PRIVACY NOTICE
Clear handling of the information behind the work.
Effective and last updated August 20, 2026. This notice covers CREWCLEAR websites, accounts, workspaces, applications, and related communications.
Privacy at a glance
- CREWCLEAR uses account and operational information to provide the service—not to build advertising profiles.
- We do not sell personal information or share it for cross-context behavioral advertising.
- Crew location check-ins are deliberate actions. CREWCLEAR does not promise or authorize hidden, continuous tracking.
- Organizations control their workspaces; requesters see their own requests, and employee access can be revoked.
- Privacy requests can be sent to notifications@crewclearapp.com with “Privacy Request” in the subject line.
1. Scope and who is responsible
For account administration, website security, direct support, and CREWCLEAR’s own service operations, CREWCLEAR determines why and how information is used and acts as the business or controller.
For work requests, workforce records, crew check-ins, attachments, and other content placed in an organization’s workspace, the customer organization generally determines the purpose and acts as the business or controller. CREWCLEAR processes that information for the organization as its service provider or processor. Your organization’s own workforce, public-records, retention, and privacy notices may also apply.
2. Notice at collection: information we collect
- Account and contact data: name, work email, email domain, optional phone, job title, password hash, email-verification state, organization, team size, role, and workspace membership.
- Operational content: requests, descriptions, categories, priority, assignments, clarifications, checklist answers, status history, notes, labor, materials, routes, and completion records.
- Location data: work-site addresses and coordinates, saved sites, and optional crew check-ins including coordinates, accuracy, and time.
- Files and evidence: photos, filenames, file type, size, integrity hash, uploader, and metadata contained in an uploaded file.
- Security and device data: session identifiers, IP-derived request information, browser and request metadata, authentication events, rate-limit records, and audit history.
- Preferences and communications: requester ticket-update choices, optional marketing preference, invitations, verification and recovery messages, and support correspondence.
- Government sales and pilot inquiries: government name, state, population, department, contact details, role, current process, operational challenge, timing, pricing or demo interest, and optional marketing choice.
- Campaign attribution: landing page, referrer, and UTM campaign fields supplied in a link when a person submits a government pilot or pricing request.
Please do not submit Social Security numbers, payment-card data, medical records, biometric identifiers, or other highly sensitive information unless CREWCLEAR has expressly agreed in writing to support that use.
3. Where information comes from
We receive information directly from users, from supervisors or administrators who invite and manage users or register an organization email domain, from requesters who describe work, from government buyers who request pricing or a demo, from devices when a user chooses a location or upload, from use of the service, and from mapping providers that return address matches. An organization may also import its own work-order records.
For public ticket intake, CREWCLEAR compares the domain portion of a work email with domains registered by customer organizations. A match routes the proposed ticket to that workspace but does not by itself prove identity. We send a single-use link to the mailbox and create the requester account and ticket only after the person reviews and confirms.
4. How we use information
- create accounts, authenticate users, enforce roles, and maintain organization-scoped access;
- receive, clarify, map, route, assign, pause, document, and complete authorized work;
- send verification, recovery, invitation, security, and opted-in ticket-update messages;
- provide exports, support, troubleshooting, reliability, fraud prevention, and audit history;
- respond to government pricing, demo, procurement, security, accessibility, and pilot inquiries; attribute those requests to the relevant first-touch campaign; and manage the resulting sales relationship;
- comply with law, respond to lawful requests, protect rights and safety, and enforce agreements; and
- improve the service using aggregated or de-identified information where practical.
Where GDPR-style law applies, the legal bases may include performing a contract, taking requested pre-contract steps, CREWCLEAR’s and its customers’ legitimate interests in secure field operations, consent for optional communications or device permissions, and compliance with legal obligations.
5. Location and workforce transparency
Work-site addresses are used to verify locations, display maps, create routes, and open directions. Address searches may be sent to and cached from an OpenStreetMap-compatible geocoding provider. Map tiles are provided by OpenStreetMap contributors.
Crew check-ins are intended to be user-initiated and visible to authorized workspace users for dispatch and safety context. CREWCLEAR does not authorize covert monitoring or location collection outside legitimate work purposes. Customer organizations are responsible for giving workers any required notices, choosing a lawful and proportionate purpose, limiting access and retention, and obtaining any consent required by employment, labor, or privacy law.
When a user chooses an external directions link, the destination is sent to the selected provider, such as Google Maps, Apple Maps, Waze, or OpenStreetMap, under that provider’s privacy terms.
6. Automated guidance—not automated employment decisions
CREWCLEAR can calculate request-thoroughness signals, surface priority work, and recommend route or assignment context. These features organize information for people; they do not make solely automated decisions with legal or similarly significant effects. Supervisors and organizations remain responsible for dispatch, safety, employment, discipline, and resource decisions.
7. When information is shared
- Inside the workspace: with authorized requesters, employees, crew leads, supervisors, and administrators according to their roles.
- Service providers: with vendors supporting hosting, databases, file storage, security, transactional email, and mapping. Cloudflare currently supplies core hosting, storage, security, and email infrastructure.
- Customer direction: when an administrator exports data, configures an integration, or instructs CREWCLEAR to disclose it.
- Legal and safety: when reasonably necessary to comply with law, protect people or the service, investigate abuse, or establish and defend legal claims.
- Business changes: in a financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice requirements.
We do not sell personal information, rent contact lists, or disclose precise location for targeted advertising.
8. Cookies and similar storage
CREWCLEAR currently uses essential session cookies to keep users signed in, maintain demo roles, and protect the service. Cloudflare may place strictly necessary security cookies for bot and abuse protection. The application also caches its software shell on the device for offline field use.
For government marketing pages, session storage may remember first-touch UTM/referrer fields until a pricing or demo form is submitted. These device-local values are not authoritative business records. Submitted inquiry and attribution fields are stored in CREWCLEAR’s database. We do not currently use third-party advertising cookies or non-essential behavioral analytics cookies. If that changes, this notice and any required consent controls will be updated first.
9. Retention
Account and workspace content is retained while needed to provide the workspace and until the customer requests deletion, closes the workspace, or a governing agreement specifies otherwise. Pending public ticket details and their password hash are held temporarily while email ownership is confirmed and expire after one hour; an unsuccessful email delivery removes the pending record. Session records expire; other verification and password-reset links are short-lived; invitations expire; and security, audit, backup, and dispute records may be retained longer when needed for integrity, fraud prevention, legal obligations, or claims.
Retention is based on the customer’s instructions, operational need, record type, legal requirements, risk, and whether secure deletion from active systems and backups is technically feasible. Administrators should export records they must retain before closing a workspace.
Government pricing and demo inquiries are retained while reasonably needed to respond, qualify a pilot or commercial opportunity, keep an accurate contact history, prevent abuse, and meet legal obligations. You may ask CREWCLEAR to delete or correct an inquiry unless retention is required for a legitimate legal, security, or recordkeeping reason.
10. Security
CREWCLEAR uses measures designed for the service, including password hashing, protected session cookies, role and organization boundaries, upload validation, security rate limits, audit history, and managed hosting controls. No service can guarantee absolute security. Users must protect credentials, use individual accounts, promptly revoke departed workers, and report suspected misuse.
11. Your choices and privacy rights
Depending on where you live and the applicable law, you may request access, correction, deletion, restriction, portability, or a copy of personal information; object to certain processing; withdraw consent; or appeal a denied request. You may change requester ticket-email preferences in the application and unsubscribe from optional marketing without losing transactional service messages.
For information controlled by your employer or customer organization, contact that organization first; CREWCLEAR will assist it as required. Otherwise email notifications@crewclearapp.com. We may verify identity and authority before acting. Authorized agents may submit requests where the law permits. You may also complain to your local privacy regulator.
12. California and other U.S. state disclosures
Where applicable, the categories described in Section 2 are collected for the business purposes in Section 4 and disclosed to the recipients in Section 7. Precise geolocation may be treated as sensitive personal information. CREWCLEAR uses it only to provide requested mapping, dispatch, routing, and safety context—not to infer sensitive traits or advertise.
CREWCLEAR does not sell personal information or share it for cross-context behavioral advertising and therefore does not currently offer a “Do Not Sell or Share” link. We do not discriminate against people for exercising applicable privacy rights.
13. International users and transfers
CREWCLEAR and its service providers may process information in the United States and other countries where they operate. Where required, transfers should be covered by an applicable adequacy decision, contractual safeguards, or another lawful mechanism. Organizations needing a data-processing addendum, regional commitments, an EU or UK representative, or sector-specific terms should arrange them in writing before regulated deployment.
14. Children
CREWCLEAR is a workplace and organizational service, not a consumer service directed to children. Users must be at least 18 years old or the age of legal majority where they live. Do not create an account for a child or knowingly submit a child’s personal information unless authorized by law and a written agreement with CREWCLEAR.
15. Changes and contact
We may update this notice as the service, providers, or law changes. Material changes will be posted here and, when appropriate, communicated to workspace administrators or affected users. The effective date above identifies the current version.
Privacy questions and requests: notifications@crewclearapp.com. Include “Privacy Request” in the subject line and identify the relevant workspace without sending passwords or unnecessary sensitive information.