GDPR
Effective Date: August 1, 2026
This statement describes how Crewfare, Inc, a Delaware corporation ("Crewfare," "we," "our," or "us"), collects and processes personal data with respect to data subjects covered by the EU General Data Protection Regulation ("GDPR") and the UK General Data Protection Regulation ("UK GDPR"). Depending on your geographic location, some parts of this statement may not apply to you. Except as described below, we are the data controller of personal data collected from our website. Our physical address is 2678 Edgewater Court, Weston, Florida 33332, USA.
Privacy Contact
For questions about this statement, our processing of your personal data, or to exercise any of the rights described below, contact our privacy team at
privacy@crewfare.com, or write to us at Crewfare, Inc., 2678 Edgewater Court, Weston, Florida 33332, USA.
We have not appointed a Data Protection Officer. Having assessed our processing against Article 37(1), we have concluded that our core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of personal data. We will reassess this position if our processing activities change.
EU and UK Representatives
EU Representative. Our representative in the European Union, appointed under Article 27 of the GDPR, is Prighter EU Rep GmbH, Schellinggasse 3, 1010 Vienna, Austria. You may contact our EU Representative at https://app.prighter.com/portal/crewfare or by writing to the address above.
UK Representative. Our representative in the United Kingdom, appointed under Article 27 of the UK GDPR, is Prighter Ltd, 20 Mortlake High Street, London SW14 8JN, United Kingdom. You may contact our UK Representative at https://app.prighter.com/portal/crewfare or by writing to the address above.
1. GDPR Principles
We comply with the principles expressed to be the core of GDPR compliance:
- Lawfulness, fairness, and transparency. We keep you as informed as possible regarding our processing of your personal data.
- Purpose limitation. All purposes for data processing and collection remain specific, explicit, and legitimate. We use collected personal data only for the purposes for which it was collected.
- Data minimization. We only collect the data which is necessary and relevant for our activities.
- Accuracy. We keep data as up to date as possible and erase or correct inaccurate data.
- Storage limitation. We keep personal information only as long as necessary for the purposes stated in our Privacy Policy.
- Integrity and confidentiality. We protect and secure all personal data we store and process, and we maintain methods to anonymize personal data.
- Accountability. We record our activities and strategies, demonstrate compliance with the GDPR, and continually review and improve our management of personal data.
2. Sources of Data Collection
We collect information about you during your visit and when you use our website, apps, and services:
- When you directly share it with us — for example when you register on the website or app, contact us, sign up for our services or newsletters, make or manage a reservation, or provide information about yourself in person, by phone, by text, or by email.
- Automatically through your use of our services — including your IP address, which pages you visit and for how long, and information about the device you use.
- From third-party sources — including social media platforms where you access our services through a social account, and our partners and processors.
- From our customers and their authorized agents — where an event organizer, production company, agency, or other customer submits a reservation, rooming list, or booking record that names you.
3. Categories of Personal Data
We collect the following categories of personal data:
- Name and last name.
- Phone number.
- Mailing address.
- Email address.
- Date of birth.
- Gender.
- Usernames or handles.
- Internet Protocol (IP) address.
- Geographic location data.
- Reservation and stay details, including arrival and departure dates, room type, number of nights, rate, room assignment, roommate assignment, and confirmation numbers.
- Special requests and preferences submitted in connection with a reservation.
- Payment method information, held in tokenized form by a PCI DSS-validated vault provider.
You have the right at all times not to disclose personal information to us. However, this may limit your use of our website, apps, and services, and we may not be able to provide services to the extent your personal data is required to do so.
4. Special Categories of Personal Data
We do not seek to collect special categories of personal data. However, information you or an event organizer includes in a special request in connection with an accommodation reservation may reveal health, disability, accessibility, or dietary information — for example, a request for an accessible room or a note about a medical requirement.
Where such information is provided, we process it solely to transmit the request to the applicable accommodation provider so that it may be accommodated. We rely on your explicit consent under Article 9(2)(a), or where applicable on Article 9(2)(f), and we do not use this information for analytics, profiling, marketing, or any purpose other than fulfilling the request. Access is restricted to personnel with a business need and each access is logged.
Please do not include sensitive information in a special request beyond what is necessary for the accommodation provider to fulfill it.
5. How We Use Your Personal Information
- To provide you with our products and services, including arranging, managing, and fulfilling accommodation reservations.
- To transmit reservation and rooming list information to accommodation providers.
- To contact you.
- To improve and optimize our products and services.
- To better understand your preferences and to develop and update our products and services.
- To market our solutions.
- To detect and prevent fraud.
- To comply with applicable legal obligations.
- For security purposes.
- For any other specific purpose to which you have specifically consented.
If any such purpose changes, we will inform you of the change.
6. Sharing of Your Personal Information
Under no circumstance do we sell, trade, or rent your personal information. We may share personal data with the following categories of recipients, on the legal bases described below:
- With accommodation providers — the hotels, resorts, and other properties at which reservations are made. To fulfill and service a reservation we disclose guest names, the names of additional guests and roommates, arrival and departure dates, room type and preferences, special requests, guest contact information, and, where a reservation is payable at the property, payment card information. Accommodation providers act as independent controllers with respect to information they process for their own purposes, and their handling of your information is governed by their own privacy policies. Accommodation providers may transmit confirmation numbers, reservation changes, and cancellations back to us, which we use to update the applicable reservation record. Where an accommodation provider is located outside your jurisdiction, this disclosure involves an international transfer, made on the basis that it is necessary for the performance of your reservation contract or of the contract between us and the organization that arranged your reservation.
- With service providers, agents, subcontractors, and vendors performing activities on our behalf, limited to the extent they need such data to perform those activities, and bound by contractual obligations protecting your data.
- With event partners associated with your booking, where you have opted in to receive marketing communications, for their own marketing purposes. Each event partner's use of your personal data is governed by that partner's own privacy policy.
- Within our company group, to better provide you with information and services.
- With professional advisors such as legal, accounting, and banking advisors.
- With public and government authorities and law enforcement, pursuant to legal obligations or where we are compelled under law to disclose personal data.
7. Legal Basis of Processing
We rely on the following legal bases:
- Your consent to the collection or processing of your personal data.
- Processing necessary to perform a contract with you.
- Processing required to comply with a legal obligation.
- Processing necessary to protect the vital interests of you or another person.
- Processing necessary for our legitimate interests or those of a third party, provided your interests or fundamental rights do not override them.
8. International Data Transfers
We are based in the United States and process and store information in the United States.
- Standard Contractual Clauses. We rely on the European Commission's Standard Contractual Clauses, as set out in our Data Processing Addendum at https://crewfare.com/dpa, together with supplementary technical and organizational measures, for transfers of personal data from the EEA and the United Kingdom.
- EU-US Data Privacy Framework. The EU-US Privacy Shield was invalidated by the Court of Justice of the European Union in July 2020 and is no longer a valid transfer mechanism. It was succeeded by the EU-US Data Privacy Framework, for which the European Commission adopted an adequacy decision in July 2023, together with a UK Extension and a Swiss-US equivalent. Organizations that self-certify to the Framework and appear on the Data Privacy Framework List maintained by the U.S. Department of Commerce may receive personal data from the EEA, the UK, and Switzerland on the basis of those adequacy decisions. Crewfare is not currently self-certified to the EU-US Data Privacy Framework.
- Transfers to accommodation providers. Where we disclose your personal data to an accommodation provider located outside the EEA or the United Kingdom in order to fulfill your reservation, that transfer is necessary for the performance of your reservation contract, or of a contract concluded in your interest between us and the organization that arranged your reservation, within the meaning of Article 49(1)(b) and (c) of the GDPR.
9. Data Processing Addendum
A Data Processing Addendum ("DPA") is a contract between a data controller and a data processor governing the processor's handling of personal data. Our DPA is available
here.
10. Your Data Subject Rights
- Right of knowledge or confirmation. To obtain confirmation of whether your personal data is being processed.
- Right of access. To obtain information about the storage of your personal data and a copy of it, together with the purposes of processing, the categories of personal data concerned, and the recipients.
- Right of rectification. To correct or request correction of your personal data.
- Right to erasure. To have your personal data erased without undue delay, where processing is no longer necessary and no overriding legitimate grounds exist.
- Right to restriction of processing. Where the accuracy of the data is contested; where processing is unlawful and you do not want deletion; where we no longer need the data but you require it for legal claims; or during verification of an objection.
- Right to data portability. To receive your personal data in a structured, machine-readable format and to transmit it to another controller.
- Right to object. To object to processing of your personal data at any time.
- Right not to be subject to automated decision-making, including profiling.
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, contact us at
privacy@crewfare.com. We may require verification of your identity before responding. We aim to respond within one month.
Where your personal data was submitted to us by one of our customers — for example by an event organizer, production company, or agency arranging accommodation on your behalf — we generally process it as a processor on that customer's behalf, and we will refer your request to them and support them in responding. Where an accommodation provider has separately processed your data for its own purposes, you may also need to contact that provider directly.
If you believe we have failed to address your request, you may lodge a complaint with a supervisory authority. A list of EU supervisory authorities is available at
https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the United Kingdom, the supervisory authority is the Information Commissioner's Office.
11. Subprocessors
We engage the following data processors, each under an agreement requiring them to process your data only for the purposes we specify and consistent with this statement and our Privacy Policy.
Last updated: August 1, 2026
| Subprocessor | Contact | Data categories | Activity | Location |
| Amazon Web Services, Inc. | aws-privacy@amazon.com | Name, contact info, IP address, usage data, application data | Cloud service provider and data hosting (including Amazon DynamoDB) | United States |
| Skyflow, Inc. | privacy@skyflow.com | Payment card data (tokenized) | PCI DSS-validated data privacy vault; tokenization of payment card data | United States |
| Ketch Kloud, Inc. | privacy@ketch.com | IP address, cookie data, usage data | Consent management and privacy compliance | United States |
| Stripe, Inc. | privacy@stripe.com | Name, contact info, financial data | Payment processing | United States |
| Authorize.net | privacy@visa.com | Name, contact info, financial data | Payment processing | United States |
| Cloudflare, Inc. | privacyquestions@cloudflare.com | IP address, usage data | CDN, DNS, web application firewall | United States |
| Freshworks Inc. | privacy@freshworks.com | Name, contact info, communication data | Customer support and CRM | Global |
| HubSpot, Inc. | privacy@hubspot.com | Name, contact info, email address, usage data | CRM, content management, and marketing email | United States |
| Slack Technologies, Inc. | privacy@slack.com | Name, contact info, communication data | Collaboration tool | United States |
| SendGrid, Inc. | privacy@sendgrid.com | Name, contact info, email address | Transactional email | United States |
| Linear Orbit, Inc. | hello@linear.app | Name, contact info, project data | Project management infrastructure | United States |
| Google LLC or its affiliates | https://policies.google.com/privacy | Name, contact info, email, IP address, location | Email, analytics, location, reCAPTCHA | Global |
We will notify customers in advance of any intended addition or replacement of a subprocessor, in accordance with our Data Processing Addendum.
12. Automated Decision-Making
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
13. Retention
We retain personal data only as long as necessary for the purposes for which it was collected, to resolve disputes, or as required by law. Reservation records, including rooming list data, are retained for the period necessary to fulfill and service the reservation and to meet our legal, tax, and accounting obligations, and are thereafter deleted or de-identified. Payment card information is purged from our vault thirty (30) days following the later of guest checkout or the applicable event end date, or upon termination of the applicable customer agreement, whichever is earlier.
14. Contact
Crewfare, Inc.
2678 Edgewater Court
Weston, Florida 33332, USA
privacy@crewfare.com