At a glance
Summary
Who
NOT ANOTHER APP BUILDER PTY. LTD. trading as Crewzon.
What
Account, business, job, customer, worker, attachment, device, diagnostic and location information where enabled.
Why
To provide Crewzon, run jobs, manage subscriptions, provide support, improve reliability and meet legal obligations.
Overview
This notice explains common collection points for personal information handled by NOT ANOTHER APP BUILDER PTY. LTD. (ACN 699 954 071, ABN 92 699 954 071) trading as Crewzon ("Crewzon"). Read it with the Crewzon Privacy Policy.
Who Is Collecting The Information
Crewzon is the operator of the Crewzon website, web application and mobile applications.
- Privacy Officer, NOT ANOTHER APP BUILDER PTY. LTD. trading as Crewzon
- Postal address: 1A Lara Way, Campbellfield VIC 3061, Australia
- Email: privacy@crewzon.com
- Support: support@crewzon.com
- Website: crewzon.com
A trade business or other organisation using a Crewzon Business Account may separately collect and control customer, worker, site and job information entered into its workspace. That Business Account should provide its own notice where required.
Where lawful and practicable, a person may make a general enquiry without identifying themselves or may use a pseudonym. Identification is ordinarily needed to create or secure an account, join a workspace, process billing, investigate an account-specific issue or verify a privacy request.
Unless Crewzon says otherwise at a collection point, Australian law does not directly require an individual to give Crewzon the information described below; it is collected to provide the requested account, feature or service. A Business Account may have its own legal reason for collecting a workplace, safety, customer or tax record, and Crewzon may be required by law to retain or disclose particular records.
Account Creation, Invitation and Authentication
When a person applies for, creates, accepts an invitation to or signs into a Crewzon account, we may collect their name, email address, phone number, business and trade details, role, workspace membership, password hash, session data, one-time-code or two-factor events, passkey public credential material, credential identifiers, device-type metadata, IP address and authentication results.
We collect this information to assess an application where applicable, create the account, connect it to the correct workspace, authenticate the user, apply permissions, prevent misuse and communicate about the account. If required identity, contact or authentication information is not provided, the person may be unable to apply, accept an invitation, sign in or use secured features.
On supported devices, a passkey may be unlocked using a device biometric, device passcode or security key. Crewzon does not receive or store the user's fingerprint, face image, biometric template, device passcode or passkey private key. Crewzon may store public passkey credential material, credential identifiers, device-type metadata and authentication results needed to verify the passkey.
Business, Customer, Site and Job Workflows
When an owner, administrator or user enters or uploads business and operational records, Crewzon may collect business identifiers and contact details; customer and site contact details; service and billing addresses; job, schedule, quote and invoice information; photos, documents, forms, certificates, messages, signatures, assets and work history.
This information is collected to operate the workspace, schedule and perform work, maintain customer and site records, generate quotes and invoices, communicate with selected recipients, keep job evidence and provide reports. If information required for a workflow is not provided, the Business Account may be unable to create or complete the relevant job, customer, quote, invoice or record.
Worker, Timesheet and Location Workflows
A Business Account may enter or collect a worker's name, contact details, role, assigned jobs, schedule, time entries, work notes, operational records and uploaded evidence. When an enabled mobile time-entry or geofence action is submitted, the app may request foreground location permission and collect a point-in-time latitude and longitude, accuracy, capture time, reverse-geocoded address and geofence result.
The Business Account uses this information for work allocation, attendance and payroll inputs, job progress, safety, record keeping and operational administration. Crewzon uses it to provide and secure the configured service. If required worker or time information is not provided, a work assignment or time entry may not be recorded. If location permission is refused or location is unavailable, the result depends on the Business Account's geofence setting and may require a reason or prevent submission.
The mobile workflow does not continuously collect background location. The employer or contracting business is responsible for giving workers any workplace surveillance, privacy or consultation notices required in its jurisdiction.
Billing, Support and Service Communications
When a Business Account manages a subscription or a person contacts Crewzon, we may collect names, business and contact details, plan and payment status, payment-provider identifiers, correspondence, attachments and diagnostic context. This information is collected to process and reconcile subscriptions, provide support, investigate issues and meet legal and accounting obligations. Crewzon does not receive complete payment-card details entered directly into a payment provider's hosted interface.
If required billing information is not provided, we may be unable to start or maintain a paid subscription. If sufficient support details are not provided, we may be unable to investigate or respond to the issue.
Device, Website and Diagnostic Collection
When the website or applications are used, Crewzon and active service providers may automatically collect IP address, device and browser type, operating system, app version, session events, page or feature usage, performance measurements, error reports and diagnostics. Essential cookies or similar storage support authentication, sessions, security and preferences. Privacy-preserving Vercel Web Analytics and Speed Insights measure aggregate usage and performance; Crewzon does not currently activate third-party marketing or cross-site advertising cookies.
We collect this technical information to operate, secure, troubleshoot and improve Crewzon. Blocking essential browser storage may prevent sign-in or other secured functions.
Usual Disclosures
Depending on the collection point and feature, personal information is usually disclosed or made available to:
- the Business Account and authorised workspace users;
- customers or other recipients chosen by the Business Account for quotes, invoices or job communications;
- Vercel for hosting, edge delivery, logs and privacy-preserving analytics;
- Neon for the production database;
- Cloudflare for API processing, security, encrypted file handling, keys and lifecycle infrastructure, and email when enabled;
- the transactional email provider identified in the current provider register during migration;
- Revolut Merchant when Crewzon subscription billing is enabled;
- Sentry for error and performance diagnostics;
- Expo for aggregate app usage, release-linked mobile performance monitoring
and mobile diagnostics, plus Expo, Apple, Google or platform geocoding services when the related mobile feature is enabled; and
- professional advisers, regulators, courts or law-enforcement bodies where required or permitted by law.
Twilio SMS, Stripe customer payments and Xero/MYOB/QuickBooks accounting apply only when the relevant service is available and enabled. The provider register distinguishes current infrastructure, user-selected providers and planned services, including rate-limiting and maps. Listing a planned service does not authorise it to receive personal information.
Crewzon may also receive information indirectly from the Business Account that invites a person or enters a record, from an enabled integration, from a payment or service provider, or from a public source where lawful. Crewzon uses this notice, the Privacy Policy and notices in invitation, sign-in or feature flows to inform affected people where reasonable. The Business Account remains responsible for any notice it must give about its own collection and use.
Overseas Processing
Some usual providers process information or provide authorised support outside Australia. Likely countries or regions, depending on the feature, include the United States, Japan, New Zealand, the Philippines, the United Kingdom, countries in the European Economic Area and other locations used by global app-platform and network operations. The production database is hosted in Sydney, Australia. Provider-specific likely locations are listed in Crewzon Subprocessors where practicable.
Access, Correction and Complaints
An individual may request access to, or correction of, personal information held by Crewzon, or make a privacy complaint, by contacting the Privacy Officer at privacy@crewzon.com. Crewzon may need to verify identity. If information is controlled by the Business Account that entered it, Crewzon may refer the person to that Business Account or assist it to respond.
We aim to acknowledge privacy complaints within 5 working days and provide an outcome or substantive update within 30 calendar days, sooner where required by law. If more time is needed, we explain the next step and expected timing. More information about handling, retention, complaints and OAIC escalation is in the Crewzon Privacy Policy.
Information collected by particular features
The following explains how particular features use information when available and enabled. Where a feature needs a specific notice or consent, that must be provided or obtained before the affected collection or use. This general notice does not replace those requirements.
| Feature | Information, purpose and choices |
|---|---|
| Leave, certificate or health-related material | Necessary leave details or certificates may be handled by Crewzon and authorised business recipients for the stated employment or work purpose. The business must explain that purpose and obtain required consent or establish a legal exception before collection. It must not request diagnoses or full records when a status is sufficient. See the Privacy Policy's Sensitive information section. |
| Maps, geofence and ETA | A deliberate foreground action may collect coordinates, accuracy and time, and send an origin/destination to the mapping provider identified before use. Location can be inaccurate; refusing permission or a geofence result may block a configured time entry. Ask the business to review disputed records, or Crewzon to investigate a technical error. A customer's ETA is not a live worker-location feed. |
| SMS and notifications | Contact details, message content and delivery information are used for the identified business sender's job or service message. Delivery is not guaranteed. Available reply and preference channels depend on the message and sender; contact the business where replies are unsupported. Crewzon messaging does not include promotional campaigns. |
| Customer payment | The trade business supplies the work and identifies the amount, fees, purpose and any separate payment authority. Payment details are entered through Stripe's payment interface. Crewzon receives necessary identifiers, status and reconciliation information. |
| Accounting connection | An authorised representative selects Xero, MYOB or QuickBooks, the company and the requested permissions. Customer, invoice, mapping and reconciliation data are exchanged for that connection. Refusing prevents the connector; disconnecting does not erase earlier provider copies. |
| Recurring maintenance | Customer, site, schedule and job details support maintenance planning and potential visits. A potential visit is a planning record. Customer contact and confirmation require separate authority; no recurring payment authority is implied. |
| Offline use | Work records, attachments and pending changes may be held on the device for later synchronisation. Check the sync state before signing out, clearing storage or removing the app; unsent work may be lost. Removing the app is not a server deletion request. |
Feature availability depends on the Business Account, supported device and enabled services. Information about a future integration does not mean it is currently available or receiving information.