At a glance
Summary
Business evidence
Purpose-specific periods, measured from the relevant completion or record-making event.
Preservation
Legal holds, active work, missing dates and retained dependencies prevent disposal.
Automation
The signed-in retention page reports whether automatic expiry is enabled.
OverviewTap to collapse
Policy version: retention-2026-09-10
Crewzon is operated by NOT ANOTHER APP BUILDER PTY. LTD. (ACN 699 954 071, ABN 92 699 954 071) trading as Crewzon.
1. What this policy meansTap to collapse
This schedule explains what records we keep, why we keep them and the events that start their retention periods. It applies alongside the Privacy Policy, Data Processing Addendum and Account Deletion and Data Retention notice.
Crewzon determines the purposes of its subscription, security and service records. Business Accounts ordinarily determine the purposes of their customer, job and worker records. Businesses remain responsible for their own record-keeping obligations and for telling Crewzon about relevant preservation requirements. This policy does not replace requirements applying to a particular trade, jurisdiction, contract, insurance policy or legal proceeding.
A period ends only after the stated event and any applicable preservation requirements have ended. Seven years means calendar years, not seven lots of 365 days. Opening a record, resending an email, importing historical information or migrating a database does not restart its clock.
2. Business and employment recordsTap to collapse
| Reference | Records | Period and starting event | Why and important exceptions |
|---|---|---|---|
| R01 | Invoices, settled payments, credits, reconciliation and subscription financial evidence | 7 years after the later of final transaction resolution and creation of required supporting evidence | Accounting, tax and transaction evidence. Unresolved debt, disputes and corrections prevent expiry. A write-off is not final resolution while recovery or a dispute continues. |
| R02 | Accepted quotes and variations | Until the later expiry of the associated financial and job evidence | Preserve the terms supporting the work and transaction. |
| R03 | Unaccepted, expired or withdrawn quotes and unsuccessful enquiries | 2 years after documented closure without conversion | Customer service and complaint evidence. Converted work follows the job/contract schedule; open negotiations do not expire. |
| R04 | Ordinary job records, checklists, materials, field reports, photos and signatures | 7 years after the latest of final job completion, final financial resolution and completion of rectification | Evidence of completed work. Open jobs and active recurring work do not expire under this rule. |
| R05 | Regulated safety, compliance and building evidence | Individual assessment, reviewed annually | Trade, jurisdiction, certificate, warranty, insurance and contract requirements determine the period. No blanket seven-year deletion applies. |
| R06 | Customer, site, contact and asset master records | Review after 2 years without an active relationship; remove unnecessary standalone contact information | Preserve the minimum links needed by retained jobs, invoices, warranties, assets and maintenance relationships. Do not delete linked records through a wholesale customer cascade. |
| R07 | Prescribed time, wage, leave and payroll evidence | 7 years from the applicable record-making event | Employment evidence. Late corrections and subtype-specific duties must be considered; shift end alone does not necessarily start this period. |
| R08 | Identity, employment profiles and credentials | Managed through the identity lifecycle, with prompt access revocation on authorised removal | Necessary employment evidence can remain without keeping a usable login or credential. |
3. Communications and service recordsTap to collapse
| Reference | Records | Period and starting event | Why and important exceptions |
|---|---|---|---|
| R09 | Routine chat, customer notes and workforce communications | 2 years after thread or case closure | Routine service history. Communications with enduring job, pay, consent, complaint or contract value follow the corresponding evidence schedule. |
| R10 | Job, financial, contract and employment communications and attachments | Follow the applicable R01, R02, R04, R05 or R07 evidence period | Keep relevant evidence without extending unrelated messages indefinitely. Mixed-purpose content must be separated before shorter expiry. |
| R11 | In-app notifications and read receipts | 90 days after final delivery or expiry, with no pending action | Short-lived communication state; canonical business evidence remains separately. |
| R12 | Email/SMS delivery metadata, callbacks and retry history | 180 days after terminal delivery/failure and closure of retries and reconciliation | Delivery troubleshooting and replay protection. Necessary consent or dispute evidence follows its own schedule. |
| R13 | Rendered email bodies and provider request payloads | 30 days after terminal delivery or failure | Minimise duplicate content while preserving necessary canonical evidence and delivery status. Pending reconciliation, retries or investigations prevent expiry. |
| R14 | Routine security and audit diagnostics | 12 months after the event | Security and abuse investigation. Incident evidence follows R15; financial, employment and business-action evidence follows its parent schedule. Unclassified audit events are not treated as disposable diagnostics. |
| R15 | Confirmed security/privacy incidents, complaints and disputes | 7 years after formal closure, with annual necessity review | Accountability and claims evidence. Investigation, litigation, regulator or insurer requirements override normal expiry. Keep a minimal case record. |
| R16 | Terms acceptance, consent and withdrawal evidence | 7 years after the relevant contractual or processing relationship ends | Evidence of authority and obligations. Minimal suppression entries remain while needed to honour an objection, reviewed annually. |
4. Temporary and operational recordsTap to collapse
| Reference | Records | Period and starting event | Why and important exceptions |
|---|---|---|---|
| R17 | Expired/revoked sessions, consumed/expired invitations, access codes and payment step-ups | Residual non-secret metadata: 30 days after final invalidation or expiry | Authentication validity ends immediately under security rules. This period never extends a token's lifetime; secrets follow their own security lifecycle. |
| R18 | App-lock attempts and rate-limit support | 30 days after the last attempt once the security purpose ends | Abuse prevention. Cleanup must not reset an active lockout or rate limit. |
| R19 | Export files and abandoned upload reservations | Export bytes: 7 days after availability; abandoned reservation metadata: 7 days after expiry; minimal completion metadata: 30 days | Temporary transfer and processing. In-flight work and retained/shared files are excluded. An export link's displayed validity may be shorter. |
| R20 | Import files, staging and processing artifacts | 30 days after completion/abandonment and reconciliation; minimal result receipts: 90 days | Processing recovery and reconciliation. Imported business records follow their own schedules. |
| R21 | Outbox/action claims, sync/reconciliation work and rebuildable projections | 90 days after acknowledged terminal processing; daily report caches: 90 days from the represented day | Operational recovery. Pending work, active mappings, replay requirements and sole financial evidence prevent deletion. |
| R22 | Maintenance schedules and potential visits | Active schedules: while active. Closed schedules: 7 years after final linked visit/financial resolution. Cancelled, unactivated potentials without evidence value: 90 days after cancellation | Preserve ongoing obligations and completed work; no automatic cancellation of future bookings. Activated visits follow job rules. |
| R23 | Services, stock catalogues, tags, templates and trade configuration | While active/referenced, then 90 days after supersession and removal of the final reference | Immutable revisions used by retained work stay with that work. Stock transactions follow financial/job rules. |
| R24 | Completed privacy/deletion requests, merge decisions and destruction receipts | 7 years after final decision or completion, reviewed annually | Minimal accountability evidence, not copies of erased content. |
| R25 | Quarantine, encryption keys and migration bookkeeping | Managed through their security and key lifecycles | Never destroy keys needed by retained content or treat malicious uploads as ordinary job evidence. |
| R26 | Precise location and geofence samples | 90 days after operational reconciliation; longer only for identified necessary evidence | Minimise unusually sensitive information. Retain necessary pay facts separately; payroll retention does not justify keeping every coordinate. |
| R27 | Organisation closure, backups and recovery copies | Assessed under the account-closure and provider-specific recovery processes | Account closure does not itself prove that every live, provider or backup copy has been erased. See the account-deletion notice for current request routes. |
5. Legal holds and other preservation requirementsTap to collapse
A legal hold suspends normal disposal where records are needed for a legal request, dispute, regulatory review or other binding preservation duty. Authorised Crewzon operators record the scope, reason, review date and finite expiry. Review is due at least every 90 days; operators must renew a hold before its technical expiry if the preservation duty continues. A software expiry does not decide whether that duty has ended.
Contact privacy@crewzon.com promptly if records need to be preserved. A support enquiry alone does not place a hold. A hold cannot recover content already deleted, and preservation of external or backup copies may require additional operator action. Business users cannot release an operator's hold.
Missing, uncertain or future start dates, active work, unexpired dependent records and shared files prevent automatic deletion. Uncertain historical dates are reviewed at least every 90 days; we do not invent dates to make records eligible. A shorter content period does not permit destruction of a whole record that also contains evidence with a longer period.
6. Applying the scheduleTap to collapse
The schedule is the business policy; the signed-in retention page separately reports whether automatic expiry is enabled. While automation is off, reaching a policy date does not automatically delete a record. Preservation, access revocation and existing short-lived security/processing cleanup continue under their own controls. An authorised review can address records that no longer have a lawful purpose; disabling automation is not permission to keep them forever.
Once a record is eligible and its disposal is authorised, our operational target is removal within 30 days, subject to stricter applicable deadlines. Failed cleanup is retried and escalated. We do not describe a pending cleanup as completed, or promise that every provider and backup copy disappears immediately. Restored information remains subject to its original preservation or deletion decision before it is returned to ordinary service.
7. Your responsibilities and questionsTap to collapse
Tell us about additional trade, workplace, warranty, contract or preservation requirements affecting your records. Keep any independent copies your business must retain and confirm that an available export actually includes what you need. Current exports are described in the account-deletion notice; not every export is a complete workspace copy.
The employment and financial periods take account of Fair Work record-keeping guidance and ASIC company record-keeping guidance. Other periods are Crewzon's purpose-based retention choices, not a claim that every period is imposed by law. Privacy minimisation follows the applicable OAIC guidance.
For access, correction, preservation or deletion questions, contact privacy@crewzon.com. This schedule does not authorise cross-business pooling, benchmarking, training or reuse of tenant data.