arrow_back Back to App
groups
Crewly
Workforce Management Platform
Privacy Policy
Last updated: May 2026 • Effective immediately • GDPR compliant
Short version: We collect only what is needed to run the scheduling platform. We never sell your data. You can request deletion of all your data at any time. This app is GDPR-compliant.
info 1. Who We Are
Crewly is a workforce management platform designed for businesses, staffing agencies, and their employees. The platform allows managers to schedule shifts, track attendance, manage payroll, and communicate with staff.
The data controller is the company (organisation) that created the workspace on this platform. If you are an employee using the platform, your employer is the data controller for your personal data.
database 2. What Data We Collect
We collect the following categories of personal data:
- Account information: Full name, job title, email address, phone number, login PIN
- Work data: Shift schedules, clock-in and clock-out timestamps, work location
- Payroll data: Hourly rate, hours worked, gross pay calculations
- Leave data: Absence requests, leave type, dates, reason
- Communication data: Messages sent within the inbox system, newsfeed posts
- Availability preferences: Days and hours you are available to work
- Device data: Browser type, device type (for technical compatibility only)
We do not collect biometric data, precise GPS location, government ID numbers, or financial account details.
gavel 3. Legal Basis for Processing (GDPR)
We process personal data under the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing your name, shifts, and clock records is necessary to deliver the scheduling service under your employment relationship
- Legitimate interests (Art. 6(1)(f)): Payroll calculation, shift management, and workforce reporting serve the legitimate interests of the employing organisation
- Legal obligation (Art. 6(1)(c)): Payroll records may be retained to comply with Danish or local tax and accounting regulations
- Consent (Art. 6(1)(a)): For optional features such as availability preferences and newsfeed interactions
share 4. How We Use Your Data
Your data is used exclusively to:
- Display your schedule, shifts, and work history
- Calculate hours worked and generate payroll reports
- Allow managers to approve leave and manage staffing
- Send shift assignment notifications via the in-app inbox
- Generate invoices for client locations (staffing agency use)
- Provide managers with reports and analytics on workforce performance
We do not use your data for advertising, profiling for third parties, or any automated decision-making with legal effects.
cloud 5. Data Storage & Security
All data is stored in Supabase, a PostgreSQL cloud database hosted on AWS infrastructure in the European Union (eu-west-1, Ireland). Data does not leave the EU.
- All connections are encrypted using TLS 1.3
- Database access is restricted by Row Level Security (RLS) policies
- Each company's data is isolated and inaccessible to other organisations
- Login PINs are stored in plain text — we recommend using 6-digit PINs for added security
- No passwords are stored; authentication is name + PIN based
group 6. Who Can See Your Data
- Your manager / employer: Can see all your shifts, clock records, payroll data, leave requests, and inbox messages within your company workspace
- Your colleagues: Can see your name in the staff directory, shift marketplace, and newsfeed
- Platform operators: Can access database records for technical support and maintenance only, under strict confidentiality
- Third parties: We do not share, sell, or rent your personal data to any third party
sync 7. Data Retention
Data is retained for the following periods:
- Active accounts: Retained for as long as the company workspace is active
- Payroll and punch records: Retained for 5 years to comply with Danish bookkeeping law (Bogføringsloven) and EU tax regulations
- Messages and newsfeed: Retained for 2 years
- Deleted accounts: Personal identifiers are anonymised within 30 days of deletion request; work records may be retained in anonymised form
verified_user 8. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right of access (Art. 15): Request a copy of all personal data we hold about you
- Right to rectification (Art. 16): Ask your manager to correct inaccurate data
- Right to erasure (Art. 17): Request deletion of your account and personal data
- Right to restrict processing (Art. 18): Request that we limit how we use your data
- Right to data portability (Art. 20): Request your data in a machine-readable format (CSV export)
- Right to object (Art. 21): Object to processing based on legitimate interests
To exercise any of these rights, use the Account Deletion & Data Request page, or contact your manager or our support email.
cookie 9. Cookies & Local Storage
This application uses browser localStorage (not cookies) to store your session information locally on your device:
- Your name, role, company name, and currency preference
- Your company ID (used to filter data from the database)
This data is stored only on your own device and is cleared when you sign out. We do not use tracking cookies, analytics cookies, or advertising cookies.
child_care 10. Children's Privacy
This platform is intended for use by adults in an employment context. We do not knowingly collect data from individuals under the age of 16. If you believe a minor's data has been submitted, please contact us immediately for removal.
edit_note 11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.
mail 12. Contact & Complaints