CrewSharp

Train · Evaluate · Schedule

Privacy Policy

Last updated 29 July 2026

This explains what CrewSharp collects, why, who it's shared with, and what you can do about it. It's written to be read, not to be impressive.

The short version

CrewSharp holds two different kinds of information: your account (the person signing in) and your team's records (the staff you manage). The second kind is your business's HR data. You decide what goes in it and who sees it; we store and process it for you and do nothing else with it.

Who is responsible for what

For your team's records, your organization is the data controller and CrewSharp is the processor. In plain terms: they're your records, we're the filing cabinet. If one of your staff asks to see or correct what's held about them, that request goes to you — and we'll help you answer it.

For your own account details, and for how we run and improve the service, CrewSharp is the controller.

What we collect

Account information. Your name, email address, and a securely hashed password. If you pay us, Stripe handles your card and gives us only the brand and last four digits so we can show you which card is on file.

Your team's records. Whatever you enter: staff names and contact details, job roles and stations, training progress, written evaluations and trainer notes, shift schedules and attendance. Some of this is an opinion about a named person's performance at work, which is exactly why we treat it carefully and never repurpose it.

Technical information. Standard server logs — IP address, browser, time of request — kept for security and debugging, and used to enforce rate limits that stop people abusing our sign-in and invitation emails.

We don't use advertising cookies or third-party trackers. The storage CrewSharp uses in your browser is what keeps you signed in and remembers your display preferences.

Why we're allowed to hold it

We process your account information to provide the service you've asked for and to take payment. We process your team's records on your instructions, under these terms. We process technical logs on the basis of our legitimate interest in keeping CrewSharp secure and working.

Who else touches your data

These are the only companies that process data on our behalf:

  • Supabase — database, authentication, and file storage. This is where your records actually live.
  • Vercel — serves the application to your browser.
  • Stripe — payments. Stripe holds your card details; we don't.
  • Resend — sends invitations, sign-in links, and the evaluation summary emails you choose to send.

Each is bound to use the data only to provide their service to us. We don't sell your data, we don't share it with advertisers, and we don't use it to train AI models. We'll disclose data if the law genuinely requires it, and we'll tell you unless we're forbidden from doing so.

Where it's stored

Your data is stored on Supabase's infrastructure. If that involves moving data between countries, it's done under the safeguards those providers have in place. Tell us at crewsharpsupport@gmail.com if you have a specific regional requirement and we'll tell you honestly whether we can meet it.

How it's protected

Everything travels over HTTPS. Access to your organization's data is enforced in the database itself, so one customer's records can't be read by another even if the app has a bug. Passwords are hashed, never stored in readable form. Two-factor authentication is available on every account and we recommend turning it on. Only the people you invite, at the permission level you give them, can see your records.

No system is perfectly secure. If a breach affects your data, we'll tell you promptly and tell you what we know.

How long we keep it

We keep your data for as long as your account is open, because that's the point of the product — a training history is only useful over time.

If you close your account, we delete your organization's data within 30 days, except anything we're legally required to keep (invoices and payment records, typically for seven years). Backups roll off on their own schedule within 90 days.

Your rights

You can see, correct, export, or delete your data at any time — most of it directly in the app, and the rest by emailing crewsharpsupport@gmail.com. You can ask us to stop processing it, and you can complain to your local data protection authority if you think we've got it wrong.

If you're a member of staff whose records are held in CrewSharp by your employer, contact your employer first — they control those records. We'll support them in answering you.

We won't charge you for any of this, and we'll respond within 30 days.

Children

CrewSharp is workplace software and isn't directed at children. Where you record staff who are under 18, you're responsible for having whatever consent your local employment law requires.

Changes

If we change this policy in a way that materially affects you, we'll tell you by email or in the app before it takes effect.

Contact

Questions, requests, or concerns — email crewsharpsupport@gmail.com. A real person reads it.