CrewBox Pro, Inc. (“CrewBox”, “we”, “us”, “our”) operates the website at https://www.crewbox.pro (the “Website”), the CrewBox web console at https://console.crewbox.pro (the “Desktop App”), and the CrewBox mobile app for iOS and Android (the “Mobile App”). Together these are the “Service”. This Privacy Policy explains what personal information we collect, why we collect it, which device permissions the Mobile App asks for and why, and the choices you have.
CrewBox is used by businesses (“Account Owners”) and the team members they invite. Content you add to a workspace is visible to the Account Owner and the authorized members of that workspace.
Our commitment
- We do not sell your data. We do not sell, rent, or trade your personal information to any third party.
- We do not share sensitive information with third parties. Your password, biometric data, and project content are never given to third parties for their own use, and we never use them for advertising.
- The only third parties we use are the service providers built into our own tools. They help us run, analyze, and improve CrewBox, they process data only on our behalf, and they may not use it for their own purposes. They are all listed in the “Service providers” section below.
Information we collect
- Account information: your name, email address, phone number, company name, and password (stored in hashed form). If you choose to sign in with Google, we receive only your name, email address, and profile picture.
- Project content: the photos, videos, voice notes, annotations, comments, tasks, documents, tags, and reports you create or upload.
- Photo metadata and location: the time a photo or video was taken and, if you allow location access, where it was taken.
- Device and usage information: device model, operating system, app version, a push notification token, IP address, the features you use, crash reports, and diagnostic logs.
- Information you send us: what you enter in the demo, support, and account deletion forms on our Website, and any email you send to support@crewbox.pro.
Mobile App permissions and why we need them
The Mobile App asks for a permission only when you first use the feature that needs it. You can grant or revoke any permission at any time in your device settings. The rest of the app keeps working if you decline, but the feature that needs that permission will not.
- Camera (Android: Camera · iOS: Camera): to take photos and record videos for your projects with the built-in jobsite camera.
- Microphone (Android: Record audio · iOS: Microphone): to record voice notes for a project and to capture sound when you record project videos. On Android, the microphone is also used for speech-to-text dictation, which is processed on your device when the device supports it.
- Location (Android: Precise and approximate location · iOS: Location when in use): to tag photos with where they were taken and to show the projects closest to you. Location is used only while the app is open. We do not track your location in the background.
- Photo library (iOS: Photos, and Add to Photos): to let you choose existing photos and videos to attach to a project, and to save photos and videos to your library when you ask. On Android, the app uses the system photo picker, which needs no permission and shares only the items you pick.
- Face ID and fingerprint (Android: Biometric and fingerprint · iOS: Face ID): to let you sign in quickly without retyping your password. Your device checks your face or fingerprint. Your biometric data never leaves your device, and CrewBox never has access to it.
- Notifications (Android: Post notifications, receive push messages, and keep the device awake long enough to deliver a notification · iOS: Push notifications and background refresh): to alert you about comments, task assignments, and project updates, and to keep your notification badge up to date.
- Internet and network status (Android: Internet and network state): to sync your work with our servers and to detect when you are offline, so the work you capture is saved on your device and uploaded once you reconnect.
The Mobile App does not request access to your contacts, calendar, text messages, call logs, files outside the app, Bluetooth, or background location.
Desktop App
The Desktop App runs in your web browser and does not ask for access to your camera, microphone, location, or notifications. It uses your browser’s local storage and cookies only to keep you signed in and to remember preferences such as theme and layout. Files are uploaded only when you choose them.
Signing in with Google
Signing in with Google is optional. When you use it, we request only the basic openid, email, and profile permissions, to confirm who you are and set up your account. We do not request access to your Google Calendar, Drive, Gmail, or contacts. You can remove CrewBox’s access at any time in your Google Account security settings. See our Google Authentication overview for details.
How we use your information
- Provide, operate, and maintain the Service, including syncing your projects across your devices and your team.
- Create and secure your account, verify your identity, and prevent unauthorized access.
- Send the notifications you have turned on, plus service, security, and account messages.
- Respond to your support requests, demo requests, and account deletion requests.
- Understand how the Service is used, diagnose crashes and errors, and improve CrewBox.
- Comply with our legal obligations.
Service providers
These are the only third parties that process personal information for us. Each one is part of the tools we use to run, analyze, and improve CrewBox.
- PostHog (Website, Desktop App, Mobile App): analytics to measure usage and performance, so we can see which features are used and find and fix problems.
- Google Firebase (Mobile App): Cloud Messaging delivers push notifications to your device, and Crashlytics sends us crash reports that are not linked to your identity.
- Google Maps Platform (Desktop App, Mobile App): suggests addresses as you type a project address. The text you type in the address field is sent to Google to find matching places. Tapping a project address or photo location opens it in Google Maps.
- Agora (Desktop App, Mobile App): delivers real-time updates between your team’s devices, so changes appear immediately without refreshing.
- Microsoft Office Online viewer (Mobile App): when you open a Word, Excel, or PowerPoint document in the Mobile App, Microsoft’s viewer loads that document to display it.
- Notion (Website): stores the requests you submit through our demo, support, and account deletion forms so our team can respond.
- Google Ads (Website only): measures whether our ads lead to visits and sign-ups on our Website. It is not used in the Desktop App or the Mobile App.
- Cloud hosting providers: store and serve your account data and project content on our behalf.
The Mobile App contains no advertising networks and does not track you across other companies’ apps or websites.
Sharing you control
Your content is shared with other people only when you or your Account Owner decide to share it: for example, by adding a team member to a workspace, sending a report, or creating a share link. Content shared into a workspace is visible to that workspace’s Account Owner and its authorized members.
When the law requires it
We disclose information only when the law requires it: for example, to comply with a valid court order or subpoena, or when it is necessary to protect the safety, rights, or property of our users or the public.
Cookies and local storage
Our Website uses first-party cookies for analytics (PostHog) and a cookie from Google Ads to measure ad performance. The Desktop App uses browser storage to keep you signed in and remember your preferences. You can block or delete cookies in your browser settings. Some features may not work without them.
How we protect your information
All data sent between your devices and our servers is encrypted in transit with HTTPS/TLS. The Mobile App stores your sign-in credentials in your device’s secure storage (the iOS Keychain, or encrypted storage on Android). Work you capture offline is kept on your device until it syncs. Access to customer data within CrewBox is limited to staff who need it to support you.
Retention and deletion
We keep your information for as long as your account is active, or as needed to provide the Service. You can ask us to delete your account and data at any time through our account deletion page or by emailing support@crewbox.pro. Once we verify your request, we complete the deletion within 30 days. Data in encrypted backups is purged no later than 90 days after your account is deleted. We keep only what we are legally required to retain, and only for as long as the law requires.
Your rights and choices
- Access, correct, or export the personal information we hold about you.
- Delete your account and data.
- Grant or revoke any Mobile App permission in your device settings.
- Turn notifications on or off in the app or in your device settings.
- Disconnect your Google account from CrewBox.
To exercise any of these rights, contact us at support@crewbox.pro.
Children
You must be at least 18 years old to use the Service. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us at support@crewbox.pro and we will delete it.
Users outside the United States and Canada
Your information may be processed in the United States, Canada, and other countries where our service providers operate. We protect it as described in this Privacy Policy wherever it is processed.
Changes to this policy
We may update this Privacy Policy from time to time. The date of the latest update is shown at the top of this page. If we make a material change, we will notify you by email or in the app before it takes effect.
Contact us
If you have any questions about this Privacy Policy or how we handle your information, contact us at support@crewbox.pro.
