Privacy Policy
Last updated: 8 May 2026
CrewFinder ("we," "us," or "our") is operated by Aimsio Inc. This Privacy Policy explains how we collect, use, share, and protect information when you use crewfinder.info, the public CrewFinder directory, and the CrewFinder Sales Hub (together, the "Service").
This policy works alongside our Terms of Service and our Sub-processors page. If anything here is unclear, email privacy@crewfinder.info.
Plain-language summary (not legally binding): The public directory is, well, public. The Sales Hub is private to your company - we don't look at your contacts, deals, or quotes for marketing, and we don't sell your data. Card numbers go to our billing partner, not us. You can take your data with you and ask us to delete it.
1. Who We Are and Scope
The Service is operated by Aimsio Inc., a Canadian corporation with offices in Calgary, Alberta. For information governed by the EU and UK General Data Protection Regulation ("GDPR"), Aimsio Inc. is the data controller for the public directory and for account information. For information you put into a Sales Hub workspace ("Customer Data"), Aimsio Inc. acts as a data processor on behalf of the customer organisation ("Customer") that controls the workspace; the Customer is the controller of that Customer Data.
This policy covers everyone who interacts with the Service, including: visitors to the public directory, individuals listed in the directory, account holders, paid and unpaid Sales Hub customers, teammates a customer invites into a workspace, and recipients of estimates sent through the Service.
2. Information We Collect
(a) Public directory information
The CrewFinder directory contains business information about contractors and service providers. Listings include company name, business address, business phone, website, services offered, certifications, and service locations. We compile this information from publicly available sources (government business registries, industry association directories, company websites, press releases, public filings) and from people who submit or claim listings.
This data is public. Anything in a directory listing is visible to anyone visiting the site and may be indexed by search engines. If you do not want a particular piece of contact information to be public, do not include it in your listing.
(b) Account information
When you create an account or claim a listing, we collect:
- Your name and email address (and, depending on the sign-in provider, your profile photo URL)
- The sign-in provider you used (Google, Microsoft, or one-time email link) - we do not store passwords
- The companies you have claimed and your role in each workspace (owner, admin, member)
(c) Sales Hub Customer Data
When you or your teammates use a Sales Hub workspace, the workspace stores the records you create. The customer organisation owns and controls this Customer Data; we hold it on the Customer's behalf. Customer Data includes:
- Contacts: name, email, phone, employer, notes, and values you enter into custom fields
- Companies: the customer organisations and prospects you track (separate from public directory listings)
- Deals: title, stage, currency value, expected close date, notes, and custom fields
- Estimates: line items, taxes, totals, the customer information snapshotted onto the estimate, the share-link token, and (on accept or decline) the moment of response, the email address typed by the recipient, and the recipient's IP address
- Tasks: title, due date, owner, status, notes
- Custom fields: workspace-defined columns (text, number, date, currency, select, multi-select, checkbox) on contacts, deals, and companies
- Files: uploaded estimate PDFs and email attachments
- Workspace membership: the email, role, and capability flags of each teammate the workspace owner has invited
- Activity timeline: a log of changes made to a deal, contact, company, or estimate, plus synced email events on the contact's timeline
(d) Email-integration data (Pro only)
When a teammate connects a Gmail or Microsoft mailbox to their workspace via OAuth, we store:
- An OAuth access key and refresh key issued by the mail provider, encrypted at rest with AES-256-GCM under a key held in our application configuration. These keys never appear in logs.
- The bodies and metadata (sender, recipients, subject, timestamps, message ID, thread ID) of inbound email only where a participant address matches a contact already in the workspace. Newsletters, internal threads, family email, and other unrelated messages are not ingested.
- The bodies and metadata of outbound email composed in the workspace, with the same matched-contact rule applied.
- A per-connection email signature you author for outbound email.
Each mailbox connection is private to the teammate who set it up. Other teammates in the same workspace do not gain access to that mailbox. When a teammate disconnects, we stop syncing immediately and delete the OAuth keys.
(e) Payment and subscription information
For paid subscriptions, our billing partner Chargebee handles card processing. CrewFinder does not receive, store, or process card numbers, expiry dates, or card security codes - those go directly to Chargebee's checkout. What we hold on our own systems is limited to:
- The workspace identifier the subscription is attached to
- The billing-contact name and email address
- The billing address you entered at checkout
- The plan, currency, seat count, and renewal status
- Identifiers used to look up the subscription with Chargebee (no card data)
(f) Estimate-recipient information
When a Customer sends an estimate to its own client, the recipient receives a tokenised link to a page hosted by us where they can view, accept, or decline the estimate. The recipient does not need a CrewFinder account.
From the recipient's interaction with that page we collect: the email address the recipient types into the response form, the IP address and browser identifier of the session, the moment of acceptance or decline, and (for uploaded PDFs) a fingerprint of the exact PDF the recipient was viewing. This information is stored on the estimate as an audit record and is visible to the Customer who sent the estimate. CrewFinder is a processor of this information on the Customer's behalf.
If you are an estimate recipient and have questions about how the Customer who sent you the estimate handles your information, contact that Customer directly. If you cannot identify the sender or believe the estimate was sent without authorisation, email privacy@crewfinder.info.
(g) Technical and log data
When you visit the Service, our hosting and database providers automatically record:
- IP address and approximate location
- Browser type, operating system, and device characteristics
- Pages visited, search queries, and referring website
- Timestamps and short request identifiers
- For sensitive endpoints (sign-in, estimate response), a short-lived rate-limit counter
We use this data to operate the Service, detect abuse, and understand site traffic in aggregate.
(h) Cookies and similar storage
We use a small number of cookies. None of them carry advertising identifiers and we do not run third-party advertising on the Service.
- Sign-in session: a secure, server-side session cookie set after you sign in, so you don't have to sign in on every page load. Required for the Sales Hub to work.
- Active workspace (cf-active-workspace-slug): remembers which workspace you were in last so the workspace-switcher can default sensibly. Lasts roughly one year.
- Mailbox connection state (cf-email-oauth-state): a short-lived (about ten minutes) cookie used during the email-integration consent dance to protect against cross-site request forgery.
- Referral attribution (cf-referral-code): set for thirty days when you arrive via a referral link, so referral credit is correctly attributed to the person who recommended us.
- Aggregate traffic analytics: our hosting provider records anonymous, aggregated visit counts on every page. No individual visitor profile is built.
- Product analytics: we use Google Analytics to understand which pages and features get used. Google Analytics records page views, clicks, and interactions using a first-party cookie (set on
crewfinder.info). Visitors who never sign in stay anonymous: analytics data is not tied to any personal profile. We do not use session replays or record form inputs.
You can clear or block cookies in your browser settings. If you block the sign-in or active-workspace cookies, the Sales Hub will not function correctly.
3. How We Use Information
We use the information described above for the following purposes:
- Provide the Service: display directory listings, run search and map features, host workspaces, sync mailboxes you have connected, send and track estimates, and keep your data available to you and your teammates.
- Verify ownership: confirm that someone claiming a listing is authorised to do so.
- Billing: process subscription charges through Chargebee, send invoices and receipts, and communicate about payment status, renewals, and price changes.
- Communicate with you: reply to support requests, send service announcements, send sign-in links, and (where you have opted in or where applicable electronic-messaging law allows) send occasional product updates. You can opt out of optional product emails at any time.
- Security and abuse prevention: detect brute-force sign-in attempts, rate-limit sensitive endpoints, investigate fraud, defend against scraping, and keep audit records of significant actions in a workspace.
- Improve the Service: understand which features people use, fix bugs, and prioritise improvements, based on aggregate or de-identified data.
- Legal compliance: meet our obligations under applicable law, respond to lawful requests from authorities, and defend legal claims.
We do not sell your personal information. We do not share your Sales Hub Customer Data with other CrewFinder customers. We do not use Customer Data to train machine-learning models.
4. Legal Basis for Processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with a similar legal-basis regime, we rely on the following bases:
- Performance of a contract when we operate a workspace for the Customer that has subscribed to the Service, process a payment, send an estimate the Customer has composed, or otherwise deliver functionality you have asked for.
- Legitimate interests for running the public directory, keeping the Service secure, preventing abuse, defending legal claims, and producing aggregate or de-identified analytics. We balance these interests against your rights and interests; you can object as described in the "Your Rights" section below.
- Consent when you connect a Gmail or Microsoft mailbox to a workspace (consent given through the provider's OAuth screen), when you opt in to optional marketing email, and where applicable law otherwise requires consent. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Compliance with a legal obligation where law requires us to process or retain information (for example, tax-record retention for invoices).
For Sales Hub Customer Data, the Customer is the controller and you should look first to that Customer's privacy notice for the legal basis they rely on. We will support the Customer in responding to data-subject requests as described below.
5. How We Share Information
Public directory listings
Information you submit for a directory listing (and information we compile from public sources for an unclaimed listing) is displayed publicly on the Service and may be indexed by search engines. To remove or edit a listing, visit our listing removal page or email listings@crewfinder.info.
Sub-processors
We rely on a small number of trusted service providers (sub-processors) to operate the Service. They process information on our behalf, limited to the function we've engaged them for, and are bound by written commitments to protect that information. The categories of sub-processor we currently use include:
- A cloud hosting and file-storage provider that runs the application, stores uploaded files (such as estimate PDFs and email attachments), and produces aggregate traffic analytics
- A managed-database provider that hosts the Service's primary database
- A transactional email provider that delivers sign-in links, account notifications, and estimate emails on our behalf
- An address-geocoding provider that converts business addresses into map coordinates
- A rate-limit counter service used to slow down brute-force and abuse traffic on sensitive endpoints
- Chargebee, our subscription-billing and payment-processing partner, visible to you at checkout
- Mapbox, our maps and tile-rendering provider, visible whenever you see a CrewFinder map
- Google and Microsoft, when you sign in with one of them or connect a Gmail or Microsoft 365 mailbox to a Pro workspace
- A product-analytics provider that helps us see which pages and features get used. No form inputs or personally identifiable information is sent
The current canonical list - naming each provider and giving its function and processing region - is published on our Sub-processors page. That page is the authoritative list and is updated whenever our sub-processors change.
Legal disclosures
We may share information when we have a good-faith belief that disclosure is required by law, court order, or other valid legal process; to defend legal claims; to enforce our Terms of Service or Acceptable Use Policy; or to protect the rights, property, or safety of CrewFinder, our customers, or the public. Where the law allows, we will give the affected Customer reasonable notice of a legal request before responding, so the Customer can seek a protective order or otherwise object.
Aggregate and de-identified data
We may compute aggregate, statistical, or de-identified data from how the Service is used (for example, counts of deals created across all workspaces) and use it to operate, secure, and improve the Service and to publish industry-level insights. Aggregate data does not include any information that identifies, or could reasonably be used to identify, the Customer, a teammate, an estimate recipient, or any individual contact.
Business transfers
If CrewFinder is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honour the commitments in this Privacy Policy with respect to your information, and we will notify the affected Customers.
What we do not do
We do not sell personal information. We do not share Sales Hub Customer Data with other CrewFinder customers. We do not run advertising networks on the Service or share information with ad-tech vendors. We do not use Customer Data to train machine-learning models.
6. Workspace Data Ownership
As between CrewFinder and the Customer, the Customer owns all Customer Data. We hold a limited licence to host, process, transmit, display, and back up Customer Data solely as needed to provide, secure, and support the Service for the Customer (see Section 5 of the Terms of Service).
Within a workspace, the workspace owner administers access: they invite teammates, assign roles (owner, admin, member), and remove teammates when needed. Removing a teammate immediately revokes that teammate's access to the workspace.
A small number of CrewFinder operations personnel may access Customer Data on a need-to-know basis to investigate support requests, fix bugs, prevent abuse, or recover lost data. Such access is limited to what the task requires and is bound by confidentiality obligations. We do not browse customer pipelines for marketing research or any unrelated purpose.
7. Data Retention
Public directory
Listing information is retained for as long as the listing is active. When a listing is removed, the associated data is deleted from our active database within 30 days. Search-engine caches and archive sites operate independently of us; you may need to contact them separately to remove cached copies.
Sales Hub workspaces
Customer Data is retained for as long as the workspace is active. Either during the term or within 30 days after termination, the workspace owner can request a one-time export of contacts, deals, and estimates by emailing legal@crewfinder.info from the registered address. After the 30-day post-termination window, we delete Customer Data from active production systems. Residual copies may persist in routine encrypted backups for a limited period (typically up to 35 days) and are then overwritten on the standard backup expiry schedule. This mirrors Section 5 of the Terms of Service.
Email-integration data
OAuth keys for a connected mailbox are deleted as soon as the teammate disconnects the mailbox. Previously synced messages remain on the matching contact's timeline until the contact (or the workspace) is deleted, at which point the associated email history is removed on the same schedule as the rest of the workspace.
Account information and logs
Account records are retained for as long as the account is active and for a reasonable period afterwards to handle disputes, complete legal obligations (such as financial record-keeping), and prevent re-creation of suspended accounts.
Server-side request logs (recording route, response code, timing, IP, and user agent) are kept by our hosting provider for the short retention period set by the relevant service plan - typically hours to days - and we do not export or persist them beyond that.
Search-query records used to operate and improve the directory (the typed query, the location filter, the count of results, the IDs of returned listings) are retained without a fixed cutoff and may be kept indefinitely, including in aggregated form. These records are not linked to individual user accounts.
Rate-limit counters used to prevent abusive request volumes are short-lived and expire automatically within minutes. Sign-in sessions are valid for a finite period and become unusable after expiry.
Billing records
Invoices, payment records, and related billing information may be retained for the period required by applicable tax and accounting law (typically several years), even after a workspace is closed.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorised access, alteration, disclosure, and destruction. These include:
- Encryption in transit: connections to the Service use the same kind of encrypted connection as online banking sites.
- Encryption at rest: stored data is encrypted on disk by our database and storage providers.
- Extra layer for mailbox keys: if you connect Gmail or Outlook, the OAuth keys that let CrewFinder read your inbox are wrapped in a second layer of encryption (AES-256-GCM) under a separately held key.
- OAuth-based sign-in (no passwords stored): you sign in with Google, with Microsoft, or with a one-time email link. We never see your provider password.
- Workspace isolation: each workspace is scoped to its owning Customer; queries are constrained so one Customer cannot read another's data.
- Rate-limiting on sensitive endpoints: automated guessing attacks against sign-in and the public estimate-response page are slowed or blocked.
- Need-to-know operations access: a small number of trained CrewFinder personnel can access Customer Data only when needed to support a Customer or operate the Service.
We do not currently hold formal third-party certifications such as SOC 2 or ISO 27001, and we do not represent that we do. No internet system is impossible to attack; we cannot guarantee absolute security, but the controls above are designed to reduce the likelihood and impact of incidents.
Breach notification
If we confirm a security incident affecting personal information we hold, we will notify affected Customers and, where applicable, individuals and regulators without undue delay, and in any event within 72 hours of confirmation, to the extent permitted by law and law enforcement. The notice will describe what we know about the incident, the categories of data affected, and the steps we are taking. This commitment is in addition to any statutory breach-notification obligations that apply to us or the Customer directly (for example, Australia's Notifiable Data Breaches scheme and the breach-reporting requirements in PIPEDA, GDPR, and applicable U.S. state laws).
9. International Data Transfers
CrewFinder is operated from Canada. Most of our infrastructure is hosted in the United States; some sub-processors operate globally (see the Sub-processors page for the current processing region of each provider). When you use the Service, information about you may be transferred to and processed in countries other than the one in which you reside, including Canada and the United States.
Where we transfer personal information out of the EEA, the United Kingdom, or another jurisdiction with cross-border transfer rules, we rely on appropriate safeguards permitted by applicable law (such as the Standard Contractual Clauses published by the European Commission, the UK International Data Transfer Addendum, or transfers to jurisdictions recognised as providing an adequate level of protection). You can request more information about the safeguards we use by emailing privacy@crewfinder.info.
10. Business Directory Information
The directory contains business information (company names, business addresses, business phone numbers, services offered). This information is distinct from personal information and is compiled from publicly available sources for the legitimate purpose of operating a business directory.
Under most privacy laws, business contact information used for business purposes does not constitute "personal information" or "personal data" in the same way that individual consumer data does.
If you submit a listing, you are providing business information for public display. Any personal contact information (personal email, personal mobile) that you choose to include will also be publicly visible.
11. Your Rights
Depending on where you live, you may have some or all of the following rights with respect to personal information we hold about you. These rights apply to information held in the public directory, account information, and (where we are the controller) Sales Hub Customer Data:
- Access: request a copy of the personal information we hold about you
- Correction: ask us to correct information that is inaccurate, incomplete, or out of date
- Deletion: ask us to delete personal information, subject to limits required to keep records for legal, tax, or security reasons
- Portability: receive a copy of personal information you have provided to us in a structured, machine-readable format
- Restriction or objection: ask us to stop or limit certain processing, including processing based on legitimate interests
- Withdraw consent: where we rely on consent, withdraw it at any time without affecting prior processing
- Complain: lodge a complaint with the data protection authority in your jurisdiction (see the region-specific sections below)
To exercise any of these rights, email privacy@crewfinder.info from the address on your account, or use the listing-removal tools described above for directory listings. We will respond within the time required by applicable law (generally 30 days in Canada, EU, and Australia; 45 days in California, with one permitted extension). We may need to verify your identity before acting on a request.
If you are an individual whose personal information appears in a Sales Hub workspace because a Customer added you (for example, you are a contact one of our Customers tracks, or you received an estimate from a Customer), the Customer is the controller of that information. Please contact the Customer first; we will support the Customer in responding to your request and, where the Customer cannot be reached, will help within the limits applicable to a processor.
12. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to know: what personal information we collect, the categories of sources, the purposes for collection, and the categories of third parties we share it with (all described in this policy)
- Right to delete: request deletion of your personal information, subject to legal exceptions
- Right to correct: request correction of inaccurate personal information
- Right to opt out of sale or sharing: CrewFinder does not sell personal information, and we do not share it with third parties for cross-context behavioural advertising. There is therefore nothing to opt out of, but you may confirm this in writing by emailing privacy@crewfinder.info.
- Right to limit use of sensitive personal information: we do not use or disclose sensitive personal information for purposes that would trigger this right under the CPRA.
- Non-discrimination: we will not deny service, charge a different price, or provide a different level of service because you exercised a privacy right.
To exercise any of these rights, email privacy@crewfinder.info. An authorised agent may submit a request on your behalf with proof of authorisation.
13. European Privacy Rights (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation and equivalent laws. We have set out our legal bases in Section 4 above. In addition to the rights listed in Section 11, you have the right to lodge a complaint with your national data protection authority.
Data Controller: Aimsio Inc., 5005 Dalhousie Dr NW, Unit 175 Suite 1490, Calgary, AB T3A 5R8, Canada. We do not currently have an appointed EU or UK representative under Article 27 GDPR; if this becomes a requirement based on our processing volume, we will appoint one and update this policy.
14. Canadian Privacy Rights (PIPEDA)
If you are in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy laws (Alberta's PIPA, British Columbia's PIPA, and Quebec's Law 25):
- Right to access: request access to your personal information held by us
- Right to correction: challenge accuracy and request corrections
- Right to withdraw consent: withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice
- Right to complain: with the Office of the Privacy Commissioner of Canada or the equivalent provincial authority
Note: business contact information (company name, business address, business phone) used for business directory purposes is generally exempt from PIPEDA when used in a business context.
To exercise your rights, email privacy@crewfinder.info.
15. Australian Privacy Rights (Privacy Act 1988)
If you are in Australia, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs):
- Right to access (APP 12): request a copy of the personal information we hold about you
- Right to correction (APP 13): request correction of personal information that is inaccurate, out of date, or incomplete
- Right to withdraw consent: request listing removal or opt out of marketing communications at any time
- Right to complain: lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have mishandled your personal information
Note: business contact information used for directory purposes is generally not considered "personal information" under the Privacy Act when used in a business context.
Notifiable Data Breaches scheme: if a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme. As described in the Security section above, our standing commitment is to notify affected Customers without undue delay and in any event within 72 hours of confirmation.
To exercise your rights, email privacy@crewfinder.info.
16. Children's Privacy
The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact privacy@crewfinder.info and we will delete it.
17. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top indicates the most recent revision. For material changes that adversely affect your rights, we will give at least 30 days' advance notice by email to the workspace owner's registered address and/or by an in-Workspace notice; the change takes effect at the end of the notice period. Non-material updates (clarifications, formatting, new contact details) take effect when posted.
Contact Us
For privacy questions, requests under this policy, or to exercise any of your rights:
Aimsio Inc.
5005 Dalhousie Dr NW, Unit 175 Suite 1490
Calgary, AB T3A 5R8, Canada
Related: Terms of Service · Sub-processor list · Acceptable Use Policy