Privacy Policy
Last updated: 19 September 2026
1. Who we are, and which data is whose
CrewCert ("we") provides certificate-of-insurance tracking software. This policy explains what we collect, why, and your rights. CrewCert is operated by SoloFive LLC, a California limited liability company.
Two different kinds of data pass through CrewCert, and we play a different role in each, so we would rather name both than use one word for both. Your own account data — your login, your company, your role, and your billing — is ours to answer for: we are the data controller, we decide what to collect and why, and the rest of this policy describes those choices. The insurance documents and vendor details you put into CrewCert are your records about your own vendors, and there we are the processor: you decide which vendors to track, what to upload, and what to require of them, and we handle that data on your instructions in order to run the service for you. We do not use it for our own purposes, we do not sell it, and we do not use it to train AI models.
SoloFive LLCc/o Northwest Registered Agent, Inc.2108 N St, Ste NSacramento, CA 95816[email protected]2. Information we collect
- Account data — your email, name, organization name, role, and (optionally) your contact phone and address.
- Authentication credentials — if you choose to set a password, we store a one-way hash of it (never the password itself). Sign-in links and email verification codes are likewise stored only as hashes, and expire.
- Vendor & document data you provide — the vendors you track and the certificates of insurance and supporting documents (W-9, licence, contract, lien waiver) uploaded, emailed to your inbound address, or submitted by a vendor through a self-service link. These may contain third parties' business and insurance information.
- Help & feedback messages — what you write to us from the app or the website, the address to reply to, and what the app reports alongside it: which screen you were on, the app and operating-system version, and your role and plan at the time.
- Usage & technical data — log data, IP address, and actions taken in the app (recorded in an append-only audit log).
- Mobile app data — if you use the CrewCert mobile app, we access your device camera and photo library only when you choose to capture or attach a document, and — with your permission — register a push-notification token so we can remind you about expiring coverage. You can revoke either permission in your device settings. Before a photo leaves your phone the app removes the metadata embedded in the image file — including any GPS coordinates, capture time, and camera make and model — so that information is never uploaded or stored.
3. How we use it
To provide the service (capture, transcribe, review, score, and send reminders on certificates), to secure and operate the platform, to communicate with you, and to comply with legal obligations. Certificate content is sent to our AI provider solely to transcribe the document into structured data — it is not used to make compliance decisions, and we do not use your data to train AI models.
4. Legal bases (GDPR/UK-GDPR)
Performance of a contract, our legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.
5. Sharing & subprocessors
We do not sell personal information. We share data only with the subprocessors below, under contract, to run the service:
- Railway — application and background-worker hosting (United States).
- Neon — managed PostgreSQL database (United States).
- Cloudflare — DNS, CDN/WAF, and R2 private object storage for your documents.
- Postmark (ActiveCampaign) — transactional email, inbound and outbound.
- Anthropic — AI transcription of certificate and contract documents.
- Stripe — payment processing for paid plans, on our own merchant account. Stripe holds your card details; we never receive them.
- Google — only if you choose to sign in with Google.
- Expo — push-notification delivery, only if you install the mobile app and enable notifications. Expo relays to Apple (APNs) and Google (FCM). What is sent is your device's push token and a count of vendors needing attention — never a vendor name or any certificate content.
We'll post changes to this list here before a new subprocessor starts processing your data.
6. Retention
We keep certificates and related data while your account is active and as needed to provide the service. Stored documents are destroyed 24 months after the coverage they evidence expires — for a certificate, 24 months after its last coverage end date; for other vendor documents, 24 months after their expiry, or after upload where they do not expire. The compliance record that a vendor was covered is kept; the file itself is deleted and cannot be retrieved.
Deleting a certificate or a vendor document removes both the record and the stored file immediately. Deleting your account from Settings removes your organization's data — vendors, certificates, projects, and every stored document — and cancels any subscription. We keep a minimal record that the deletion happened: the organization name, the date, its plan, subscription status and Stripe subscription id, whether the subscription was cancelled, how much was removed, whether every stored file was removed, and the internal id of the person who deleted it. That record contains none of your vendors' documents and stores the account owner's email address only as a one-way hash (SHA-256), not the address itself — so we can confirm a request came from the right person. A hash is not anonymous: anyone who already knows an address can check whether it matches.
Help and feedback messages are kept while your account exists, so we can answer and follow up, and are deleted when you delete your account. Messages sent through the public contact form without an account are kept so we can follow up; email [email protected] to have one deleted.
7. Security
Each organization's data is isolated at the database layer (row-level security scoped per organization), documents are stored in a private bucket and served only through short-lived signed links, uploads are verified by file type before they are stored, access is authenticated, and compliance changes are recorded in an append-only audit log.
8. Your rights
Depending on your location you may have rights to access, correct, delete, port, or restrict your personal data, and (CCPA/CPRA) to know and to opt out of sale/sharing — we do not sell personal information or share it for cross-context behavioural advertising. Contact [email protected] to exercise them.
That is for your own account data, which is ours to answer for (section 1). For the vendor details and documents a CrewCert customer uploaded, the customer decides — so if you are a vendor asking about information one of them holds about you, write to [email protected] and we will pass your request to that customer and help them answer it, rather than deciding it ourselves.
9. Cookies
We use three strictly-necessary cookies: one to keep you signed in, one short-lived cookie that ties a sign-in link to the browser that asked for it, and one short-lived cookie that protects the “Sign in with Google” exchange. We do not use advertising or cross-site tracking cookies. If that changes, we will add a consent banner as required by law.
10. Changes & contact
We'll post updates here and, for material changes, notify you. Questions: [email protected].