Privacy Policy
Effective date: March 13, 2026
CrewDash ("we", "us", or "our"), operated by SJP, is a crew management platform for live events. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. By using CrewDash (the mobile app or web app), you agree to the collection and use of information as described in this policy.
1. Information We Collect
Account Information
- Email address (required) - used for authentication and account communication
- Name (required) - displayed to other crew members within your shows
- Phone number (optional) - used for crew contact purposes if you choose to provide it
Location Data (Optional)
- GPS location - used for crew tracking and finding nearby event sites
- Location is only collected when you grant permission and the app is in use
- You can opt out of location tracking at any time through your device settings
Device Identifiers
- Anonymous device identifiers used for push notification delivery, crash reporting, and app analytics
Purchase History
- Subscription status and purchase records managed through RevenueCat for in-app subscription verification
Camera & Photos
- Camera access - used to scan QR codes when joining a show
- Photo library access - used for uploading a profile picture
Bluetooth & LoRa (Local Only)
- Bluetooth Low Energy (BLE) is used for peer-to-peer crew sync when internet is unavailable
- LoRa radio is used for long-range offline mesh communication between devices
- All Bluetooth and LoRa data stays local between devices and is never transmitted to the cloud
- All mesh communication is encrypted with AES-256-GCM
Push Notification Tokens
- Device push tokens (via Firebase Cloud Messaging) used to deliver schedule updates, emergency alerts, and crew notifications
Show & Event Data
- Tasks, schedules, department assignments, emergency alerts, catering info, chat messages, and other show-related data you create or interact with
2. How We Use Your Data
- Crew coordination and show management (schedules, tasks, departments, chat)
- Offline sync between devices via Bluetooth mesh and LoRa radio
- Sending push notifications for alerts, schedule changes, and emergencies
- Sending transactional emails (account verification, password reset, invitations)
- Displaying nearby event locations (when location permission is granted)
- User authentication and account management
- Managing subscriptions and in-app purchases
- Improving app performance and fixing bugs
3. Data Sharing
We do not sell, rent, or trade your personal information to third parties. Ever.
We share data only with the following service providers, solely to operate the app:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Cloud database & authentication | Account info, show data, chat messages |
| Firebase (Google) | Push notifications via FCM | Device push tokens |
| RevenueCat | Subscription & purchase management | Device identifiers, purchase history |
| Resend | Transactional email delivery | Email address, name |
These providers process data on our behalf under their own privacy policies and are not permitted to use your data for their own purposes.
4. Data Storage & Retention
- Cloud data is stored via Supabase (hosted on AWS, US region)
- Show-related data is retained while a show is active and for a reasonable period afterward for reference
- Account data persists until you delete your account or request deletion
- Chat messages are retained for the duration of the associated show
- Offline sync data stored on your device is temporary and cleared when no longer needed
5. Data Security
- AES-256-GCM encryption for all Bluetooth and LoRa mesh communication
- HTTPS/TLS for all cloud communication
- Row Level Security (RLS) on Supabase - users can only access data for shows they belong to
- Push tokens and credentials are stored securely and never exposed to other users
- Passwords are hashed and never stored in plain text
6. Your Rights
You have the right to:
- Access & Export - request a copy of the personal data we hold about you in a portable format
- Correction - update or correct inaccurate information via your profile settings
- Deletion - delete your account and all associated data from within the app or by contacting us
- Opt out of location tracking - disable location permissions at any time through your device settings without affecting other app functionality
- Withdraw consent - revoke any permissions (location, camera, Bluetooth, notifications) at any time through your device settings
To exercise any of these rights, contact us at support@crewdash.app.
7. Children's Privacy
CrewDash is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided us with personal data, please contact us immediately and we will promptly delete it.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page. Material changes will be communicated through the app or via email. We encourage you to review this page periodically.
9. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: