Back to Trust Centre

Privacy Policy

Draft

Last updated: 3 August 2026

Draft document

This Privacy Policy is a working draft while the CrewGrid legal entity, ABN or ACN and public business address are being finalised. It will be reviewed before CrewGrid accepts paying customers.

1. About This Privacy Policy

This Privacy Policy explains how CrewGrid collects, holds, uses, discloses, protects and manages personal information through the CrewGrid website, web application, support services and related platform features.

CrewGrid is operated under the CrewGrid trading name. The intended operating entity is CrewGrid Pty Ltd, registration pending. References to “CrewGrid”, “we”, “us” or “our” mean the entity that operates the CrewGrid platform.

CrewGrid is designed for use by scaffolding companies, their authorised representatives and their employees or contractors. It is not intended for personal or household use.

2. CrewGrid and Customer Companies

Customer companies decide which authorised users may use CrewGrid and which workforce, project and operational information is entered into the platform. A customer company may collect and manage information about its employees, contractors, clients, projects and sites through CrewGrid.

CrewGrid processes that information to provide the platform and related services. Customer companies remain responsible for ensuring that they have a lawful basis, authority and any required notices or permissions to collect, upload, use and manage information through CrewGrid.

Some privacy requests may need to be handled together with the relevant customer company because that company controls the employment, project or operational context in which the information was collected.

3. Personal Information We May Collect

The information CrewGrid collects depends on the features used by the customer company and the permissions assigned to each user.

  • Names, email addresses, telephone numbers, residential addresses and profile information.
  • Dates of birth, emergency contacts and employment-related details.
  • Company, branch, role, job and project assignments.
  • Profile photographs, attendance selfies, uploaded images and message photos.
  • Licences, tickets, certificates, qualifications and compliance records.
  • Employee documents and identification documents uploaded by authorised users.
  • Clock-in and clock-out records, attendance times, shifts and timesheets.
  • Exact location coordinates, calculated distance from a selected site and geofence results collected during specific clock-related actions.
  • Safety sign-ons, acknowledgements, declarations, scaffold handovers, inspections, reports and signatures.
  • Fitness-for-work information and other workforce compliance information where entered by a customer company.
  • Payroll-related, taxation, bank and superannuation information where supported by CrewGrid features.
  • Private messages, group messages, announcements and uploaded message attachments.
  • Support requests, feature requests, bug reports and related communications.
  • Client, builder, project, site, estimate, drawing and operational information.
  • Account, subscription, invoice and payment-status information.
  • Browser, device, IP address, analytics identifiers, page visits, referral information, authentication, security and system-usage information.

4. Sensitive and Workforce Information

Some information entered into CrewGrid may be sensitive or require additional protection, including health or fitness information, identification documents, qualifications, licences and workplace compliance records.

CrewGrid only processes this information where it is provided by the individual, provided or authorised by a customer company, required to deliver an enabled CrewGrid feature, or otherwise permitted by law.

Customer companies must not upload sensitive information unless it is reasonably necessary for their use of CrewGrid and they are authorised to collect and disclose it.

5. How Information Is Collected

CrewGrid may collect information:

  • Directly from a user when an account is created or information is entered into the platform.
  • From a customer company, administrator, manager, supervisor or other authorised representative.
  • Through forms, uploads, messages, reports, support requests and platform workflows.
  • From the device camera when a user chooses or is required to capture a photo or attendance selfie.
  • From the device location service during specific location-related actions such as clocking in or clocking out.
  • Automatically through authentication, security, browser, device and platform logs.
  • From payment and subscription providers in connection with a customer subscription.
  • From service providers used to operate, secure and support the platform.

6. How We Use Information

CrewGrid may collect, hold, use and disclose information for the following purposes:

  • Creating, authenticating and administering CrewGrid accounts.
  • Providing company, branch, user and role-based platform access.
  • Managing employees, projects, shifts, attendance and workforce operations.
  • Verifying clock-related attendance actions against an assigned worksite.
  • Managing safety, compliance, tickets, licences, documents and expiry information.
  • Generating reports, PDFs, timesheets, payroll-related outputs, summaries and operational records.
  • Providing private messaging, group messaging, announcements and push notifications.
  • Providing scaffold handover, inspection, reporting and project-management features.
  • Providing estimating, document-processing and AI-assisted features where enabled.
  • Processing subscriptions, invoices and payment status.
  • Providing customer support and responding to bug reports and feature requests.
  • Maintaining security, detecting misuse, investigating incidents and enforcing platform permissions.
  • Monitoring service availability, diagnosing technical problems and improving platform performance.
  • Complying with legal obligations, resolving disputes and protecting lawful rights.

7. Attendance, GPS and Site Verification

CrewGrid may access a user’s current device location when the user performs a specific location-related action, including clocking in or clocking out.

CrewGrid may store the exact latitude and longitude recorded during that action, the selected site, the calculated distance from that site and whether the action was within the configured attendance radius.

CrewGrid does not currently use continuous background location tracking. If continuous or route-based tracking is introduced in the future, this Privacy Policy and the relevant collection notices will be updated before that feature is used.

Authorised representatives of the customer company may view attendance and location-verification information. Customer companies remain responsible for providing any workplace notices and obtaining any permissions required by applicable employment, privacy or workplace surveillance laws.

8. Photos, Selfies, Signatures and Documents

CrewGrid may store profile photographs, mandatory attendance selfies, scaffold and site photographs, message photos, electronic signatures and uploaded documents.

These materials may be visible to authorised users of the relevant customer company according to their account role and platform permissions. Authorised company users may download employee compliance documents where the platform permits that action.

Users must not upload photographs, documents, signatures or other information unless they are authorised to do so.

9. Messages and Communications

CrewGrid stores private messages, company or branch group messages, announcements and message attachments so that authorised users can communicate through the platform.

Message content may be accessible to the sender, recipients and other authorised participants in the relevant conversation. CrewGrid may access message records where reasonably necessary to provide support, investigate misuse, protect platform security or comply with law.

CrewGrid may also send account, operational, support and browser push notifications. Delivery of browser notifications may involve push services operated by the user’s browser or device provider.

10. Payments and Stripe

CrewGrid uses Stripe to process subscription payments. Payment-card details are entered into and processed by Stripe rather than being stored in full by CrewGrid.

CrewGrid may receive and store limited billing information from Stripe, including a Stripe customer or subscription identifier, invoice information, transaction status, payment method type, card brand and the final digits of a payment card.

Stripe may process information for payment processing, fraud prevention, security, regulatory compliance and related payment services under its own legal and privacy obligations.

11. AI-Assisted and Automated Features

CrewGrid may provide automated rules, calculations and AI-assisted features, including features that analyse project information or uploaded documents and assist with estimates, reports or operational workflows.

Automated results may contain errors, omissions or incomplete information. CrewGrid is designed to assist authorised users and does not replace required human review, professional judgement, engineering approval, safety assessment or commercial approval.

CrewGrid does not currently intend automated output to independently make final employment, safety, engineering or commercial decisions about an individual or project.

12. Service Providers and Disclosure

CrewGrid may disclose information to service providers where reasonably necessary to operate, support and secure the platform.

  • Supabase for authentication, database and managed file-storage services.
  • Vercel for web hosting, content delivery and server-side application functions.
  • Stripe for subscription billing and payment processing.
  • Namecheap Private Email and related email infrastructure for service and support communications.
  • OpenStreetMap Nominatim for address geocoding.
  • Google Maps Platform as a fallback geocoding provider where an address cannot be resolved through the primary provider.
  • Google Analytics for website and platform usage measurement, traffic analysis and audience insights.
  • Browser and device push services for Web Push notification delivery.
  • Professional advisers, insurers, regulators, courts or law-enforcement bodies where disclosure is required or permitted by law.

Site or project addresses submitted for geocoding may be sent to OpenStreetMap Nominatim or Google Maps Platform to obtain latitude and longitude coordinates.

CrewGrid does not sell personal information.

13. Data Hosting and Overseas Processing

CrewGrid’s primary production database and managed file storage are currently hosted through Supabase in Sydney, Australia.

Some providers used by CrewGrid operate globally, and information may be processed or accessed outside Australia depending on the provider, service and current configuration. This may include processing in the United States and other countries where those providers or their infrastructure operate.

CrewGrid will maintain an up-to-date list of material service providers and will update this policy when its established overseas-processing arrangements materially change.

14. Data Security

CrewGrid takes reasonable technical and organisational steps to protect information against misuse, interference, loss and unauthorised access, modification or disclosure.

  • Authenticated account access.
  • Role-based and company-based permissions.
  • Company and branch data-separation controls.
  • Encrypted HTTPS connections.
  • Managed database and file-storage infrastructure.
  • Private storage controls for sensitive files where configured.
  • System monitoring, logging and service-health checks.
  • Access restrictions for administrative functions.
  • Security and dependency updates as the platform evolves.

No internet-based platform can guarantee complete security. Users and customer companies must protect passwords, control authorised access and promptly report suspected misuse or compromised accounts.

15. Data Retention After Cancellation

Customer information is retained while required to provide an active CrewGrid subscription and for the periods described below.

  • Full platform access continues until the end of the customer’s current trial or paid access period, as applicable.
  • For 30 days after access ends, the customer account may remain available in read-only mode so existing information can be viewed and available reports or PDFs can be downloaded.
  • During the read-only period, customers may reactivate the account or request deletion.
  • From day 31 to day 90, standard user access may be removed while the information is retained temporarily for authorised export, reactivation or deletion requests.
  • After 90 days, customer operational information may be deleted from active systems unless longer retention is required by law, for payment or accounting obligations, fraud or security investigations, an active dispute, enforcement of an agreement or another written arrangement.
  • Residual copies may remain temporarily in protected backups until they are removed through the normal backup-rotation process.

An authorised customer representative may request earlier deletion by contacting CrewGrid. CrewGrid may require identity and authority verification before acting on the request.

16. Other Retention Periods

CrewGrid may retain limited business, support, security and legal records after customer operational data has been deleted.

  • Billing, invoice, taxation and accounting records may be retained for up to seven years or another period required by law.
  • Contracts, accepted policy versions and commercial correspondence may be retained for up to seven years after the relationship ends.
  • Support requests, feature requests and bug reports may be retained for up to two years after closure.
  • Security and access logs may ordinarily be retained for up to 12 months.
  • Security incident, fraud, dispute or investigation records may be retained for as long as reasonably necessary to resolve the matter and satisfy legal obligations.

CrewGrid may retain de-identified or aggregated information that no longer reasonably identifies an individual.

17. Access and Correction

An individual may request access to personal information CrewGrid holds about them or request that inaccurate, incomplete, out-of-date, irrelevant or misleading information be corrected.

Requests may be sent to info@crewgrid.co. CrewGrid may need to verify the requester’s identity and may consult the relevant customer company where that company controls the employment or operational record.

Some information may also be viewed or corrected directly through an authorised CrewGrid account. CrewGrid will respond within a reasonable period and will explain any lawful reason why access or correction cannot be provided.

18. Privacy Complaints

Privacy concerns or complaints may be sent to info@crewgrid.co.

The complaint should explain the concern, the information or CrewGrid feature involved and the outcome requested. CrewGrid may request further details where necessary to investigate the matter.

CrewGrid will acknowledge and investigate privacy complaints and aims to provide a substantive response within 30 days. Where the matter involves information controlled by a customer company, CrewGrid may work with that company to investigate and respond.

If a person is not satisfied with CrewGrid’s response and the Privacy Act 1988 (Cth) applies, they may be entitled to contact the Office of the Australian Information Commissioner.

19. Data Breaches

CrewGrid maintains processes for assessing and responding to suspected security incidents and personal information breaches.

Where a breach is likely to result in serious harm and notification is required by applicable law, CrewGrid will take reasonable steps to notify affected parties and relevant regulators.

Customer companies and users should promptly report suspected unauthorised access, compromised credentials or information exposure to info@crewgrid.co.

20. Communications and Direct Marketing

CrewGrid may send operational messages required to provide the service, including authentication, subscription, security, support, compliance and notification messages.

CrewGrid may also send product, service or marketing communications where permitted by law. Recipients may unsubscribe from optional marketing communications using the method provided in the message.

Unsubscribing from marketing messages will not prevent CrewGrid from sending essential service, security, billing or account communications.

21. Children

CrewGrid is a business workforce-management platform and is not directed to children. Customer companies must not create accounts for, or upload personal information about, a person who is not legally permitted to participate in the relevant workplace or service.

22. Changes to This Privacy Policy

CrewGrid may update this Privacy Policy when its product, providers, business structure or legal obligations change.

The updated version will be published with a revised “Last updated” date. Where a change materially affects how personal information is handled, CrewGrid will take reasonable steps to notify affected customer companies or users.

23. Contact

Privacy, access, correction, deletion and security enquiries may be sent to:

CrewGrid

Intended legal entity: CrewGrid Pty Ltd — registration pending

Western Australia, Australia

support@crewgrid.co