Last updated: September 30, 2026
This Privacy Policy explains what personal data CRDD handles, where it is kept, who is responsible for it, and the choices available to users.
Thank you for choosing CRDD. CRDD, made by Flynch MB ("Flynch," "we," or "us"), is an ID scanner for door staff at bars, clubs, and other venues. It reads the barcode or machine-readable zone of an ID document, works out the holder's age, and shows whether to admit, deny, or check the document by hand. CRDD has no account system and no server of its own. Everything the app reads from an ID is processed and stored on the device that made the scan. We never receive it.
In this Policy, "you" and "the venue" mean the business, and its staff, that uses CRDD. "Guests" means the people whose ID documents are scanned. If you do not agree with this Policy, please discontinue use of the Service. Capitalized terms not defined here have the meanings given in the CRDD Terms of Service.
CRDD needs no sign-up, email address, or password. The app has no server of its own and sends no scan data over the internet. All reading, checking, and storing of ID data happens on the device.
With your permission, CRDD uses the device camera to read:
Camera frames are processed in memory and are never stored or sent anywhere. CRDD keeps only the result of the scan, as described in Section 1.4. You can withdraw the camera permission in your device settings at any time, but CRDD cannot scan without it.
If you use the optional chip check, CRDD reads the chip in a passport or ID card over NFC, on the device. To open the chip, the app uses a key derived from the document's MRZ (the BAC or PACE protocols). It then checks the issuing country's digital signature on the chip data against a master list of country signing certificates (CSCA) published by ICAO and the German Federal Office for Information Security (BSI). This master list is bundled in the app, so the check does not contact any server. The chip check also reads the holder's facial photo from the chip, so staff can compare it with the person at the door.
For each scan, CRDD stores the following on the device:
The scan log is kept in an encrypted SQLite database (SQLCipher). The encryption key is kept in the iOS Keychain. The log is used for the in-app history, passback warnings, and statistics.
When staff add a guest to the ban list or the VIP list, CRDD stores on the device the keyed hash of the document number, the guest's name, the reason, and the end date entered by staff, together with a copy of that guest's last chip photo, if there is one. List entries are kept until they are removed from the list.
CRDD keeps an encrypted diagnostic log on the device to help with troubleshooting. It is never sent anywhere.
CRDD also keeps your settings on the device, such as the door name, the venue's age limit, the retention period, and whether CRDD Pro is unlocked. Deleting the app deletes this data.
Apple or Google sells CRDD Pro subscriptions through its store. RevenueCat receives an anonymous app user ID and purchase metadata for subscription access and restore. Metadata includes the plan, price, currency, trial state, and renewal state. Use the same store account to restore Pro on another device. Apple or Google processes the payment. CRDD receives no name, card number, or payment account details. CRDD sends no guest data to RevenueCat, Apple, or Google.
The CRDD app contains no advertising SDKs and no third-party analytics SDKs. We do not build behavioral profiles and we do not sell personal data. If we add privacy-friendly usage analytics in the future, we will update this Policy first.
When you contact hello@theflynch.com, we collect the information you provide, including attachments, to respond and improve our services. Please do not send us photos of guests' ID documents or screenshots that show guest data.
CRDD is a tool that runs on the venue's devices. The venue decides whose ID documents are scanned, why, and for how long the results are kept. The venue is therefore the controller of the guest data it scans. Flynch never receives guest data and has no access to it, and cannot see, search, correct, or delete it.
If you use CRDD, you are responsible for:
Guests who have questions about a scan should contact the venue that scanned their ID.
The app uses the data described above, on the device, to show the scan result, warn of passbacks, apply the ban and VIP lists, and show statistics. Flynch uses the limited data we receive to:
Where GDPR or similar laws apply, Flynch processes the personal data it receives based on:
The lawful basis for scanning guests' ID documents is decided by the venue, as described in Section 2.
We do not sell personal data. Guest data never leaves the device through CRDD. The only data that leaves the device goes to the following categories of recipients, each to the extent needed to provide the Service:
On the device, the venue chooses how long scans are kept: 7, 30, or 90 days. Older scans, and their chip photos, are deleted automatically. "Clear the log" in the app deletes all scans at once. Ban and VIP list entries, and their photos, are kept until they are removed from the list. Deleting the app deletes all CRDD data on the device, including the log, the lists, the photos, and the diagnostic log.
RevenueCat, Apple, and Google retain purchase records according to their own policies. To request deletion of support correspondence, contact hello@theflynch.com.
CRDD is designed to keep ID data on the device and protected there. The scan log and the diagnostic log are encrypted, the database key is kept in protected storage on your device, document numbers are stored only as a keyed hash, and camera frames are never saved. Purchase requests use transport encryption. No service is completely secure. Please protect the devices that run CRDD with a passcode, keep your device operating system updated, and notify us of any suspected security problem in the app.
We operate in the European Union. CRDD transfers no guest data. RevenueCat, Apple, and Google are located in the United States. For international personal data transfers, we rely on appropriate safeguards, such as Standard Contractual Clauses, to protect your rights.
Depending on your location, you may have the right to:
You can change the retention period, clear the log, and remove list entries in the app, and turn off camera access in your device settings. To exercise any other right, email hello@theflynch.com. Because CRDD has no account and we hold no scan data, requests about guest data must be made to the venue that scanned the ID.
CRDD is a tool for businesses and is not directed to children. We do not knowingly collect personal information from children. Venues may scan the ID of a person under their age limit, including a minor, when that person tries to enter. That data stays on the venue's device, under the venue's responsibility, and is deleted in the same way as any other scan.
The Service includes links to websites and platforms we do not control, such as the Apple App Store. This Privacy Policy does not apply to those third parties. Review their policies before providing personal information.
If you are a California resident, you have the right to know the categories of personal information we collect, use, and disclose, as described in Sections 1–5. You may also request deletion of personal information, subject to exemptions under the California Consumer Privacy Act (CCPA). We do not sell or share personal information for cross-context behavioral advertising.
If you reside in the European Union, you may lodge a complaint with your local data protection authority. You can find contact details at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
We may update this Policy to reflect changes in laws, technology, or our practices. When we make material changes, we will notify you by in-app notice or by posting an update on our website, and indicate the "Last updated" date at the top. Continued use of the Service after the effective date means you accept the revised Policy.
If you have questions, requests, or concerns about this Privacy Policy or our data practices, contact us at:
Flynch MB
Vilnius, Lithuania
hello@theflynch.com
We will respond within the timelines required by applicable law.