Crew Route Pro Privacy Policy
1. Scope and Business Role
This Privacy Policy explains how Divergent Logic LLC ("Divergent Logic," "we," "us," or "our") handles personal information in connection with Crew Route Pro, including its websites, web application, companion mobile application, support services, and related communications (the "Service"). Crew Route Pro is business software for companies that schedule and manage office and field-service work.
The business that obtains a Crew Route Pro workspace is the "Customer." In many situations, the Customer decides what information to enter, why to use it, who may access it, and which reports or communications to send. Divergent Logic processes that information to provide the Service to the Customer. Where applicable privacy law distinguishes these roles, the Customer generally acts as the business or controller for information it places in the Service, and Divergent Logic may act as its service provider or processor to the extent provided by the applicable written agreement and law. The U.S. Data Processing Addendum describes those processing obligations when it applies. The Customer is responsible for its own notices, permissions, instructions, and compliance concerning employees, contractors, customers, property owners, and other people whose information it places in the Service.
Divergent Logic independently decides how to handle account registration, billing metadata, website and Service security, support operations, product administration, and its own business communications. This Policy applies to that handling as well.
2. Information Provided by Customer Businesses and Users
Customers and users may provide account and profile information such as names, business contact details, email addresses, telephone numbers, company codes, language preferences, login credentials in protected form, roles, license assignments, and account settings.
Customers may also provide company information such as business name, addresses, telephone numbers, email addresses, websites, logos, industry profiles, service offerings, operating settings, feature selections, and billing contacts. When someone requests a demonstration, asks for support, joins a company workspace, or communicates with us, we receive the information included in that request.
Users choose much of the content entered into the Service. They should provide only information that is appropriate and necessary for legitimate business operations. Customers and users must not submit the prohibited high-risk data identified in the Terms of Service. The Terms are the controlling list if this Policy describes a category differently.
3. Operational, Workforce, Billing, Device, and Security Information
Depending on the features a Customer enables and uses, the Service may process:
- Customer and property information, including names, business names, contact details, billing and service addresses, sites, access instructions, and service history.
- Job and field-service information, including services, estimates, schedules, routes, assignments, notes, forms, materials, completion details, issues, and extra work.
- Photos, files, receipts, insurance documents, signatures, reports, exports, imports, and other content uploaded or generated by users.
- Workforce information, including names, contact details, roles, license types, crew assignments, schedules, time-clock records, notices, PTO or sick balances, and time-off requests. Crew Route Pro PTO and sick forms are not designed to request a medical diagnosis, and Customers should not enter diagnosis details.
- Vehicle and maintenance information, including vehicle descriptions, assignments, insurance metadata and documents, maintenance schedules, odometer information, locations associated with service or maintenance, costs, and receipts.
- Billing and subscription information, including Stripe customer or subscription identifiers, selected licenses, billing interval, trial dates, subscription status, invoice or payment status, and billing events. Stripe processes payment card details through its hosted services; Crew Route Pro is not designed to store full payment card numbers.
- Device and application information, including device type, operating system, application version, language, push-notification tokens, and settings needed to operate web or mobile features.
- Usage, support, and security information, including feature interactions, authentication and session events, request metadata, error and system-health information, support requests and notes, email delivery logs, audit records, and Support View records.
The Service does not use biometric identifiers to identify or authenticate people. Customers must not submit biometric identifiers used for identification. Crew Route Pro handles ordinary job photos and electronic signatures as Customer Data and does not use them for biometric identification.
Not every Customer uses every category. Customers control which optional modules they enable and much of the information their users submit.
4. Sources of Information
We receive personal information:
- Directly from Customers, users, demonstration requesters, and support contacts.
- From Customer administrators or other authorized users who create accounts, assign work, import records, upload content, or send reports.
- Automatically from browsers, mobile devices, servers, security tools, and use of the Service.
- From service providers and integrations, such as Stripe for subscription events, email providers for delivery status, and mapping or weather providers when those features are used.
- From professional advisers or business counterparties when necessary to respond to a request, protect the Service, or maintain business records.
If a Customer provides information about another person, the Customer is responsible for having authority to do so and for giving any notice or choice required by law.
5. How We Use Information
We use personal information as reasonably necessary to:
- Create and administer accounts, authenticate users, maintain sessions, and enforce role and license permissions.
- Provide scheduling, routing, job, customer, workforce, time, PTO, vehicle, maintenance, reporting, mobile, notification, and related features selected by the Customer.
- Store and deliver Customer Data, generate reports, process imports and exports, and send Customer-directed communications.
- Operate trials, subscriptions, billing status, license counts, payment recovery, and Stripe-hosted billing tools.
- Provide support, investigate reported problems, maintain service quality, and communicate about the Service.
- Protect accounts, prevent fraud and abuse, enforce our agreements, audit sensitive actions, and maintain the security and integrity of the Service.
- Monitor performance, diagnose failures, understand feature use, and improve usability, reliability, and functionality.
- Comply with law, respond to valid legal process, exercise or defend legal claims, and protect the rights and safety of Customers, users, Divergent Logic, and others.
- Send administrative messages such as verification, password-reset, security, billing, support, product-operation, and policy notices.
Where applicable law requires a particular legal basis, the basis may include performing a contract, following the Customer's instructions, pursuing legitimate interests such as security and service improvement, complying with legal obligations, or obtaining consent.
6. No Sale of Personal Information and No Generalized AI Training
We do not sell personal information. We do not use personal information or Customer Data from the Service to train a generalized machine-learning or artificial-intelligence model for use across unrelated customers.
We may use aggregated or deidentified information to understand and improve the Service, plan capacity, measure reliability, and develop features. We will take reasonable measures designed to prevent that information from being associated with an identified person or Customer and will not try to reidentify it except to test whether deidentification safeguards work.
We may use automated tools to protect, operate, or support the Service when the tools process information only for those limited purposes and subject to appropriate contractual and security controls.
7. Service Providers and Third-Party Integrations
We disclose information to service providers that help us operate the Service. Their functions may include cloud hosting, databases, private file storage, content delivery, security, error monitoring, authentication support, email delivery, customer support, payment processing, mapping, weather information, mobile application distribution, and push notifications. When the U.S. Data Processing Addendum applies, its verified Schedule 3 and subprocessor terms govern providers that process Customer Personal Information for the permitted purposes.
Stripe provides hosted checkout and customer billing tools. Stripe receives payment and billing information under its own privacy terms. Mapping, weather, mobile-platform, and other optional integrations may also collect or receive information under their own terms. Customers should review third-party terms before enabling or directing users to use an integration.
We may also disclose information to professional advisers, auditors, insurers, financing or transaction participants, government authorities, or other parties when reasonably necessary to comply with law, protect rights or security, investigate abuse, complete a corporate transaction, or establish, exercise, or defend legal claims. If ownership of all or part of the business changes, information may transfer subject to applicable law and appropriate confidentiality protections.
We do not disclose Customer Data to another customer except at the Customer's direction or when legally required.
8. Customer Administrators and Customer-Directed Disclosures
Customer administrators control workspace membership, roles, licenses, settings, and access to Customer Data. Depending on assigned permissions, other authorized users may view, add, change, export, or send information. A Customer may also direct the Service to send reports, notices, invitations, files, or other content to recipients it selects.
Divergent Logic does not decide whether a Customer's recipient list, workforce monitoring, photograph, signature, time record, route, access note, or report is appropriate. The Customer is responsible for limiting access, selecting the correct recipients, obtaining necessary permissions, and honoring requests from its employees, contractors, and customers. People seeking access to or correction of Customer-controlled records should normally contact the Customer first.
9. Support View and Internal Access
Authorized Divergent Logic personnel may access account information and Customer Data when reasonably necessary to provide support, investigate security or abuse, maintain the Service, comply with law, or protect rights and safety. Access is limited by role and business need.
Where Support View is used, the current controls require an authorized platform role and a stated reason, create audit records, show a persistent Support View banner, and provide an action to end the session. Support View is a powerful troubleshooting capability and is not represented as a technically hard read-only mode. We expect personnel to avoid changing Customer Data unless the Customer authorizes the change or action is necessary to address a security, legal, or service-integrity issue.
10. Cookies, Local Storage, Sessions, and Mobile Permissions
The web Service uses cookies and similar browser storage to authenticate users, maintain secure sessions, prevent cross-site request forgery, remember preferences such as theme and language, preserve limited interface state, and support troubleshooting. Some security cookies are HttpOnly and are not readable by normal browser scripts. Local or session storage may hold account or interface identifiers and cached state needed for the experience. Customers can clear browser storage, but doing so may sign a user out or reset preferences.
The mobile application may request access to the camera or photo library when a user chooses to capture or upload job photos or other authorized content. It may request notification permission to deliver work or account alerts. Device settings control these permissions, and disabling them may limit the related feature.
The mobile application does not currently request device GPS or other precise-location permission or track live device location. Users may enter service addresses, routes, and vehicle or maintenance locations, and enabled integrations may provide them. Crew Route Pro does not treat a service address as proof of a user's live device location.
Our providers may use necessary technologies to deliver their services. We will describe any materially different advertising or analytics technology before using it where notice or consent is required.
11. Security Practices and Incident Notification
We use administrative, technical, and organizational measures designed to protect personal information. Current measures include authenticated routes, server-side permission checks, organization-scoped access, protected sessions, private-file handling, signed or authenticated file access, upload type and size checks, server-side email sending, secret-management requirements, rate limits, audit records for sensitive actions where implemented, and security monitoring.
If we discover a security incident involving Customer Data, we will notify the affected Customer and provide reasonable cooperation as required by applicable law and any applicable written agreement. The Customer remains responsible for notices it must give to its employees, customers, regulators, or other people concerning Customer-controlled information.
Customers also affect security. They must use appropriate roles, protect credentials, remove access promptly, secure their devices and email accounts, and avoid uploading unnecessary sensitive information.
No internet service, storage system, or transmission method is completely secure. We do not guarantee that unauthorized access, loss, or misuse will never occur. Customers should contact `support@crewroutepro.com` promptly if they suspect an account or security problem.
12. Retention and Deletion
We retain personal information for as long as reasonably necessary to provide the Service, maintain legitimate business and security records, comply with legal obligations, resolve disputes, enforce agreements, and complete backup or deletion processes. The appropriate period depends on the information type, account status, Customer instructions, operational need, sensitivity, security risk, legal requirements, and applicable limitation periods.
Payment problems alone do not trigger immediate deletion of Customer Data. After cancellation or termination, access may end before all information is removed from active systems or backups. Information may remain for a limited period in backups, audit records, fraud-prevention records, email logs, billing records, or legal files and may be isolated from ordinary use until deletion or expiration. Aggregated or deidentified information may be retained when it no longer identifies a person or Customer.
Customers should export information available through the Service before access ends and contact `support@crewroutepro.com` about account deletion or available export options. We do not promise a fixed post-cancellation export window or a single retention period for every category.
13. Cross-State and International Use
Divergent Logic operates the Service from the United States and may use providers that process information in the United States or other places where they operate. Privacy and data-protection laws may differ across locations.
Customers are responsible for determining whether they may use the Service for people or operations in a particular state or country and whether they need additional notices, agreements, consents, transfer safeguards, or settings. This Policy does not represent that the Service is designed to satisfy every international, state, industry-specific, or regulated-data requirement.
14. Privacy Rights and Requests
Depending on where a person lives and how the Service is used, applicable law may provide rights to request access, correction, deletion, or a copy of personal information; to object to or restrict certain processing; to withdraw consent; or to appeal a denied request. These rights are subject to definitions, thresholds, exceptions, identity verification, and the respective responsibilities of Divergent Logic and the Customer.
For Customer-controlled workforce, customer, job, photo, signature, time, PTO, or report information, contact the Customer business that collected the information. The Customer may use Service tools or ask us for reasonable assistance. For information Divergent Logic controls directly, send a request to `support@crewroutepro.com` and describe the account and request. We may ask for information reasonably necessary to verify identity and authority. An authorized agent may make a request where applicable law allows it, subject to verification.
If we deny a request, we will give the general reason when applicable law requires it. Where applicable law provides an appeal right, the response will include appeal instructions, or the person may appeal by replying to the response. If we deny the appeal, applicable law may permit the person to contact the relevant privacy regulator.
We will not discriminate against a person for exercising an applicable privacy right. We may retain information when required or permitted for security, fraud prevention, billing, recordkeeping, legal compliance, disputes, or the rights of others.
15. Children and Workforce Users
The Service is offered to businesses and is not directed to children under 13. A person who creates or purchases a Customer account must have legal authority to bind the business and must not be under 18.
A Customer may have workforce users who are under 18 where employment and privacy laws permit. The Customer, not Divergent Logic, decides whether to create those accounts and is responsible for obtaining parental, guardian, worker, or other authorization when required. If we learn that personal information from a child under 13 was submitted without valid authorization, we will work with the Customer to investigate and take appropriate action.
16. Changes, Language, and Contact
We may update this Policy as the Service, our practices, or legal requirements change. The published Policy will identify its effective date and version. We will provide notice of a material change through the Service, by email, or by another reasonable method as required by applicable law. If a change requires consent, we will seek it before applying the change as required.
English is the controlling language of this Policy. A Spanish translation may be provided for convenience and accessibility. If the versions conflict, the English version controls to the extent permitted by law. We intend the Spanish version to communicate the same substance and will correct a confirmed translation error.
Questions, privacy requests, and security concerns may be sent to `support@crewroutepro.com`.