Last Updated: February 2026
Privacy Policy
CrewAlign ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web-based project management platform and related services (collectively, the "Service"). By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree with the terms of this policy, please do not use the Service.
1. Information We Collect
1.1 Account Information
When you create an account or sign in through a third-party authentication provider (such as Google OAuth), we collect the following information:
- Full name
- Email address
- Profile picture (if provided by the authentication provider)
- Authentication tokens necessary to maintain your session and secure your account
1.2 Project and Workspace Data
In the course of using the Service, you and your team members may create, upload, or input data including but not limited to:
- Workspace names and configuration settings
- Project details such as names, descriptions, schedules, phases, and milestones
- Contact information for subcontractors and collaborators
- Task assignments, notes, and status updates
- Files, documents, and images uploaded to projects or workspaces
- Notification preferences and communication settings
1.3 Usage Data
We automatically collect certain technical information when you interact with the Service, including:
- IP address and approximate geographic location
- Browser type, version, and language preferences
- Device type, operating system, and screen resolution
- Pages visited, features used, and actions taken within the Service
- Date and time of access, session duration, and referring URLs
- Error logs and performance data
1.4 Cookies and Similar Technologies
We use cookies and similar tracking technologies to operate and improve the Service. Specifically, we use:
- Essential cookies: HTTP-only cookies for authentication (access tokens and refresh tokens) that are strictly necessary for the Service to function.
- Preference cookies: To remember your settings, such as theme preferences and workspace selections.
- Analytics cookies: To understand how users interact with the Service so we can improve performance and user experience.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and maintain the Service: To create and manage your account, authenticate your identity, and deliver the core features of the platform.
- Improve the Service: To analyze usage patterns, diagnose technical issues, and develop new features and enhancements.
- Communicate with you: To send transactional emails (such as account verification, password resets, and project notifications), respond to support requests, and provide updates about the Service.
- Ensure security: To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity.
- Comply with legal obligations: To meet applicable legal requirements, enforce our Terms of Service, and protect our rights and the rights of our users.
3. Data Storage and Security
We take the security of your data seriously and implement industry-standard technical and organizational measures to protect it. These measures include:
- Encryption of data in transit using TLS/SSL and encryption of sensitive data at rest
- Secure authentication using HTTP-only cookies with short-lived access tokens and rotating refresh tokens
- Role-based access controls and multi-tenant isolation to ensure that workspace data is accessible only to authorized members
- Regular security assessments, vulnerability scanning, and software updates
- Database backups and disaster recovery procedures to ensure data availability
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
4. Data Sharing and Third Parties
We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:
- Service providers: We engage trusted third-party service providers who perform services on our behalf, such as cloud hosting, email delivery, analytics, and payment processing. These providers are contractually obligated to use your data only as necessary to provide their services to us and to maintain appropriate security measures.
- Within your workspace: Information you enter into a workspace (projects, tasks, contacts, etc.) is accessible to other members of that workspace in accordance with the permissions and roles configured by the workspace administrator.
- Legal requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
- Business transfers: If CrewAlign is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
5. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may request that we correct any inaccurate or incomplete personal information.
- Deletion: You may request that we delete your personal information, subject to certain exceptions (for example, where we are required to retain data for legal or compliance purposes).
- Data portability: You may request a copy of your data in a structured, commonly used, and machine-readable format.
- Objection and restriction: You may object to or request restriction of certain processing activities.
- Withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
6. Cookie Policy
Cookies are small text files stored on your device by your web browser. We use cookies as described in Section 1.4 above. You can control cookie behavior through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent. Please note that if you disable essential cookies, the Service may not function properly, as authentication relies on HTTP-only cookies.
For more information about cookies and how to manage them, visit www.allaboutcookies.org.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. If you request deletion of your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain data for legal, regulatory, or legitimate business purposes (such as maintaining records of transactions or resolving disputes).
Project and workspace data is retained for the duration of the workspace's active subscription. Upon termination of a subscription, workspace administrators will have a grace period of 30 days to export their data before it is permanently deleted.
8. Children's Privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16 without verification of parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child under 16, please contact us at [email protected].
9. International Data Transfers
Your information may be transferred to, stored, and processed in countries other than your country of residence. These countries may have data protection laws that differ from the laws of your country. By using the Service, you consent to the transfer of your information to such countries. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy.
10. Canadian Privacy Rights (PIPEDA)
If you are a resident of Canada, the Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy legislation may apply to our collection, use, and disclosure of your personal information. In addition to the rights described in Section 5 above, Canadian residents have the following rights under PIPEDA:
- Knowledge and consent: We will obtain your meaningful consent before collecting, using, or disclosing your personal information, except where permitted or required by law. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice.
- Access and accuracy: You have the right to request access to the personal information we hold about you and to challenge its accuracy and completeness. We will amend information that is shown to be inaccurate or incomplete.
- Accountability: We are responsible for personal information in our possession or custody, including information that has been transferred to a third party for processing.
- Challenging compliance: You have the right to challenge our compliance with PIPEDA by contacting our Privacy Officer. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada.
Privacy Officer: To exercise your rights under PIPEDA, make an access request, or file a complaint, please contact our Privacy Officer at [email protected]. We will respond to your request within 30 days.
Office of the Privacy Commissioner of Canada: If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or by phone at 1-800-282-1376.
10.1 Quebec Residents
If you are a resident of Quebec, Act respecting the protection of personal information in the private sector (Quebec Law 25) provides additional protections. You have the right to be informed of the specific purposes for which your personal information is collected, to access and rectify your information, and to withdraw consent. We will obtain your express consent before collecting sensitive personal information. For any questions regarding your rights under Quebec law, please contact our Privacy Officer at the email address above or the Commission d'accès à l'information du Québec at www.cai.gouv.qc.ca.
11. Commercial Electronic Messages (CASL)
Canada's Anti-Spam Legislation ("CASL") regulates the sending of commercial electronic messages ("CEMs") to Canadian recipients. We comply with CASL as follows:
- Consent: We will only send you commercial electronic messages (such as marketing emails or product announcements) if you have provided express consent (for example, by joining our waitlist) or where we have implied consent under CASL.
- Identification: All commercial electronic messages will clearly identify CrewAlign as the sender and include our contact information.
- Unsubscribe: Every commercial electronic message will include a functional unsubscribe mechanism. We will process unsubscribe requests within 10 business days.
Transactional messages (such as account confirmations, security alerts, and project notifications) are not considered commercial electronic messages under CASL and will continue to be sent as necessary for the operation of the Service.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by posting the updated policy on this page and updating the "Last Updated" date at the top. For significant changes, we may also send you an email notification or display a prominent notice within the Service. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
CrewAlign
Email: [email protected]
This privacy policy is effective as of February 2026.