This is a working draft, not a finished legal document. It describes, accurately, the data Crewshot's current app actually collects and where it goes — but it hasn't been reviewed by a lawyer, and privacy law (especially around location data, audio recording, and any future expansion to California, the EU, or other jurisdictions) is genuinely complex.
1. Who we are
This Privacy Policy explains how Los Gatos Taxi Innovators LLC, doing business as Crewshot ("we," "us"), collects, uses, and shares information when you use the Crewshot mobile app and related services (the "Service").
2. Information we collect
Account and organization information
- Name, email address, and password (stored as a secure hash, never in plain text) when you register.
- Your role within your organization (admin or crew) and which organization you belong to.
- Optional profile information you choose to add.
Content you create
- Photos and videos you capture through the app, including embedded GPS location and capture timestamp metadata — this is a core, intentional part of how Crewshot works, since geotagged/timestamped media is the documentation the Service is built to produce. Depending on your team's camera settings, this location and timestamp may be visibly burned into the image or video itself.
- Audio. Videos recorded in the app capture sound as well as picture, using your device's microphone. Photo capture does not use the microphone. Recording audio of other people may require their consent depending on where you are — see the Acceptable Use section of our Terms of Service.
- Photos you choose from your device's existing photo library. In some places the app lets you attach an existing photo instead of taking a new one (for example, adding a photo to a project or a checklist item, or uploading your company logo for report branding). A photo imported this way is uploaded with whatever metadata it already carries, which may include the location and time it was originally taken — potentially somewhere other than the job site.
- Project and customer information your organization's admins enter — for example, a job address, a customer's name, phone number, or email address.
- Tags, labels, notes, checklist responses, and comments you add to projects and media.
- PDF reports generated from the above.
Billing information
- We use Stripe to process subscription payments. We do not collect or store your payment card number — Stripe handles card entry directly on its own hosted checkout page, and we only receive limited billing metadata back from Stripe (like your subscription status and plan). See Stripe's own privacy policy for how Stripe handles payment data.
Device and usage information
- Device push-notification token (if you enable push notifications), used only to deliver in-app notifications like new comments.
- Standard technical information the app and our servers naturally generate to function (for example, request logs), used for debugging and security, not for advertising or tracking.
- Face ID / biometric login, where offered, is handled entirely by your device's own operating system (Apple/Google). We never receive, see, or store any biometric data ourselves — your device simply tells our app "yes, this person is authorized" after checking your face or fingerprint locally on-device.
Device permissions we ask for
Camera and microphone (to capture photos and videos), location (to geotag captures), photo library access (to save captures to your camera roll if you turn that on, and to attach existing photos), and biometrics (only if you turn on Face ID login). You can decline or later revoke any of these in your device settings; declining a permission disables the feature that needs it rather than blocking the app entirely.
What we don't collect
We don't run advertising trackers, we don't use any third-party analytics or crash-reporting SDKs, and we don't sell your data to data brokers or advertisers.
3. How we use your information
We use the information above to:
- Provide the core Service — storing and organizing your photos/videos/projects, generating reports, and syncing offline captures once you're back online;
- Operate your account and organization, including team membership and role-based permissions;
- Process billing through Stripe and manage your subscription;
- Send you service-related communications (for example, password reset emails, billing receipts, or comment notifications you've opted into);
- Maintain the security and reliability of the Service;
- Comply with legal obligations.
We do not use your Customer Content (photos, project data, etc.) to train any AI models, and we do not use it for any purpose beyond providing the Service to your organization.
4. Who we share information with
We share information only as needed to run the Service:
- Stripe (payment processing) — receives billing/subscription information needed to process your payments. Stripe's own privacy practices govern the payment data it handles directly.
- Cloudflare R2 (our cloud storage provider) — stores your uploaded photos, videos, thumbnails, and generated PDF reports. Files are held in a private bucket and served only through temporary signed links (see Section 6).
- OpenStreetMap's Nominatim service — when you look up or confirm a project address on the map, that address text is sent to Nominatim's geocoding service to find its coordinates, per Nominatim's usage policy. This lookup runs from our servers rather than from your device, so your device's IP address isn't shared with Nominatim.
- Expo's push notification service (exp.host) — if you enable push notifications, your device's push token is sent through Expo's infrastructure to deliver notifications to your device.
- Our email provider — not yet connected. As of this draft, no transactional email provider is in place, and password reset emails are logged rather than sent. This section will be updated with the actual provider once one is configured.
- Your organization's other members, according to normal use of the Service — for example, a project's photos are visible to your teammates per their role, the same way they would be in a shared team folder.
- A CRM or other system your organization chooses to connect (optional, org-by-org) — if your organization's admin enables an integration, relevant project data is sent to that connected system. We're not responsible for how that external system handles data once it arrives there; see the Terms of Service.
We do not sell your personal information. We only disclose information beyond the above if required by law (for example, in response to a valid legal request) or to protect the rights, property, or safety of Crewshot, our users, or the public.
5. Data retention and deletion
We retain your account and Customer Content for as long as your organization's account is active. If your organization cancels its subscription or an account is closed, we retain data for 90 days afterward to allow for account recovery, after which it may be deleted.
What you can delete yourself, from inside the app. In every case below, deletion removes both the database record and the underlying file in our cloud storage — the file is not left behind:
- A single photo or video — press and hold it in a project's grid. Available to anyone on the team, not just whoever captured it.
- A generated report, including its PDF.
- A whole project, with all of its photos, videos, reports and comments (admins).
- Your account — Settings → Delete account. If you are the only person on your team, this also deletes your organization and everything in it. If your team has other members, your personal account is erased (name, email, password and push token are all destroyed and you can no longer log in) while the photos and comments you contributed stay with your organization, which owns them; your name is removed from them.
Deletion is immediate and permanent — we do not keep a recoverable copy, so please be certain before confirming.
If you would prefer us to handle a deletion for you, or you want something removed that the app does not cover, contact us (Section 11).
6. Data security
We use industry-standard measures to protect your information, including encrypted connections (HTTPS) between the app and our servers, hashed password storage (bcrypt), and server-side access controls that keep one organization's records separate from another's — every request is checked against the organization the requesting account belongs to.
Your photos, videos and PDF reports are held in private cloud storage that is not publicly readable. When the app shows you a photo, it requests a temporary signed link that works for a limited time and then stops working, so a link that leaks or is forwarded does not grant permanent access to your files. One exception worth knowing about: a link embedded inside a generated PDF report (the "tap to play" link on a video) is signed for a longer period, up to seven days, because the PDF is a file you keep — after that it expires and the video must be opened in the app.
No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable steps to protect your information and will notify affected users as required by law in the event of a breach affecting their data.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, or request deletion of your personal information. You can:
- Update your profile information directly in the app;
- Delete a whole project from within the app if you're an admin (see Section 5 for what that does and doesn't remove);
- Contact us (Section 11) to request a copy of your data, or to request deletion of your account and associated data, subject to our legitimate need to retain certain records (e.g., billing history) as required by law.
If you plan to serve California residents, add CCPA-specific disclosures here. If you plan to serve the EU/UK, add GDPR-specific disclosures (legal basis for processing, right to lodge a complaint with a supervisory authority, etc.) — these are real, distinct legal regimes and shouldn't be papered over with generic language.
8. Children's privacy
Crewshot is a business tool intended for use by adults on behalf of a company. It is not directed at children, and we don't knowingly collect information from anyone under 18. If we learn we've collected information from a child, we'll delete it.
9. International users
Placeholder: if Crewshot will be used, or store data, outside the United States, add detail here about where data is stored/processed and any cross-border transfer mechanisms. As of this draft, the product is being built and launched within the U.S.
10. Changes to this policy
We may update this Privacy Policy from time to time. We'll notify you of material changes (for example, via email or an in-app notice) before they take effect.
11. Contact us
Questions about this Privacy Policy, or want to make a data access/deletion request? Contact us at support@crewshot.org.