Back to Trust Centre

Data Security

Draft

Last updated: 3 August 2026

Draft security overview

This page describes CrewGrid's current security approach at a general level. It does not disclose confidential infrastructure details and does not create a guarantee that every security incident or service interruption can be prevented.

Cloud Infrastructure

CrewGrid operates using established cloud infrastructure providers. The application, authentication services, database and uploaded files are hosted through managed services designed for modern web applications.

Encrypted Connections

CrewGrid uses HTTPS connections to protect information transmitted between supported browsers, devices and CrewGrid platform services.

Authenticated Access

CrewGrid requires authenticated user accounts for access to protected platform features. Account invitations, sign-in, password recovery and session management are handled through the platform’s authentication system.

Role-Based Permissions

Platform access is controlled through assigned roles and permissions. Administrators, managers, supervisors, team leaders and employees receive different access according to their responsibilities.

Company and Branch Separation

CrewGrid is designed as a multi-company platform. Database access controls and application permissions are used to restrict users to authorised companies, branches and records.

Documents and File Storage

Employee documents, compliance records, photos, signatures and operational files are stored through managed cloud storage. Access depends on authentication, company membership, assigned permissions and the storage controls applied to each file category.

Messages and Photos

Private and group message photos are stored in private file storage. Temporary signed links are used to display protected message images to authorised users.

Attendance and Location Records

Location information is collected only during specific clock-related actions. CrewGrid stores the recorded coordinates, calculated distance from the selected site and attendance verification result for authorised workplace use.

Attendance Selfies

CrewGrid can require an attendance selfie during clock actions. These images are stored as workforce records and are available only through authorised platform access.

Payment Security

CrewGrid uses Stripe to process subscription payments. Full payment-card details are entered into and processed by Stripe rather than being stored in full by CrewGrid.

Browser Notifications

CrewGrid uses standard Web Push technology for supported browser notifications. Notification delivery may pass through the push service operated by the user’s browser or device provider.

Service Monitoring

CrewGrid checks key services including the web application, authentication, database, file storage and support email systems to help identify availability problems.

Logging and Troubleshooting

CrewGrid may maintain authentication, application, security and operational logs where reasonably necessary to investigate errors, support requests, suspicious activity and service incidents.

Updates and Maintenance

CrewGrid reviews and updates its application, dependencies, permissions and infrastructure configuration as the platform evolves and security improvements become available.

Security Incident Response

CrewGrid maintains processes for assessing and responding to suspected security incidents, account compromise and unauthorised access. Relevant customers or individuals will be notified where notification is required by applicable law.

Data Retention and Removal

CrewGrid limits post-subscription operational data retention under its stated retention process. Customer operational data may be removed from active systems after the applicable retention period, while limited legal, billing, security or backup records may remain where necessary.

Ongoing Security Improvement

CrewGrid’s security controls will continue to develop as the platform, customer base and product capabilities grow. Future improvements may include additional authentication, monitoring, recovery and administrative security controls.

Infrastructure and Data Location

CrewGrid's primary production database and managed file storage are currently hosted through Supabase in Sydney, Australia. The web application and server-side functions are hosted through Vercel, with web content distributed through its network.

CrewGrid also uses third-party services for payments, email, geocoding and browser notifications. Some providers operate globally, and limited information may be processed in other countries according to the service involved and its infrastructure.

Backups and Recovery

CrewGrid uses managed infrastructure and may rely on provider backup, restoration and recovery capabilities to support service continuity. Backup configuration and recovery processes may change as the platform develops.

Backups are not intended to provide customers with an unlimited archive. Customer companies should download reports and records they are legally or operationally required to retain.

Shared Responsibility

CrewGrid provides authentication, permissions and access controls to support secure workforce management. Customer companies remain responsible for deciding who should have access, assigning suitable roles, reviewing user permissions and disabling access when it is no longer required.

Customer companies and users must protect account credentials, use suitable device security, keep information accurate and ensure that employee and project information is collected and managed lawfully.

Reporting a Security Concern

Report suspected unauthorised access, exposed information, compromised accounts or another CrewGrid security concern as soon as possible.

support@crewgrid.co

Please include a clear description of the issue and the affected CrewGrid page or account. Do not include passwords, private keys or other secret credentials in the email.

This Data Security page is provided as a general overview. Detailed security commitments may be included in a separate written agreement or Data Processing Addendum where applicable.