Useful controls, clear responsibilities
CrewSteps provides organization-based access, role permissions, protected credentials, and purpose-specific privacy controls for CrewPulse. These controls support responsible use; they do not establish an organization’s legal compliance on their own.
We are not displaying a “GDPR Ready” or CCPA compliance badge. Applicability, contracts, processing purposes, lawful grounds, notices, retention, and international transfers need to be assessed for the actual deployment.
Your organization’s role
Your employer or organization decides why employee information is entered into CrewSteps, which people have access, and which optional features or integrations are used. Ask your organization for its employee privacy notice and rules for using the platform.
Organizations should review their processing agreement requirements and the provider overview before introducing personal data. Sharing company content with optional AI tools requires an administrator’s explicit action and the appropriate authorization.
Access, correction, deletion, and other requests
For employee information held in your company’s workspace, start with your company administrator or privacy contact. Depending on the applicable law and circumstances, you may be able to request access, correction, deletion, restriction, objection, or a copy of your information.
For information you supplied directly to the public CrewSteps website, or if you need help directing a request, email info@crewsteps.com. Tell us the type of request and your organization. We may need to verify identity and authority through an appropriate channel.
Do not email identity documents or sensitive employee records unless a suitable process has been arranged. These are contact-based requests, not a promise that a particular automated export or deletion tool is available.
CrewPulse choices
Check-ins are voluntary, with an anonymous option. Personal follow-up uses a separate support request and disclosure naming the recipients. Authorized group insights use minimum-size privacy thresholds.
CrewPulse check-ins, support requests, and their access records use a 180-day retention period. This is specific to CrewPulse; it is not a platform-wide retention promise for all employee, training, account, or backup data.
Read the check-in guide and support-request guide for your choices.
Public website privacy
Google Ads measurement starts on for US visitors unless they opt out. Outside the US, or when location is unavailable, it stays off until allowed. Saved opt-outs, Global Privacy Control and Do Not Track take priority. Campaign parameters can be retained in tab storage for up to 30 minutes while measurement is enabled. Website fonts are served directly by CrewSteps. Read our Privacy Policy and Cookie Policy for the public-site scope.
Customer-specific retention, data-location commitments, and contractual terms must be confirmed separately. Contact us if they are part of your procurement requirements.