Archived version
Privacy Policy
Version 2.3 · Effective 2026-07-26 · jamcrew-privacy-v2.3
SHA-256 9c8e58523bf2aec87c3977af21813ce3306d820f7a6313f9c154eb403af5ab5a
This page is a permanent record. Its words are frozen at the hash above and will never change. Later revisions are published as new versions at their own addresses.
For the version in force today, read Privacy Policy.
Privacy Policy
Version 2.3 · Effective July 26, 2026 · Replaces the version dated February 15, 2026
JamCrew is crew management software for live events. Production companies sign up, get a workspace, and use it to run rosters, gigs, schedules, timesheets, and pay. Crew members use it to take gig offers, check in on site, message their team, and get paid.
This policy covers the JamCrew marketing site at jamcrew.io, the crew app, the admin dashboard, and every workspace subdomain. It describes what the platform actually does today. Where we have not verified something, we say so rather than guess.
JamCrew is operated by Made by Jam LLC, based in Gainesville, Georgia, United States. For anything in this document, write to privacy@jamcrew.io (mailto:privacy@jamcrew.io).
1 · Two roles, and why the difference matters to you
JamCrew handles two kinds of data, and we have a different job for each one. This split is the backbone of everything below.
Data your employer puts into their workspace
Crew profiles, skills, availability, gigs and assignments, schedules, timesheets, check-ins, documents, pay records, and messages inside a workspace belong to the company that runs that workspace. That company decides what to collect, who on their team can see it, how long to keep it, and when to delete it. In privacy law terms they are the controller, and JamCrew is the processor. We hold and move that data on their instructions and under our agreement with them. We do not use it to build our own profile of you, we do not sell it, and we do not repurpose it.
In practice, if you are on a crew: your employer is the one to talk to first. Ask them to correct a wrong pay rate, delete an old document, change who can see your phone number, or remove you from the roster. We cannot make those decisions for them, and if you ask us directly we will normally pass the request to the workspace that holds the record and tell you we did. We will help them carry it out.
Data we decide about ourselves
For some things JamCrew is the controller, meaning we decide the purpose and we answer for it directly:
- Your JamCrew account itself: your login identity, email address, and the security records tied to signing in.
- Workspace billing: the subscription, the plan, invoices, and what we need to charge for the service.
- Visitors to jamcrew.io: marketing pages, demo requests, contact forms, newsletter signups.
- Measurement, error monitoring, and session replay across the site and the app.
- Our own security, fraud prevention, support correspondence, and legal records.
Some records sit in both buckets. Your name and email are account data we control and also part of a crew profile your employer controls. When that happens, both sets of rules apply to their own copy of the record.
2 · What the platform holds
This is the honest list. Not every workspace uses every feature, so not every field below will exist for you. Fields marked optional are only present if you or your admin filled them in.
Profile and identity
Full name, email address, phone number, profile photo, short bio, job role, skills, certifications, preferred language, and your membership in one or more workspaces. Optional: legal name, legal address, home address with approximate coordinates used for travel distance, and birthday stored as month and day.
Travel and passport data
If your workspace books flights for you, we store the passenger details an airline requires: date of birth, gender, passport number, passport expiry, passport country, and known traveler number. These are sent to Duffel to search and book flights, and flight status is looked up through AviationStack. This is the most sensitive category on the platform. It exists only for people whose workspace uses gig travel booking.
Pay, banking, and tax
Timesheets, approved hours, pay rates, pay runs, and payout records. Payouts run through Stripe Connect, so we hold your Stripe Connect account identifier, the payout status, and the last four digits of the bank account. We do not hold your full bank account number or card number. Stripe does. For tax we hold the last four digits of a tax identification number and, where a workspace generates them, 1099-NEC records with the total compensation for the year and the generated PDF.
Location at check-in
When you check in to a gig, the app asks your browser for your position and stores the latitude and longitude with the time entry, so your admin can confirm you were on site. Your browser asks for permission first, and you can refuse: a time entry can also be recorded manually without coordinates. We store the coordinates from the moment of check-in. We do not track your location in the background or between check-ins.
Messages, SMS, and notifications
In-app messages are stored with their full text, the sender, and the channel. When your workspace sends you an SMS, we log the destination phone number, the full message body, the delivery status, the notification type, and any error the carrier returned. That log exists so admins can prove a notice was sent and so we can debug delivery. Twilio also processes those messages. If you turned on web push notifications, we store the push subscription your browser issued, which includes an endpoint URL and the encryption keys needed to deliver a message to that browser.
Documents and emergency contacts
Crew documents uploaded by you or your admin: contracts, tax forms, identification, certifications, and anything else a workspace asks for. We store the file, its name, size, type, who uploaded it, and any expiry date. We do not inspect the contents.
Emergency contacts are personal data about somebody else. If you add one, you are giving us that person's name, phone number, relationship to you, and any note you write. Please tell them you did. Your workspace can see it, and it is there so somebody can be reached if something happens on site.
Workspace and account records
Company name, subdomain, logo, brand colors and fonts, plan and subscription state, invoices, the members of the workspace and their roles, marketing email preferences, and the time you accepted our Terms of Service.
Device and usage data
Requests to our servers carry the ordinary things a request carries: IP address, approximate country derived from it, browser and operating system, referring page, and the time. We also record pages viewed, features used, and errors encountered. Some of that is essential to serving the site and securing it. The optional part is described in sections 4 and 5.
3 · Why we process it
- To run the service. Authenticate you, resolve your workspace, show gigs, record hours, move payouts, deliver messages and notifications, and book the travel a workspace asks for.
- To bill for it. Subscriptions, invoices, dunning, and the records an accountant needs.
- To keep it working and safe. Error monitoring, abuse and fraud prevention, rate limiting, and investigating incidents.
- To improve it. Measurement and session replay, under the controls in sections 4 and 5.
- To talk to you. Transactional notices you cannot switch off because they are the service, and marketing email you can switch off at any time.
- To meet legal obligations. Tax, accounting, responding to lawful requests, and defending or bringing a claim.
Where a legal basis is required, we rely on performance of a contract for running and billing the service, legitimate interests for security, debugging, and defending the business, consent for optional measurement, diagnostics, session replay, and marketing email where consent applies, and legal obligation for tax and compliance records. For workspace crew data we act on our customer's instructions and that customer sets the basis.
4 · Session replay, named plainly
This section deserves your attention more than any other, so we are not burying it.
We use PostHog session replay. When it is running, PostHog reconstructs your session: the pages you moved through, where you clicked, where you scrolled, and how the interface changed. It runs on the JamCrew marketing site, not only inside the app. Masking cuts down what a recording contains, but a replay is still a record of one real person's visit, tied to the browser it came from, and to your account if you were signed in.
When it runs
- If your visit resolves to the United States, replay is permitted by default under notice and opt out. Recording still does not start on page load. It starts only after your first interaction: a pointer press, a touch, a key press, or a scroll. If you arrive, read, and leave without touching anything, nothing is recorded.
- If your visit resolves to the EEA, the UK, or Switzerland, or if we cannot determine your region, replay stays off until you allow the Session replay category in the consent banner. It is its own category. Allowing analytics does not turn it on. If you do allow it, the same first-interaction rule applies: the interaction gate is not a United States rule, it runs everywhere.
- If your browser sends Global Privacy Control, replay is off everywhere and a saved allow does not override that.
- You can turn it off at any time from Cookie settings, in any region. When you do, recording stops immediately and PostHog storage in your browser is cleared.
What is masked or excluded
- Every input field is masked, along with page text and element attributes, before anything leaves your browser.
- Console logs, request and response bodies, request headers, fonts, and cross-origin frames are not recorded.
- Sensitive areas of a page can be blocked from recording entirely, and we mark them in our own code.
- Replay never runs on sign-in, sign-up, login, settings, billing, payroll, payments, invoices, onboarding, or account pages. If a recording is in progress and you navigate into one of those, it stops.
Sentry also records a replay when something breaks
We use Sentry for error monitoring. Sentry does not sample ordinary sessions, but when an error occurs it captures a replay of the moments around that error so we can see what went wrong. That is a separate recording from PostHog, it happens only on an error, and it runs only when the Diagnostics category is permitted for your region and your choice. Error reports are run through a filter that redacts email addresses, cuts URLs back to the origin and path so query strings never arrive, and drops keys that carry contact, identity, financial, location, or credential material.
5 · Analytics, cookies, and how your region changes the default
JamCrew is region gated rather than banner free. Which default you get depends on the country your request resolves to, and you can change it in any region from the Cookie settings (#cookie-settings) panel, which is also linked in the footer of every page.
If your visit resolves to the EEA, the United Kingdom, or Switzerland, or if we cannot determine your region at all, nothing optional loads until you allow it and you get a banner where refusing is exactly as easy as agreeing. Everywhere else, measurement and diagnostics run under notice and opt out, and this policy is that notice. Session replay is its own category in every region and defaults on only for a confirmed United States visit. If your browser sends Global Privacy Control, every optional category is denied in every region, and a saved allow does not override it. The full matrix, region by region and category by category, along with the per-cookie list, is on the Cookie Declaration (/cookies).
Essential cookies are never optional: your sign-in session, the cookie that routes you to the right workspace, the cookie that stores your privacy choice, and the request-forgery protection. Your choice is stored in a first-party cookie named jc_consent for 180 days, along with which region policy applied and how the choice was made.
- Google Analytics 4 loads only for non-regulated regions, and only when Measurement is permitted. A visitor in the EEA, the UK, Switzerland, or an unknown region never gets GA4, even after allowing Measurement. Advertising storage, advertising user data, and ad personalization are set to denied in every region for every visitor, and Google Signals is off. We send page views by hand with the URL cut back to origin and path, so query strings never reach Google.
- PostHog loads when Measurement or Session replay is permitted, and covers product analytics, replay, and feature flags. Surveys and duplicate performance collection are switched off.
- Vercel Analytics and Speed Insights run in every region without a consent gate. They set no cookies and collect no identifiers.
- Sentry follows the Diagnostics category, as described in section 4.
Both optional scripts load on browser idle rather than during page load, so withdrawing consent is immediate while loading is not. When you withdraw, we stop recording, opt the vendor out, and erase that vendor's cookies and browser storage.
We do not act on the older Do Not Track browser header. We do act on Global Privacy Control, which is described in the next section.
6 · Providers we send data to
These are the providers live on the platform today. Each processes data under its own terms and its agreement with us. Some appear only when your workspace admin connects them.
The platform itself runs on Clerk for authentication and sign-in, Convex for the application database, and Vercel for hosting, content delivery, and the cookieless Vercel Analytics and Speed Insights. Stripe handles subscription billing and crew payouts. Resend delivers email and Twilio delivers SMS, including the message bodies. Sentry receives sanitized error reports and records a replay when something breaks, Google runs Google Analytics 4 in service-provider mode with advertising signals off in every region and is also one of the sign-in providers, and PostHog runs product analytics, session replay, and feature flags. Duffel searches and books flights and receives the passenger record, passport number included, while AviationStack looks up flight status from flight numbers and dates. Browser push services at Apple, Google, or Mozilla deliver web push notifications. Three more receive nothing until one of your workspace admins connects them: Slack for channel notifications, and QuickBooks and Xero for accounting sync.
One page owns that list rather than two. Subprocessors (/subprocessors) carries the full table, what each provider does for you, where it processes data, the 30 day notice before a new one starts, and your right to object to a change.
We also disclose data to professional advisers, and to authorities where we are legally required to or where it is necessary to investigate fraud, abuse, or a security incident. If the business is ever sold or merged, records may transfer with it, and this policy travels with them until it is replaced. If you run a workspace, our Data Processing Addendum (/dpa) already applies to you automatically. It carries the standard contractual clauses and the 30 day subprocessor change notice, and there is nothing to request. We will countersign a copy for your procurement file on request at legal@jamcrew.io.
7 · Your privacy rights
Depending on where you live, you have some or all of the following rights. We extend the core ones to everyone rather than checking your address first. Some of these laws may not apply to a company our size yet. We are not going to make you look that up before we answer you.
- Know and access. Ask what we hold about you, the categories, the sources, why we process it, and who we share it with. Ask for a copy.
- Correct. Fix anything inaccurate.
- Delete. Ask us to erase your personal data, subject to the exceptions in section 8.
- Portability. Get your data in a portable format.
- Opt out. Opt out of any sale or sharing of personal information, of targeted advertising, and of profiling with legal or similarly significant effects.
- Limit sensitive data. Ask us to limit use of sensitive personal information to what is needed to provide the service. The sensitive material on this platform is passport data, tax identifiers, and precise check-in location.
- Appeal. If we turn a request down, you can appeal. Reply to our decision and we will review it and answer in writing, with the reasons.
- No retaliation. We will not degrade the service, change your price, or treat you differently for exercising any of this.
- If you are in the EEA or the UK, you also have the right to object to processing, to restrict it, to withdraw consent at any time without affecting what came before, and to complain to your local supervisory authority.
We do not sell your personal information
JamCrew does not sell personal information. Selling data is not our business model and it is not going to become one.
What your employer puts into a workspace is walled off from all of this, permanently. Crew profiles, phone numbers, client contacts, gigs, schedules, timesheets, messages and pay records are held under our agreement with that company. They are never sold, never shared with advertisers, and never used to target anything, here or anywhere else. That does not change.
Today we also do not share any personal information for cross-context behavioral advertising. We run no advertising network, no ad pixels, and no remarketing. Advertising signals are denied in Google Analytics in every region, for every visitor, whatever anyone has consented to.
If that ever changes for visitors to our marketing pages, it will be said here first, and a "Do Not Sell or Share My Personal Information" link will appear in the footer with a working control behind it. Workspace data stays out of it either way.
Global Privacy Control
Your browser right now
Global Privacy Control:
We honor Global Privacy Control as an absolute opt-out, in every region, for every visitor. If your browser or extension sends the signal, every optional category is switched off, no optional script loads, no session replay runs, and no consent banner is shown. A saved "allow" does not override it. We read the signal both from the request header and from your browser, and either one is enough.
Some browsers send it on their own, some have a setting for it, and for the rest there are free extensions that add it. The maintained list lives at globalprivacycontrol.org (https://globalprivacycontrol.org). Turn it on, reload this page, and the card above will say active.
How to exercise a right
Email privacy@jamcrew.io (mailto:privacy@jamcrew.io?subject=Privacy%20request) from the address on your account, tell us what you want, and we will take it from there. That is the whole process.
- Verification. We confirm it is you by writing back to the email address on the account, and for sensitive requests we may ask something only the account holder would know. We will not ask you to send us a photo of your driver license to prove who you are. Collecting more identity documents to protect identity documents is not a trade we are willing to make.
- Timing. We confirm receipt, and we aim to respond within 30 days, and within 45 where the law allows an extension for a complicated request. If we need the extra time, we will tell you before the first 30 days are up, along with why.
- Authorized agents. Someone can act for you if you give them written permission. We will ask to see it, and we may ask you to confirm directly.
- Cost. Free. If someone files the same request over and over we may charge for the repeats or decline them, and we will say which.
If we say no
We will tell you why, in the reply, in plain words. To appeal, reply to that email with the word appeal in it. A different person reviews it and responds within 45 days, with the reasoning either way. If you are still unhappy, you can complain to your state attorney general, or to your data protection authority if you are in the European Economic Area, the United Kingdom, or Switzerland. We would rather you came back to us first, but nothing here is meant to stop you.
Email, SMS, and push
- Marketing email. Every one carries an unsubscribe link. It works immediately. Operational email about a gig you are booked on, a payment, or your account keeps coming, because that is the product doing its job.
- Text messages. Reply STOP to any JamCrew message, or email privacy@jamcrew.io (mailto:privacy@jamcrew.io) and we will switch them off for you.
- Push notifications. Turn them off in your browser or device settings, which removes the subscription we send to.
One important limit, from section 1: if the record lives inside a workspace your employer runs, they decide. Send the request to them. If you send it to us, we will route it and tell you where it went, and we will help them act on it. We cannot delete a customer record on your behalf without their instruction, and we cannot delete records another provider keeps for its own purposes.
8 · How long we keep things
We describe the model rather than pretend to a single number, because different records have different clocks.
- Workspace crew data stays while the workspace keeps it. Your employer sets the schedule and can delete records at any time. When a workspace closes its account, we delete or return its data on request.
- Your account data stays while your account is active. When you ask us to delete your account, we remove your personal data from the live platform within 30 days of the request, except for the records listed below.
- Payment, payout, invoice, and tax records survive account deletion. We keep them for as long as tax, accounting, and anti-fraud law requires, and no longer. A 1099-NEC is a tax record and cannot be deleted on request.
- Security, abuse, and legal-hold records are kept while the reason for them lasts.
- Your privacy choice lives for 180 days in the jc_consent cookie. The country cookie set at the edge lasts 24 hours.
- Support and privacy correspondence is kept while it is useful for handling your matter and any follow-up.
- Measurement, error, and replay data is held by the provider that collects it. Google Analytics keeps events and user data for 14 months. PostHog keeps product analytics events for seven years and session recordings for 90 days. Sentry keeps error events for 30 days. These live in each provider's console rather than in our code, so they can change. Ask us and we will confirm the current value.
Backups and provider recovery systems can hold a residual copy for a limited window after a deletion. Those copies are not used to serve the product, and they age out.
9 · Security
Traffic between your browser and JamCrew, and between JamCrew and the providers in section 6, runs over TLS. Our infrastructure and database providers encrypt stored data at rest under their own published standards, which are theirs to state rather than ours. Sign-in runs through Clerk, and you can add an authenticator app as a second factor on your account. Access to production is limited to the people who need it to operate and support the service.
Workspaces are kept separate at the application layer: every read and write runs through a server function that checks your identity, your workspace membership, and your role on each request before it returns or changes any data. It is not enforced by database row policies, and we name the mechanism rather than the buzzword so you can judge it for yourself.
We hold no SOC 2 report and no ISO 27001 certificate today. We are working toward SOC 2 Type II and will say so here when it is real, not before. Several of the providers in section 6 do hold those certifications, and we can point you at their reports, but that is their audit and not ours. No service can promise perfect security, and we will not pretend otherwise. The full set of technical and organizational measures is section 8 of the Data Processing Addendum (/dpa).
10 · Children
JamCrew is a workplace tool and is not intended for anyone under 18. We do not knowingly collect personal data from children. If we learn that we hold data about someone under 18, we will delete it promptly. If you believe a child has given us personal data, contact privacy@jamcrew.io and we will act on it.
11 · Where your data goes
Made by Jam LLC is in the United States, and the platform is built and operated to be served from United States infrastructure. If you use JamCrew from anywhere else, your data is transferred to and processed in the United States, which may have different privacy protections than your home country.
We do not currently market JamCrew in the European Economic Area or the United Kingdom. If you arrive from there anyway, the region-gated consent model in section 5 applies to you: nothing optional loads until you allow it. For the personal data a workspace uploads about its crew, clients, and contacts, our Data Processing Addendum (/dpa) applies automatically from the moment a workspace is created. It already incorporates the European Commission's standard contractual clauses, the UK International Data Transfer Addendum, and the Swiss readings. Nothing needs to be requested or signed to turn that on.
12 · Changes to this policy
This policy carries a version number and an effective date at the top of the page, and both change whenever the document does. It is linked from the footer of every page on jamcrew.io and from inside the app, so it is always one click away.
When we make a material change, we will update the version and effective date, post a notice on this page, and email account holders at least 30 days before it takes effect. Smaller corrections, such as adding a provider to section 6 or fixing wording, are published here with a new version and date and take effect when posted. If you keep using JamCrew after the effective date, the updated policy applies to you. If a change requires your consent, we will ask rather than assume.
13 · Contact
Made by Jam LLC Gainesville, Georgia, United States privacy@jamcrew.io (mailto:privacy@jamcrew.io)
Privacy Policy · Version 2.3 · Effective July 26, 2026