In short
We collect what we need to run the service and nothing else. We never sell your data or your customers’ data. Analytics on this marketing site only run if you accept cookies, and there is no analytics inside the app itself. Deleting your account erases it immediately and permanently.
1. Who is responsible for what
CrewSpur is operated by IE Hayk Hayrapetyan, 0091 Zakaria Sarkavagi 151/2 26, Yerevan, Armenia. Contact us about privacy at hello@crewspur.com.
There are two different relationships here, and they matter:
- Your own account data — your name, email, business details, billing. We are the data controller for this.
- Your customers’ data — the clients, addresses, job notes and photos you put into the app. You are the controller for this; we are your processor. We hold it to run the service for you, act on your instructions, and do not use it for our own purposes.
2. What we collect
When you create an account
- Your name and email address, and a hashed password — we never store it in readable form.
- Your business name, contact details and address, if you enter them for invoice branding.
- A verification code, stored hashed and deleted once used or expired.
When you use the app
- Clients you add: names, contact details, addresses, notes.
- Jobs, schedules, assignments and status history.
- Photographs you or your team upload against a job.
- Invoices, payments recorded, and the emails sent about them.
- Team members you invite: name, email, and their activity in the app.
- An audit log of significant changes, for support and accountability.
When you pay
Payment is handled by Paddle as merchant of record. We never see or store your card details. We keep a subscription reference, your plan, and its status.
On this marketing site
If, and only if, you accept analytics cookies, we collect anonymised usage statistics — pages viewed, which pricing options are clicked. Decline and none of that is collected; the site works identically. There is no advertising or analytics tracking inside the app.
3. Why we are allowed to hold it
| Purpose | Legal basis |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Taking payment and preventing fraud | Contract and legal obligation |
| Service emails: verification, receipts, trial and renewal notices | Contract |
| Keeping the service secure and diagnosing faults | Legitimate interests |
| Accounting and tax records | Legal obligation |
| Marketing-site analytics | Consent, which you can withdraw at any time |
4. Who else can see it
We use a small number of service providers. Each is bound by contract to protect the data and to use it only to provide their service to us.
| Provider | What for | What they see |
|---|---|---|
| Paddle | Payments and tax (merchant of record) | Name, email, billing address, payment details |
| Laravel Cloud | Application hosting and database | All account and business data |
| Amazon Web Services / Cloudflare R2 | Storage for job photos | Photographs you upload |
| Mailgun | Sending email | Recipient address and message content |
| Cloudflare | DNS, security and email routing | Network traffic metadata |
| Netlify | Hosting this marketing site | Request logs for crewspur.com only |
| Google Analytics | Marketing site statistics, only with consent | Anonymised usage data from crewspur.com |
Some of these are based outside your country, including in the United States. Where data leaves the UK or EEA it is protected by an approved transfer mechanism, such as Standard Contractual Clauses.
We will also disclose data if the law requires it. If that ever happens we will tell you, unless we are legally prevented from doing so.
5. Our own access
Our support and administration tools are deliberately built not to show your clients, invoices or revenue. Staff can see account-level information — your plan, seat usage, subscription status — which is what is needed to answer a billing question, and no more. Access to customer records is off by default and would require a deliberate configuration change.
6. How long we keep it
- While your account is open — for as long as you keep it, so your history stays intact.
- Items you delete inside the app — clients, jobs, invoices and team members are hidden immediately and retained in a recoverable state, so an accidental deletion can be undone and so invoicing history stays consistent. Nobody but you sees them.
- Billing records — kept as long as tax law requires, typically six to seven years. Paddle keeps its own records as merchant of record.
7. Deleting your account
Deleting your account from profile settings is immediate and permanent. It is not a soft delete and there is no recovery window — once it is done we cannot get the data back for you, even if you ask the same day.
We do not currently offer a self-service export, so please save anything you need first: download the invoice PDFs and any job photos that matter to you. If you would like a copy of your data before deleting, email us and we will provide one.
Records we are legally required to keep — principally billing and tax records — are retained for the statutory period, and are held by Paddle as well.
8. Your rights
Depending on where you live, you have the right to:
- ask what we hold about you, and get a copy;
- have inaccurate information corrected;
- have your data erased;
- receive your data in a portable format;
- object to, or ask us to restrict, certain processing;
- withdraw consent — for analytics cookies, any time, from the link in the footer.
Email hello@crewspur.com and we will respond within one month. If you are unhappy with our response you can complain to your local data protection authority.
If your request concerns data held by one of our customers about you — for example if a trade business used CrewSpur to invoice you — we are the processor, not the controller. Contact that business directly; we will help them respond.
9. Cookies
On this marketing site we set:
- Strictly necessary — one cookie remembering your cookie choice, so we do not ask again. This one cannot be switched off, because it is your choice.
- Analytics — Google Analytics, only after you accept. These tell us which pages help people decide.
- Marketing — off unless you turn them on. Used to tell whether an advert led to a signup.
Until you accept, analytics run in a cookieless mode that stores nothing on your device and cannot identify you. Change your mind whenever you like using Cookie preferences in the footer.
Inside the app we set only the cookies needed to keep you logged in and to protect forms against cross-site request forgery. No analytics, no advertising.
10. Security
Traffic is encrypted in transit. Passwords are hashed, never stored in readable form. Third-party credentials you give us are encrypted at rest. Access to production systems is limited to those who need it.
No system is perfect. If a breach affects your data we will tell you and the relevant authority as the law requires, and we will tell you what we know rather than wait until we know everything.
11. Children
The service is for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.
12. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always shows the current version.