Legal

Privacy

Last updated 29 August 2026. This explains what CrewByte stores, why, and what you can do about it.

Who we are

CrewByte provides operations and compliance software to hospitality businesses. For data your team enters into the platform, you are the data controller and we act as your processor. For data you give us directly — an access request, a support email — we are the controller.

What we store

Account data

Name, work email, job title, optional phone number, role, and the sites a person is assigned to. Passwords are never stored — only an Argon2id hash. Staff PINs are hashed the same way.

Operational data

Checklist completions, temperature readings, corrective actions, issues, SOP completions and shift handovers, each with the time it happened and the person who recorded it. This is the evidence trail, and it is the point of the product.

Evidence photos

Photos attached to checks are re-encoded on upload, which strips EXIF metadata including any GPS coordinates the device attached. They are stored outside the public web root and served only to signed-in users with access to that site.

Technical data

IP address and browser user-agent at sign-in and at sign-off events, retained as part of the audit trail. Session cookies are strictly necessary and are not used for advertising. We do not run third-party analytics, advertising pixels or session recording.

Why we store it

  • Contract. To provide the service you've signed up for.
  • Legal obligation and legitimate interest. Food-safety and health-and-safety records exist to be produced on request; the audit trail is what makes them credible.
  • Security. Sign-in metadata and rate-limit records exist to detect and slow down account attacks.

Who we share it with

Nobody, other than the infrastructure providers needed to run the service — hosting and transactional email. We do not sell data, we do not share it with advertisers, and we do not use your operational records to train anything.

How long we keep it

Operational records are retained for as long as your workspace is active, because compliance evidence loses its value if it disappears. On closure we retain data for 30 days so it can be recovered in error, then delete it. You can export everything at any point before that.

Your rights

You can request access, correction, deletion or a copy of your personal data, and object to processing. Email privacy@crewbyte.io and we will respond within 30 days. If a member of your team asks us directly, we will direct them to you as the controller and tell you about it.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Cookies

One session cookie per surface (cb_site, cb_app, cb_console). They are HttpOnly, SameSite=Lax and secure in production. There are no tracking cookies, so there is no consent banner to click through.

Contact

privacy@crewbyte.io