C CrewCert

Privacy Policy

Last updated: 13 August 2026

1. Who we are

CrewCert ("we") provides certificate-of-insurance tracking software. This policy explains what we collect, why, and your rights. Data controller: SoloFive LLC, a California limited liability company.

SoloFive LLCc/o Northwest Registered Agent, Inc.2108 N St, Ste NSacramento, CA 95816[email protected]

2. Information we collect

  • Account data — your email, name, organization name, role, and (optionally) your contact phone and address.
  • Vendor & document data you provide — the vendors you track and the certificates of insurance and supporting documents (W-9, licence, contract, lien waiver) uploaded, emailed to your inbound address, or submitted by a vendor through a self-service link. These may contain third parties' business and insurance information.
  • Usage & technical data — log data, IP address, and actions taken in the app (recorded in an append-only audit log).
  • Mobile app data — if you use the CrewCert mobile app, we access your device camera and photo library only when you choose to capture or attach a document, and — with your permission — register a push-notification token so we can remind you about expiring coverage. You can revoke either permission in your device settings.

3. How we use it

To provide the service (capture, transcribe, review, score, and send reminders on certificates), to secure and operate the platform, to communicate with you, and to comply with legal obligations. Certificate content is sent to our AI provider solely to transcribe the document into structured data — it is not used to make compliance decisions, and we do not use your data to train AI models.

4. Legal bases (GDPR/UK-GDPR)

Performance of a contract, our legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.

5. Sharing & subprocessors

We do not sell personal information. We share data only with the subprocessors below, under contract, to run the service:

  • Railway — application and background-worker hosting (United States).
  • Neon — managed PostgreSQL database (United States).
  • Cloudflare — DNS, CDN/WAF, and R2 private object storage for your documents.
  • Postmark (ActiveCampaign) — transactional email, inbound and outbound.
  • Anthropic — AI transcription of certificate and contract documents.
  • Stripe — payment processing, only if and when paid plans are enabled for your account.
  • Google — only if you choose to sign in with Google.
  • Expo — push-notification delivery, only if you install the mobile app and enable notifications. Expo relays to Apple (APNs) and Google (FCM). What is sent is your device's push token and a count of vendors needing attention — never a vendor name or any certificate content.

We'll post changes to this list here before a new subprocessor starts processing your data.

6. Retention

We keep certificates and related data while your account is active and as needed to provide the service. Stored documents are destroyed 24 months after the coverage they evidence expires — for a certificate, 24 months after its last coverage end date; for other vendor documents, 24 months after their expiry, or after upload where they do not expire. The compliance record that a vendor was covered is kept; the file itself is deleted and cannot be retrieved.

Deleting a certificate or a vendor document removes both the record and the stored file immediately. Deleting your account from Settings removes your organization's data — vendors, certificates, projects, and every stored document — and cancels any subscription. We keep a minimal record that the deletion happened: the organization name, the date, whether the subscription was cancelled, and how much was removed. That record contains none of your vendors' documents and stores the account owner's email address only as an irreversible digest, so we can confirm a request came from the right person without keeping the address itself.

7. Security

Each organization's data is isolated at the database layer (row-level security scoped per organization), documents are stored in a private bucket and served only through short-lived signed links, uploads are verified by file type before they are stored, access is authenticated, and compliance changes are recorded in an append-only audit log.

8. Your rights

Depending on your location you may have rights to access, correct, delete, port, or restrict your personal data, and (CCPA/CPRA) to know and to opt out of sale/sharing — we do not sell personal information or share it for cross-context behavioural advertising. Contact [email protected] to exercise them.

9. Cookies

We use a single strictly-necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. If that changes, we will add a consent banner as required by law.

10. Changes & contact

We'll post updates here and, for material changes, notify you. Questions: [email protected].