1. Two kinds of data, two different roles
The distinction matters for everything below, so it comes first.
- Data about our customers. A contracting business signs up, and we hold their account and billing information. Here CrewOS is the controller — we decide how that data is used.
- Data our customers put into the platform. Their leads, homeowners, job addresses, photos, invoices, and crew records. Here CrewOS is a processor acting on that business's instructions. The contracting business owns this data and decides what happens to it; we store and process it on their behalf and do not sell it or use it to build our own marketing lists.
If you are a homeowner who contacted a contractor and your details ended up in CrewOS, that contractor is who decides how your information is used. Requests about your data are fastest when made to them directly, but you can also reach us at the address in section 9 and we will route it.
2. What we collect
Account and billing data
- Name, business name, email address, phone number, and role of the people who use the platform
- Authentication data — password hashes, session tokens, and API keys (we never store passwords in readable form)
- Payment and subscription records, processed by Stripe; full card numbers never touch our servers
Business data entered or generated in the platform
- Customer and lead records: names, addresses, phone numbers, email addresses, and notes
- Job data: scope, service line items, pricing, scheduling, crew and truck assignments, and job-site photos
- Financial records: quotes, invoices, payments, expenses, and crew payroll
- Message logs for the email and SMS the platform sends on a business's behalf
Data accessed by the CrewOS browser extension
CrewOS publishes an optional Chrome extension that puts the CRM beside the user's inbox. It is installed by a person who already has a CrewOS login, and it acts only within that person's own organization, using a key CrewOS issues to them. It can do exactly what that user can already do when signed in to CrewOS, and nothing more.
| What it accesses | Why | Where it goes |
|---|---|---|
| The email address of the sender of the message currently open in Gmail or HEY | To tell the user whether that person is already a customer in their own CRM, and link to the record | Sent to that user's own CrewOS workspace to look up a match. Not stored by the extension |
| The text of the open message — only for organizations that switch on the optional AI inbox assist feature, which is off by default | To suggest a next action or draft a reply for the user | Sent to that organization's CrewOS server, which forwards it to OpenAI. Not used to train anyone's models |
| The job-site coordinates, or town and state, of a job the user is viewing | To show the weather forecast at that job site | Sent to Open-Meteo, a third-party weather service, which receives the location and the requesting device's IP address |
| The user's CrewOS API key, organization name, email address, and connection date | So the user does not have to reconnect every time the browser restarts | Held in the browser's own local storage on that device. Never synced to other devices or profiles |
Messages from senders who do not match a customer in that user's CRM are never read or transmitted, whatever the settings. When AI inbox assist is off — the default — message text is never read into the extension's storage at all. The extension does not read browsing history, does not track activity across sites, and adds nothing to any page beyond a link next to a matched sender's name.
Data obtained from Meta (Facebook and Instagram)
When a contracting business connects its Facebook assets to CrewOS, it authorizes us to access specific data on its behalf. We request only what the connected features need:
| What we access | Why | Where it goes |
|---|---|---|
| Lead form submissions from the business's Facebook Lead Ads | So a lead reaches the contractor's pipeline in seconds instead of being retyped from a Meta export | Stored as a lead and job record in that business's workspace |
| The list of Facebook Pages, ad accounts, and pixels the person connecting can access | So they can pick which assets to connect, instead of pasting raw IDs | Stored as connection settings for that business |
| Advertising metrics — spend, impressions, clicks, and conversions | To report what each lead and each job actually cost to win | Stored as aggregated daily ad statistics |
| Page content and engagement, where the business enables those features | To publish posts and surface comments inside the platform | Stored with that business's marketing records |
| Basic profile data of the person who connects the account | To show who linked the integration and to detect when access is revoked | Stored on the connection record |
Data obtained through Meta is used only to provide these features to the business that authorized it. It is never sold, never used for advertising to the people in it, and never combined across different businesses on the platform.
Website and product usage data
- Standard server logs: IP address, browser and device type, pages requested, and timestamps
- Error and performance diagnostics used to keep the product working
- Visitor activity on marketing websites the platform hosts for our customers, including advertising click identifiers used to attribute a lead to the ad that produced it
3. How we use it
- To operate the platform and the features each business has switched on
- To route a new lead into the right business's pipeline and notify their team
- To send email and SMS on a business's behalf to their own customers, subject to consent and quiet-hours rules
- To calculate reporting — revenue, close rates, cost per lead, and crew payroll
- To process payments and issue invoices
- To secure the platform, investigate abuse, and meet legal obligations
- To support customers when they ask us for help
Some features use AI services to draft text, map incoming lead form fields to the right record, or read a receipt. Content sent to those providers is processed to return a result for that business and is not used by us to train models.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. Who we share it with
We share data with service providers who process it under contract, only to run the platform:
- Hosting, databases, and file storage
- Stripe, for payment processing
- SendGrid, for email delivery, and our SMS delivery provider
- Meta, Google, and other advertising or business platforms a customer chooses to connect
- OpenAI, Google, and xAI, for the AI-assisted features described above
- Open-Meteo, which receives a job site's location to return that site's weather forecast
- Error monitoring and analytics providers
We also disclose data when the law requires it, to protect rights and safety, or as part of a merger or acquisition — in which case the acquirer remains bound by this policy.
5. How long we keep it
- Business data stays for as long as the account is active, because it is the customer's operating record
- After an account closes, data is deleted within 90 days unless we must keep it longer for tax, accounting, or legal reasons
- Data obtained from Meta is deleted when the business disconnects the integration, when the account closes, or on request — see the deletion page
- Server logs and diagnostics are kept on a short rolling window
6. How we protect it
- Encryption in transit, and encryption at rest for access tokens and other credentials
- Every business's data is isolated in its own workspace, enforced on every request
- Role-based permissions so staff see only what their role allows
- Access to production systems limited to the people who need it, with audit logging
No system is perfectly secure, but we treat a defect that could expose one business's data to another as our highest-severity class of bug.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. Exercising these rights never costs you service or a worse price.
To make a request, email support@crewos.site. We respond within 30 days. If the data belongs to one of our customers' records, we will forward the request to that business and support them in answering it.
8. Children, and where data is processed
CrewOS is business software and is not directed to children under 16. We do not knowingly collect their personal information.
The platform is operated from the United States, and data is processed there. If you use it from elsewhere, you understand that your information is transferred to and processed in the US.
9. Changes and contact
If we make a material change to this policy, we will update the date at the top and notify account holders in the product or by email.
Questions, requests, or complaints: support@crewos.site, RJ Galactic Consulting LLC.