Last updated: September 3, 2026·Version: privacy-v3.1
These documents are published in English. The English version is the governing version; any translation is provided for convenience only.
crewline Privacy Policy
Effective date: September 3, 2026 · Version privacy-v3.1 · Companion to the crewline Terms of Service (v3.3)
RyeCreek Labs, LLC, a Colorado limited liability company, 361 S Camino Del Rio #271, Durango, CO 81301 · support@crewlineops.com
1. Who we are, and the two hats we wear
For businesses (Customers): when a business creates a workspace, we act primarily as a processor/service provider for the data it puts in — its clients, sites, bookings, photos, documents, and pay records. That business decides why and how that data is used; this policy describes how we handle it on their behalf.
For account holders and visitors: for the account information of people who sign in (owners, admins, bookkeepers, providers) and for visitors to our website, we act as a controller.
For Providers: a Provider wears both hats at once. Your account information is ours as controller; the records your employer or contracting business creates about your work — visits, checklists, photos, location readings at check-in and check-out, pay records, and the documents it asked you to submit — belong to that business, and we handle them on its instructions. Questions about those records should go to that business first; we support businesses in answering such requests, and will route a request to the right business if you contact us instead.
2. What we collect
Account data — Name/preferred name, email, phone, password (hashed), role(s), workspace memberships, language preference, profile photo. Source: signup, invitations, onboarding.
Invitation contacts — Names, emails, phone numbers of people a business invites. Source: provided by the business.
Business & client data — Accounts (the business's clients), contacts, billing emails, sites and site addresses, access notes including gate/door/lockbox codes and alarm information, custom invoice fields (e.g., PO numbers). Source: entered by the business.
Visit records — Bookings, checklists and completion states (including skips and reasons), photos of work, supply reports, check-out question answers, visit reports. Source: created during work.
Location data — Coordinates and accuracy at check-in and check-out; coordinates of rejected check-in attempts; site geofence pins and radii. Source: the Provider's device at those moments only — see §3.
Money records — Invoices and line items, payment records including the payment amount, processor fees, any crewline fee historically applicable to that payment, refunds and the net amount, provider pay amounts and settlement records, job costs, exports. Source: created by the business; online payment events via Stripe.
Compliance documents — sensitive — Documents and information a business requires of its Providers, which vary by the worker type it selects. For contractors: W-9s (which contain an SSN or TIN), certificates of insurance with policy numbers and expiration dates, and signed work-authorization attestations. For employees: Form I-9 and supporting identity- and work-authorization document uploads (which may include passports, driver's licenses, Social Security cards, and immigration documents), Form W-4, direct deposit authorizations containing bank account and routing numbers, and emergency contact names and phone numbers. Also the business's own record of its review of each item. Source: uploaded or signed by Providers at the business's request; emergency contacts may be entered by the Provider or the business.
Messages — Owner–provider messages and their machine translations. Source: sent in the app.
Support requests — Category and description of the issue, whether it is blocking, reply-to email and phone, and any files you attach (including screenshots and photos). Submitting also captures context automatically: your name, email and role, your workspace name and identifier, plan and trial status, the app build, browser/OS/screen and whether you are using the installed app, the page you came from, and your timestamp, time zone and locale. Source: submitted through the in-app Support page or the public Help page.
Payment method (subscriptions) — Handled by Stripe; card numbers never touch our servers — we store Stripe identifiers and subscription status. Source: checkout / billing portal.
Usage & technical data — Log data, device/browser info, IP address, basic site analytics. Source: automatic.
Website behavior analytics (public pages only) — sensitive to us, so we limit it strictly: on our public marketing and educational pages only (home, blog, community, affiliates, and help), we use Microsoft Clarity to understand how those pages are used. Clarity collects heat maps and session recordings of page interactions, clicks and taps, scrolling and mouse movement, pages viewed, referring page, and device, browser, operating system, screen size, approximate location derived from IP address, and it sets cookies and similar identifiers on your browser. Text you type, form fields, and personal details are masked and are not recorded. Clarity is never loaded on sign-in, onboarding, invoice, payment, settings, or any signed-in owner or provider page, and we never send Clarity your name, email, account, or workspace identifiers. Source: automatic on those public pages. You can opt out for all Clarity-enabled sites at https://clarity.microsoft.com/terms and by using your browser's cookie controls or a Global Privacy Control signal.
3. Location: only at visit moments
The apps request location only to record check-in and check-out (and to evaluate a check-in against the site's geofence where the business has enabled that). We do not track location continuously or in the background, and there is no location "tracking session" outside those moments.
Rejected check-in attempts (too far from the site, or an imprecise reading) are recorded with their coordinates and shown to the business so it can fix pins and radii.
Geofencing is a plan-gated feature that a business turns on. Businesses are responsible for notifying their workforce about this monitoring and for obtaining any consents the law requires (see Terms §4).
4. How we use data
To provide and secure the Service (including authentication, workspaces, roles, and records).
To power features the business uses: invoicing and email delivery, machine translation of messages, geocoding of site addresses, AI features (§5), reminders and in-app alerts (for example, insurance expirations and needs-attention items), and recurring booking generation.
To receive, triage, and answer support requests, including the automatic context described in §2.
To bill subscriptions, maintain and reconcile payment records (including refunds and any historically applicable crewline fee), answer support and accounting questions, meet legal and tax recordkeeping obligations, prevent abuse and enforce usage caps, comply with law, and communicate service messages.
We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use workspace data for advertising.
5. AI features
Sweep (assistant), message translation, and AI photo review send the relevant content — prompts, messages, photos and reference photos, and the workspace context needed to answer — to AI models run by our infrastructure providers.
Support requests submitted in a language other than English are machine-translated to English through the same infrastructure before our team reads them.
Our AI providers process this data to provide these features on our behalf.
Compliance documents are not sent to AI models. AI outputs can be wrong; the product requires human confirmation for consequential actions.
6. Who we share with (subprocessors)
Supabase — Database, authentication, file storage (photos, compliance documents, support attachments) — United States.
Lovable — Application hosting and build/runtime infrastructure — United States.
Google (Gemini models), via our AI gateway — AI photo review, Sweep, message translation, and support-request translation — United States.
Stripe — Subscription billing; and, where a business connects its own Stripe account, its client payments — United States.
Resend — Transactional email (invitations, invoices, account, billing, and support emails) — United States.
OpenStreetMap Nominatim — Converting site addresses to map coordinates when a business uses "Set from address" — European Union.
Microsoft Clarity — Heat maps and session recordings of our public marketing and educational pages, with typing and form fields masked and no user or account identifiers sent — United States.
We share data with these providers only as needed for the purposes above, and with authorities where legally required. We may also share data in connection with a merger, acquisition, or sale of assets, subject to this policy.
7. Retention
Workspace data is retained while the workspace exists; businesses can export it at any time, on any plan. Visit records are designed to preserve history for the business's records and cannot be deleted through the product.
Cancelled workspaces remain in read-and-export mode. We may delete workspace data 12 months after termination, with notice where practicable.
Compliance documents are retained until the business deletes them or the workspace is deleted. A business is responsible for its own retention obligations — several of these document types carry statutory retention periods of their own.
Support requests and their attachments are retained for 24 months after the request is closed.
8. Security
We use encryption in transit, access controls and role-based permissions, tenant isolation enforced at the database layer with row-level security, private storage buckets with time-limited signed links for stored files, and least-privilege service credentials. Compliance documents and support attachments are stored in private buckets and are not publicly addressable.
No system is perfectly secure. We will notify affected businesses and, where required, affected individuals and regulators, of a security breach as required by law.
9. Your rights
Account holders may access and correct their account information, and may contact us to close their account. Closing an account does not delete the work records a business holds about you, which remain that business's records.
Where the Colorado Privacy Act or a similar state law applies, you may have the right to access, correct, delete, or obtain a portable copy of your personal data, to opt out of certain processing, and to appeal a decision we make about your request. Contact support@crewlineops.com. For data a business controls, we will route or support the request as processor rather than deciding it ourselves.
We will not discriminate against you for exercising these rights.
10. Children
The Service is for business use and is not directed to children under 16; we do not knowingly collect children's data.
11. Changes; contact
We will post updates here and notify materially affected users at least 15 days before they take effect, consistent with Terms §18. Questions: support@crewlineops.com · RyeCreek Labs, LLC, 361 S Camino Del Rio #271, Durango, CO 81301.