At a glance
Summary
Core data
Infrastructure includes Neon and Cloudflare processing, storage and lifecycle services; optional services depend on configuration.
Comms
Email, transactional SMS and push providers process information for the services enabled for your account.
Billing
Revolut subscription billing, Stripe customer payments and selected accounting providers have distinct roles and require the relevant service to be available and authorised.
Operations
Provider roles, likely countries and change notices are disclosed separately from feature availability.
Overview
Register updated: 19 September 2026. Provider status and location information reflect the service records described below; feature-dependent and planned services are identified separately.
Crewzon is operated by NOT ANOTHER APP BUILDER PTY. LTD. (ACN 699 954 071, ABN 92 699 954 071). Contact privacy@crewzon.com about this register.
2. Independent and user-selected services
Payment providers have their own payment, identity-verification and compliance obligations. Revolut subscription billing and Stripe customer payments are separate activities. Each requires the relevant service to be available and enabled, and separate authority for a charge or refund.
The business chooses and authorises its Xero, MYOB or QuickBooks company and permissions. Those providers apply their own terms to their service. Connection does not transfer the business's accounting responsibilities to Crewzon. Disconnection does not erase posted transactions or records a provider must retain. Crewzon remains responsible for its own integration and processing.
A native navigation handoff uses the selected device service under its terms. For server mapping/traffic ETA, Crewzon will identify the provider and the origin/destination information it receives before the function is available.
3. Pending providers and processing changes
Rows marked Planned are not authorised to receive information through those services. Processing can begin only after the required agreements and notices are in place and the relevant service is available and enabled. This includes the selected mail replacement, transactional SMS, payment and accounting features and new server mapping. This register does not authorise marketing or AI processing. A material new processing activity of an existing provider also follows the DPA change process.
4. Provider inventory and locations
This inventory records data flows and service status; it is not a blanket subprocessor authorisation or a representation that every feature is available. The roles and pending-service exclusions above govern how each entry is used.
- **Active** identifies the operational infrastructure recorded for Crewzon;
optional services and processing locations can vary as described below.
- **Feature-dependent** means processing depends on actual configuration,
permission and use, including the current mail transition.
- **Planned** identifies a future service that is not currently authorised to
receive information through the listed integration.
| Provider | Status | Purpose | Data processed | Likely processing location |
|---|---|---|---|---|
| Vercel | Active | Infrastructure processor: web hosting/delivery, logs and performance analytics | Requests, IP/device context and minimised performance events | US by default; configured Sydney, edge, support and failover regions may also process information |
| Neon | Active | Infrastructure processor: PostgreSQL, backups and diagnostics | Workspace records, encrypted content, routing metadata and database diagnostics | Australia (AWS Sydney) for the recorded core database; backup, support and diagnostic handling can differ |
| Cloudflare R2 | Active | Infrastructure processor: uploads, exports and restricted lifecycle/compliance storage | Encrypted files, scoped content during authorised handling, metadata, object keys and restricted evidence | Recorded production upload-bucket hint: Eastern North America; other buckets and network/support operations can differ |
| Cloudflare Workers and lifecycle services | Active | Infrastructure processor: API Workers, queues/workflows, scanning, Durable Objects and key services | Requests, scoped plaintext during authorised processing, encrypted content, keys, delivery/security and lifecycle metadata | Cloudflare distributed network; location depends on service, account settings, processing and support |
| Sentry | Active | Infrastructure processor: error/performance diagnostics | Minimised stack/route/device context and identifiers | Recorded US ingest; authorised support may operate elsewhere |
| Expo EAS Insights and Observe | Active | Infrastructure processor: mobile usage and release-linked diagnostics | Installation/build/device information, filtered routes, performance and error events | US and other countries used by Expo and its subprocessors |
| Resend | Feature-dependent | Mail processor during the controlled transition | Addresses, rendered content, delivery events and metadata | Recorded US metadata and Tokyo outgoing region; delivery/support may involve other countries |
| Upstash Redis | Feature-dependent | Infrastructure processor where configured: rate limiting and abuse prevention | Scoped counters/request or identity keys; business content is not required | Configured primary/read-replica regions and support locations; no Australia-only commitment |
| Expo Push / APNs / FCM | Feature-dependent | Notification processors for enabled mobile features | Device tokens, minimised notification content and delivery metadata | US and other countries used by Expo, Apple and Google |
| platform geocoding | Feature-dependent | Selected platform service: foreground address lookup | Coordinates, derived address and necessary request/device metadata | Australia and other countries used by the device-platform service |
| Revolut Merchant | Planned | Payment provider with independent payment/compliance roles: Crewzon subscriptions | Billing contact, customer/subscription identifiers, payment status and provider-hosted payment information | UK, EEA, US and other payment/compliance/support locations |
| Stripe Connect | Planned | Selected payment provider with its own obligations: customer-to-business payments | Connected-account/onboarding information, transaction and reconciliation metadata; payment details entered with Stripe | Australia, US and other Stripe/service-provider payment, compliance and support locations |
| Xero | Planned | User-selected AU accounting provider | Selected company/scopes, customer, invoice, tax/mapping, payment, credit and refund records | Australia, New Zealand, US and other locations described by Xero |
| MYOB | Planned | User-selected supported AU online company-file provider | Company/file authority, customer, invoice, mapping and reconciliation records | Australia; overseas recipients include New Zealand, Philippines and US |
| Intuit QuickBooks Online | Planned | User-selected AU accounting provider | Company/scopes, customer, invoice, mapping, payment, credit and refund records | US and other countries where Intuit, group companies and providers operate |
| Cloudflare Email Sending | Planned | Replacement mail processor | Addresses, rendered content, delivery events and metadata | Cloudflare network and delivery/security/support chain; not an Australia-only service |
| Twilio | Planned | Transactional SMS processor | Recipient numbers, message content, delivery status and metadata | Configured service region/edge where supported, plus US and other delivery/support locations |
| Server maps and traffic ETA | Planned | Route calculation and arrival estimates; service not currently available | Deliberately supplied origin/destination, coordinates and derived route/ETA | Provider and processing countries will be published before use; no processing is authorised by this entry |
Server maps and traffic ETA are a planned feature. The provider has not yet been identified in this register, and this function is not authorised to send information to a mapping service. Crewzon will publish the provider, processing countries and handling of deliberately supplied origins, destinations, coordinates and route/ETA results before the feature is available.
5. Location and contractual safeguards
Sydney database storage does not mean all requests, diagnostics, backups, support access or messages remain in Australia. An R2 location hint is not contractual residency. Before enabling processing, Crewzon assesses and records the actual service/account, countries, onward processors, support access, security, retention/deletion, incident contact and applicable overseas-disclosure requirements under Australian Privacy Principle 8. Locations described as likely or dependent on settings are not exclusive storage commitments.
Relevant provider notices include Cloudflare's DPA and subprocessors, Upstash's DPA and region model, Stripe's Australian connected-account terms, Xero privacy, MYOB privacy and Intuit privacy. These notices describe the providers' practices; the scope of their processing for Crewzon is described in this register and the DPA.
Backups, customer downloads, local devices and externally delivered messages have separate lifecycles. The retention schedule and deletion notice explain their treatment. Restored copies remain isolated until current deletion/hold decisions are applied.
6. Changes and questions
Material subprocessor changes follow DPA section 8, including ordinarily 30 days' direct advance notice, a 14-day objection period and an affected-service remedy if no reasonable solution is available. Urgent legal/security changes require prompt notice and reasons. A website edit alone does not replace a required direct notice or retrospectively authorise processing. Ask privacy@crewzon.com for relevant non-sensitive processing information.