CrewHow web app and Chrome extension · Effective July 17, 2026
CrewHow (company details to be finalized, "we," "us") makes a web app and Chrome extension that small businesses use to build training guides and SOPs, run checklists, and let staff practice with AI. This policy explains what we collect, why, where it goes, and your choices.
Two roles. For account and billing data, and for how the Service works overall, we act as a controller. For the content our customers put into their workspaces (including any personal data about their own staff or their own customers that appears in that content), the customer is the controller and CrewHow acts as a processor on their behalf. Our Data Processing Addendum covers that relationship.
| Data | Examples | Why |
|---|---|---|
| Account data | Staff names, work emails, roles | Create accounts, sign-in, support |
| Workspace content | Guide and SOP text, screenshots and page text captured by users, checklists | Provide the core product |
| Checklist records | Completion records, who and when, optional photo proof, notes | Operational tracking chosen by the customer |
| Practice data | Practice-session transcripts and AI scores of employees | Deliver the practice and scoring feature |
| Kiosk PINs | Short PINs for shared-device sign-in (stored hashed) | Attribute actions on shared devices |
| Usage analytics | Feature usage, guide views, events | Keep the product working and improve it |
| Billing data | Plan, seat count (payments handled by our processor) | Billing and account management |
Screenshots and page content that users capture may contain personal data about the customer's own customers. In that case the customer is the controller for that personal data, and we process it under their instructions.
We host in the United States and use a small set of vendors ("subprocessors") to run the Service. We do not sell data and do not use it for advertising.
| Subprocessor | Role | Location | Notes |
|---|---|---|---|
| Supabase | Postgres database, authentication, file storage | US | Primary data store |
| Netlify | Web app hosting and content delivery | US | Serves the app |
| OpenAI | AI features (drafting, Q&A, translation, scoring) | US | Content sent for processing only; per OpenAI's API policy, API data is not used to train its models |
| Stripe | Payment processing | US | Upcoming; handles card data directly |
| Resend | Email delivery (notifications, invites, account emails) | US | Processes recipient email addresses and the content of notification and invite emails |
We send content to OpenAI only when a user invokes an AI feature, and only the content needed for that feature. Changes to this list are handled under the Data Processing Addendum.
The extension captures a screenshot or the text of a page only when a user takes an explicit action (starting a recording or capturing a page). It sends that capture to the user's own CrewHow workspace. The extension does not collect browsing history, does not track pages in the background, and we do not sell extension data. It may read the address of the current page only to suggest relevant guides, as the user allows.
We use the minimum needed to run the Service, mainly a cookie or token to keep you signed in and to keep the app secure. We do not use advertising or cross-site tracking cookies.
We keep data while an organization is active. Checklist runs are snapshotted so history stays accurate. On request, we will delete personal data or an organization's data, subject to legal retention needs and reasonable backup cycles. Backups roll off over time. An organization owner can request export of their organization's data before deletion. See the Data Processing Addendum for deletion on termination.
We do not sell or rent personal data, do not share it with data brokers, and do not use it to serve ads. We do not use Customer Content to train our own models, and our AI vendor does not train on the API data we send under its API terms.
The Service is a workplace tool. It is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children.
We take reasonable measures to protect data, stated honestly here rather than as a guarantee:
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping credentials safe.
Depending on where you live, US state privacy laws (such as the California Consumer Privacy Act as amended, and similar laws in other states) may give you rights to access, correct, delete, or receive a copy of your personal data, and to not be discriminated against for exercising those rights. Because much of the data in CrewHow belongs to a customer's workspace, requests about that data are usually directed to that customer (the controller), and we will help them respond. To make a request to us, contact hello@crewhow.com. We will verify requests as required and respond within the time the law allows. We do not sell or "share" personal data as those terms are defined by these laws.
We operate in the United States and store data in the United States. If you use the Service from outside the US, you understand your data will be processed in the US.
We may update this policy. If a change is material, we will give reasonable notice. The effective date below shows the current version.
Questions or requests: hello@crewhow.com
Effective date: July 17, 2026
This policy is a working draft pending review by legal counsel and is not legal advice. Company registration and mailing address details will be finalized before general availability.