CrewSteps.

CrewSteps · Norka Enterprises Inc.

App privacy policy

Effective October 10, 2026. This policy covers the CrewSteps web app and its Android and iOS apps, including account setup and workplace services. Our website privacy policy separately covers the marketing website and enquiries.

Who handles your information

CrewSteps is owned and operated by Norka Enterprises Inc., Akron, Ohio, United States. Contact info@crewsteps.com about privacy. Your employer or other workspace organization determines how its workplace records are used and who has access. CrewSteps processes those records to provide the service and also uses account, security and service information to operate and protect it.

Information we process

  • Account and contact information: name, phone number, email address, organization membership, role, profile photo, sign-in verification and recovery information.
  • Workplace records: information you or your organization enter, including job and department details, employment dates, onboarding submissions, training progress and assessments, acknowledgments, signatures, certificates, documents, forms and recruiting information. Fields may include addresses, emergency contacts or other employment information requested by your organization.
  • Communications: messages, announcements, attachments, replies and support requests, together with delivery/read status and related activity.
  • Optional wellbeing information: CrewPulse check-ins and surveys may include mood, workload, stress or burnout responses, department context and notes. A request for personal support is a separate, named request.
  • Technical and security information: IP address, session and authentication activity, browser/app/device information, notification installation identifiers and push tokens, permission/preferences, errors and audit events.
  • Organization billing and integrations: subscription status, customer and transaction references and information your organization authorizes us to exchange with connected services. Payment providers handle payment-entry details; do not send card details in chats or support requests.

The information present depends on your role, enabled features, what you submit and what your organization supplies. The app uses files or photos you choose to upload. It does not require access to your address book or background location for these features.

How we use it

We use information to verify sign-in, provide organization-scoped access, deliver onboarding and training, manage workplace documents and communication, provide requested support and wellbeing features, maintain subscriptions and integrations, and investigate errors, abuse and security events. We use essential cookies or session storage to keep you signed in and protect requests.

Phone sign-in uses Google Firebase. Your number and authentication-related information are processed by Google to provide authentication and abuse prevention. Requesting a verification text does not enroll you in marketing texts. See Google’s privacy policy.

Public signup measurement and cookie choices

The public marketing website and employer signup flow use optional Google Ads measurement. Google Ads measurement starts on for US visitors unless they opt out. Outside the US, or when location is unavailable, it stays off until allowed. Saved opt-outs, Global Privacy Control and Do Not Track take priority. The Cookie settings footer link allows or declines measurement across crewsteps.com and app.crewsteps.com. Declining while signed in saves an account-level opt-out, checked before advertising can load in another signed-in browser. If preferences cannot be checked, advertising stays off.

Google may receive public campaign URLs, technical browser information and a random receipt ID after successful trial creation. No signup form contents, passwords, contact fields, employee or patient information, private URLs, documents or messages are included. Advertising tags are excluded from authenticated app screens, native mobile apps and CRM/client or other sensitive workflows. This setup disables remarketing and enhanced conversions; Meta and Google Analytics are not configured. No server-side advertising events are sent. See the Cookie Policy for storage details and choices. Contact our monitored privacy inbox at info@crewsteps.com about applicable privacy rights.

Text messages and preferences

Optional workplace texts use Twilio to process your phone number, message and delivery status. You can opt in from Profile → Communication preferences and opt out there or by replying STOP. Account invitations are sent when your organization has permission to contact you. SMS consent is not shared for third-party marketing. We retain delivery references, verified segment counts and a hashed recipient identifier for organization usage and billing. A minimal opt-out hash may remain after account deletion so we do not contact a suppressed number again. Incoming replies are not routed to workplace conversations; use Messages in CrewSteps. Contact info@crewsteps.com for help.

CrewPulse privacy choices

Check-ins default to anonymous. Anonymous responses are stored without a user ID, private note or direct response-to-participation link. Participation is recorded separately. Choosing private history explicitly links the check-in to your account; organization administrators do not receive that personal history. Department context is optional. Group reports apply minimum participation and answer thresholds to reduce identification of individuals.

Employee surveys are anonymous. Named support requests share the information you choose to submit with the authorized recipients identified in that flow. CrewPulse is a workplace wellbeing tool, not a medical diagnosis, treatment or emergency service.

Who can receive information

  • Your organization and intended recipients: workplace information is available according to roles and permissions. Messages, documents and requests are shared with their authorized recipients. Private and anonymous wellbeing choices follow the rules above.
  • Service providers: hosting, storage, authentication, email/SMS delivery, notifications, payment processing and support providers process information needed for their service. Native notifications use Google Firebase Cloud Messaging on Android and Apple Push Notification service on iOS when enabled. Notification tokens and opaque routing identifiers are used for delivery; native lock-screen messages use generic text.
  • Connected services and optional AI: authorized integrations exchange the information needed for their function. Where an authorized user invokes an enabled AI feature, the prompt and relevant submitted material may be processed by the configured AI provider. Do not include sensitive information that you are not authorized to share. AI features are not necessary for phone sign-in or ordinary account access.
  • Legal and security purposes: information may be disclosed where necessary to comply with applicable requirements, protect rights or address fraud, abuse or security incidents.

CrewSteps does not display advertising or use the Android advertising ID for these services. We do not sell personal information for money or use workplace or wellbeing data for advertising. Optional advertising measurement on the separate public employer signup flow may involve sharing online identifiers with Google; this can qualify as sale, sharing or targeted advertising under applicable law. Data may be processed in the United States and locations used by our service providers.

Paused integrations and employee exports

When an integration is unavailable, customer access and new synchronization are paused. Existing connection settings, imported employee records, mappings, synchronization history and previously verified onboarding progress are retained under the retention and deletion process below. Authorized organization administrators can separately download a manual employee CSV export. These files contain selected employee identity, contact and job details; they do not include Social Security numbers or bank account details. No payroll connection is needed to download a file, and no data is sent to the payroll provider automatically.

Your choices and security

You can edit available profile information, manage notification and communication preferences, decline optional device permissions, and review or revoke signed-in devices. Your organization controls some employment records and access permissions. Contact it or us to correct information you cannot edit yourself.

We use HTTPS, authenticated sessions and server-side organization permissions to protect access. No storage or transmission method guarantees absolute security. Keep verification codes private and use the account-recovery flow if you lose access.

Retention and account deletion

We retain information while needed to operate your account and the organization’s services and for applicable legal, security and recordkeeping purposes. Canceled workspaces and unpaid trials are normally retained for 60 days after cancellation or trial expiry. The specific deletion date is shown in Billing and account notices. Restoring a paid subscription before deletion keeps your workspace records. Active organizations and legally required workplace records may have different retention requirements.

You can request deletion of your account and associated personal data without signing in or reinstalling the app. Email info@crewsteps.com; our target is 30 days after identity verification. We will explain any retained records, reason and applicable retention period, including employer recordkeeping or restricted backup exceptions. Uninstalling the app or signing out does not delete your account. The deletion page explains the process and available help.

Age and policy updates

CrewSteps is intended for workplace users aged 16 and older, including employees aged 16–17 where permitted by their organization and applicable requirements. It is not intended for children under 16. Contact us if you believe information about a child under 16 has been submitted.

We may update this policy as the service changes. The effective date identifies the current version. We will provide additional notice where required. Privacy questions and requests can be sent to info@crewsteps.com.

CrewSteps · Norka Enterprises Inc.