CrewSync Pro™ ("we," "us," or "our") is committed to protecting your personal information and complying with applicable global privacy laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our construction management software platform, including integrations with third-party services such as QuickBooks by Intuit Inc. This policy is publicly accessible and does not require a login to view.
1. Information We Collect
1.1 Information You Provide Directly
- Account registration details (name, email address, company name, phone number)
- Billing and payment information (processed securely via third-party payment processors)
- Project data, crew schedules, job site information, and documents you upload
- Communications you send to our support team
1.2 Information Collected Automatically
- Log data (IP address, browser type, pages visited, timestamps)
- Device information (operating system, device identifiers)
- Usage analytics to improve platform performance
- Cookies and similar tracking technologies
1.3 Data Minimization
We only collect information that is strictly necessary for the operation of our platform and the delivery of services you have requested. We do not collect data beyond what is required for these functional purposes.
1.4 Information from Third-Party Integrations (QuickBooks)
When you connect CrewSync Pro™ to QuickBooks, we receive only the data scopes you explicitly authorize via Intuit's OAuth 2.0 flow. This may include financial records, vendor information, and payroll data. This data is used solely to provide the integration features you have enabled — it is never exported, stored for unrelated purposes, or used outside the functional scope of your request.
2. Purpose of Data Collection & Use
We collect and use your data only for the following explicitly stated purposes. Data is never used for purposes beyond those listed below without your prior consent:
- To provide, operate, and maintain the CrewSync Pro™ platform
- To process transactions and send related billing communications
- To enable and manage third-party integrations you authorize (e.g., QuickBooks sync)
- To send product updates, security alerts, and support messages
- To analyze usage patterns and improve our services
- To comply with legal obligations and enforce our Terms of Service
- To detect, prevent, and address fraud or security incidents
3. Consent & User Control
We obtain clear, specific, and unambiguous consent before collecting or using your personal information for any purpose. You have the right to:
- Withdraw consent at any time without affecting the lawfulness of prior processing
- Revoke QuickBooks access at any time through your CrewSync Pro™ account settings or directly via your Intuit account dashboard
- Opt out of non-essential data collection (e.g., analytics cookies) via your browser or account preferences
- Request that we stop using your data for any specific purpose
4. QuickBooks Integration & Intuit Data Handling
CrewSync Pro™ integrates with Intuit QuickBooks to provide seamless financial management for construction businesses. When you authorize this integration:
- We access only the QuickBooks data scopes you explicitly authorize via OAuth 2.0
- OAuth tokens and customer-identifying information are never exposed or shared with unauthorized parties
- Financial data synced from QuickBooks is used solely to provide the integration features you have enabled
- We do not provide third parties with access to your QuickBooks data via external API calls
- We do not sell, rent, or share your QuickBooks data with any third parties for commercial purposes
- Data exchanged with QuickBooks is encrypted in transit using TLS 1.2 or higher
- You may revoke QuickBooks access at any time through your account settings or directly via your Intuit account
- Our app card and integration documentation clearly state which QuickBooks products CrewSync Pro™ shares data with
QuickBooks is a registered trademark of Intuit Inc. CrewSync Pro™ is an independent application and is not affiliated with, endorsed by, or sponsored by Intuit Inc. For information on how Intuit handles your data, please review the Intuit Privacy Statement.
5. Data Sharing & Disclosure
We do not sell your personal information. If we share data across different customer accounts for any analytical purpose, such data is always aggregated and anonymized — no individual user's data is identifiable. We may share your data only in the following limited circumstances:
- Service Providers: Trusted vendors who assist in operating our platform (hosting, payment processing, analytics) under strict confidentiality agreements and data processing agreements
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to you
- With Your Consent: For any other purpose with your explicit, informed consent
6. Global Privacy Law Compliance
CrewSync Pro™ takes responsibility for compliance with applicable privacy regulations worldwide, including:
- GDPR (EU/EEA): We maintain a lawful basis for processing personal data of EU residents (consent or contract performance). Users may exercise all GDPR rights including access, rectification, erasure, portability, and objection.
- CCPA (California): California residents have the right to know what personal data is collected, to opt out of its sale (we do not sell data), and to request deletion.
- LGPD (Brazil): We comply with Brazil's Lei Geral de Proteção de Dados for users in Brazil.
- PIPEDA (Canada): We comply with Canada's Personal Information Protection and Electronic Documents Act for Canadian users.
To exercise any rights under these regulations, contact us at privacy@crewsyncpro.com.
7. Data Security
We implement industry-standard security measures including:
- Encryption at rest and in transit (TLS 1.2+)
- Role-based access controls and least-privilege principles
- Regular security audits and vulnerability assessments
- HTTPS enforced across all platform pages; caching disabled on pages containing sensitive data
- Immediate reporting protocols for any security breaches
No method of transmission over the internet is 100% secure. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Upon account termination, we will delete or anonymize your data within 90 days, unless retention is required by applicable law. QuickBooks integration data is deleted immediately upon revocation of access.
9. Your Rights
Regardless of your location, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data ("right to be forgotten")
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing of your data for specific purposes
- Opt-Out: Unsubscribe from marketing communications at any time
- Withdraw Consent: Revoke any previously given consent at any time
To exercise any of these rights, contact us at privacy@crewsyncpro.com. We will respond within 30 days.
10. Cookies
We use cookies and similar technologies to enhance your experience, analyze usage, and support marketing. You can control cookie preferences through your browser settings or our in-app cookie preferences panel. Disabling certain cookies may affect platform functionality. We do not use cookies to track users across third-party websites.
11. Children's Privacy
CrewSync Pro™ is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a minor has provided us with personal data, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on our platform at least 30 days before the changes take effect. The updated policy will always be publicly accessible at this URL without requiring a login. Continued use of the platform after changes constitutes acceptance of the updated policy.