crew

Crew Privacy Policy

Effective date: September 12, 2026
Operator: Bradley Portnoy ("Crew," "we," "us")
Contact: privacy@crewfests.com

Crew is a festival companion app for coordinating with your friend group at music festivals. Anyone can create an account; crews themselves are private and invite-only. This policy explains what we collect, why, and your choices.

1. What we collect

Account information. When you sign in with Apple, we receive your name (or the name you choose to share), email address (which may be an Apple private-relay address), and an identifier. You may add a display name and avatar.

Android interest signup. If you join the Android waitlist on our website, we collect the email address you submit and the time you joined. This signup is not linked to a Crew account, and we do not retain your IP address with it.

Content you create. Votes on sets, set ratings, "vibe" reactions, statuses, check-ins, meeting-point pins, saved spots, emoji reactions, feedback (including screenshots you choose to attach), and festival requests (festival name, city, country, approximate dates, and an optional note). If you explicitly attach your exact spot to a meeting-point pin or saved spot, that content includes one fixed precise coordinate.

Safety reports and blocks. When you report content or a user, we collect the reason, any optional details you provide, a bounded snapshot of the reported content, and relevant crew or event context. We also store the user-block relationships you create. Other users cannot enumerate your reports or block list.

Presence information. Crew is built around manual and optional automatic presence. A check-in records the stage or set, time, source, and your account. A stage- or set-level check-in describes your approximate location at that moment. Ordinary check-ins do not continuously track your location. Separately consented administrator surveys are described below.

Location (optional). Auto Check-In needs your location to work out which stage you are standing at. It runs two ways.

While you have the app open, Crew reads a current location fix on your device.

In the background, if you grant Crew Always location access, iOS wakes Crew when you cross the boundary of a stage at a festival you joined. Each time it wakes, Crew takes one accurate reading to work out which stage you are at. Between those readings, while it waits to see whether you stay, Crew keeps a rougher fix on your position — around a hundred metres, enough to tell that you are still at the stage. If you are still there after a few minutes, Crew writes the check-in and lets the rough fix go. If you walked past and left, Crew writes nothing. Crew does not follow you between stages and records no route.

To do this Crew keeps one file on your phone. It records which stage you are at and when you got there, your account identifier, a copy of the festival's schedule and its stage locations so Crew can match a wake without asking our servers, and a note of the last check-in it wrote. It never stores a location reading taken from your phone — the stage locations in it belong to the festival, not to you, and every reading Crew takes is used and then thrown away.

Crew forgets which stage you are at once the check-in is written or the wait runs out. The next time you open Crew after the festival ends or after you turn Auto Check-In off, it drops the festival's schedule. It deletes the whole file when you sign out.

On both Auto Check-In paths Crew uploads only the resulting stage- or set-level check-in, which describes approximate location. Auto Check-In never uploads the location fix itself, and Crew builds no route and no location history.

Crew asks for Always once, from the Auto Check-In settings screen. It asks when you first turn Auto Check-In on, and it explains what it does before iOS asks. If you gave Crew While-Using access instead, that same screen offers an upgrade to Always later, and the upgrade asks the same question. iOS allows the ask once per install, so after that the screen sends you to iOS Settings instead. You can say no and keep using the rest of the app. To stop it later, turn Auto Check-In off in the app, or change Crew's location access in iOS Settings. Either one ends the background wakes.

Separately, when creating a meeting point you may choose Attach My Exact Spot. That action uploads one fixed precise coordinate to the pin and, if you choose to save it, the saved spot. The coordinate is associated with your account when collected and is visible only to members of the selected crew. Exact-spot sharing starts off for every new pin and is not implied by granting location permission or enabling Auto Check-In.

Optional stage-map observation (separate choice). After a successful eligible stage check-in, Crew may offer an action to help improve that stage's map. Before anything is sent, Crew explains the purpose and asks you to share one observation or skip. Sharing authorizes one sample from the location fix held for that check-in. Crew rounds it on your device to a 20 metre grid and uploads the grid cell and horizontal accuracy, not the raw coordinate or observation time. Skip, a missing or stale fix, or cancellation before upload sends nothing. There is no lasting setting, passive trail, or later replay with a new fix. An upload failure is reported and never changes your completed check-in. If the response is lost, the server may already have accepted the sample.

The sample is linked privately to your account and exact check-in until its fixed hourly group closes two hours after the hour starts. Neither other users nor system administrators can read these pending samples directly. Crew creates an administrator-only aggregate only when at least three distinct accounts contributed to the same cell, source type, and hourly group. It then deletes every closed pending sample for that target in the same transaction, including samples from groups that did not reach three accounts. A pending sample expires no later than 24 hours after its group's start, is removed if you delete your account, and cannot be accepted while the protected cleanup process is unhealthy. The retained aggregate has no account, device, crew, pin, check-in, group, observation timestamp, or raw coordinate. Because it has no account link, it cannot later be removed for one account.

Administrator surveys (separate consent). A system administrator can explicitly start a stage survey after agreeing to its disclosure. Crew records precise locations, accuracy and timestamps during that active session, linked to the recording administrator. It can keep recording with the screen locked. Pause, Finish, Discard, permission loss and the displayed timeout stop recording; reopening the app never resumes it automatically. Current system administrators can read the raw trail to review the walked area. Only its recording owner, while still an administrator, can upload samples or change the session. Raw trails are deleted within 30 days, when the owner deletes their account, or when a Discard reaches the server. Offline work stays in protected storage on the owner’s phone until it can sync; expired local work is removed before access. Reviewed boundaries and non-trail evidence remain separate from the raw trail. Ordinary attendee check-ins do not consent to these surveys, and survey coordinates are not sent to analytics or diagnostic logs.

Device and technical data. We collect push notification tokens to deliver notifications you enable. Sentry receives crash reports, sampled performance traces, handled errors, device model and OS version, connectivity and operation tags, and diagnostic breadcrumbs such as screen session duration and the number of zone changes during that session. These events are linked to your signed-in Crew account identifier so we can diagnose recurring failures. The iOS client disables Sentry's default collection of personal information and removes location coordinates from event fields and messages before transmission. Crew does not currently provide an in-app switch to disable this diagnostic reporting. Offline actions are stored locally on your device and synced when you reconnect.

Product analytics. When product analytics is enabled, Crew sends a bounded, closed set of product-interaction events to PostHog server-side through a first-party route. These events describe account and crew acquisition, onboarding progress, voting and lineup completion, Auto Check-In mode selections and whether they saved, invite timing, curated navigation actions, notification lifecycle, public-web traffic/acquisition, and wrap use. There is no PostHog client SDK. The server replaces your Crew account identifier with a random analytics pseudonym; notification-funnel events use a separate random UUID for one logical notification. Public-web events use only closed categories for the public page, source type (direct, search, social, or other), and funnel step. A homepage platform selection creates one random journey UUID in a timestamped destination URL fragment so that explicit attempt can be joined to its iOS or Android outcome. The fragment is removed on arrival, the UUID remains only in page memory, and both the browser and report expire it after 30 minutes; ordinary page views have no visitor or session identifier. Crew does not send PostHog a raw URL, query, referrer, cookie, session identity, persistent browser identifier, IP address, user agent, location, native APNs device token, notification text, advertising identifier, or account, crew, festival, stage, or set identifier. PostHog autocapture and session replay are disabled. This information is not used for tracking or advertising. Share product usage data controls authenticated, account-linked analytics only. Turning it off stops future authenticated, account-linked collection. Signed-out personless invite/wrap opens and public-web events remain default-on; they use no cookie, install identifier, account identifier, or persistent browser identifier.

PostHog processes these events in the United States, on PostHog's US Cloud. Events from an app build also carry that build's release channel — TestFlight, App Store, or a development build — so we can tell whether a change in the numbers tracks a particular build. That value describes the build, not you: it is the same for everyone using that build. Crew's own web pages declare a fourth channel, `web`, when they ask our server whether capture is on. That fourth channel is not an app build; it is Crew's pages open in your browser, such as a wrap page or a join page. Events sent from those pages carry that `web` value. It describes the page origin, not you: it is the same value for every visitor, whether you are signed in or not.

Crew turns analytics on separately for TestFlight builds, App Store builds, and the web. Each has its own conditions.

TestFlight capture will not be enabled until the TestFlight build includes Settings → Privacy → Share product usage data, this policy describes the collection as it will actually run, Crew has executed PostHog's Data Processing Agreement (DPA) incorporating the Standard Contractual Clauses, and Crew has published its App Store privacy answers for this collection. Because TestFlight testers are real users, this policy is accurate before that capture begins rather than after.

App Store capture will not be enabled until everything above is true and, in addition, Apple has accepted an App Store build declaring this collection.

Web capture covers signed-in use of Crew's own web pages. Before those pages capture anything, they ask our server whether capture is on for the `web` channel and whether you have left Share product usage data on. Web capture will not be enabled until this policy describes the collection as it will actually run and Crew has executed the DPA above. The two Apple conditions do not apply, because a website carries no App Store privacy label and no App Store build. The web has no separate switch. Signed-in web capture follows the same Share product usage data setting you choose in the app. Signed-out invite, wrap, and public-web events sit outside this gate entirely: they are personless, no channel check applies to them, and they stay default-on as described above.

Data we do not collect. Outside the separately consented administrator surveys described above, Crew does not track attendee location continuously or keep an attendee location history, in the foreground or background. Background Auto Check-In is limited to the stage arrivals described above, and only the resulting check-in is uploaded. The separate location uploads are the exact meeting-point coordinate, an explicitly shared single 20 metre stage-map cell, and the separately consented administrator survey. We do not collect contacts, health data, or advertising identifiers. We do not sell personal information as defined by the CCPA/CPRA, and we do not serve ads. Section 3 describes the aggregated, de-identified statistics we may share or license; those statistics do not identify you.

2. How we use it

  • Operate the core product: showing your crew where you've checked in, your statuses, votes, and ratings
  • Attach an exact meeting spot only when you explicitly request it
  • Use de-identified, aggregated presence observations to improve app functionality, including suggested festival stage boundaries
  • Use de-identified, aggregated presence and vote observations to produce the aggregate insights described in Section 3
  • Send push notifications you've enabled (each category is individually toggleable in Settings)
  • Generate your post-festival recap ("wrap")
  • Maintain streaks and other in-app features
  • Debug, secure, and improve the service
  • Respond to feedback and support requests
  • Measure interest in an Android app and send Android availability and testing updates to people who join that waitlist
  • Filter shared text before publication, investigate reports (including profile reports with exact current photo evidence), hide violating content, and enforce our Terms

We keep an append-only history of votes, ratings, vibes, and check-ins (changes create new entries rather than overwriting old ones). This history powers features like re-rating sets and your festival recap. Crew may retain location-derived observations for stage-boundary improvement and for the aggregate insights described in Section 3, in each case only after removing direct account, device, crew, pin, and check-in identifiers and preventing the retained aggregate from being joined back to account data. We do not use retained de-identified observations to identify or reconstruct anyone's movements.

3. Who can see your information

Your crew. Crew is a group product. Members of a crew you join can see your display name, avatar, and the statuses you post in that crew. Your check-ins, the presence freshness derived from them, votes, ratings, and reactions work differently. Crew stores each of them once, not once per crew, so anyone who shares any crew with you can see them — not only the crew you were thinking of at the time. A per-crew switch therefore decides what Crew records for you, not who can read a record that already exists. The per-crew Auto Check-In switch is one of these: it decides whether an automatic check-in gets written for you at all. An exact coordinate attached to a meeting point or saved spot is the exception, and it is genuinely crew-scoped: it is visible only to that pin's selected crew. If either of two users blocks the other, Crew hides their profiles and authored activity from each other across shared crews; blocking does not remove either person's crew membership.

Multi-crew privacy. If you belong to more than one crew at the same festival, membership in one crew is never revealed to another. Crew-membership badges are visible only to you.

Service providers. We use Supabase for database, authentication, storage, and backend services; Vercel for web hosting and app-server routes; Sentry for crash, performance, handled-error, and interaction diagnostics; Apple for Sign in with Apple, TestFlight, and push notifications; GitHub for TestFlight feedback and festival-request triage; and Resend for transactional support alerts. We plan to use PostHog (United States) for server-side product analytics only after the capture gates in this policy are complete for the release channel concerned.

Android waitlist emails pass through Vercel's app-server route and are stored privately in Supabase. We do not give either provider permission to use those addresses for its own marketing.

TestFlight-native feedback may send the tester's comment, name/email, device/OS/build metadata, and screenshots from App Store Connect to a private GitHub repository under the Crew operator's personal account. Festival requests may send the submitted name, city, country, dates, note, account identifier, and review metadata to that same repository. In-app feedback remains in Supabase unless separately moved through an operator workflow. Vercel-hosted routes receive open-text requests before Crew's deterministic shared-text filter runs. Shared text and profile photos are not sent to an AI provider, and festival requests are queued for manual review rather than AI review.

Apple receives the APNs token and notification payload needed for delivery. Some current presence and meeting notifications may include a display name, meeting-point name, or stage/set presence in that payload. Resend receives a report identifier, content-type label, and exact report creation timestamp; report details, snapshots, and evidence are never sent by email.

Aggregate insights. We may share or license aggregated, de-identified statistics (e.g., how many users voted for a set, or overall attendance patterns at an event) with festivals, organizers, or other partners, including on a paid or otherwise commercial basis. These insights never identify you, your crew, or your individual activity, and we apply minimum group sizes before sharing. We do not share individual location observations or exact crew-pin coordinates with these partners.

Legal. We may disclose information if required by law, or to protect the rights, safety, or security of users or the service.

We do not sell or share personal information for advertising purposes.

4. Data retention and deletion

  • You can delete your account in Settings. Account deletion immediately removes your profile and personal activity from our active systems, except where retention is required by law. Shared crew content you created, such as saved spots, may remain after we remove its association with your account. Residual copies in encrypted database backups are purged as those backups age out.
  • Open safety reports and their private evidence remain until resolution. After resolution, report evidence, alert metadata, and moderation-audit details are retained for 24 months, then deleted or de-linked. We may retain them longer under a documented legal hold or for a severe or repeat-abuse enforcement need. The minimal tombstone that keeps moderator-hidden content from reappearing may remain while that content exists, but its actor, reason, report link, and other audit metadata are scrubbed after the retention period. Account deletion de-links identifiers where the evidence contract permits; it does not erase evidence that is still inside this safety window.
  • A shared stage-map sample remains privately linked to your account and exact check-in until its fixed hourly group closes two hours after the hour starts. It is removed if you delete your account and expires no later than 24 hours after the group's start. When a group closes, Crew aggregates only groups with at least three distinct accounts and deletes every closed pending sample for that target in the same transaction, including groups below the threshold.
  • Aggregated or de-identified data may be retained while it supports app functionality or the aggregate insights described in Section 3. This can include spatial evidence derived from check-ins for suggesting festival stage boundaries. Retained evidence contains no account, device, crew, pin, check-in, hourly group, observation timestamp, or raw coordinate, and Crew does not attempt to re-link it. Because it no longer identifies an account, it cannot be located or removed through an individual account-deletion request.
  • Local data on your device (offline cache) is removed when you delete the app.
  • We retain an Android waitlist email while we evaluate demand and may contact that address about Android availability or testing. You can withdraw at any time by emailing privacy@crewfests.com, after which we will delete the current signup.
  • PostHog keeps these analytics events for about one year. That period comes from the plan Crew is on. It is not a limit Crew can enforce: PostHog does not offer a retention period it enforces or contractually guarantees, so Crew does not promise one. If Crew's plan changed, the period could change, and we would update this policy. An earlier version of this policy said Crew would evidence an enforced one-year retention limit before turning analytics on. That was wrong, because no such enforcement is available to Crew. This paragraph replaces it.
  • Once analytics capture is enabled, account deletion will remove the private pseudonym mapping and de-link future use of retained events; it will not retroactively erase already retained de-linked analytics events.

5. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing.

European Economic Area / UK. We process your data on the following legal bases: performance of a contract (providing the app), your consent (the Android waitlist and optional features such as Auto Check-In, exact-spot sharing, location contributions for stage-boundary improvement, and push notifications), and legitimate interests (security, debugging, service improvement). We separately rely on your consent to contribute your presence and vote records to the de-identified aggregate insights described in Section 3, including where those insights are shared or licensed to partners on a paid or otherwise commercial basis. There is no in-app setting for that purpose: to refuse it, or to withdraw your consent to it later, email privacy@crewfests.com, and we will exclude your future records from those insights. Refusing or withdrawing it does not limit any part of the app — your votes and check-ins are still collected to operate the product under our contract with you. You may withdraw consent at any time and may lodge a complaint with your local supervisory authority. Withdrawing consent stops future collection and future use for the purpose you withdrew; it cannot identify or remove observations that were already converted into a non-identifying aggregate.

California. We do not sell or share personal information as defined by the CCPA/CPRA. You may request access to or deletion of your information by contacting us.

To exercise any right, email privacy@crewfests.com. We will verify requests from Crew users through their account. If you joined the Android waitlist without a Crew account, we will verify your request through control of the email address you submitted.

6. International transfers

Crew is operated from the United States. If you use Crew from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our providers operate, which may have different data protection laws than your country. PostHog product analytics is planned for its US Cloud, so those events are processed in the United States. For EU and UK data subjects, our approved transfer mechanism is PostHog's Data Processing Agreement (DPA) incorporating the Standard Contractual Clauses. Analytics capture will not be enabled on any release channel — TestFlight, App Store, or the web — until that DPA is executed.

7. Children

Crew is an adults-only service and is not intended for anyone under 18 (or the age of legal majority in their country, if higher). If we learn that an underage person has created an account or provided us information, we will close the account and delete the information except where retention is legally required. Contact us if you believe an underage person is using Crew.

8. Security

We use industry-standard safeguards, including row-level security on our database, transport encryption, and access controls. No system is perfectly secure; please use a strong device passcode and report any suspected issue to security@crewfests.com.

9. Festival and lineup information

Festival schedules displayed in Crew are factual, publicly available event information (artist names, stage names, set times). This content is not personal information about you. See our Terms of Use regarding festival names and trademarks.

10. Changes

We may update this policy as the Service evolves. Material changes will be announced in the app or by notification. Continued use after changes take effect constitutes acceptance.

11. Contact

Bradley Portnoy
privacy@crewfests.com