GDPR & CCPA Privacy Compliance

Privacy Policy

Effective Date: August 29, 2026Last Updated: August 29, 2026

Enterprise Data Isolation & Privacy Safeguards

Crewmark is committed to protecting the privacy of our customers and field technicians. We process personal data strictly in compliance with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), and global data protection standards.

1. Information We Collect

We collect information directly provided by account administrators, automatically logged during platform usage, and submitted via mobile field devices:

  • Account & Organization Data: Name, business email, phone number, company address, and Paddle customer IDs.
  • Field Technician Data: Worker name, email address, assigned organization ID, and 4-digit PIN passcode.
  • GPS Coordinates & Geofence Verification: Real-time latitude, longitude, and accuracy radius recorded strictly at clock-in and clock-out events to verify property proximity. We do not track continuous background GPS location.
  • Photo Evidence & Camera Metadata: Images uploaded as task proofs, timestamp data, location coordinates, device type, and photo source tagging (camera vs gallery).
  • Safety Alerts & Technical Logs: Emergency panic triggers, emergency timestamps, skip task reasons, IP addresses, and session tokens (crew_session_token).

2. How We Use Data (GDPR Legal Basis)

Processing PurposeData Categories UsedGDPR Legal Basis
Service Access & AuthCredentials, PIN passcodes, session tokensContract Performance (Art. 6(1)(b))
Geofence Clock-in VerificationGPS lat/lng, location target coordinatesLegitimate Interest / Contract Performance
QA Proof WatermarkingPhoto evidence, camera metadata, worker nameContract Performance (Art. 6(1)(b))
Emergency Panic AlertsWorker ID, emergency timestamp, locationVital Interests (Art. 6(1)(d))
Billing & Seat AccountingMember counts, Paddle IDs, invoice logsLegal Obligation / Contract Performance

3. Camera Evidence vs. Gallery Upload Processing

When field technicians submit photo proofs:

  • Live Camera Captures: Processed client-side via HTML5 Canvas to burn hardcoded GPS coordinates and UTC timestamps directly onto the JPEG pixels. Tagged as source: 'camera' in photo metadata.
  • Gallery Uploads: Compressed client-side via Canvas JPEG optimization (max 150KB) to ensure rapid mobile transfer without executing external dynamic scripts. Tagged as source: 'gallery' in photo metadata.
  • Private Cloud Storage: Stored securely in encrypted private buckets on Supabase Storage. Full-resolution proofs are accessed strictly via short-lived signed URLs generated for authorized Organization users.

4. Third-Party Sub-Processors

We share data only with essential infrastructure sub-processors:

Paddle.com (Merchant of Record)
Processes payments, subscription billing, taxes, and merchant compliance.
Supabase Inc. (Database & Auth)
Hosts encrypted PostgreSQL database, auth tokens, and private photo storage.
Resend Inc. (Email Notifications)
Delivers transactional emails, account invites, and password reset notifications.
Vercel Inc. (Cloud Infrastructure)
Hosts web application edge functions and frontend UI delivery.

5. Data Retention & User Deletion Rights

Shift audit records and photo proofs are retained according to your active subscription plan tier:

  • Starter Plan: 30-day retention schedule.
  • Growth Plan: 365-day (1-year) retention schedule.
  • Scale Plan: 730-day (2-year) retention schedule.
  • Enterprise Plan: Custom retention policy.

Under GDPR and CCPA, users have the right to request access to, rectification of, or permanent deletion of their personal profiles and verification logs. To submit a data deletion request, email privacy@getcrewmark.com.

6. Privacy Officer Contact

If you have questions regarding this Privacy Policy or wish to exercise data subject rights, contact our Data Privacy Lead:

Data Privacy Lead, Crewmark