CrewWith Privacy Policy
Last updated: August 2, 2026
This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service, and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access our Service or parts of our Service.
- Business, for the purpose of the CCPA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information.
- CCPA means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CPRA).
- Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to Event Attendee Solutions, LLC, 116 North Washington Ave, Floor 3 Suite 3235, Scranton, PA 18503.
- Consumer, for the purpose of the CCPA, means a natural person who is a California resident.
- Cookies are small files that are placed on Your Device by a website, containing information about Your use of that website.
- Crew Member means an individual whose name, nickname, or shift assignment You enter into a Schedule. Crew Members do not create Accounts and typically have no direct relationship with the Company.
- Data Controller, for the purposes of the GDPR, refers to the Company as the legal person which determines the purposes and means of the processing of Personal Data.
- Demo Schedule means a temporary, account-less Schedule created through Our demo feature and reachable only through a private link sent by email.
- Device means any device that can access the Service such as a computer, a cellphone, or a digital tablet.
- Do Not Track (DNT) is a concept promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
- GDPR means the EU General Data Protection Regulation.
- Personal Data is any information that relates to an identified or identifiable individual.
- Sale, for the purpose of the CCPA, means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic means, a Consumer's Personal Data to another business or a third party for monetary or other valuable consideration.
- Schedule means a crew schedule document created and edited through the Service, including the crew names, assignments, and other information entered into it.
- Service refers to the Website.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, or to perform services related to the Service.
- Share Link means the read-only public link that the Service can generate for a Schedule, which allows anyone holding the link to view that Schedule without an Account.
- Third-party Social Media Service refers to any website or social network website through which a User can log in or create an account to use the Service.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.
- Website refers to CrewWith, accessible from https://crewwith.org.
- You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Data
Types of Data Collected
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. What We collect is limited to what the Service actually needs in order to function:
- Email address. Collected when You create an Account, and separately when You request a Demo Schedule.
- Account identifier and display name. A unique user identifier, a display name or nickname, and whether Your email address has been verified. These come from Our identity provider when You sign up or log in.
- Authorization roles. Internal permission labels associated with Your Account.
- Billing identifiers. A payment-processor customer identifier, subscription or pass identifiers, subscription status, and the dates on which Your access begins and ends.
- IP address. Processed when You request a Demo Schedule, in order to limit abuse of that feature, and observed by the infrastructure that serves the Website.
- Schedule content. Everything You enter into a Schedule, including its title, days and times, crew names or nicknames, shift and activity labels, staffing targets, and theme or event bands.
We do not collect Your payment card details. All card entry happens on the hosted checkout page of Our payment processor. Card numbers, security codes, expiration dates, and billing addresses never reach Our systems.
We also do not collect telephone numbers, dates of birth, precise geolocation, biometric information, government identification numbers, financial account numbers, health information, or uploaded files. Where the Service offers a schedule import feature, the file You select is read entirely within Your own browser and only the resulting schedule data is transmitted to Us.
Information You Enter About Other People
The core purpose of the Service is to build a crew schedule, which means much of the information You enter is information about other people: Your volunteers and staff. When You add a Crew Member, We store the name or nickname You typed and any shift, activity, or note labels You attach to them.
With respect to that information, You act as the controller and We act as a processor on Your behalf. You are responsible for having a lawful basis to enter Crew Member information, for telling Crew Members how their information will be used, and for honoring any request a Crew Member makes to You directly. We recommend using first names, nicknames, or handles rather than full legal names, and We ask that You do not enter sensitive personal information - such as health details, disability status, or home addresses - into a Schedule.
If a Crew Member contacts Us directly about information that appears in Your Schedule, We will ordinarily refer them to You as the account holder who controls that Schedule, and We will notify You of the request.
Usage Data
Usage Data is collected automatically when using the Service. Our servers keep operational logs recording events such as requests made, error conditions, and timing information, which We use to keep the Service running correctly and to diagnose faults. Our logging is deliberately limited: We do not log request bodies, Schedule content, or authentication tokens.
Information from Third-party Social Media Services
The Company allows You to create an Account and log in through a Third-party Social Media Service. If You choose to do so, We may collect Personal Data that is already associated with that account, such as Your name, email address, and profile picture. Your use of that Third-party Social Media Service is governed by its own terms and privacy policy.
Demo Schedules
If You request a Demo Schedule, We collect the email address You submit in order to send You the private demo link. That email address is stored alongside the Demo Schedule and is deleted automatically when the Demo Schedule expires, approximately seven (7) days after it is created. We also record short-lived counters keyed to Your email address and to Your IP address so that the demo feature cannot be used to send unwanted mail to others; those counters expire within twenty-four (24) hours and one (1) hour respectively.
A demo request is a transactional request, not a subscription to marketing. We do not add demo requesters to a mailing list, and We do not send follow-up or promotional email to an address that has only been used to request a demo.
Tracking Technologies and Cookies
We use cookies and similar technologies only where they are strictly necessary to operate the Service. Cookies can be "Persistent" or "Session" cookies: persistent cookies remain on Your Device when You go offline, while session cookies are deleted as soon as You close Your web browser.
The technologies We use are:
- Session cookie (persistent, administered by the Company, and set only after You log in). This cookie holds Your encrypted login session, including Your user identifier, name, email address, profile picture, and permission roles, together with the tokens that keep You signed in. It is encrypted, marked HttpOnly so that scripts cannot read it, and expires after a period of inactivity. Where the encrypted session is too large for a single cookie, it is split across several numbered cookies that behave identically. The Service cannot keep You logged in without it.
- Login transaction cookie (short-lived, administered by the Company, expiring within one hour). A cookie written while You are being redirected to Our identity provider, holding the security values that protect the login exchange against tampering. It is deleted when the login completes; if You abandon the login part-way through, it expires on its own within one hour.
- Consent record(browser local storage, not a cookie). When You accept the Terms of Use and this Privacy Policy before creating an Account, We record that acceptance in Your browser's local storage so You are not asked again on that Device. This value never leaves Your browser and is never transmitted to Us.
We do not use analytics, advertising, or tracking cookies. The Service contains no web analytics platform, no product analytics or session-recording tool, no advertising network, no social media tracking pixel, and no third-party tag manager. Because We set no non-essential cookies, there is no cookie preference control to offer and no analytics opt-out to provide.
You can instruct Your browser to refuse cookies or to indicate when a cookie is being sent. However, if You do not accept the cookies described above, You will not be able to log in to the Service.
Do Not Track and Global Privacy Control
Because We do not track You across third-party websites or over time, and because We do not sell or share Personal Data, there is no cross-site tracking behavior for a Do Not Track (DNT) or Global Privacy Control (GPC) signal to change. We honor those signals by default, in the sense that the behavior they are designed to prevent does not occur on the Service.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain the Service, including storing Your Schedules, computing coverage, and serving Share Links to the people You give them to.
- To manage Your Account, including registration, authentication, and the permissions associated with Your Account.
- To perform a contract, namely the purchase of a plan or pass and the provision of the Service under the Terms of Use.
- To process payments and manage renewals, through Our payment processor, including sending receipts and, where applicable, advance notice of an upcoming renewal charge.
- To contact You about the Service, including sending You the private link to a Demo Schedule You requested, verifying Your email address, and communicating necessary administrative or security information.
- To prevent abuse and maintain security, including rate-limiting demo requests by email address and IP address, detecting fraudulent or unauthorized use, and protecting the integrity of the Service.
- To diagnose and fix problems, using operational logs and error records.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
- To evaluate or conduct a business transaction, such as a merger, reorganization, or sale of assets, in which Personal Data held by Us may be among the assets transferred.
We do not use Your Personal Data for behavioral advertising, and We do not build advertising or marketing profiles about You.
Sharing of Your Personal Data
We may share Your personal information in the following situations:
- With Service Providers. We share the minimum information necessary with the providers listed below so that they can perform their function.
- With anyone You give a Share Link or demo link to. This is a deliberate feature of the Service and is described in its own section below.
- For business transfers. We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates. We may share Your information with Our affiliates, in which case We will require those affiliates to honor this Privacy Policy.
- With Your consent. We may disclose Your Personal Data for any other purpose with Your consent.
We do not sell Your Personal Data, and We do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve (12) months.
Our Service Providers
We keep the number of third parties involved in the Service deliberately small. Each of the following is contractually obligated to use Personal Data only to provide its service to Us:
- Our identity provider (Auth0, a product of Okta, Inc.) handles signup, login, password and social authentication, and email verification. It receives Your email address, Your name or nickname, Your credentials or social login identity, and - because Your browser connects to it directly during login - Your IP address and browser user agent.
- Our payment processor (Stripe, Inc.) handles all payments and hosts the checkout page. When You first make a purchase We send Stripe Your email address and an internal account identifier; thereafter Stripe tells Us the status of Your plan. You provide Your card details directly to Stripe, which also receives Your IP address and billing information as part of that transaction. Stripe processes that information under its own privacy policy.
- Our email delivery provider (Mailgun, a Sinch company) delivers the one message the Service itself sends: the private link to a Demo Schedule. It receives the recipient email address and the contents of that message.
The databases, caches, logging, and monitoring systems that run the Service are operated by the Company on infrastructure it controls, and are not third-party data processors. A current list of Our Service Providers is available on request.
Share Links and Demo Links
Two features of the Service intentionally make information available to people who do not have an Account, and it is important that You understand exactly how they behave.
Share Links give read-only access to a Schedule. Anyone who has the link can view that Schedule in full - including every crew name and shift label on it - without logging in, and can pass the link on to others. The link contains a long, randomly generated token, so it is not guessable, but the link itself is the only thing protecting the Schedule. A Share Link does not expire on its own.
Demo links give full edit access to a Demo Schedule. Anyone who has the link can change its contents, again without logging in. Demo links are sent by email in plain text and expire approximately seven (7) days after the Demo Schedule is created.
We instruct search engines not to index pages reached through either kind of link, but that is a request to search engines, not an access control. Treat both link types as credentials: share them only with people You intend to give access to, and avoid posting them publicly. Because possession of the link is what grants access, We cannot tell You who has viewed a Schedule through a Share Link.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, and to the extent necessary to comply with Our legal obligations, resolve disputes, and enforce Our legal agreements and policies. In practice:
- Your Account record is retained for as long as Your Account exists, and until You ask Us to delete it.
- Your Schedules are retained until You delete them. Importantly, allowing a plan or pass to lapse does not delete Your Schedules - they remain stored and viewable in read-only form so that Your data is still there if You return.
- Demo Schedules, including the email address used to request them, are deleted automatically approximately seven (7) days after creation.
- Abuse-prevention counters keyed to an email address or IP address expire within twenty-four (24) hours and one (1) hour respectively.
- Operational logs are retained for troubleshooting and security purposes.
- Records held by Our payment processor are retained under its own schedule, which is generally measured in years because tax, accounting, and anti-money-laundering rules require it. We cannot shorten that period.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and stored on servers located in the United States. Our identity, payment, and email providers may process Personal Data in other countries in which they or their sub-processors operate.
If You are located outside the United States, please be aware that information We collect will be transferred to and processed in the United States, where data protection laws may differ from those in Your jurisdiction. Your submission of information to the Service represents Your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy, and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place, including the security of Your data and other personal information.
Delete Your Personal Data
You have the right to delete, or to request that We assist in deleting, the Personal Data We have collected about You.
While Your plan or pass is active, You can delete any individual Schedule You own from within the Service. Deleting a Schedule removes it and everything on it, and revokes its Share Link. Deletion is currently the only way to revoke a Share Link.
If Your plan or pass has lapsed, the in-app delete control is unavailable, because editing operations require an active plan. Your right to have Your data deleted does not lapse with Your plan: contact Us at the address in the "Contact Us" section below and We will delete the Schedule, or revoke its Share Link, on Your behalf.
There is currently no self-service control for deleting Your entire Account. To delete Your Account and the Personal Data associated with it, please contact Us at the address in the "Contact Us" section below and We will carry out the deletion manually. We may ask You to verify Your identity before We act, and We may need to retain certain information where We have a legal obligation or other lawful basis to do so.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law Enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities, such as a court or a government agency.
Other Legal Requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us. Traffic between Your browser and the Service is encrypted in transit. Login sessions are held in encrypted, HttpOnly cookies. Share Link and demo tokens are generated using a cryptographically secure random source. Payment card data is handled entirely by Our payment processor and never reaches Our systems.
However, remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security. You can help by choosing a strong, unique password, by not reusing passwords from other services, and by being careful about who You send Share Links and demo links to.
Children's Privacy
The Service is intended for adults. You must be at least 18 years of age to create an Account or use the Service, and individuals 17 years of age or younger may not use the Service.
In compliance with the Children's Online Privacy Protection Act (COPPA), We do not knowingly collect or solicit personally identifiable information from children under 13. If We become aware that We have collected Personal Data from a child under 13 without verification of parental consent, We will take steps to delete that information promptly. If You believe a child under 13 has provided Us with Personal Data, please contact Us.
Please note that a Schedule may contain the name of a volunteer who is a minor, because the account holder - not the minor - entered it. If You are an account holder scheduling minors, You are responsible for obtaining whatever consent applicable law requires, and We ask that You use first names or handles rather than identifying details.
GDPR Privacy
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following legal bases:
- Performance of a contract - providing the Service and Your plan, and the pre-contractual steps You take before purchasing.
- Legitimate interests - keeping the Service secure and available, preventing abuse of the demo feature, and diagnosing faults, where those interests are not overridden by Your rights.
- Consent - where You have given Us consent for a specific purpose, which You may withdraw at any time.
- Legal obligations - where processing is necessary for compliance with a legal obligation to which We are subject.
- Vital interests - where processing is necessary to protect Your vital interests or those of another natural person.
Where You enter Crew Member information into a Schedule, You are the controller of that information and We process it as Your processor, on Your instructions, for the purpose of operating the Service.
Your Rights under the GDPR
The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights. If You are within the European Economic Area or the United Kingdom, You have the right to:
- Request access to the Personal Data We hold about You, and to obtain a copy of it.
- Request correction of Personal Data that is inaccurate or incomplete.
- Object to processing where We rely on legitimate interests as the legal basis and Your particular situation warrants objection.
- Request erasure of Your Personal Data where there is no continuing reason for Us to process it.
- Request the transfer of Your Personal Data to You or to a third party in a structured, commonly used, machine-readable format.
- Withdraw consent where We rely on Your consent. Withdrawing consent may mean We cannot continue to provide certain functionality to You.
- Restrict processing in the circumstances set out in the GDPR.
Exercising Your GDPR Data Protection Rights
You may exercise these rights by contacting Us at the address in the "Contact Us" section. We may ask You to verify Your identity before responding, and We will respond within the period required by law. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU or EEA member state of Your habitual residence, place of work, or place of an alleged infringement.
CCPA Privacy
This section of Our Privacy Policy supplements the rest of this Privacy Policy and applies solely to visitors, users, and others who reside in the State of California.
Categories of Personal Information Collected
In the preceding twelve (12) months, We have collected the following categories of personal information, as those categories are defined by the CCPA:
- Category A: Identifiers. Examples: real name, alias, online identifier, Internet Protocol address, email address, account name, or other similar identifiers. Collected: Yes.
- Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Examples: name, address, telephone number, financial account or card number, and similar records. Collected: Yes - limited to name and email address.We do not collect Social Security numbers, driver's license numbers, passport numbers, telephone numbers, physical addresses, medical or health insurance information, financial account numbers, or payment card numbers.
- Category C: Protected classification characteristics under California or federal law. Examples: age, race, national origin, religion, disability, sex, gender identity, sexual orientation, veteran status, genetic information. Collected: No.
- Category D: Commercial information. Examples: records of products or services purchased or considered. Collected: Yes - which plan or pass You purchased, and the status and term of that purchase.
- Category E: Biometric information. Collected: No.
- Category F: Internet or other similar network activity. Examples: interaction with the Service, server request logs. Collected: Yes.
- Category G: Geolocation data. Examples: precise physical location. Collected: No. We do not request or use device location. An IP address can be used to infer an approximate region, but We do not perform such lookups.
- Category H: Sensory data. Examples: audio, electronic, visual, thermal, olfactory, or similar information. Collected: No.
- Category I: Professional or employment-related information. Collected: Yes - limited, and entered by account holders. A Schedule records volunteer or staff role assignments and shift times for the Crew Members an account holder enters. We do not collect employment history, performance evaluations, or compensation information.
- Category J: Non-public education information. Collected: No.
- Category K: Inferences drawn from other personal information. Examples: profiles reflecting preferences, characteristics, behavior, or aptitudes. Collected: No. We do not profile Users.
- Sensitive Personal Information as defined by the CPRA. Collected: No.Because We do not collect sensitive personal information, We are not required to offer a "Limit the Use of My Sensitive Personal Information" control.
Personal information under the CCPA does not include:
- Publicly available information from government records
- Deidentified or aggregated consumer information
- Information excluded from the CCPA's scope, such as health or medical information covered by HIPAA, and personal information covered by certain sector-specific privacy laws including the FCRA, GLBA, and the Driver's Privacy Protection Act of 1994
Sources of Personal Information
- Directly from You - information You enter into forms and into Your Schedules.
- Automatically from You - Your IP address and server request records generated as You use the Service.
- From Our Service Providers - profile information from Our identity provider when You log in, and plan status from Our payment processor.
- From other account holders - where an account holder enters a Crew Member's name into a Schedule.
Use and Disclosure for Business Purposes
We use the personal information We collect for the business purposes described under "Use of Your Personal Data" above. In the preceding twelve (12) months, We have disclosed personal information in Categories A, B, D, F, and I to Service Providers for business purposes, under contracts that require confidentiality and prohibit use for any purpose other than performing that contract.
No Sale or Sharing of Personal Information
We do not sell personal information, and We do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding twelve (12) months, including the personal information of Consumers under 16 years of age.
Your Rights under the CCPA
- The right to notice. You have the right to be notified, before or at the point of collection, of the categories of personal information being collected and the purposes for which it is used.
- The right to know and access. You have the right to request that We disclose the categories of personal information We collected, the categories of sources, the business or commercial purpose for collecting it, the categories of third parties with whom We share it, and the specific pieces of personal information We hold about You.
- The right to correct inaccurate personal information We maintain about You.
- The right to delete personal information We have collected from You, subject to the exceptions permitted by the CCPA - for example where the information is necessary to complete a transaction, to detect security incidents, to debug and repair errors, to comply with a legal obligation, or for other internal uses reasonably aligned with Your expectations.
- The right to opt out of the sale or sharingof personal information. As stated above, We do not sell or share personal information, so there is nothing to opt out of and We do not offer a "Do Not Sell or Share My Personal Information" link.
- The right not to be discriminated against for exercising any of Your rights. We will not deny You goods or services, charge You a different price, or provide You a different level or quality of service because You exercised a privacy right.
Exercising Your CCPA Data Protection Rights
To exercise any of the rights described above, please contact Us by email at the address in the "Contact Us" section below. Only You, or a person registered with the California Secretary of State that You authorize to act on Your behalf, may make a verifiable request related to Your personal information.
Your request must provide sufficient information to allow Us to reasonably verify that You are the person about whom We collected personal information, and must describe Your request with enough detail that We can properly understand, evaluate, and respond to it. We cannot respond to Your request or provide You with personal information if We cannot verify Your identity. We will respond within the timeframes required by the CCPA.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.
Changes to This Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, or wish to exercise any of the rights described above, You can contact us:
- By email: support@crashwith.com
- By mail: Event Attendee Solutions, LLC, 116 North Washington Ave, Floor 3 Suite 3235, Scranton, PA 18503, United States