CrewDash logo CrewDash

Privacy Policy

Effective date: July 18, 2026

CrewDash is made by SJP Productions ("we", "us"). This policy explains what information the CrewDash app and crewdash.app collect, how we use it, and the choices you have. We built CrewDash for working crews, and we keep this simple: we collect what the app needs to run your show, and nothing else.

We don't sell your data, we don't show ads, and we don't use advertising or analytics trackers.

What we collect

Account information

When you create an account we collect your email address and a password (handled by our authentication provider, Supabase — we never see your password in plain text). Your profile includes the name you enter, an optional phone number (visible to other crew in your show unless you turn on "hide phone" in your profile), and an optional profile/pass photo you choose to upload.

Show invites

When someone invites you (or you invite someone else) to a show, we send an email to the invited address containing the show name and inviter's name, delivered through our email provider, Resend. If the invited person doesn't already have an account, this is the only information we hold about them until they sign up.

Show and work content

Things you and your crew create in the app: schedules, tasks, chat messages, announcements, documents, photos you upload, credential and pass details (role, department, access zones, meal entitlements), and scan events (for example, a pass scanned at the gate or at catering). This content is visible to other members of your show according to your show's roles and department settings.

Location — only if you turn it on

The crew map has a location-sharing toggle that is off by default. If you turn it on, the app collects your device's precise GPS position and shares it with the other members of your current show so they can find you on site. Positions older than 15 minutes are not shown. When you turn sharing off, your position is deleted from our servers. Your local "breadcrumb trail" (distance walked, step estimate) stays on your device only and is never uploaded. We never collect your location in the background or when sharing is off.

Push notification token

So we can deliver notifications (messages, schedule changes, emergency alerts), the app registers a push token for your device with Google Firebase Cloud Messaging and stores it with your account. The token is removed when you sign out.

Purchases

Subscriptions are billed by Google Play. We use RevenueCat to know which tier your account has. We receive subscription status and an anonymous purchase identifier — never your card number or billing details.

What we don't collect

No advertising identifiers, no contact list, no call logs, no browsing history, no background location, no analytics profiles, and no crash-reporting or usage analytics. Scanning a QR code with the camera happens on your device; camera frames are not stored or uploaded.

How the mesh works (Bluetooth and LoRa)

CrewDash can sync directly between nearby devices over Bluetooth, and over optional LoRa radio hardware, so your crew stays connected without internet. Mesh traffic contains the same show content described above (messages, tasks, schedule changes, and — if you enabled it — your map position) and is exchanged only between devices that are members of the same show. Bluetooth scanning is used solely to find crew devices and LoRa boards; we declare to Android that it is never used to derive your location.

How we use information

We do not use your information for advertising, and we do not sell or rent it to anyone.

Who can see your information

Your crew

CrewDash is a team tool. Your name, photo, role, department, pass details, the content you post, and (only if you enable it) your map position are visible to other members of your show according to the show's role and department structure. Show organizers (producers and leads) can see crew rosters and scan activity for their show.

Service providers (processors)

We use a small number of services to run CrewDash. They process data on our instructions and can't use it for their own purposes:

Provider What for What they hold
Supabase Database, authentication, realtime sync, file storage Account, profile, show content, positions, push tokens
Google Firebase Cloud Messaging Push notification delivery Device push token, notification payloads
RevenueCat Subscription management Anonymous app user ID, subscription status
Resend Show-invite emails Invited recipient's email address, inviter's name, show name
OpenStreetMap Nominatim Venue address lookup The venue address a producer types
US National Weather Service Severe-weather alerts Venue coordinates
Esri / ArcGIS Online Satellite map tiles (crew map, gate map, pins) Map-viewport tile coordinates only — not your device location

Legal. We may disclose information if required by law, or to protect the safety of users (for example, emergency-alert records relevant to a safety incident).

We never share your data with advertisers or data brokers, and we never sell or rent your personal information.

Security

All traffic between the app and our servers is encrypted in transit (TLS). Credentials and sensitive local data are stored in your device's secure keystore. Access to show content on the server is enforced per-show and per-role by database row-level security. Bluetooth and LoRa mesh traffic between devices is encrypted (AES-256-GCM).

Your choices and rights

Show content you created may remain visible to your show (e.g., chat messages, schedule entries) in de-identified or attributed-to-show form where removing it would break the show's records; personal identifiers are removed on account deletion.

If you are in a region with statutory privacy rights (e.g., GDPR, UK GDPR, CCPA), you may exercise access, portability, correction, deletion, and objection rights via the same contact. We do not sell personal information as defined by the CCPA.

Children

CrewDash is a workplace tool for event crews and is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

Data retention

Account and profile data are kept while your account is active. Live map positions expire from view after 15 minutes and are deleted when you stop sharing. Show content is retained for the life of the show/workspace so your team's records stay intact. Push tokens are deleted on sign-out.

Changes to this policy

If we make material changes we will update this page and change the effective date, and for significant changes we'll notify you in the app.

Contact

SJP Productions
Email: jeremy@sjplive.com
Web: https://crewdash.app