Legal
Privacy Policy
In effect from 1 October 2026 · Version 2026-10-01.3
Draft for legal review. The section for Crew Off is not written yet.
This is the Privacy Policy of Crew Cab Ventures, for every app we run: the part for every app, then each app’s own section.
For every app we run
This policy explains what our apps collect, why, who else handles it, how long we keep it, and how to see, fix or delete it. One part applies to every app we run, and each app has its own section saying what that app collects and which providers it uses. An app we have not released yet collects nothing until this policy has a section for it.
We do not sell personal information, we do not use it for advertising, and we never have.
Who we are
Crew Cab Ventures, of Edmonton, Alberta, Canada, runs our apps. Our website is crewcabstudios.com. In this policy “we” and “us” mean Crew Cab Ventures.
Our privacy officer is Darren Wood. Write to him at hello@crewcabstudios.com about anything in this policy.
Two kinds of information
Our apps hold two kinds of information, and we handle them differently.
Yours. If you run or work for a business that uses our apps, we hold your account and your business's records. You deal with us directly, and this policy governs that.
Your customers' and other people's. When you use our apps, you give us information about other people, such as the customers you send a change order to. We hold that for you, as your service provider, and use it only to run the app for you. You decide what to collect and how long to keep it. If one of your customers asks us about their information, we send them to you and help you answer.
What every app collects
- Your account: your name, email address, your role on your team, when you last signed in, and your settings.
- Signing in: an emailed code or link, or Google sign-in, or a service such as Jobber. From Google we get your name, email address and picture. We keep a session record so you stay signed in.
- Your business's records: what you and your team put into the app, and what it brings in from services you connect. Each app's section says what that is.
- Agreeing to our terms: when you agree to our Terms of Service and this policy, for example by continuing past the line under a sign-in button, we record who agreed, for which company, to which version, when, and from which IP address and browser.
- Billing: your plan, and the IDs Stripe gives your subscription. Stripe holds your card details; we never see your full card number.
- Help: what you send when you ask for help or give feedback.
- Technical data: server logs, IP addresses, browser and device type, and error reports, so the apps work and we can stop abuse. Usage counters for our limits hold a one-way hash, not your email or address.
Why we use it
We use information to run the apps you signed up for, to sign you in and keep your account secure, to send the messages you ask the app to send, to bill you, to answer you, to find and fix problems, to improve the apps using statistics that do not identify anyone, and to meet our legal duties. We rely on your consent, given when you sign up and use the apps, and on what is needed to provide the service.
We do not use your information, or your customers', for marketing, and we do not let our providers use it for theirs.
Who else handles it
We use a small number of service providers, each for one job. They may use the information only to provide their service to us, and must protect it. These are used by every app or most of them:
- Vercel: runs our websites and apps, and measures how fast pages load. United States.
- Neon: the databases. United States.
- Stripe: subscription payments and sales tax, if you are on a paid plan. United States.
- Google: sign-in with Google, when you choose it. United States.
- Sentry: error reports, when switched on. United States.
- PostHog: usage analytics and session replays, when switched on. United States.
- Anthropic: the AI behind some app features, described in each app's section. United States.
Each app's section lists the others it uses, such as the email service, file storage and the services you connect. We may also disclose information if the law requires it, and we will tell you unless we are not allowed to.
Where it is stored
Most of our providers store and process information in the United States, so your information leaves Canada and may be reachable by courts and authorities there. We choose providers that protect it to a standard comparable to Canadian law.
AI features
Some apps send information to an AI provider to draft, read or answer. Each app's section says which feature sends what, and to whom. We send only what the feature needs, only when someone uses it, and we choose providers whose business terms say they do not train their models on it. What an AI feature produces is a suggestion that a person reviews.
If you connect your own AI assistant (such as Claude, ChatGPT or Muse) to one of our apps, the assistant reads what you ask it to from the app. That assistant is yours: its provider's policy, not ours, covers what it does with what it reads.
Error reports and usage analytics
When they are switched on, our websites and apps send error reports to Sentry and record how pages are used with PostHog, so we can find bugs and make things easier to use.
- An error report says what went wrong, on which page, in which browser and device. Before it is sent we remove anything you typed into a form, your cookies, and the query part of the web address.
- PostHog records the pages you visit and what you tap, and can record a replay of a visit. Anything typed into a form is hidden and never recorded. In the signed-in parts of our apps the replay also hides the text on screen, except labels and buttons we checked hold no customer information.
- When you are signed in, Sentry and PostHog know you only by an internal number, never your name or email. On our websites a visit is known only by a random ID stored in your browser.
- If your browser sends a Do Not Track or Global Privacy Control signal, we do not load PostHog.
Cookies and storage in your browser
- Needed to work: a cookie that keeps you signed in, and short-lived cookies that protect sign-in with services such as Jobber and Google. The apps do not work without them.
- Analytics: when PostHog is switched on, a random ID in your browser, as described above.
- Your preferences: some apps remember things on your device, such as a dismissed tip or where to save photos. That stays in your browser and is never sent to us.
We do not use advertising cookies or trackers.
How long we keep it
We keep your records while your account is open, because that is what they are for: a record from two years ago can matter today. After you close your account you have 60 days to ask for an export. After that we delete your account and its records within 30 days, and from backups within a further 90 days. Logs are kept for up to 12 months. We keep what the law requires longer, such as billing records for tax, and what we need for a legal claim. An app's section says where it differs.
Your rights
You can ask us to show you the personal information we hold about you, to correct it, or to delete it, and you can withdraw your consent (which may mean we can no longer provide an app). Write to hello@crewcabstudios.com. We will answer within 30 days, and we may need to check who you are first.
In Canada, the Personal Information Protection and Electronic Documents Act and Alberta's Personal Information Protection Act give you these rights. If you are not satisfied with our answer, you can complain to the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.
In the United States, some state laws give residents similar rights, such as the right to know, correct and delete. We honour them where they apply. We do not sell or share personal information for advertising, and we will not treat you differently for asking.
If you are one of our customers' customers, ask the business that sent you the link first, since it is their record. If you write to us, we will pass your request to them and help them answer.
Security
Connections use TLS. Keys and tokens for services you connect are encrypted before they are stored. Access to production systems is limited to the people who need it. No service can promise perfect security. If a breach creates a real risk of significant harm to you, we will tell you and the regulator as the law requires.
Children
Our apps are for businesses. They are not meant for children, and we do not knowingly collect information about children.
Changes to this policy
Each version of this policy has a version number and an effective date at the top of the page. When a change matters, we tell account holders at least 14 days before it takes effect, by email and in the app, and our apps show a notice the next time you open them.
Contact and complaints
Darren Wood, privacy officer, Crew Cab Ventures, Edmonton, Alberta, Canada.
Email: hello@crewcabstudios.com
Our apps
Changed
Changed (itschanged.app) is our app for change orders. A contractor writes a change order, sends it to their customer, and the customer signs off from a link on their phone. The part of this policy for every app applies to Changed too; this section adds what is particular to it.
What Changed collects
From the contractor and their team:
- Company details: the company name, logo, phone and email for customers, the terms they add to every change order, and an optional payment link.
- Jobs and customers: jobs, addresses, and customers' names, email addresses and phone numbers, typed in or brought in from Jobber.
- Change orders: the reason, the lines and prices, photos, videos the team records, the schedule, and the timeline of what happened and who did it.
- Forwarded email: emails and attachments a contractor or supplier sends to the company's Changed address.
- Connections: encrypted keys and tokens for Jobber and Quo, and records of the AI assistants the team has connected (we keep only a one-way hash of each assistant's tokens).
From Jobber, when the contractor connects it: the account's name and phone, jobs with their properties and line items, clients' names, emails and phone numbers, products and services, and team members' names, emails and roles.
From Quo, when the contractor connects it: delivery reports for the texts Changed sent, and replies to them.
People who sign off in Changed
If a contractor sent you a change order through Changed, this part is for you. You do not have an account with us, and you never agree to our terms; the change order is between you and the contractor.
What we record when you open and sign off. When you first open the link; whether you ticked the consent box, when, and which version of the disclosure you saw; your name as typed; your signature, drawn or typed; when you signed off; your IP address and browser; and a fingerprint (a hash) of exactly what the page showed you. If you ask for changes, we keep your note. These are recorded so the sign-off can be proven later, which is the point of the product.
Where it goes. Into the signed PDF and its certificate page, emailed to you and to anyone else who signed off with an email address, and available from your link. The contractor's team sees it in Changed, and when the contractor uses Jobber, a link to the PDF goes on the job. Anyone with the PDF's check page address can see the change order's details with emails and phone numbers partly hidden.
Who controls it. The contractor. We hold it for them as their service provider and use it only to run Changed for them. We never use it to market to you, and we never sell it.
What we do not record. Your page and its PDF are never recorded by analytics or session replay, and your signature is never sent to an error report.
How long. As long as the contractor's account is open, then as the part for every app describes. Keep the PDF you were emailed: your link stops working once the records are deleted.
Your requests. To see, correct or delete your information, ask the contractor; their contact details are at the bottom of your page. If you write to us at hello@crewcabstudios.com, we will pass your request to them and help them answer.
Service providers for Changed
Besides those in the part for every app (Vercel, Neon, Stripe, Google, Sentry, PostHog and Anthropic):
- Vercel Blob: stores photos, videos, logos and signed PDFs. United States.
- Resend: sends sign-in codes, invites, change orders and signed copies by email, and receives email sent to company addresses. United States.
- Anthropic: Autofill, reading forwarded emails, and the Ask Changed help chat. United States.
- Cloudflare Workers AI or Groq: turn the sound of a video note into words. The sound is not stored. United States.
- Jobber: only if the contractor connects it, as described above. Canada and the United States.
- Quo: only if the contractor connects it, to send texts from their number. United States.
Texts that go from a tech's own phone are sent by that phone, not by us.
AI in Changed
- Autofill sends the tech's note, the photos, the job's title, address and lines, the last few change orders on the job, and the company's products and services to Anthropic, to draft the change order. It runs only when someone taps Autofill or records a video note.
- Video notes send the sound, in short pieces, to Cloudflare Workers AI or Groq to write down what was said. The sound is not kept, and the words are not logged.
- Forwarded emails and their attachments are read by Anthropic to draft a change order.
- Ask Changed sends the question and the conversation to Anthropic to answer from our help articles. Changed does not keep the conversation.
Nothing the AI drafts goes to a customer until someone on the team sends it.
Photos and videos
Photos, videos and logos are stored at unlisted web addresses so the customer's page, emails and PDF can show them. Anyone with one of those addresses can open it. A video uploaded and then thrown away before its change order was saved may stay in storage until we clear it out.
Analytics in Changed
The customer's page and its PDF are never recorded by PostHog, and the private link to that page is removed from every error report and analytics event before it is sent. Signatures, and what customers see or type, are never recorded anywhere outside Changed's own database.
Matched
Matched (itsmatched.com) links a company's Jobber account to its company card platform. It suggests a Jobber job for each card charge, and when a person confirms, it writes the expense and the receipt link to that job. The part of this policy for every app applies to Matched too; this section adds what is particular to it.
What Matched collects
- From your card platform (Float, Ramp or Brex, or a bank card through Plaid), when you connect it: each charge's merchant, amount, date, cardholder, memo, category and card ID. We keep the platform's key or token encrypted. Receipt images stay with the card platform; Matched keeps only the receipt's ID and fetches a short-lived link when someone opens it.
- Statements you upload: the file, stored encrypted, with card numbers cut to the last four digits.
- From Jobber: clients, jobs, team members, clock-ins and expenses.
- Written to Jobber: an expense with its receipt link on the job you confirm, removed again if you take it out.
- Help: questions you ask Ask Matched and its answers, with a short summary of your account (your plan and usage, which connections are on, and your latest unmatched charges); support requests (name, email, message, the page, your browser, and a hash of your IP address); and feedback on help articles.
Service providers for Matched
Besides those in the part for every app:
- Resend: sign-in emails, the morning email, and support email. United States.
- Anthropic: Ask Matched, the help assistant. United States.
- Your card platform (Float, Ramp or Brex) and Plaid: only if you connect them, to read card charges. Canada or the United States, depending on the platform.
- Jobber: reads your jobs and writes confirmed expenses back. Canada and the United States.
The help assistant
Ask Matched answers questions in plain English. When you ask it something, your question, the conversation so far and the account summary above go to Anthropic. It only answers; it cannot change anything in your account. We keep the conversations with your account so we can answer follow-ups and improve our help articles, and anything we take from them to plan the product is counted and stripped of names and details first.
How long, in Matched
An owner can delete the company in Settings. That removes the company, its people, sign-ins, tokens, charges, chats and statements. Nothing in Jobber or your card platform changes. Support requests and feedback are kept after a company is deleted, with the company link removed, so we can answer them.
Dose
Dose (doseapp.ai) is our app for pool service companies on Jobber. Techs log water chemistry on their phones, Dose reads test strips from a photo, readings sync back to Jobber, and the office sees everything in a dashboard. Dose also has its own privacy policy at doseapp.ai/privacy. The part of this policy for every app applies to Dose too; this section adds what is particular to it.
What Dose collects
- From Jobber, when the company installs Dose: visits and their instructions, job IDs, property addresses, client names, and team members' names, emails and roles. Dose does not store invoices, payments, quotes or message history.
- Pools and readings: each pool's size, shape, surface, targets and address, and each reading with its chemistry and how confident the strip reader was.
- Photos: test strip photos are sent to the AI providers to read and are not kept. An optional pool photo for each reading is stored. Both are resized and have their location data removed on the phone before they are sent.
- Service reports: emailed to the pool owner's address, only after an admin confirms it. We keep the recipient, subject and report.
- On your device: readings saved for working offline, until they sync.
Dose does not use your device's location.
Service providers for Dose
Besides those in the part for every app:
- Railway: runs Dose's server. United States.
- Upstash: a job queue. United States.
- Cloudflare R2: stores pool photos and export files. United States.
- SendGrid: sign-in emails, service reports and export links. United States.
- Google (Gemini) and Anthropic: read test strip photos. Gemini reads first and Anthropic checks. United States.
- Jobber: the integration itself. Canada and the United States.
How long, in Dose
When a company uninstalls Dose from Jobber, access stops, the admin is emailed a link to an export, and 30 days later everything is permanently deleted, including photos and Jobber tokens. An admin can also ask for deletion, which can be cancelled for 7 days. Export links work for 24 hours. A removed tech's past readings stay attributed to them.
The same policy is at crewcabstudios.com/privacy. See also our Terms of Service.