), as amended by the CPRA. This section may not apply to you if you are a Crux client under a separate agreement.
California consumer privacy rights
- Right to Know — categories of personal information collected; sources; business or commercial purpose; categories of third parties with whom we share; and specific pieces collected about you over the past 12 months.
- Right to Delete — request deletion of personal data subject to exceptions permitted by law.
- Right to Opt-Out of Sale/Share — we do not sell personal information. Use Cookie settings or email info@cruxocm.com to exercise applicable opt-out rights.
- Right to Non-Discrimination — we will not discriminate against you for exercising CCPA rights.
In the preceding 12 months, Crux has disclosed the following categories of personal data for a business purpose:
| Category of Personal Information | Categories of Recipients |
|---|---|
| Personal identifiers such as name, address, phone number, email address. | Service Providers |
| Internet and Network Activity — IP address, unique device identifiers, and device attributes, like operating system and browser type. | Service Providers |
| Interaction with our services or our advertisements. | Service Providers |
We do not knowingly sell the personal data of consumers under 16 years of age. You may make a CCPA request by email to info@cruxocm.com. We will verify your identity before responding. You may designate an authorized agent subject to CCPA agent requirements.
California’s Shine the Light Law. We do not share personal data with third parties for their own direct marketing purposes without your consent. Once a year, free of charge, California residents may request information regarding disclosure of personal data to third parties for their direct marketing purposes by contacting info@cruxocm.com or writing to the Houston address below with the reference “CA Shine the Light Disclosure”.
Do Not Track / GPC. Industry standards for browser Do Not Track (DNT) signals remain limited; we honor Global Privacy Control (GPC) for applicable sale/share opt-outs where required.
Notice to Canadian residents
Personal data we collect directly from consumers on our websites, apps, or through our services is collected with consent. Personal data from other sources is collected with assurance that individuals provided consent for that sharing.
You may ask us to:
- access your personal information;
- verify or correct inaccuracies in your personal information;
- where you have provided consent, withdraw your consent under certain circumstances.
Submit requests by email to info@cruxocm.com. We may require information to verify your identity. If we decline a request, we will tell you why, subject to legal restrictions. If you withdraw consent, we may not be able to provide a particular product or service.
Notice to international residents
If you are accessing our website or services from the European Union, Asia, South America, or any other region with laws governing personal data that differ from United States or Canadian laws (such as the GDPR), please be advised that through your continued use of our website and services, you may be transferring personal information into the United States and you consent to that transfer.
If you have a complaint relating to our use of personal information and you are accessing from the EU, you may lodge a complaint with a supervisory authority competent for your country or region. A list of data protection authorities is available at ec.europa.eu.
External links and third-party websites
This Privacy Policy does not apply to third-party websites and apps, including any linked from our services. Those sites have their own privacy policies. We are not responsible for transactions between you and a third-party website.
Children’s privacy
Our website, apps and services are not designed for and are not marketed to people under the age of 16 (“minors”). We do not knowingly collect information from minors. If you believe we might have information from or about a minor, contact us at info@cruxocm.com.
Changes to this Privacy Policy
We reserve the right to update or modify this Privacy Policy from time to time. We will indicate changes by updating the “Last updated” date at the beginning of this policy. Your continued use of our services after any update will constitute your acceptance of our changes.
Questions?
For questions, concerns, or complaints regarding our data handling practices, compliance with laws, or this Privacy Policy, contact us via info@cruxocm.com or write to:
CruxOCM Inc.
12436 FM 1960 Rd. W
PMB 1025
Houston, Texas 77065
Attention: Privacy Team
Related pages: Terms of Use · Security · Safety and Security · Contact