Who this policy covers
This policy applies when you visit CrewLog’s website, create or use a CrewLog account, use the web or mobile application, join a Company as a Company Member or Collaborator, contact support, submit product feedback, or join the waitlist.
CrewLog is the controller for the website, direct customer relationships, account administration, billing administration, security, and support. When a customer Company uses CrewLog to manage its own crew and operational records, that Company decides why those records are used and CrewLog processes them to provide the service.
Privacy questions and rights requests:support@getcrewlog.app
Data we process
Account & contact
Name, email, optional phone number, authentication identifiers, role, membership status, and account preferences.
Company
Company name, legal name, VAT number, timezone, Company Members, invitations, and Product Tier information.
Operational records
Events, venues, Work Days, Assignments, role labels, planned and actual hours, breaks, notes, Work Requests, approvals, rejection reasons, Correction Notices, and Exports.
Billing
Stripe customer and subscription references, selected Product Tier, subscription status, billing period, and related event records. CrewLog does not store full card details.
Support & feedback
Your message, feedback category, current app route, Company and role context, and whether you allow us to contact you.
Technical & security
IP address, timestamps, request metadata, device or browser information, authentication and error logs, and security events generated by our infrastructure.
We receive most of this data from you or your Company. We also receive service status and billing data from providers such as Supabase, Cloudflare, and Stripe.
Why we use it
- Provide the service and perform our contract: authenticate users, operate Companies, Events, Work Days, Assignments, Time Entries, approvals, Exports, support, and subscriptions.
- Comply with law: maintain billing, tax, accounting, security, and rights-request records where required.
- Legitimate interests: protect CrewLog, prevent abuse, diagnose failures, improve reliability, answer support requests, and understand product feedback without overriding your rights.
- Consent: only where we specifically ask for it, such as optional follow-up to product feedback. You may withdraw consent at any time.
CrewLog does not sell personal data and does not use it for cross-site advertising or behavioral profiling.
Retention & security
We keep account and operational data while the relevant account or customer relationship is active. After closure or deletion, some records may remain for a limited period in backups, security logs, dispute records, and legally required billing or accounting archives. We delete or anonymize data when it is no longer needed for those purposes.
CrewLog uses access controls, encryption in transit, restricted production credentials, tenant authorization, and monitored infrastructure. No system can promise absolute security, so please contact us promptly if you suspect unauthorized access.
Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. If your Company created or controls the operational record, we may coordinate the request with that Company.
Email support@getcrewlog.app. We may need to verify your identity. You may also complain to the Italian data-protection authority, the Garante per la protezione dei dati personali, or your local supervisory authority.
CrewLog is not directed to children. A Company that engages minors remains responsible for having an appropriate legal basis and providing required workforce notices.
Changes to this policy
We will update the effective date when this policy changes. If a change materially affects how we use personal data, we will provide an appropriate notice in the service or by email.