Privacy policy
Stacked & Settled · THE Crown Legacy · Local workspace and optional accounts
This policy describes Stacked & Settled and its support service, published by THE Crown Legacy. Effective 7 October 2026. The account and backup sections apply when you use account features in the account-enabled version 1.4. Availability depends on the installed app version and service configuration; this policy update does not activate these features or add them to earlier local-only versions.
Information kept on your iPhone
You can use the local workspace without an app account. Business and client names, email addresses, phone numbers, entered job locations, appointments, services, notes, prices, tax and deposit settings, payment instructions, manual payment records and quotes are saved in protected app storage. Creating these records locally does not by itself upload a business workspace to THE Crown Legacy.
Preview timing, access choices and free-export usage are stored locally, including a device-only Keychain integrity record. Quote follow-up reminders are scheduled on your device with permission. Their notification displays a quote number, not customer details.
Optional Apple and Google sign-in
If you choose Sign in with Apple or Google, the provider authenticates you and our account service receives the identifiers and authorization information needed to create or access your app account. We do not receive your provider password. Signing in alone does not upload your business workspace or grant a Pro subscription.
Our Apple sign-in integration requests no name or email scopes. Our Google integration requests no Google Drive or Gmail access. Names and contact details you enter into the workspace can still be included when you choose a backup.
Information in a chosen backup
When you save a backup, our account service receives a workspace snapshot linked to your app account. This can include your business profile, customer names, email addresses and phone numbers, job or appointment locations, jobs, quotes, templates, descriptions, notes, payment instructions, service amounts, tax settings, deposits, payment-method references and manually recorded service-payment history. Include only information needed for your work. Manual payment records do not verify or move money.
The backup includes descriptive reference metadata, but does not include referenced photo files. New uploads remove cached signed image links. Subscription entitlements, preview/export counters, provider tokens, ad-consent choices and automatic-backup preferences are not part of the workspace snapshot.
The service uses Cloudflare Workers, D1 and private R2 storage. The backup bucket has public access disabled and a reported Asia Pacific location. This is not a claim that all account records, processing, support or provider data remain in India or in one region. This is the app’s account storage, not your personal iCloud Drive or Google Drive. Backups are readable by the service and are not end-to-end encrypted.
Your backup and restore choices
Manual backup requires your choice. Automatic backup is a separate opt-in on each iPhone and follows saved changes while the app is open and connected. A newer cloud revision pauses uploads for review. Turning automatic backup off or signing out keeps the existing cloud copy.
Only completed backups are recoverable. Sign in to the same app account on another iPhone and review the backup before restoring. Restore replaces the device’s workspace rather than merging records; prior local files remain in device recovery archives. Keep independent copies of important records.
Linking sign-in methods and deleting an account
Linking Apple and Google sign-in requires fresh proof of both provider identities. We do not merge accounts just because email addresses match.
From the app menu, open Quotes, Pro & Settings → Secure Account & Backup, use Delete App Account & Cloud Backup and reauthenticate to request deletion. Accepted deletion disables ordinary app-account access. Cloud-data cleanup and provider-authorization revocation have separate progress states; use Check Deletion Status to review them. An unfinished or failed provider revocation is not reported as completed.
Deleting the app account does not delete your Apple or Google account, cancel an Apple subscription, erase local records or recovery archives, or remove copies you already shared. Deleting the local workspace pauses automatic backup and preserves the last cloud backup for review.
Technical information and Google Sign-In
Our service processes account, session and security-challenge identifiers, authorization timestamps and protected provider credentials for authentication, account linking and authorization revocation. Service diagnostics include request status, path, duration and errors. IP-derived rate-limit records help prevent abuse. Hashed technical identifiers are not treated as anonymous.
Google’s sign-in component declares account and contact information, approximate location, user and device identifiers, usage information and other technical data. Its declared purposes include sign-in functionality and technical analytics; Google documents IP-derived approximate location for fraud prevention. These disclosures inform the privacy information for the account-enabled release. See Google’s sign-in privacy guidance and Google’s privacy policy.
We use the account service and chosen workspace backup for app functionality, reliability and security. This release does not use workspace contents for cross-company advertising profiles or data brokerage. It does not enable external ad serving or rewarded ads. Bundled app promotions may appear; hiding one stores that choice locally. Google sign-in analytics are separate from advertising.
Retention and cleanup
The service keeps your current completed backup for account recovery until it is replaced or you request account deletion. Replaced or unreferenced backup objects enter guarded cleanup after a minimum one-hour grace period; this is not a guarantee of deletion within one hour. Active references and uploads are checked before removal. Account-deletion cleanup and authorization revocation can require further processing.
App sessions expire after 24 hours. Deletion-status access expires after seven days. These access periods do not promise that all associated records are erased at those times. Rate-limit records older than 24 hours become eligible for removal during cleanup. The storage provider’s seven-day rule for unfinished multipart uploads is not a lifetime for completed backups.
Service, security, support and provider infrastructure records follow their applicable retention processes. Account deletion does not instantly remove every provider log, recovery copy or support message. For access, correction or deletion requests, contact support@thecrownslegacy.in. We may require limited information to verify the request and will explain information that must be retained.
Apple purchases and sharing
Apple StoreKit supplies product and verified transaction/entitlement information for optional Pro purchases and restoration. The app evaluates that information locally; it does not upload purchase receipts to THE Crown Legacy or request your Apple Account password or full card credentials. Apple handles its own service information.
You choose the recipient or destination when sharing a PDF or message through the iPhone share sheet. That destination receives the selected content. Temporary PDFs are removed after sharing where possible, with cleanup retried on launch; copies sent elsewhere follow the recipient’s practices.
Public online booking and online customer-payment collection are not enabled in this release. Previously imported records and inactive connection credentials may remain on the device. This release does not refresh those legacy services or delete information previously held by them.
Support information
If you email support@thecrownslegacy.in, THE Crown Legacy and its mail service receive your sender name and email address, message and any attachments you choose to send. We use these data only to respond, troubleshoot and handle privacy requests. We do not use support messages for marketing, advertising tracking or data brokerage. We limit access to people and service providers needed to handle support.
We retain support information only as needed to resolve requests, provide necessary ongoing support and meet applicable obligations. We review closed requests and remove information no longer needed. To request access, correction or deletion of support information, email the same address. We may need limited information to verify a request and will explain any information that must be retained.
Do not send passwords, verification codes, customer records or payment-card details. Remove client information from screenshots. Provider backup, trash and security records follow the applicable provider processes; deleting an inbox message is not a guarantee of immediate deletion from every provider system.
We use Hostinger Email for support correspondence. Its documented Trash recovery window is up to 30 days; messages manually removed from Trash cannot be restored through that recovery process. This provider recovery window is separate from our support-retention decisions and is not a promise that all security records, backups or copies in other mail clients disappear at the same time. See Hostinger’s message-recovery guidance.
This website
These pages use a separate static Cloudflare Pages project, without app backend functions, analytics scripts, forms, tracking pixels or external fonts. Cloudflare processes connection/request information, which may include IP addresses and technical traffic details, to deliver and protect the site. We do not add that information to advertising profiles. Provider processing is described in Cloudflare’s privacy policy; this website has its own policy here.
Your local controls and requests
Menu → Quotes, Pro & Settings includes Delete Local Stack Workspace. Professional Quotes has separate records and deletion controls. Local deletion preserves preview timing, free-export usage and subscription access. Recovery copies and already shared files are separate from ordinary records. Deleting the app can remove local business files; device backup settings remain under your control.
THE Crown Legacy cannot retrieve a workspace that was never sent to it. For privacy questions, including our support records, use support@thecrownslegacy.in. We will update this policy when supported data practices change.