← CrewAssign

Privacy Policy

Last updated: August 5, 2026

CrewAssign is workforce scheduling software for construction businesses. This policy explains what information the service collects, why, where it is stored, and what choices you have. It covers the CrewAssign web applications and the CrewAssign mobile apps for iOS and Android.

Who controls your information

CrewAssign is multi-tenant: each customer company is a separate tenant and its data is scoped to that tenant. If you use CrewAssign because your employer provides it, your employer controls your record and decides who within the company may view it. CrewAssign operates the service on their behalf.

What we collect

Account information. Name, email address, phone number, role, and the company you belong to. Passwords are never stored — only an Argon2id hash, which cannot be reversed to recover the original password.

Work records. Scheduled visits, job sites, tasks, time entries (clock in and clock out times), materials requests, equipment reservations, permits and inspections, estimates and invoices, time-off requests, and availability.

Location, at clock in and clock out only. When you clock in or out using the mobile app, it attempts to record a single GPS reading (latitude, longitude and an accuracy figure) so your employer has a record of where the time entry was made.

Files and photos. Photographs and documents you attach to job sites, tasks and inspection results. Metadata is stripped from images and PDFs on your device before upload — including EXIF data, which is where camera GPS coordinates would otherwise be recorded.

Security and audit records. Sign-in history, failed sign-in attempts, and an audit log of administrative actions. These exist so account owners can detect unauthorised access and reconstruct who changed what.

Device information for notifications. If you enable push notifications, a device token issued by Apple, by Google, or by your browser. Stored encrypted with a dedicated encryption key.

Two-factor secrets. If two-factor authentication is enabled, the shared secret for your authenticator app, stored encrypted with a separate key.

What we do not collect

How we use it

To operate the service — showing you your schedule, recording your hours, routing materials requests to an administrator, generating estimates and invoices, and sending notifications you have asked for. We also use it to keep accounts secure (rate limiting, detecting suspicious sign-ins) and to troubleshoot faults. We do not use your work records to train machine learning models.

Notifications

Depending on your settings, the service may send email, SMS, browser push, or mobile push notifications about schedule changes, urgent materials requests and time-off decisions. Notification content is limited to what is needed to identify the event. You can disable push notifications in your device or browser settings at any time.

Where your information is stored

On Amazon Web Services infrastructure in the US West (Oregon) region, United States. Records are held in Amazon DynamoDB; files and photographs are held in Amazon S3. Encryption keys and credentials are held in AWS Secrets Manager. AWS is our only infrastructure subprocessor. Email is delivered via Amazon SES, SMS via Amazon SNS, iOS push via Apple Push Notification service, and Android push via Firebase Cloud Messaging.

Data is encrypted in transit using HTTPS/TLS, and at rest by the underlying AWS services. Device tokens and two-factor secrets receive an additional layer of application-level encryption.

Sharing with people outside your company

An administrator can generate a read-only customer share link for a job site, so a client can see progress without an account. These links carry a token, expire, and can be revoked. Only the job-site information intended for the client is exposed through them.

How long we keep it

Work records are kept while your company’s account is active, because they are business records your employer relies on. Short-lived security records expire automatically: password reset tokens, revoked session tokens, rate-limit counters, customer share-link tokens and request-deduplication keys are all deleted automatically once they are no longer valid.

Your choices

Access and correction. You can view and edit your own profile in the app. Because your employer controls the wider record, requests to correct work records should go to your company administrator.

Account deletion. The app has a Delete Account option on your profile, and you can also request deletion from the web without installing the app. Submitting it records a deletion request and starts a review of up to 30 days — a review window exists because tenant business records cannot always be removed immediately without destroying records your employer is required to keep. You will be told what happens to your data.

Notifications. Disable them per device at any time; the service continues to work.

Children

CrewAssign is business software and is not directed at children. We do not knowingly collect information from anyone under 16.

Changes to this policy

If this policy changes materially, we will update the date above and, where the change affects how personal information is used, notify account administrators.

Contact

Questions about this policy or about your information: crewassign@j0e.us

Terms of Service