← Back to Crewshot

Legal

Privacy Policy

Last updated: September 8, 2026
This is a working draft, not a finished legal document. It describes, accurately, the data Crewshot's current app actually collects and where it goes — but it hasn't been reviewed by a lawyer, and privacy law (especially around location data, audio recording, and any future expansion to California, the EU, or other jurisdictions) is genuinely complex.

1. Who we are

This Privacy Policy explains how Los Gatos Taxi Innovators LLC, doing business as Crewshot ("we," "us"), collects, uses, and shares information when you use the Crewshot mobile app and related services (the "Service").

2. Information we collect

Account and organization information

Content you create

Billing information

Device and usage information

Device permissions we ask for

Camera and microphone (to capture photos and videos), location (to geotag captures), photo library access (to save captures to your camera roll if you turn that on, and to attach existing photos), and biometrics (only if you turn on Face ID login). You can decline or later revoke any of these in your device settings; declining a permission disables the feature that needs it rather than blocking the app entirely.

What we don't collect

We don't run advertising trackers, we don't use any third-party analytics or crash-reporting SDKs, and we don't sell your data to data brokers or advertisers.

3. How we use your information

We use the information above to:

We do not use your Customer Content (photos, project data, etc.) to train any AI models, and we do not use it for any purpose beyond providing the Service to your organization.

4. Who we share information with

We share information only as needed to run the Service:

We do not sell your personal information. We only disclose information beyond the above if required by law (for example, in response to a valid legal request) or to protect the rights, property, or safety of Crewshot, our users, or the public.

5. Data retention and deletion

We retain your account and Customer Content for as long as your organization's account is active. If your organization cancels its subscription or an account is closed, we retain data for 90 days afterward to allow for account recovery, after which it may be deleted.

What you can delete yourself, from inside the app. In every case below, deletion removes both the database record and the underlying file in our cloud storage — the file is not left behind:

Deletion is immediate and permanent — we do not keep a recoverable copy, so please be certain before confirming.

If you would prefer us to handle a deletion for you, or you want something removed that the app does not cover, contact us (Section 11).

6. Data security

We use industry-standard measures to protect your information, including encrypted connections (HTTPS) between the app and our servers, hashed password storage (bcrypt), and server-side access controls that keep one organization's records separate from another's — every request is checked against the organization the requesting account belongs to.

Your photos, videos and PDF reports are held in private cloud storage that is not publicly readable. When the app shows you a photo, it requests a temporary signed link that works for a limited time and then stops working, so a link that leaks or is forwarded does not grant permanent access to your files. One exception worth knowing about: a link embedded inside a generated PDF report (the "tap to play" link on a video) is signed for a longer period, up to seven days, because the PDF is a file you keep — after that it expires and the video must be opened in the app.

No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable steps to protect your information and will notify affected users as required by law in the event of a breach affecting their data.

7. Your rights and choices

Depending on where you live, you may have rights to access, correct, or request deletion of your personal information. You can:

If you plan to serve California residents, add CCPA-specific disclosures here. If you plan to serve the EU/UK, add GDPR-specific disclosures (legal basis for processing, right to lodge a complaint with a supervisory authority, etc.) — these are real, distinct legal regimes and shouldn't be papered over with generic language.

8. Children's privacy

Crewshot is a business tool intended for use by adults on behalf of a company. It is not directed at children, and we don't knowingly collect information from anyone under 18. If we learn we've collected information from a child, we'll delete it.

9. International users

Placeholder: if Crewshot will be used, or store data, outside the United States, add detail here about where data is stored/processed and any cross-border transfer mechanisms. As of this draft, the product is being built and launched within the U.S.

10. Changes to this policy

We may update this Privacy Policy from time to time. We'll notify you of material changes (for example, via email or an in-app notice) before they take effect.

11. Contact us

Questions about this Privacy Policy, or want to make a data access/deletion request? Contact us at support@crewshot.org.

Draft prepared September 5, 2026; revised September 8, 2026. Not yet reviewed by counsel. Describes the app's actual current data practices as of this build — in-app account deletion, storage cleanup on delete, and signed media URLs are all shipped and described here as shipped. Revisit this document any time a new feature changes what data is collected or where it goes (for example, when a transactional email provider is connected, or an EU launch lands).

Draft prepared September 5, 2026; revised September 8, 2026. Not yet reviewed by counsel. Describes the app's actual current data practices — revisit any time a new feature changes what data is collected or where it goes.