Privacy Policy
Last updated: February 1, 2026
CrewStat ("we", "our", or "us") operates the CrewStat ERP platform, including the web application at crewstat.com and the CrewStat mobile application available on Android and iOS (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website or when data is processed through our Service.
1. Definitions
- Customer / Subscriber: The organization (company, business, or entity) that subscribes to CrewStat ERP and enters into a service agreement with us.
- Authorized User / End User: Employees or personnel of a Customer who are granted access to the Service by their employer.
- Service Data: All data submitted to, stored within, or processed through the Service by or on behalf of the Customer, including employee records, attendance data, project data, and all other business data.
- Account Data: Information collected directly by CrewStat for the purpose of managing the Customer's account (e.g., billing contact, subscription details).
- Website Data: Information collected from visitors to our website (crewstat.com) who are not using the Service.
2. Our Role: Data Processor vs Data Controller
For Service Data (employee/business data in the platform): CrewStat acts as a Data Processor. Your employer (the Customer) is the Data Controller. We process Service Data only according to the Customer's instructions and our service agreement.
For Website Data and Account Data: CrewStat acts as the Data Controller for information we collect directly from website visitors and Customer account administrators.
3. Data Ownership
Your employer owns the Service Data. All data that your organization enters, uploads, or generates within the CrewStat platform belongs to the Customer. We do not claim ownership of Service Data. We store it securely, limit access to it, and process it only in accordance with the Customer's instructions and our service agreement.
4. Information We Process
4.1 Service Data (Processed on behalf of the Customer)
When a Customer uses our platform to manage their workforce, the following types of data may be processed through the Service. The Customer determines what data is entered:
- Employee information: Name, email, phone number, employee ID, designation, department, date of birth, date of joining, emergency contacts
- Payroll data: Bank account details, salary information, tax details (as configured by the Customer)
- Attendance and location data: Check-in/check-out timestamps and GPS coordinates for geofence-based attendance verification
- Files and documents: Profile photos, project documents, expense receipts, quality control photos
- Work data: Tasks, project assignments, leave requests, performance records
4.2 Device Information (Mobile App)
When Authorized Users use the CrewStat mobile application, we collect:
- Device model and operating system version
- Firebase Cloud Messaging (FCM) tokens for push notifications
- App version information
4.3 Website Data (Collected directly by CrewStat)
When you visit our website, we may collect:
- IP address and browser information
- Pages visited and interactions
- Contact form submissions (name, email, message)
5. How Data Is Used
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Service Data | Providing the ERP platform to the Customer as contracted | Performance of contract with Customer |
| Location data | Geofence-based attendance verification during check-in/check-out | Customer's legitimate interest (attendance management) |
| Device information | Delivering push notifications and ensuring app compatibility | Legitimate interest (service delivery) |
| Website data | Improving our website, responding to inquiries | Legitimate interest / consent |
6. Location Data
The CrewStat mobile app collects precise location data (GPS coordinates) when an Authorized User performs an attendance check-in or check-out. This data is used for geofence-based attendance verification as configured by the Customer.
Important: Location data is collected only at the moment of check-in or check-out. We do not track location in the background or continuously. The Customer (your employer) determines whether geofence-based attendance is enabled.
7. Data Sharing and Disclosure
We do not sell Service Data or personal information to third parties. Data may be shared only as follows:
- With the Customer: Customer administrators can access all Service Data within their organization's workspace, as part of their role as Data Controller.
- Sub-processors: We use trusted third-party services to operate the platform:
- Cloud hosting and infrastructure (AWS)
- File storage (Amazon S3)
- Push notification delivery (Firebase Cloud Messaging)
- Legal requirements: We may disclose information if required by applicable law, court order, or governmental regulation.
- Business transfers: In the event of a merger, acquisition, or sale of assets, data may be transferred. Customers will be notified in advance.
8. Customer Responsibilities
As the Data Controller, each Customer is responsible for:
- Having a lawful basis (such as an employment contract or legitimate interest) for collecting and uploading employee data to CrewStat
- Informing their employees that their data will be processed through the CrewStat platform
- Responding to data access, correction, and deletion requests from their employees
- Complying with applicable data protection and labor laws in their jurisdiction
- Ensuring accuracy of the data entered into the platform
9. Rights of Authorized Users (Employees)
If you are an employee whose data is processed through CrewStat by your employer, you have the following rights:
- Access and correction: You can view and update your own profile information through the mobile app. For data you cannot modify directly, contact your employer's HR/admin team.
- Deletion: To request deletion of your data, please contact your employer. As a Data Processor, we act on the Customer's instructions regarding data deletion. See our Account Deletion page for more details.
- Data portability: Contact your employer to request a copy of your data.
- Complaints: If your employer does not address your concern, you may contact us at [email protected] and we will work with your employer to resolve the matter.
Why should I contact my employer? Because your employer is the Data Controller who decides what data is collected and how it is used. CrewStat processes data only on your employer's behalf and instructions. Your employer is best positioned to address your data-related requests.
10. Data Storage and Security
We implement industry-standard security measures to protect data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Role-based access controls and multi-tenant data isolation
- Regular security monitoring and audits
- Secure authentication with hashed passwords and JWT tokens
- Infrastructure hosted on reputable cloud providers with SOC 2 compliance
While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
11. Data Retention
- Service Data: Retained for as long as the Customer's account is active. Upon termination of the Customer's subscription, Service Data is deleted within 90 days, subject to any legal retention requirements.
- Individual employee data: Retained until the Customer deletes it or the employee's account is deactivated by the Customer.
- Attendance and location records: Retained as configured by the Customer and in accordance with applicable labor laws.
- Website data: Contact form submissions retained for up to 12 months.
12. Account Deletion
Account deletion can be requested through multiple channels. See our Account Deletion page for complete details.
- Authorized Users (employees): Contact your employer to request removal from the platform, or use the in-app account deletion option.
- Customers (organizations): Contact us to terminate your subscription and request complete data deletion.
13. Children's Privacy
The Service is designed for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child's data has been processed through the platform, we will work with the Customer to address it promptly.
14. Cookies and Tracking
Our web application uses essential cookies for session management and authentication. We do not use advertising or third-party tracking cookies. The mobile application does not use cookies.
15. International Data Transfers
Data may be processed and stored on servers located outside the Customer's or Authorized User's country of residence. We ensure appropriate safeguards are in place to protect data in accordance with this Privacy Policy and applicable data protection laws.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify Customers of material changes via email or through the Service. The updated policy will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
17. Contact Us
If you have any questions about this Privacy Policy or our data practices: