Privacy Policy
Last updated: August 8, 2026
Crewmate (“Crewmate,” “we,” “us”) provides practice-management software to professional-services firms (the “Service”). This policy explains what we collect, how we use it, and the choices you have. Crewmate is a business-to-business product; each firm is an isolated tenant and controls its own data.
Information we collect
- Account data — name, email, and role of staff users who sign in.
- Client & document data — information firms enter or upload about their clients, including intake forms and tax documents. This may include sensitive personal information (e.g. SSNs, dates of birth) that the firm chooses to store.
- Connected-service data — when a firm connects Google, Dropbox, or Square, we access data from those services on the firm’s behalf (see below).
- Usage data — logs and metrics needed to operate and secure the Service.
Google user data
When a firm connects a Google account, Crewmate requests only the scopes needed to provide features the firm turns on:
- Gmail (read, modify, compose, send) — to index email for search/Q&A, triage incoming client mail, draft replies for staff to review, and send client communications (such as document requests) from the firm’s own mailbox.
- Google Calendar — to read and create events for scheduling.
- Basic profile email — to show which account is connected.
Limited Use disclosure. Crewmate’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except (a) with the user’s consent, (b) for security or to comply with law, or (c) where the data is aggregated and anonymized. Data obtained through Google Workspace APIs is not used to develop, improve, or train generalized AI/ML models.
How we use data
- To provide and operate the features each firm enables.
- To secure the Service, prevent abuse, and meet legal obligations.
- We do not sell personal information or use connected-service data for advertising.
How data is stored and protected
- Data is stored in access-controlled cloud infrastructure with strict per-tenant isolation (row-level security).
- Sensitive client information (e.g. SSNs, uploaded documents) is encrypted at rest.
- OAuth tokens for connected services are stored encrypted and used only to provide the connected features.
Sharing
We share data only with infrastructure sub-processors that operate the Service (e.g. cloud hosting, database, and AI processing providers) under contract, and as required by law. We never sell your data.
Retention & deletion
Firms control their tenant data and may request export or deletion. A firm can disconnect any integration at any time, which revokes Crewmate’s access; connected-service data already indexed can be deleted on request. To request deletion, contact us at privacy@trycrewmate.com.
Your choices
- Connecting Google, Dropbox, or Square is optional and controlled by each firm.
- You may revoke Crewmate’s access to your Google account at any time via your Google Account permissions.
Contact
Questions about this policy: privacy@trycrewmate.com.
See also our Terms of Service.