Legal
Privacy Policy
Last updated: August 16, 2026
This Privacy Policy explains what personal data JetCrewz collects through the JetCrewz platform ("Service"), why, and how it is protected. JetCrewz is a business-to-business product: the companies that subscribe ("Customers") control what data is entered about their own personnel ("Users" - company administrators, payroll staff, and pilots/crew). For data Customers submit about their Users, JetCrewz acts as a data processor on the Customer's behalf; the Customer is the data controller responsible for having a lawful basis to provide that data to us.
1. What we collect
- Account data: name, work email, hashed password, role, and company affiliation.
- Schedule & duty data: rotations, duty codes, calendar entries, daily reports, shift-swap requests.
- Payroll data: compensation terms, duty/per-diem/overtime calculations, pay statements, 401(k) contribution figures. We do not store full bank account numbers; payment card data for company billing is tokenized by our payment processor and never touches our servers in raw form.
- Compliance & travel data: medical and training certification dates, and - where a company uses crew travel booking - travel profile details including phone number and passport number/country/expiry, entered voluntarily to support booking.
- Authentication data: if you enable Face ID / Touch ID / Windows Hello sign-in, we store the public-key credential your device registers (a WebAuthn passkey). We never receive or store your biometric data itself - that stays on your device, under your device manufacturer's control.
- Usage & log data: sign-in timestamps, and error/audit logs needed to operate and secure the Service.
2. How we use it
We use this data to:
- Operate core features - scheduling, payroll calculation and approval, compliance tracking, travel booking;
- Authenticate users and enforce each company's own access permissions;
- Send account-related email (invitations, password resets, pay-period reminders, booking confirmations);
- Process subscription billing;
- Investigate and respond to security incidents, and maintain audit trails of sensitive actions (e.g. payroll approvals, permission changes).
We do not sell personal data, and we do not use Customer Data to train third-party AI models beyond the specific, in-product feature described below.
3. Who we share it with
We share data only with service providers who help us run the Service ("subprocessors"), under contracts that limit their use of it to providing that service:
- Neon - our database host, storing all Customer Data;
- Vercel - application hosting and file storage for uploaded documents;
- Stripe - payment processing for subscription billing and, where enabled, crew travel payments;
- Duffel and Amadeus - flight search and booking providers, used only when a company actively searches or books travel;
- Gmail / Resend - transactional email delivery (invitations, resets, reminders, confirmations);
- Anthropic - used only when a company uploads a certification/compliance document, to extract dates and details from the document image via AI so staff don't have to retype them.
We do not otherwise disclose personal data to third parties except: with your direction, to comply with a legal obligation (such as a valid subpoena), to protect the rights and safety of JetCrewz or others, or in connection with a merger or acquisition of JetCrewz (with notice as required by law).
4. Data retention
We retain Customer Data for as long as the subscription is active, plus a reasonable period afterward to allow export and to satisfy legal, tax, and payroll-recordkeeping obligations. When a Customer deletes their organization, associated data is removed from active systems; backups age out on our standard backup rotation schedule.
5. Security
Passwords are hashed (never stored in plain text). Data is encrypted in transit via HTTPS. Access to Customer Data within the Service is scoped per company - one company's data is never visible to another. We restrict internal access to production data to what is needed to operate and support the Service. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we work to apply reasonable, industry-standard safeguards and improve them over time.
6. Cookies
We use a small number of strictly necessary cookies: a signed session cookie to keep you signed in, and a short-lived cookie used only during Face ID / passkey sign-in. We do not use advertising or cross-site tracking cookies.
7. Your rights
Depending on your location, you may have rights to access, correct, export, or request deletion of your personal data. Because JetCrewz processes User data on behalf of the Customer (your employer), requests should generally start with your company administrator, who can action most of these directly in the product; where that's not possible, contact us at the address below and we will coordinate with the relevant Customer.
8. Children's data
The Service is intended for use by employed aviation crew and company staff, not by children, and we do not knowingly collect data from anyone under 16.
9. International transfers
Our infrastructure providers may process and store data in the United States. Where required, we rely on appropriate safeguards for any cross-border transfer of personal data.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted here with an updated effective date.
11. Contact
Questions about this policy or your data can be sent to privacy@jetcrewz.com.