Privacy Policy
Last updated: 21 July 2026
1. Who we are
CrewCert ("we") provides certificate-of-insurance tracking software. This policy explains what we collect, why, and your rights. Data controller: Soloware LLC (in formation), California, United States. Contact: [email protected].
2. Information we collect
- Account data — your email, name, organization name, role, and (optionally) your contact phone and address.
- Vendor & document data you provide — the vendors you track and the certificates of insurance and supporting documents (W-9, licence, contract, lien waiver) uploaded, emailed to your inbound address, or submitted by a vendor through a self-service link. These may contain third parties' business and insurance information.
- Usage & technical data — log data, IP address, and actions taken in the app (recorded in an append-only audit log).
3. How we use it
To provide the service (capture, transcribe, review, score, and send reminders on certificates), to secure and operate the platform, to communicate with you, and to comply with legal obligations. Certificate content is sent to our AI provider solely to transcribe the document into structured data — it is not used to make compliance decisions, and we do not use your data to train AI models.
4. Legal bases (GDPR/UK-GDPR)
Performance of a contract, our legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.
5. Sharing & subprocessors
We do not sell personal information. We share data only with the subprocessors below, under contract, to run the service:
- Railway — application and background-worker hosting (United States).
- Neon — managed PostgreSQL database (United States).
- Cloudflare — DNS, CDN/WAF, and R2 private object storage for your documents.
- Postmark (ActiveCampaign) — transactional email, inbound and outbound.
- Anthropic — AI transcription of certificate and contract documents.
- Stripe — payment processing, only if and when paid plans are enabled for your account.
- Google — only if you choose to sign in with Google.
We'll post changes to this list here before a new subprocessor starts processing your data.
6. Retention
We keep certificates and related data while your account is active and as needed to provide the service. Certificate documents are purged 24 months after the certificate's expiry date unless you ask us to keep them longer. Cancelling your account from Settings deletes your organization's data, including vendors, certificates, and stored documents.
7. Security
Each organization's data is isolated at the database layer (row-level security scoped per organization), documents are stored in a private bucket and served only through short-lived signed links, uploads are verified by file type before they are stored, access is authenticated, and compliance changes are recorded in an append-only audit log.
8. Your rights
Depending on your location you may have rights to access, correct, delete, port, or restrict your personal data, and (CCPA/CPRA) to know and to opt out of sale/sharing — we do not sell personal information or share it for cross-context behavioural advertising. Contact [email protected] to exercise them.
9. Cookies
We use a single strictly-necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. If that changes, we will add a consent banner as required by law.
10. Changes & contact
We'll post updates here and, for material changes, notify you. Questions: [email protected].