CrewSlate privacy baseline
Privacy Policy
This implementation baseline documents CrewSlate's launch-bound privacy posture for supervisor scheduling workflows. It is not legal advice and still requires owner/legal approval before live customer use.
- CrewSlate collects only the supervisor and staffing information needed to create workspaces, roster entries, shift templates, schedule assignments, manager access records, invite handoffs, approvals, and export/delivery audit history.
- Roster and manager records can include names, roles, qualifications, availability, weekly hour constraints, contact methods, invite email addresses, and workspace-access history; do not enter unnecessary personal details into free-text fields.
- Authenticated live workspace data must stay protected by Supabase row-level security and bearer-backed data clients when owner-approved deployment gates pass.
- The parks-rec demo path uses local fixture data only and must not write demo submissions into production Supabase.
- CrewSlate does not authorize outbound invite, email, text, or delivery messages from this pilot shell until the owner approves runtime email setup and customer-facing launch gates.
- Access, correction, deletion, retention, subprocessors, and production support contacts require owner/legal review before public or customer-facing use.
Before production launch
Replace this baseline with counsel-reviewed policy text naming the production operator, monitored privacy contact, retention windows, subprocessors, jurisdiction-specific rights process, and effective date. Do not publish it as lawyer-approved compliance evidence.