CrewDocket Sign in Start your workspace

Privacy policy

Effective 3 August 2026 · Canada — PIPEDA and the substantially similar provincial statutes

Your customers’ names, phone numbers, home addresses and photographs of their property go into this software. This page says exactly what happens to all of it, in the order a person actually wants to know.

1The two roles, first

Almost every confusing thing about privacy in software like this comes from mixing up two different relationships. So they are separated at the top.

When it is your information

Your name, your business, your email and phone number, your billing details, your support messages. Here CrewDocket is the organisation accountable for that information, and this policy tells you what we do with it.

When it is your customers’ information

The client list, addresses, phone numbers, job notes, photographs, invoices and message threads you keep in CrewDocket. Here you are the organisation accountable, and CrewDocket is your service provider. We hold and process it for you, on your instructions, to run the Service and for nothing else.

That division is not a preference, it is how PIPEDA works: an organisation that collects personal information stays accountable for it even when it hands it to a third party for processing, and it is required to use contractual means to ensure comparable protection. That is why the terms of service say the same thing, and why the written agreement between us is not optional paperwork.

Where the two overlap — a crew member is both a person we hold information about and someone you employ — the more protective reading applies.

2What we collect about you

When you open a workspace from the website

Four things, and there is no fifth: the trade you pick, your business name, your email address, and a password. No card, no phone number, no home address, nothing about your revenue and nothing about how you heard of us. The password goes to our sign-in provider and is stored as a hash that we cannot read or reverse.

When you ask about the product instead

The founding-operator enquiry collects your name, your business name, your town, your crew size, what software you use now, and a phone number or email address. That is all of it, and every field is there because somebody reads the answer before calling you.

When you are a customer

  • Account details: name, business name, email, phone, the crew you set up.
  • Billing details: what we invoiced, what was paid, and the tax applied. We do not see or store your card number; if you pay by card, the processor handles it.
  • Support: the emails, texts and calls between us, so that the next conversation starts where the last one ended.
  • Technical records: server logs containing IP address, timestamp, the page or request, and a browser user-agent string. Kept for security and debugging.

We do not buy personal information about you from data brokers, and we do not enrich your record from third-party sources.

3What this website does

This website sets no cookies, runs no third-party analytics, carries no advertising or tracking pixels, and embeds nothing from another company’s domain. There is no consent banner because there is nothing to consent to.

The same is true inside the product, and it is worth stating because it is unusual: the typeface is served from our own domain rather than rented from a font network. So neither this site nor the pages your customers open — a quote, an invoice, a share link — hand a visitor’s address to a third party just to draw the text.

One disclosure for completeness, because “we don’t track you” is the kind of sentence that has to survive being checked: our web host records ordinary server logs for every request, including your IP address. That is how a web server works; it is not a profile and it is not shared.

4What the product holds for you

When you use CrewDocket to run your crew, it stores what you put in it. Stated plainly rather than as “service data”, because these are real people’s details:

  • Your customers’ phone numbers, email addresses and the service address of their home or business — street, city and postal code.
  • Photographs of a customer’s property — the before-and-after pictures your crew takes on site, stored against the job.
  • Text-message threads between your business and your customers, in both directions, kept as written.
  • Job dates, notes and status; quotes, invoices, and what was paid.
  • Crew names, pay rates and payout records.

All of that is your customers’ and your crew’s information, held under section 1’s second heading. We do not mine it, sell it, share it with other operators, or use it to train anything.

Do not put things in it that it is not built for. Card numbers, social insurance numbers, driver’s licence numbers, health information and immigration status do not belong in a free-text job note. The terms say the same, and it is genuinely the single most useful privacy instruction on this page.

5Photographs, and location

Two facts that are unusual enough to state plainly, because they are the opposite of what most field-service software does.

  • Photographs are stripped of their metadata. A phone photo of a house carries GPS coordinates accurate to the metre, the device serial and an exact timestamp. Every photo uploaded to CrewDocket is re-encoded before it is stored, and none of that is carried forward. Only the orientation is preserved, so portrait photos are not sideways. A customer’s home address never ends up embedded in an image behind a shareable link.
  • CrewDocket does not track your crew’s location. There is no background location, no live map, no breadcrumb trail. The product does not ask the browser for a position at all.

If either of those ever changes, it will change with notice, as an explicit setting that is off until somebody turns it on — not quietly in a release.

6Why we use information

PurposeWhat it uses
Answering your enquiryThe details you sent, so a human can call you back.
Providing the ServiceYour account details, and your operator data only as needed to run the features you use.
Delivering messages you sendYour customer’s phone number and the text you wrote, passed to the carrier.
Billing youYour account and billing details, and the tax rules that apply to you.
SupportYour messages to us, and — only when you ask us to look at something — the relevant part of your account.
Security and reliabilityServer logs, error reports, access records.
Improving the productAggregated, de-identified counts. Never one operator’s numbers as marketing, never a customer’s identity.
Legal obligationsTax and accounting records, and anything a court or regulator lawfully requires.

We do not use personal information for a new purpose without asking, and we make no automated decisions about anyone that would have a legal or similarly significant effect on them.

7Consent, and text messages

We collect and use your information with your consent, which for most of this is implied by asking us for the product and then using it. Consent for anything sensitive, or for a purpose you would not reasonably expect, is asked for expressly.

You can withdraw consent at any time, subject to legal and contractual limits — withdrawing consent to hold your account information means closing your account, because there is no account without it. Tell us and we will explain what withdrawing actually means before anything happens.

For your customers’ information, the consent that matters is the consent they gave you. Obtaining it, recording it and honouring its withdrawal is your responsibility as the accountable organisation. What the software does to help you keep that promise is concrete, so it is written out rather than implied.

How a customer opts out

  • A customer who replies STOP is recorded as opted out immediately, by the software, without waiting for anybody to notice. The words it accepts are the ones the carriers accept — STOP, STOPALL, UNSUBSCRIBE, UNSUB, CANCEL, QUIT, END — and the keyword has to be the whole message, so “can you cancel Thursday” is treated as the reschedule it is, not as a withdrawal of consent.
  • From that moment they are excluded from every campaign and every bulk send. Their card in the app shows the opt-out plainly, with the date, so nobody has to remember.
  • A customer who later replies START, UNSTOP or YES is recorded as opted back in. Only they can do that — consent comes back from the person, not from the operator.
  • The opt-out is carried out at the carrier by our messaging provider as well as in the app, so it holds even if something on our side goes wrong.
  • Opt-out status travels with your data. It is a column in the export, so if you leave you take the record of who said no with you, and you can honour it wherever you go next.

How often it messages

There is no message frequency to publish, because nothing sends itself. The software has no scheduler and no automatic outbound path: every text that reaches a customer was sent by a person pressing send. The one thing it does on its own is record an opt-out, which is the opposite of contacting somebody. So the frequency is whatever you choose — and keeping it reasonable is on you, because CASL applies to your messages exactly as it applies to ours.

Section 9 of the terms sets out what you are agreeing to about consent, identification and unsubscribes when you send messages through CrewDocket.

8Who else touches it

Running the Service means other companies process information on our behalf. This is the complete current list. We will give notice before adding one that handles personal information.

WhoWhat they doWhere
Google LLC — Firebase and Google Cloud Hosting, the database your records live in, file storage for the photographs, sign-in and accounts, and the server code that runs the product. United States
Twilio Inc. Sending and receiving the text messages between your business and your customers. They process the phone number and the content of the message. United States
Stripe Card payments on your own invoices, through your own Stripe account and keys. Card details go to Stripe and never to us. United States and Canada
Google Workspace Our own business email, and — where you connect it — the pipeline that brings your business inbox into the product. United States
Anthropic PBC The AI assistant. When it is switched on and you use it, the message content you ask about is sent to Anthropic, which can include a customer’s own words and their phone number. It is off unless it has been configured for your account, and while it is off nothing is sent. United States

Each of these is bound by its own agreement with us to process information only on our instructions and to protect it. We do not sell personal information to anyone, and there is no advertising network in this list because there is no advertising.

9Where it is stored, and crossing the border

The providers above store and process information outside Canada, principally in the United States. That has a consequence PIPEDA requires us to state plainly rather than bury:

While information is in another country it is subject to that country’s laws, and may be accessible to its courts, law enforcement and national-security authorities under that country’s legal process, without notice to you or to us.

This is true of essentially every cloud service a Canadian business uses, and saying it is not a warning about us in particular. It is the disclosure you are owed so that you can make your own decision — and so that you can make the same disclosure to your customers, which as the accountable organisation you may need to.

Where a Canadian region is available for a component, we intend to use it. We are not promising Canadian residency for your data today, because a database’s region cannot be changed once it is created, and a promise we would have to migrate to keep is not a promise. If it matters to your business, say so before you start: it is a decision made once, at setup, and it is far easier to make it then.

10How long we keep it

WhatHow long
Enquiries about the productTwo years, or until you ask us to delete it, whichever comes first.
Your operator dataFor as long as your account is open. After it closes: readable for thirty days, deleted from live systems within ninety days after that, or sooner on your written request.
Point-in-time backupsSeven days on a rolling window, then gone. Not available for ordinary use in the meantime.
Server logsThirty days.
Invoices and tax recordsAs long as Canadian tax law requires us to keep them — generally six years.
Breach recordsTwenty-four months from the day the breach was determined to have occurred, as PIPEDA requires.

Deleted photographs are worth naming separately: when a photo is removed it is removed from storage, and a marker is kept so that a phone which had already cached it cannot quietly bring it back.

11How it is protected, and what we do not claim

What is true today:

  • Everything travels over TLS. There is no unencrypted path into or out of the product.
  • Our infrastructure provider encrypts data at rest by default, on disks we never touch.
  • Every person who signs in has their own account and a role, and the role is set by the server on the sign-in token rather than chosen by the device. What a role may write is enforced by the database itself, not by hiding a button: a crew account cannot alter the payout ledger, the crew adjustments or the business settings, and the stored credentials document is readable by the owner alone.
  • Stated plainly because it is the limit of the above: operator data is held as a single record that the app loads onto the device in one piece, which is what makes the day readable with no signal. Read access inside a business is therefore not yet as narrow as write access. A signed-in crew account holds more of the operator’s book on the device than its screens present, including pay rates. Splitting that record so that reads are gated per collection is planned work, and it is described here rather than after it is finished.
  • There is no shared login. There was one — several accounts on a single password — and it was removed, because an account that walks out with a departing worker is a hole nothing else on this list can close.
  • Each operator runs in their own project, with its own database, its own file storage and its own keys.
  • Access to production data is limited to the people who operate the Service, which today is one person.
  • Point-in-time recovery is on, so an accidental deletion can be undone within the recovery window.
  • Job photographs are stripped of metadata before storage (section 5).

What we do not claim, because claiming it would be false:

  • No SOC 2, ISO 27001 or equivalent certification, and none in progress. If that changes, the auditor will be named here.
  • No published uptime guarantee and no service-level agreement.
  • No independent penetration test has been performed.
  • No claim that any system is unbreakable. Nobody can honestly make it.

If a security certification is a hard requirement for your business, this is the wrong software this year — and you should read that here rather than discover it in a procurement review.

12If there is a breach

If personal information under our control is lost, accessed or disclosed without authority, we will:

  • contain it first, and record it;
  • notify the affected operator without undue delay, and in any event within seventy-two hours of becoming aware — with what we know, what we do not yet know, and what we are doing;
  • help you meet your own obligations, including working out whether the breach creates a real risk of significant harm to an individual;
  • where the breach concerns information for which we are the accountable organisation and there is a real risk of significant harm, report it to the Office of the Privacy Commissioner of Canada and notify the individuals affected, as PIPEDA requires;
  • keep a record of every breach for twenty-four months, whether or not it was reportable, and produce it to the Commissioner on request.

Where you are the accountable organisation, the decision to notify your customers and the regulator is yours. We will give you what you need to make it, and we will not stall.

13Requests from your customers

If one of your customers asks to see, correct or delete what is held about them, that request goes to you — they are your customer and you are the accountable organisation. You can answer it yourself from inside the product.

If such a request reaches us directly, we will not answer it on your behalf. We will tell the person to contact you, tell you promptly that it came in, and help you respond if you ask.

14Your own rights, and how to complain

For the information we hold about you, you can ask us to:

  • tell you what we hold and what we have done with it;
  • give you a copy;
  • correct anything inaccurate;
  • delete it, subject to what we are legally required to keep;
  • explain a decision we made using it.

Write to the address in section 15. We will answer within thirty days, free of charge, or tell you why we need longer — which PIPEDA permits in limited circumstances, with notice.

If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3, 1-800-282-1376, priv.gc.ca. Residents of Alberta, British Columbia and Quebec may also have a provincial commissioner to go to. We would rather you told us first, but you are not required to.

15Marketing, children, changes, contact

Marketing to you

If you give us your details and we send you a commercial email or text, it identifies us, says why you are receiving it, and carries an unsubscribe that works and that we honour within ten business days — because CASL applies to us exactly as it applies to you. Account, billing, security and service messages are not marketing, and they continue while you have an account.

Children

CrewDocket is sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under sixteen. If a crew member is a minor, their information is handled as employment information, and the operator is responsible for whatever consent that requires.

Changes to this policy

If we change it materially we will email account holders at least thirty days before it takes effect, and the date at the top will change. Old versions stay available on request.

Contact

The individual accountable for personal information at CrewDocket is Sam, who built it and who operates it. There is no privacy department to be routed through and no ticket queue: the person who answers is the person accountable.

Write to sam@crewdocket.com. By post: CrewDocket, Collingwood, Ontario, Canada — email first and you will get the full mailing address the same day.

The plain-language version

The questions this policy is the formal answer to — who can see my customers, can I get my book back out, what happens if you disappear — are answered in ordinary words, against what the software actually does, on the questions page.

Read the questions

If you read this because you were deciding

Most people who get to the bottom of a privacy policy came here to find out whether they could trust it, not to study it. If the answer was yes, you can start from here — you don’t have to go back to the front page.

Start your workspace Ask me a privacy question

No card, no trial clock. If something on this page is the thing standing in your way — where the data sits, what leaves the country, what I won’t claim — email me and say which part. I wrote it, so I can answer it.