Privacy Policy

Last updated: March 25, 2026

CrewScan ("Service") is operated by CrewScan ("Company", "we", "us"). This policy describes how we collect, use, and protect your information.

1. Information We Collect

Data TypeExamplesPurpose
Account infoEmail, name, password hashAuthentication, account management
Organization infoBusiness name, team membersMulti-user access, billing
Receipt imagesPhotographs of receipts and invoicesAI extraction, record keeping, QBO sync
Expense dataVendor, amount, date, line items, job/cost code assignmentsExpense tracking, QBO sync
QuickBooks dataCustomer list, class list, vendor list (cached)Job/cost code suggestions
Usage dataFeature usage, error logsService improvement, debugging
Payment infoProcessed by Stripe (we do not store card numbers)Subscription billing

2. How We Use Your Information

3. AI Processing

Receipt images are processed using third-party AI services (xAI) to extract text and categorize expenses. Images are sent to the AI provider's API for processing and are not retained by the AI provider beyond the API request. We do not use your receipt data to train AI models.

4. Third-Party Services

ServicePurposeData Shared
Intuit QuickBooks OnlineAccounting syncExpense data, receipt images (via your OAuth authorization)
xAI (Grok)Receipt OCR and classificationReceipt images (for processing only)
StripePayment processingPayment method, billing address
Amazon Web ServicesCloud infrastructureAll service data (hosted on AWS)
NeonDatabase hostingBusiness data (hosted on Neon's infrastructure)
CloudflareDNS, CDN, frontend hostingWeb traffic

5. Data Retention

Receipt images and expense data are retained for as long as your account is active. After account deletion, data is retained for 30 days for recovery purposes, then permanently deleted. Anonymized aggregate data may be retained indefinitely.

6. Data Security

We use industry-standard security measures including: encryption in transit (TLS), encryption at rest (AWS KMS for sensitive data like OAuth tokens), row-level security for tenant isolation, and secure password hashing (bcrypt). We do not store QuickBooks OAuth tokens in plaintext.

7. Your Rights

You may: access your data at any time through the Service; export your data; request deletion of your account and data; opt out of non-essential emails. To exercise these rights, contact us at alex@crewscan.app.

8. Cookies

We use essential cookies for authentication (session tokens). We do not use tracking cookies or third-party advertising cookies.

9. Children's Privacy

The Service is not intended for users under 18. We do not knowingly collect data from minors.

10. Changes to This Policy

We may update this policy at any time. We will notify you of material changes via email. Continued use after changes constitutes acceptance.

11. Contact

Questions about this policy? Contact us at alex@crewscan.app.

← Back to CrewScan