Privacy Policy
Effective 2026-10-01 · MyCrew by Commonbase
1.Scope
MyCrew is field-ticketing software provided by Commonbase LLC of 4 Yard Court, Flemington, New Jersey 08822. This policy governs the MyCrew application at https://mycrew.commonbase.io and the documents it generates. It does not extend to any other website or service.
MyCrew is offered to businesses in the United States (each, a “Customer”) and is hosted there. It is not offered to individuals, nor directed at any other territory. That gives rise to two distinct relationships, which carry different obligations and different rights:
- Commonbase as controller
- In respect of the accounts of individuals who sign in — their name, business email address, and assigned role. Commonbase determines the purposes and means of that processing.
- Commonbase as processor
- In respect of all information a Customer records within its own workspace, including information about its own clients and contacts, the records it keeps, and any documents, images, and signatures it stores. The Customer is the controller of that information. Commonbase processes it on the Customer’s documented instructions, and requests concerning it should in the first instance be directed to the Customer.
2.Information we collect
Commonbase collects only such information as is necessary for the operation of the service. Information is either provided by the Customer, collected automatically in the course of operating the service, or received from a service the Customer has elected to connect. The source of each category is stated below.
| Category | Purpose | Source |
|---|---|---|
| Account information — name, business email address, assigned role, and a hashed password | Creating an account, authenticating a user, and applying access permissions | Provided by the Customer |
| Session information — a hashed token, an expiry time, and a last-seen time | Maintaining and ending an authenticated session | Generated by the service |
| Contact information — the names, email addresses, telephone numbers, and addresses of the Customer’s own clients and contacts | Addressing documents to the correct recipient and requesting signatures | Provided by the Customer |
| Business records — the Customer’s own records of work performed and amounts billed | Providing the service for which the Customer uses it | Provided by the Customer |
| Documents and images uploaded by the Customer | Storing and presenting them as the Customer directs | Provided by the Customer |
| Signature information — the signatory’s name, their handwritten signature, the originating IP address, a timestamp, and the method of signature | Establishing who approved a document and when, which is the purpose of obtaining a signature | Captured at the time of signature |
| Communications — recipient address, subject, and message contents | Sending documents and confirming delivery | Generated by the service |
| Audit information — the nature of each change, the person who made it, and the values before and after | Reconstructing a record in the event of a dispute | Generated by the service |
| Security information — the IP address from which a sign-in is attempted | Detecting and limiting repeated failed sign-in attempts | Collected automatically |
| Technical logs — the route of a failed request and the resulting error | Diagnosing faults in the service | Collected automatically |
| Integration data — such categories of information as a connected service makes available and the relevant integration requires | Operating the integration the Customer has elected to enable, and reconciling records between the service and that system | Received from the connected service at the Customer’s direction |
Signature information warrants specific mention. Where an individual signs a document, Commonbase retains their handwritten signature as part of the executed document, together with their name, the IP address from which the signature was submitted, and the time of submission. That combination is retained in order to render the signature evidentially reliable. It is held with the document and is accessible to the Customer that requested it.
3.Information not collected
Commonbase does not collect, and the service does not record:
- device or browser information, including browser type, operating system, or device identifiers;
- analytics or usage tracking of any kind, within the service or across other websites;
- payment card or bank account details, billing being conducted outside the service; or
- information purchased from data brokers, obtained from social media, or otherwise acquired from sources other than those described above.
Correspondence sent to Commonbase, such as a support request, is retained for so long as is necessary to deal with the matter raised.
5.Disclosure
Commonbase does not sell personal information, does not disclose it for advertising purposes, and does not use it to train artificial intelligence models. Information is disclosed only to processors engaged in the operation of the service, and account administrators will be notified before any material addition takes effect.
Those processors, the purpose of each, and the country in which each operates are published and maintained at Subprocessors. Certain of them support optional integrations and receive information only where a Customer elects to connect the service in question.
Commonbase may further disclose information where required to do so by law, or where necessary to establish, exercise, or defend a legal claim.
6.Storage and security
Information is hosted in the United States. Commonbase maintains administrative, technical, and physical safeguards appropriate to the sensitivity of the information held, including:
- encryption of all data in transit and at rest;
- storage of passwords in hashed form only, such that Commonbase is unable to read or recover a password;
- segregation of each Customer’s data, so that one Customer cannot access another’s;
- signature links that are single-use and subject to expiry; and
- restriction of access to production systems to personnel who require it.
No system is capable of absolute security. In the event of a breach affecting personal information, Commonbase will notify the affected Customer without undue delay, and will notify the relevant supervisory authorities where required by law.
7.Retention
Workspace information is retained for so long as the Customer maintains an account, on the basis that a signed record of work and the amounts billed for it constitute financial records the Customer is generally obliged to retain.
- Workspace information, including signed documents and audit information, is retained for the duration of the account.
- Sessions expire after 30 days and are deleted upon sign-out.
- Database backups are retained for 14 days and are thereafter destroyed on a rolling basis.
- Upon termination, workspace information is deleted or returned in accordance with the applicable terms, subject to the backup period stated above.
8.Rights of data subjects
Depending upon the jurisdiction in which an individual resides, they may have the right to access their personal information, to have it corrected or erased, to obtain a copy of it, and to object to or restrict certain processing.
Where an individual’s information is held within a Customer’s workspace — whether as a contact or as a signatory — the Customer is the controller, and a request should in the first instance be directed to it. A request made to Commonbase will be referred to the Customer, and Commonbase will assist it in responding.
In respect of a MyCrew account, a request may be made in writing to jake@commonbase.io. Commonbase will respond within 30 days. Verification of identity may be required, and no charge will be made in respect of a reasonable request.
9.Notice to California residents
Residents of California are afforded, under the California Consumer Privacy Act, the right to know what personal information is collected and for what purposes, to request a copy of that information or its deletion, to have it corrected, and not to be subjected to discriminatory treatment for having exercised any of those rights.
Commonbase does not sell personal information and does not share it for the purposes of cross-context behavioral advertising. It has not done so during the preceding twelve months, including in respect of any individual known to be under 16 years of age. The categories of information collected are those described in section 2 — identifiers, commercial information, internet activity limited to a signatory’s IP address, and electronic signatures — collected for the business purposes there described and retained for the periods stated in section 7.
A request may be submitted in writing to jake@commonbase.io. An authorized agent may act on an individual’s behalf upon production of written authorization. The majority of information held concerning a Customer’s own clients and contacts resides within that Customer’s workspace, in respect of which the Customer is responsible; such requests will be referred to it and Commonbase will assist in responding.
10.Amendment
Commonbase may amend this policy as the service develops. Where an amendment materially affects the treatment of personal information, account administrators will be notified before it takes effect. The effective date stated above reflects the version currently in force.
11.Contact
Commonbase LLC, 4 Yard Court, Flemington, New Jersey 08822. Inquiries concerning this policy may be addressed to jake@commonbase.io.
See also the Terms of Service.