Privacy Policy
Last updated: September 3, 2026
1. Who We Are
CrewLog (“CrewLog,” “we,” “us,” or “our”) provides software that helps construction professionals create, document, and deliver daily site reports. CrewLog is operated from Ontario, Canada. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to crewlog.ai and the CrewLog application (the “Service”).
Where CrewLog is offered. CrewLog is offered in, and intended for, Canada and the United States only. We do not market, target, or offer the Service anywhere else. If you are outside Canada or the United States, the Service is not directed at you. This policy is written for the privacy laws that apply to us here: Canada's federal PIPEDA, Quebec's Law 25, and U.S. state privacy laws including California's CCPA/CPRA. Section 16 explains what that means if you are in Europe.
This page is in English only. Parts of CrewLog are available in French and Spanish, but this policy and our Terms of Service are published in English and English is the version that governs. If you would like help understanding any of it, email us and we will explain it.
This policy is a notice about how we handle information: it is not a contract. Your agreement with us is our Terms of Service. If anything here is unclear, contact us; details are in the last section.
2. Information We Collect
Account information. When you create an account, we collect your name, email address, password (stored only in hashed form by our authentication provider), optional company name, and (if you add one) a profile photo and a drawn signature, both stored on your profile. You can also set your country and state/province, and your company logo if you upload one. If you sign in with Google instead of a password, Google confirms your identity to our authentication provider and passes us the basic profile it holds for you: your name, email address, and profile picture. We never receive your Google password.
Sign in with Apple. You can also sign in with your Apple Account. Apple confirms your identity to our authentication provider and passes us your name and an email address; we never receive your Apple password, and Apple does not tell us anything else about you or your device. Apple offers you the choice to hide your real address, in which case what we receive is a private relay address ending in privaterelay.appleid.com. If you choose that, the relay address is the only address we have: it is what we store on your account, what we send your reports and notifications to, and what Apple forwards on to your real inbox. You can stop that forwarding at any time from your Apple Account settings, and if you do, our email to you will stop arriving. We cannot see your real address, and we cannot recover your account by it.
Content you create. We collect the content you put into the Service, including daily report notes, voice recordings, AI-generated reports, site photos and their captions, job and client details, safety/toolbox-talk records and the per-attendee signatures on them, workplace incident records (including who was involved, the part of the body, the type of injury, and what happened), corrective actions, tasks, schedule and forecast plans, the crews you create and who you put in them, where each crew is scheduled to work on each day, crew time entries and hours, the shifts your crew clock in and out of on the time clock and the append-only log of every correction a manager makes to one, wage and pay-rate information, time-off requests, material delivery records, change-order details and amounts, job cost and expense entries and the receipt images you upload, plans, drawings, and documents you upload and the markup you draw on them, requests for information (RFIs) you create, any signature you draw, the country and state/province you set, the messages and images you send to the AI Construction Assistant, and recipient contact information you add. If you use the Service offline, some of this content is stored locally on your device until it syncs to our servers when you reconnect.
Information from people outside your account. Some CrewLog features work by sending someone a link they can use without logging in. When a client signs a change order that way, we collect the name they give, the signature they draw or type, the date and time, and the internet (IP) address and browser user-agent string the signature was submitted from: a technical record of how and when the signature arrived, which is shown to the contractor on the change order. When someone answers an RFI by link, we collect their name and their answer. When a report is shared by link, the person opening it does not sign in and we do not collect anything about them beyond the ordinary server and analytics information described below.
If you contact us or book a demo. Our contact and demo-request forms collect what you type in them: your name, email, and, on the demo form, your phone number, company, team size, and postal or ZIP code, plus anything you write in the message box. We use it to reply to you and to arrange the demo. It is emailed to our team and also posted to our own internal team chat so someone sees it quickly; both providers are named in Section 6.
Payment information. When you start a free trial, subscribe to a paid plan, or make a one-time purchase (such as additional AI usage), our payment processor (Stripe) collects and processes your payment details on its own systems. Starting a free trial requires a valid card, which Stripe verifies with a $0 authorization to confirm it is genuine. We never see, receive, or store your card number, expiry, or security code: not even the last four digits. What we keep is the Stripe customer and subscription identifiers, your plan, your billing interval, your subscription status, and your trial end date. To see or change your card you go to Stripe's own billing portal, which we link to from your settings.
If you buy inside the iOS or Android app. Anything bought inside the app is processed by Apple or Google on their own systems, under their own privacy policies. We see even less than we do with Stripe: no card details, and no customer record we could use to look you up with them. What reaches us is confirmation of what was bought, passed on by RevenueCat, which checks the store's receipt is genuine and tells our servers which plan or AI credit pack to apply. RevenueCat receives a random identifier we generate for your account — not your name, not your email — along with the product purchased and the store's transaction record. To cancel or change a subscription bought this way you use the App Store or Google Play, not us, because they are the ones billing you.
Trial-abuse records. The free trial is one per person, so we keep two small records to enforce that. We store a one-way SHA-256 hash of the email address (not the address itself) so the same address cannot claim a second free trial later. It is written when an account that has had a trial is deleted, and also at sign-in if we find that a trial has already been used on that device. And we set a browser flag (cl_tr, described in Section 7) recording that a trial has been seen on that device. Neither is used for anything else.
Who you email reports and updates to. When you email a daily report or an owner/progress update from CrewLog, we record each recipient's email address against your account, together with when we first and last mailed it, what kind of send it was, and which report or job it related to. This is anti-abuse infrastructure, not a marketing list: it is how we cap how many different addresses one account can mail in a day, which is what stops CrewLog being used to send spam from our domain. It is stored in our own database, it is not readable from the browser by anyone including you, we never mail these addresses ourselves, and we never sell, rent, or share them. Note that these are addresses belonging to people who did not sign up for CrewLog (you chose to email them) so please read “Information about other people” below. Retention is in Section 9.
Work saved on your own device. So you don't lose what you are typing when you switch tabs or lose signal, CrewLog saves work in progress in your browser's own storage on your device. That covers text you are part-way through (report notes, safety-talk notes and attendee lists, incident descriptions, immediate actions and root causes, corrective actions, change-order notes and documents, RFI questions and answers, owner updates, schedule-phase notes, job instructions, email messages, and what you type to the Assistant) and, for the report capture form, the photos and voice recording attached to a report you haven't submitted yet. Some of this is health-adjacent: an incident description can say who was hurt and how.
This never leaves your device until you save or send. Each saved item is keyed to the signed-in user, so one person's draft is not shown to the next person on a shared site tablet; if we cannot tell who is signed in, nothing is saved and nothing is restored. Text drafts expire after 7 days, and signing out wipes them all along with the saved photos and voice recording. Clearing your browser's site data removes them too. Reports you queued while offline are the deliberate exception: they survive sign-out so they can still be sent by the person who captured them.
Usage and device information. We use exactly one usage-measurement tool: Vercel Web Analytics, built into our hosting provider. It counts page views across the whole site: the public pages, the app once you log in, and pages opened from a share link. It sets no cookies, stores nothing on your device, does not follow you to other websites, and does not build a profile of you. Visits are identified only by a temporary value our hosting provider works out from the incoming request, which it rotates daily. What we see is the page, the time, the page you came from, your browser, operating system and device type, and a rough location (country/region level) estimated from your IP address.
That is the only third-party measurement in CrewLog. We do not use session recording, session replay, or heatmaps: there is no tool in CrewLog that plays back how an individual moved through the app. We do not use any advertising, retargeting, or cross-site tracking technology, and we do not use event, funnel, or cohort analytics products (we removed the one we had tried, so this stays true).
AI usage records. Every plan includes a monthly AI allowance shared across an account, so we have to count what gets used. Each time an AI feature runs we record what kind of action it was, when it happened, how much of the allowance it consumed, the account it belongs to, and which member of the account made the request. We record the measurement, not the content: these entries do not contain your notes, your messages, or the AI's answer. Because they are what the allowance is counted from, they are kept as a running ledger and are not removed when you delete an Assistant conversation or a report. The account owner can see how much of the account's allowance each member has used, so they can divide it up: see the note below about your responsibilities as an employer.
Location information. Several things in CrewLog touch location, and they work differently. Read the first one first: the time clock is the only feature in CrewLog that records where a person is and sends it to us.
• Clocking in and out on the time clock. If your employer uses CrewLog's time clock, we take a location fix when you clock in, when you clock out, and every so often while a shift is running and you have the app open on screen, and we store it on that shift. Exactly three points are kept per shift: where it started, where it ended, and the most recent one while it is running. The most recent one is overwritten each time it refreshes, so there is no trail, no route, and no history of where you went between those points. Nothing is collected while the app is closed or in the background, or while your phone is locked. The apps ask for “while using the app” location only; they have no background-location permission and we are not adding one. It is used for two things: tying a work session to a place, and flagging a clock-in that is a long way from the job site so somebody can check it. It is not used for advertising, and it is never sold. Who can see it: your employer — the account owner and the admins who approve timesheets — and you, on your own shifts. Approving timesheets is what grants the view: an admin the owner has put on the submitting side files their own hours like the crew and sees only their own shifts, in the app and in the database alike. Nobody outside your account. Two switches turn it off: the account owner can switch location collection off for the whole account, and you can deny your phone's location permission, in which case you can still clock in and out normally and your name simply shows as “location off” or “unavailable” on your employer's board. It is kept for as long as the shift and its timesheet are (Section 9). Because this is monitoring of employees, please read “If you record your crew's hours, wages, or locations” below.
• Photos. Most phone cameras save GPS coordinates inside the photo file. When you upload a site photo that carries those coordinates, we read them and store them with the photo so the Field Map can drop a pin where the photo was taken. These coordinates are precise: they show where the person holding the phone was standing. Photos taken without location data (and photos uploaded from a desktop, or with the location stripped out) are stored with no coordinates. If you don't want coordinates collected, turn off location tagging in your phone's camera settings before taking the photo.
• Job addresses. When you enter a job address, we send it to a mapping service to turn it into map coordinates so the job appears on the map. That is a job site, not a person. While you type an address, what you type is sent from your browser to an address-lookup service to suggest matches.
• Your own position on the Field Map. If you tap the “My location” button on the map, your browser asks your permission and then reports your position (precisely, and continuously while the map is open) so the map can show where you are and measure a route. This happens between your device and the map in your browser: we do not send it to our servers and we do not store it. That is true of the map button and only of the map button — it is a separate feature from the time clock above, which does send and store the three points it takes. Your browser and your device settings control the map button, and denying or revoking the permission turns it off.
• The map itself. The street map is drawn from map data and lettering your browser fetches directly from a mapping provider, so that provider sees your IP address and roughly which part of the map you are looking at. It is named in Section 6.
• Satellite view. When you switch the map to satellite, the aerial photographs are fetched by our servers, not by your device. The imagery providers therefore never see your IP address or anything else about you: they receive only a request for a numbered square of the map. Aerial imagery covers the United States, all of Ontario, and the City of Toronto in extra detail, with a worldwide satellite mosaic everywhere else; the optional terrain layer's elevation data is fetched the same way: by our servers, never by your device.
• Directions. If you tap Directions or open a route in Google Maps or Apple Maps, we hand the job's address or coordinates to that app in the link; from there their own privacy policy applies.
Information about other people. Some content you submit may include personal information about other individuals, such as your clients, crew members, subcontractors, or anyone named or shown in reports, photos, and toolbox talks. For that information, you decide what to collect and why, and we process it on your behalf to provide the Service. You are responsible for ensuring you have the authority and any consents required to provide it to us and for honouring those individuals' privacy rights. If an individual contacts us about information you submitted about them, we may refer them to you as the party responsible for it.
If you record your crew's hours, wages, or locations. Timesheets, pay rates, worker photos, photo GPS coordinates, safety-talk signatures, injury details, crew assignments: which named people are in a crew and which job that crew is sent to on a given day, where each shift was clocked in and out and where the worker last was while it was running, and the per-member AI usage figures described above are information about your employees, and you are the one deciding to collect it. Telling your workers what you collect and why is your job as their employer, not ours. Some places require it in writing (Ontario, for example, requires employers with 25 or more employees to have a written electronic-monitoring policy), and Alberta and British Columbia require notice before collecting employee information. Using CrewLog does not satisfy those obligations for you.
The time clock is electronic monitoring, and switching it on is your decision. Location on the time clock is on by default and the account owner can switch it off for the whole account in settings. If you leave it on, your crew's clock-in and clock-out positions are collected and you can see them — that is the feature working as intended, and it is the kind of collection an electronic-monitoring policy has to describe. We will not tell your workers on your behalf, and CrewLog is not a substitute for the notice or written policy your law requires. Individual workers can still decline the phone permission, and the clock keeps working for them without a position.
3. How We Use Your Information
We use your information to: provide, operate, and maintain the Service; generate AI-powered reports from your notes; deliver reports to recipients you choose; process payments and manage subscriptions; provide customer support; secure the Service and prevent fraud or abuse; understand and improve how the Service is used; and communicate with you about your account, security, and product updates.
We do not sell your personal information and we do not share it for advertising. We do not use your content to train any AI model. We build no models, we run no training, and we do not hand your content to anyone for that purpose. That part is entirely within our control and we can promise it outright. Our AI providers, Anthropic and OpenAI, both state in the standard commercial API terms we use them under that they do not train their models on data submitted through the API. That is their commitment rather than ours, so we describe it as what their terms say, not as something we can independently guarantee. If either provider changed that, we would tell you before it took effect (Section 19).
4. AI Processing of Your Content
CrewLog uses third-party artificial-intelligence services to power core features. Specifically:
• Voice recordings you make (on a report, a change order, or in the Assistant) are sent as an audio file to OpenAI for transcription into text. The recording is used for that and nothing else; we keep the recording attached to the report you made it on, and you can delete it.
• Your report notes and transcripts are sent to Anthropic to generate written daily reports and to flag items such as delays, deliveries, and safety events. To keep a report consistent with the day before, we may also send yesterday's report, your open tasks and RFIs, your scheduled phases, and the names of crew who clocked in that day.
• Your job information (such as report notes, change-order and cost figures, safety records, and schedule data) may be sent to Anthropic to draft change orders and requests for information (RFIs), write cost briefings and owner updates, score a job's “health,” and forecast schedule risk. A change order also sends the site address and the client contact name; your internal cost and margin are deliberately withheld from it.
• Receipt and expense images you upload for job costing are sent to Anthropic as images to read them and pull out the vendor, date, total, a category, and a short description. (It does not itemise the receipt line by line.)
• Translation. When a teammate chooses to view typed crew content (such as reports, notes, safety talks, tasks, or photo captions) in a language other than the one it was written in, that text is sent to Anthropic to translate it, and the translation is cached: see “About the translation cache” below.
• The AI Construction Assistant (your messages, the country and state/province you set, and whatever it looks up in your account) are sent to Anthropic to generate answers. See “What the Assistant sends” below.
Your site photos are never sent to an AI provider. This is worth stating plainly, because it is the thing people ask about most. When CrewLog writes a daily report it is told how many photos are attached and nothing more: not the images, not what is in them. There is no photo captioning, photo analysis, or facial recognition anywhere in CrewLog. Only two things send an actual image out: a receipt you upload for expense scanning, and an image you deliberately attach to an Assistant message (used for that one message and not stored). Everything else the AI knows about a photo is the caption you typed.
What the Assistant sends. The Assistant is not only a question-and-answer tool: it can look things up in your own account to answer a question about your jobs, and what it finds is sent to Anthropic as part of writing the answer. Depending on what you ask and what your role and permissions allow, that can include your job names, statuses and addresses, tasks and who they are assigned to, open RFIs, the text of your daily reports, photo captions, schedule phases, change orders with their amounts and client contact names, job budgets, costs and margins, safety incidents including the free-text description of what happened and who was hurt, deliveries, and crew hours by person and by job.
It can also look up your crew. If you ask about a person (“what is Mike working on?”) the Assistant looks them up in your team list and sends what it finds to Anthropic. For anyone on the account that means the person's name, role, and status. If the person asking is the account owner or an admin, it also includes that teammate's email address, when they were invited and joined, and, for a small number of matches, the jobs they are on, their open and overdue tasks, and how recently they filed reports. It never sends pay rates or wages (that is deliberately walled off) though crew hours can be sent if you ask about hours. If your crew's names and work emails being processed by an AI provider is a problem for you, that is a reason to tell them about it (see “If you record your crew's hours, wages, or locations” in Section 2).
A short list of your jobs is included with every message so the Assistant knows what you are talking about. Your recent messages in the same conversation are sent again with each new message so it can follow the thread. If you attach an image, it is sent to the provider for that message only and is not stored. Your Assistant conversations are stored in your account so you can refer back to them, and you can delete them at any time, though the usage measurements described in Section 2 remain.
The Assistant does not change anything on its own. When it proposes a task, a report draft, a schedule change, a safety talk, a change order, an RFI, or an email to your client, it produces a draft and shows you exactly what would be written before anything happens. Nothing is saved and nothing is sent until you confirm it. When you do confirm, the same rules that apply everywhere else in CrewLog are checked again: your plan, your role, your job access, and the feature permissions your account owner set.
About the translation cache. To avoid paying to translate the same sentence twice, a translated piece of text is stored in a shared cache. The cache is keyed by a one-way fingerprint (a SHA-256 hash) of the original text, and it holds the translated text. It is shared across all of CrewLog rather than kept inside your account, so a phrase translated once is reused for everyone, and it holds no account, job, or person attached to the text. Because a row can only be found by someone who already has the exact original text, it is not browsable or searchable. But the translated text itself is stored in readable form. Cached translations are kept indefinitely and, being outside any one account, are not deleted when you delete your account. If that matters for your business, contact us.
About the AI providers. We use two established AI companies, and only two. Anthropic (Claude) handles written reports, change orders, RFIs, cost briefings, owner updates, job-health narration, schedule forecasts, receipt reading, translation, and the AI Assistant. OpenAI handles voice transcription, and read-aloud on iPhone and iPad (see the paragraph below). Nothing else goes to them. Both are used under their standard commercial API terms, which state that they do not train their models on data submitted through the API (see Section 3 for exactly how far that promise goes). Each may hold what is sent to it for a limited period (currently up to 30 days under those standard terms) only to detect misuse of its own service, and then deletes it. Both process data in the United States. If we change AI providers, we will update this policy and tell you before the change takes effect.
About read-aloud. On a computer and on Android, read-aloud is produced by your own device's web browser and nothing is sent to us or to anyone else. On an iPhone or iPad it is different, because Apple gives a web page no good voice to use: there the text you asked to have read — a report, a toolbox talk, or an Assistant answer, up to about 12,000 characters — is sent to our server and on to OpenAI, which returns the audio. The audio is cached on your device so the same text is not sent twice. If you would rather nothing left your iPhone, don't use read-aloud there.
We process your content this way because it is what you signed up for: AI is part of what CrewLog does. If you would rather not have content processed by AI, don't use the voice-recording, AI-report, translation, receipt-scanning, or AI Assistant features. The rest of CrewLog works without them.
5. Automated Decisions
Some CrewLog features produce a score or a prediction: a job “health” score, a schedule-risk forecast, a flagged safety item. These are suggestions for a person to look at, not decisions.
We do not make any decision about you (about your pay, your employment, your credit, or your access to the Service) based only on automated processing. AI output can be wrong, and it is built to be reviewed before anyone relies on it.
6. Service Providers We Share Data With
We share personal information with service providers who process it on our behalf, only as needed to run the Service, and under terms that require them to protect it and use it only for us. They are:
• Supabase: cloud database, login, and file storage; where your account and content live
• Vercel: application hosting and cookieless web analytics; serves the app and counts page views
• Stripe: payments, subscriptions, and card verification, for anything bought on our website
• Apple and Google: process the payment for anything bought inside the iOS or Android app, on their own systems and under their own privacy policies
• RevenueCat: checks those in-app purchases are genuine and tells us what to unlock; it receives a random identifier for your account, never your name or email
• OpenAI: voice-to-text transcription
• Anthropic: AI reports, drafting, receipt reading, translation, and the AI Assistant
• Resend: sends reports, invitations, and account emails
• Google: only if you choose to sign in with Google, to confirm who you are
• Slack: only for the demo-request and contact forms on our website; the details you type there are posted to our own team channel so we see the enquiry
• OpenStreetMap Foundation (Nominatim): turns a job address into map coordinates
• NOAA / U.S. National Weather Service and Environment and Climate Change Canada: weather for a job's coordinates
• U.S. Geological Survey, GEOspatial Ontario, the City of Toronto and EOX IT Services GmbH (worldwide Sentinel-2 satellite mosaic): the imagery behind the map's satellite view, fetched by our servers so these providers never see you
• AWS Open Data (Terrain Tiles): the elevation data behind the map's terrain layer, built from USGS and Government of Canada elevation sources and fetched by our servers the same way
• Environment and Climate Change Canada and NOAA/NCEP: the live precipitation radar behind the map's rain radar layer, also fetched by our servers
Canadian weather contains information licensed under the Open Government Licence – Canada, and observations provided by NAV CANADA. U.S. weather is public-domain data from the National Weather Service. Aerial imagery is from the U.S. Geological Survey / USDA National Agriculture Imagery Program (public domain), and contains information licensed under the Open Government Licence – Ontario and the Open Government Licence – Toronto. The worldwide mosaic is Sentinel-2 cloudless by EOX IT Services GmbH (CC BY 4.0, contains modified Copernicus Sentinel data 2016 & 2017). Elevation data is from USGS 3DEP/SRTM and contains information licensed under the Open Government Licence – Canada. Precipitation radar is from NOAA/NCEP (public domain) and contains information licensed under the Open Government Licence – Canada.
Services your own browser contacts directly. A few things are fetched by your device rather than sent by us, which means those companies see your IP address and what you requested, even though we send them nothing about you:
• OpenFreeMap (using OpenMapTiles and OpenStreetMap data): the map images and the fonts used to label them
• Komoot (Photon): address suggestions while you type a job address
• Google Maps or Apple Maps: only when you tap Directions, which opens their app or site
Vercel's cookieless page-view counter, listed above, is the only usage-measurement service we use. We use no session-replay, heatmap, advertising, or cross-site tracking service, and no event or funnel analytics product.
This is our current list, and it is the whole list: there is no unnamed “and others.” If we add or change a provider we will update this policy, as described in Section 19.
We may also disclose information if required by law, to enforce our Terms, to protect the rights, safety, or property of CrewLog or others, or in connection with a merger, acquisition, or sale of assets (in which case we will tell you).
7. Cookies and How We Measure Usage
Browsing crewlog.ai sets no cookies at all. Nothing is stored on or read from your device while you look around our public website, which is why there is no cookie banner: there is nothing to consent to. Cookies only start once you log in. Every one of them is set by CrewLog itself (first-party), none are advertising cookies, none belong to a third-party tracker, and none follow you to other websites.
Here is every cookie we use:
• sb-… (authentication): keeps you logged in and keeps your session secure. Strictly necessary. Lasts while you stay signed in, and is cleared when you sign out.
• cl_tr: a flag on your browser so the same device can't repeatedly claim a new free trial. Fraud prevention. Lasts up to 180 days.
• tz: your time zone, so hours, dates, and reports land on the right day. Functional. Lasts one year.
• cl-locale: the language you picked for the app. Functional. Lasts one year.
• cl_sx: when you turn off “stay signed in on this device,” this holds the time your session should end, so a shared or borrowed device signs itself out. Security. It holds a timestamp and nothing else, and it only exists while that setting is off. Turning it back on deletes it.
The cl_tr flag is the only one that recognises a device rather than an account. It is written once (the first time you sign in on that browser to an account that has had a trial, which may be at signup or later) and it holds nothing but a timestamp. It is used for nothing except declining a second free trial on a browser that already had one, and it never blocks a sign-up or an account on its own. It does not profile you, does not record where you go, and does not follow you off our site.
Clearing or blocking cookies. Clearing your browser cookies removes all five, including cl_tr. In Chrome: Settings → Privacy and security → Delete browsing data. In Safari: Settings (or Preferences) → Privacy → Manage Website Data. In Firefox: Settings → Privacy & Security → Cookies and Site Data. In Edge: Settings → Cookies and site permissions. The same settings let you block cookies for any site, at any time. But blocking the sign-in cookie will stop you being able to log in.
For measuring usage we use our hosting provider's built-in web analytics, which is cookieless: it sets no cookie and stores nothing on your device (see Section 2). We do not use session recording, session replay, or heatmaps. We do not use cookie data for advertising, and we do not sell it.
8. International Data Transfers
CrewLog is operated from Ontario, Canada, and serves customers in Canada and the United States. Several of our providers store and process data in the United States. That means your information may be held and handled outside your own province, state, or country, in places whose privacy laws are different from yours, and where courts, law enforcement, and government authorities may in some circumstances be able to get access to it. If you are a Canadian customer, assume your data is processed in the United States; if you are a U.S. customer, assume it is administered from Canada.
A few of the services your own browser contacts (the map, address suggestions) are run from Europe, and the weather services are run by the U.S. and Canadian governments. Those receive only your IP address and what was requested (a piece of map, a partial address, a job's coordinates); we send them nothing that identifies you, and no account, report, photo, or crew information ever reaches them.
Sending your information to a provider so they can do a job for us is a use of that information: it is not a sale, and it is not us handing your data over for someone else's purposes. Every provider listed in Section 6 is bound by written terms that require them to protect the information they hold for us and to use it only to provide their service to us.
9. Data Retention
We keep your information for as long as your account is active and for as long as we need it to run the Service.
When you delete something inside CrewLog. Deleting a job, a daily report, a safety incident, a corrective action, or a toolbox talk hides it everywhere in the app and it never comes back: there is no restore, no trash, and no undo. Behind the scenes the record itself is kept in a hidden state, because our monthly plan allowances are counted from it and otherwise deleting and recreating reports would reset your limits. Deleting a job also hides all of that job's reports. Two things are different: the photos and drawings attached to what you deleted are permanently erased from storage straight away and cannot be recovered, and the AI usage entries in Section 2 always remain. So “delete” inside CrewLog means: gone for you and your crew immediately, photos gone for good immediately, and the underlying record retained by us until you delete your whole account.
Shift locations. The three location points on a shift (Section 2) live on the shift record and are kept for as long as that shift and the timesheet it rolls up into are — which is as long as the account keeps its payroll records. There is no location history to age out, because only those three points exist and the most recent one is overwritten rather than appended. One other place holds a copy: the append-only correction log records the whole shift record as it stood before and after each change, so the copy it keeps includes those three points. A line is written when a shift is opened, closed, corrected, voided or auto-closed — not each time the position refreshes — so the log is a record of changes to the shift, not a trail of where anyone went. They are deleted with the account. If a manager corrects or voids a shift, the shift record changes but the append-only correction log does not: it is kept so the worker can see what was changed, and it is deleted with the account like everything else.
When you delete your account. Account deletion is done by the account owner and is permanent. We cancel your subscription and delete your Stripe customer record so you can never be billed again, erase every file you uploaded (photos, drawings, documents, receipts, signed change orders, signatures, and your logo, including the ones belonging to records you had already deleted) and then delete your account and everything cascading from it. Team members keep their own accounts and are simply unlinked. In practice erasure completes within 30 days, but a few things are different:
• Encrypted backups are overwritten on a rolling cycle, so copies can survive for a short period after the live data is gone.
• Stripe keeps payment and invoice records to meet its own tax and chargeback obligations.
• Apple, Google and RevenueCat keep their own records of purchases made inside the apps, for the same reasons. A subscription bought through a store must also be cancelled there: deleting your CrewLog account does not cancel it, because we are not the ones billing you.
• Our AI providers may hold what was sent to them for up to 30 days for abuse detection, then delete it.
• AI usage entries (Section 2) are the ledger our monthly allowances are counted from. They hold no content, they are attached to your account, and they are deleted with it.
• The recipient log (Section 2) is attached to your account and is deleted with it. While your account is live we keep it as long as we need it to enforce the daily sending cap and to investigate abuse; we do not currently delete individual entries on a fixed schedule, and if you want a specific recipient removed, ask us.
• A one-way hash of your email address is kept after deletion, on purpose, so the same address cannot claim a second free trial. It is a hash, not an address, and is used for nothing else.
• Cached machine translations (Section 4) sit in a shared cache keyed by a fingerprint of the original text, not by account, so they are not deleted with your account and are kept indefinitely. The cache holds the translated text itself, with nothing stored beside it linking it to you, your job, or your company. But the text is stored in readable form. If a piece of your content was ever viewed in another language, assume its translation persists. If that matters for your business, contact us before deleting.
• We keep the minimum records we need for tax, accounting, legal-hold, and fraud-prevention obligations.
A few things time out on their own. Drafts saved in your browser expire after 7 days and are wiped when you sign out (Section 2). Photo links inside a report you emailed stay openable for about 60 days, so the recipient can still see the pictures weeks later: treat an emailed report as something you can't take back. A report share link has no expiry: anyone holding it can open that report until you delete it.
10. Data Security
Here is what actually protects your data. Everything travels over an encrypted connection (TLS). Our database and file storage sit with Supabase, which encrypts data at rest on its own infrastructure. Access is enforced in the database itself with row-level security, so one account cannot read another's data even if the app has a bug, and your role, job access, and feature permissions are re-checked on the server on every request rather than only being hidden in the interface. Files are served through short-lived signed links, not public URLs. Passwords are stored only as hashes by our authentication provider: we never see them.
What we are not claiming: we hold no security certification, we have not completed a SOC 2 or ISO audit, and we are a small company rather than a security organisation. No method of transmission or storage is completely secure and we cannot guarantee absolute security. You are responsible for keeping your password confidential and for activity under your account. If you handle data that needs certified infrastructure, please take that into account.
11. If Something Goes Wrong
If a security incident happens that creates a real risk of serious harm to you, we will notify you and the appropriate privacy regulator without undue delay. We will tell you what happened, what information was involved, what we've done about it, and what you can do. We keep a record of every confidentiality incident, whether or not it has to be reported.
12. Biometrics and Signatures
We do not collect biometric information. When you or a client signs a change order, we save the signature as a picture. We do not measure pressure, speed, or stroke timing, and we do not turn a signature into a biometric template. Illinois' biometric privacy law specifically excludes written signatures and photographs from what counts as a biometric identifier.
What we keep alongside a signature. A signature on its own proves little, so we also record the plain circumstances of the submission: the name given, the date and time, and the internet (IP) address and browser user-agent string it came from. That is a technical record of how and when the signature arrived, kept so the contractor has some evidence of it, and it is shown to the contractor on the change order. It is not identity verification: we do not confirm who actually signed. If you send a change order for signature, telling the person that this record is kept is your responsibility as the sender.
Signatures on toolbox talks. When your crew signs a safety talk, we record each attendee's name, whether they tapped or typed it, and when. That is an attendance record about your workers: see Section 2 about your responsibilities as their employer.
Voice recordings are used for one thing: turning speech into text. We do not create voiceprints, we do not use voice to identify or authenticate anyone, and we do not run facial recognition on your photos.
13. Your Rights & Choices
Wherever you live, we will honour these rights: see the personal information we hold about you; correct it if it's wrong; delete it; get a copy of the information you gave us in a structured, commonly used electronic format so you can take it somewhere else; and withdraw consent where we relied on it. We give these to everyone, not only to people whose local law requires them.
How to actually do it. You can edit most of your own information in your account settings, and you can delete your whole account there. For a copy of your data, email us: we will put it together and send it to you, free, whatever plan you are on. We want to be straight about why: CrewLog has handy per-feature exports (reports to CSV, timesheets, expenses, contacts, safety and report PDFs), but some of them are on paid plans only and there is no single “download everything” button in settings. Those exports are a product feature. Your right to a copy of your data is not a product feature, it is not gated on your plan or your role, and asking us is how you use it.
We will respond within 30 days, or sooner where the law where you live requires it. We may need to confirm who you are first, usually by confirming you control the email address on the account. We will not treat you differently for asking.
If you are an employee or a client of a CrewLog customer rather than an account holder yourself (a crew member whose hours are logged, or a client who signed a change order) the contractor decided to collect that information and controls it. Contact them first. If you contact us, we will help, but we may need to refer you to them, and we will tell you who they are.
If we turn down a request, we'll tell you why, and you can ask us to reconsider. If we still say no, you can take it further: Canadians can complain to the Office of the Privacy Commissioner of Canada under PIPEDA; Quebec residents can complain to the Commission d'accès à l'information du Québec; and if you are in a U.S. state that gives you an appeal right, we will give you your attorney general's contact information.
14. California Privacy Rights (CCPA / CPRA)
California is one of the states we serve, so this section describes your rights under the CCPA as amended by the CPRA if you are a California resident. We give the rights below to every California user who asks, without arguing about whether a business our size is technically covered.
What we collect and where it comes from. The categories are in Section 2: identifiers (name, email address, and the email addresses of people you send reports to), commercial information (your plan, billing interval, and subscription status; we hold no card details at all), internet and device activity, coarse location from your IP address, precise location from the time clock and from photo GPS data, audio in the form of voice notes, visual information in the form of photos and a profile picture, professional and employment information about the crew you log, and the content you put into the Service. It comes from you, from the teammates you work with, automatically from your device, and from our payment processor.
Sensitive personal information. Three things qualify. The first is precise geolocation, and it now reaches us from two places: the time clock, which stores where a shift was clocked in, where it was clocked out, and the most recent position while it was running (Section 2), and GPS coordinates saved inside a photo you upload, when the photo carries them. A third location feature, the “My location” button on the Field Map, stays on your device and is never sent to us, so it is not information we hold. The second is voice recordings. The third arises where an employer records a workplace injury: the injury details in an incident record are health-related information about the person involved, submitted by the employer who collected it. We use each only to deliver the feature that was asked for: recording where a work shift started and ended and flagging one clocked in far from the job site, dropping a pin on the map, turning speech into text, and keeping the safety record you entered. We do not use any of it to infer anything about you, we do not create voiceprints, and we do not sell or share any of it. Because we only use sensitive information for purposes the CCPA permits, there is no “Limit the Use of My Sensitive Personal Information” link: there is nothing to limit.
We do not sell or share your personal information as the CCPA defines those words, and we have not in the last 12 months. We do no cross-context behavioural advertising. That's why there is no “Do Not Sell or Share My Personal Information” link: there is nothing to opt out of, and nothing for a browser opt-out signal such as Global Privacy Control to switch off.
How long we keep it is set out in Section 9. Your rights (to know, access, correct, delete, take a copy, and not be treated differently for asking) are in Section 13. Email support@crewlog.ai to use them. You may use an authorized agent.
15. Quebec (Law 25)
If you live in Quebec, Quebec's Law 25 gives you extra rights and gives us extra duties. It applies to us even though we operate from Ontario, and it is stricter than Canada's federal law in several places. That is why it has its own section rather than being folded into the rest. We ship CrewLog in French, so we expect Quebec users and we would rather set this out properly than hope it doesn't come up.
Technology that can identify or locate you. Four things in CrewLog fall into this category, and we're required to tell you about them and how to switch them off. The first is the cl_tr browser flag described in Section 7, which recognises a device so the same device can't claim repeat free trials: clearing your browser cookies removes it at any time. The second is reading GPS coordinates out of photos you upload, described in Section 2: turning off location tagging in your phone's camera settings stops those coordinates from ever reaching us. The third is the “My location” button on the Field Map, which asks your browser for your position and follows it while the map is open: it only runs if you tap it and grant permission, we never receive or store the position, and denying or revoking the permission in your browser turns it off. The first three are not used to profile you, to track your movements, or to monitor your work.
The fourth is the time clock, and we will not describe it the same way, because it is different in kind. It takes a location fix when a worker clocks in, when they clock out, and periodically while the shift is running with the app open, and it stores those three points on the shift so the employer can see where the work session was and whether it started far from the job site (Section 2). That is workplace monitoring, it is switched on by the employer who holds the account, and it is the employer — not CrewLog — who decides to use it and who has to tell their workers about it before collecting it. Two things switch it off: the account owner can turn location collection off for the entire account in settings, and any worker can deny the location permission on their own phone and go on clocking in and out normally. Even at its fullest, it records three points per shift, only while the app is open, and never when the app is closed or the phone is locked; it does not follow a worker between shifts or after hours.
Sending information outside Quebec. Quebec law requires us to assess, before sending personal information outside Quebec, whether it will receive a comparable level of protection there. Section 6 names the providers we use and what each one does, and Section 8 explains where they process data and what that means for you.
Your Quebec rights. On top of the rights in Section 13, you can ask us for the personal information you gave us in a structured, commonly used electronic format, and you can complain to the Commission d'accès à l'information du Québec.
Person in charge. Our Privacy Officer is the person in charge of the protection of personal information at CrewLog. Contact details are in the last section.
16. Europe, the UK, and Switzerland: What We Do and Don't Claim
An earlier version of this policy said CrewLog was available “anywhere, including the European Economic Area, the United Kingdom, and Switzerland,” and pointed European users at their data protection authorities. That was more than we can stand behind, so we have corrected it rather than quietly leaving it in place.
CrewLog is offered in Canada and the United States only. We do not market or sell into Europe, our prices are in U.S. dollars, and our support and our whole company sit in Ontario. Our French and Spanish translations are there for Quebec and for Spanish-speaking crews in North America, not to reach Europe.
We do not claim to be GDPR compliant, and we are not going to pretend otherwise. The GDPR asks a business for specific things: a documented lawful basis for each use, records of processing, an appointed EU representative, assessments before high-risk AI processing, a standard-form data processing agreement for business customers. We have not done that work, because we do not serve that market. Saying “GDPR compliant” without it would be a promise we could not keep, and a false compliance claim is worse for you than an honest gap.
What you get anyway. The protections in this policy are not geographic. If you somehow end up with data in CrewLog while in Europe, the UK, or Switzerland, everything here still applies to you: the rights in Section 13 (access, correction, deletion, a copy of your data, withdrawing consent), no sale of personal information, no advertising or cross-site tracking, no training AI models on your content, and the same security and retention practices. Section 8 tells you where your data is processed. Email us and we will handle your request the same way we handle everyone else's.
Who is responsible for what. For your own account information, CrewLog decides how it's used. For the content you upload about other people (your clients, crew, and subcontractors) you decide what to collect and why, and we handle it on your instructions to run the Service for you. If you need that relationship set out in writing for your own records, contact us and we will do our best, but we do not have an off-the-shelf European data processing agreement to hand you.
17. Your Data Is Yours
You own the content you create on CrewLog: your reports, photos, voice recordings, and job data belong to you. We claim only the limited rights needed to operate the Service for you, as described in our Terms of Service.
18. Children's Privacy
The Service is intended for business use by individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, please contact us and we will delete it.
19. Changes to This Policy
We may update this policy. If we make a material change (a new provider, a new use of your information, a new category of data we collect) we'll update the “Last updated” date and tell you by email or in the app before the change takes effect.
This policy is a notice about how we handle information. It isn't a contract, and reading it or continuing to use CrewLog isn't you signing anything.
20. Contact Us
For questions about this policy, about how we handle your information, or to use any of the rights in Section 13, contact our Privacy Officer at support@crewlog.ai. Our Privacy Officer is the person accountable for how CrewLog handles personal information, and complaints can be sent to the same address.
CrewLog Technologies Inc. · Ontario, Canada
If you aren't satisfied with how we handled your request or complaint, you can contact the Office of the Privacy Commissioner of Canada at priv.gc.ca, or, if you live in Quebec, the Commission d'accès à l'information du Québec at cai.gouv.qc.ca.