Effective Date: 09/17/2025
1. INTRODUCTION
Crew Eats Inc. (" Crew Eats," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service") for food delivery and pickup at airports.
By using our Service, you consent to the data practices described in this Privacy Policy.
2. INFORMATION WE COLLECT
2.1 Personal Information You Provide
We collect information you voluntarily provide when using our Service:
- Account Information: Name, email address, phone number, password
- Profile Information: Communication preferences, dietary restrictions, crew member verification details
- Payment Information: Credit/debit card details, billing address (processed securely through Stripe)
- Flight Information: Flight numbers, departure/arrival times, airline affiliation
- Order Information: Food preferences, delivery instructions, special requests
2.2 Information Automatically Collected
- Location Data: GPS coordinates, airport location, terminal information (with your permission)
- Device Information: Device type, operating system, unique device identifiers
- Usage Data: App interactions, order history, favorite restaurants, time spent on features
- Technical Data: IP address, browser type, access times, referring URLs
2.3 Information from Third Parties
- Restaurant Partners: Menu availability, order status, preparation times
- Payment Processors: Transaction confirmations, payment status
- Airport Authorities: Security clearance verification (when required)
- Delivery Partners: Delivery status, location tracking
3. HOW WE USE YOUR INFORMATION
We use your information for the following purposes:
3.1 Service Provision
- Process and fulfill food orders
- Coordinate delivery and pickup services
- Facilitate payment processing
- Provide customer support
- Send order confirmations and updates
3.2 Service Improvement
- Analyze usage patterns and preferences
- Improve app functionality and user experience
- Develop new features and services
- Conduct research and analytics
3.3 Communication
- Send service-related notifications
- Provide promotional offers and updates (with consent)
- Respond to inquiries and support requests
- Send important policy or service changes
3.4 Safety and Security
- Verify crew member eligibility
- Prevent fraud and unauthorized access
- Comply with legal obligations
- Protect our rights and interests
3.5 Business Operations
- Manage vendor relationships
- Process payments and commissions
- Maintain business records
- Comply with regulatory requirements
4. INFORMATION SHARING AND DISCLOSURE
We may share your information in the following circumstances:
4.1 Service Providers
- Restaurant Partners: Order details, dietary requirements, delivery preferences
- Delivery Personnel: Contact information, delivery location, order specifications
- Payment Processors: Stripe and other authorized payment services
- Technology Providers: AWS cloud services, analytics platforms, customer support tools
4.2 Legal Requirements
- Compliance with applicable laws and regulations
- Response to legal process (subpoenas, court orders)
- Protection of our rights, property, and safety
- Investigation of potential violations of our Terms of Service
4.3 Business Transfers
- Merger, acquisition, or sale of assets
- Bankruptcy or similar proceedings
- Corporate restructuring or reorganization
4.4 Consent-Based Sharing
- With your explicit consent
- For purposes you specifically authorize
- Marketing partnerships (opt-in only)
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5. DATA SECURITY
5.1 Security Measures
We implement industry-standard security measures to protect your information:
- Encryption: Data encrypted in transit and at rest
- Access Controls: Limited access on need-to-know basis
- Secure Infrastructure: AWS cloud hosting with robust security protocols
- Payment Security: PCI DSS compliant payment processing through Stripe
- Regular Audits: Periodic security assessments and vulnerability testing
5.2 Data Breach Response
In the event of a data breach affecting personal information:
- We will notify affected users within 72 hours
- We will report to relevant authorities as required by law
- We will take immediate steps to contain and remedy the breach
- We will provide regular updates on investigation progress
Note: No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. DATA RETENTION
6.1 Retention Periods
- Account Data: Retained for 3 years after account closure or last activity
- Transaction Records: Retained for 7 years for accounting and tax purposes
- Support Communications: Retained for 2 years after resolution
- Analytics Data: Aggregated and anonymized data may be retained indefinitely
6.2 Data Deletion
You may request deletion of your personal information by:
- Contacting us at privacy@creweats.com
- Using in-app account deletion features
- Submitting a written request to our corporate address
Note: We may retain certain information as required by law or for legitimate business purposes.
7. YOUR PRIVACY RIGHTS
7.1 Access and Control
You have the right to:
- Access: Request copies of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
- Restriction: Request limitations on how we use your data
7.2 Communication Preferences
You can control communications by:
- Updating notification settings in the app
- Unsubscribing from marketing emails
- Contacting customer support
- Adjusting device-level permissions
7.3 Location Services
You can control location access by:
- Adjusting app permissions on your device
- Disabling location services (may limit functionality)
- Using precise vs. approximate location settings
8. INTERNATIONAL DATA TRANSFERS
8.1 Data Storage Location
Your information is primarily stored on Amazon Web Services (AWS) servers located in the United States (North Virginia region).
8.2 Cross-Border Transfers
If you access our Service from outside the United States:
- Your information will be transferred to and processed in the United States
- We implement appropriate safeguards for international transfers
- We comply with applicable data protection laws
8.3 GDPR Compliance
For users in the European Economic Area:
- We provide all rights required under GDPR
- We have a lawful basis for all processing activities
- We implement privacy by design principles
- We conduct impact assessments for high-risk processing
9. CHILDREN'S PRIVACY
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18, we will take steps to delete such information promptly.
10. CALIFORNIA PRIVACY RIGHTS (CCPA)
California residents have additional rights under the California Consumer Privacy Act:
10.1 Right to Know
You have the right to request information about:
- Categories of personal information collected
- Sources of personal information
- Business purposes for collection
- Categories of third parties with whom we share information
10.2 Right to Delete
You have the right to request deletion of personal information we have collected from you.
10.3 Right to Opt-Out
You have the right to opt-out of the sale of personal information (we do not sell personal information).
10.4 Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
To exercise your rights, contact us at privacy@creweats.com or call 1-800-CREW-EAT.
11. COOKIES AND TRACKING TECHNOLOGIES
11.1 Types of Cookies
We use the following types of cookies:
- Essential Cookies: Required for basic app functionality
- Performance Cookies: Help us analyze app usage and performance
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Used for targeted advertising (with consent)
11.2 Cookie Management
You can control cookies through:
- Your device settings
- App preference settings
- Browser controls (for web-based features)
12. THIRD-PARTY SERVICES
Our Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to third-party practices. We encourage you to review the privacy policies of any third-party services you use.
Key Third-Party Services:
- Stripe: Payment processing (see Stripe Privacy Policy)
- AWS: Cloud hosting and data storage
- Analytics Providers: App performance and usage analytics
13. UPDATES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. We will:
- Post the updated policy on our app and website
- Send notifications for material changes
- Indicate the effective date of changes
- Provide at least 30 days' notice for significant changes
Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.
14. CONTACT INFORMATION
14.1 Privacy Inquiries
For questions about this Privacy Policy or our privacy practices:
14.2 Data Protection Officer
For GDPR-related inquiries:
Email: tech.team@creweats.com
14.3 Response Time
We will respond to privacy inquiries within:
- General Inquiries: 5 business days
- Access Requests: 30 days
- GDPR Requests: 30 days
- CCPA Requests: 45 days
15. GOVERNING LAW
This Privacy Policy is governed by the laws of the State of Georgia, United States, without regard to conflict of law principles.
© 2025 Crew Eats Inc. All rights reserved.
This Privacy Policy was last updated on 09/17/2025.