crewmuster.
Features Pricing Switching Reporting Franchises
Log in Start free trial

Data processing agreement

Last updated: July 18, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of service between Mount Dora Holdings NC LLC (“crewmuster,” “processor”) and the customer (“you,” “controller”) and governs crewmuster’s processing of personal data on your behalf — primarily the personal data of your employees and crew.

1. Roles of the parties

For the personal data you manage in crewmuster about your crew, you are the controller and crewmuster is the processor. You determine the purposes and means of the processing; crewmuster processes that data only to provide the service and on your documented instructions. Where you are itself a processor for another controller, crewmuster acts as a sub-processor and the same obligations apply.

2. Definitions

“Personal data,” “processing,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given in applicable data protection law, including the EU and UK GDPR. “Applicable data protection law” means the privacy and data protection laws that apply to the processing, including the GDPR, UK GDPR, and the CCPA/CPRA where relevant.

3. Scope and instructions

crewmuster will process personal data only: (a) to provide and support the service; (b) on your documented instructions, including those in the Terms, this DPA, and your use of the service; and (c) as required by law (in which case crewmuster will inform you unless legally prohibited). The details of processing are set out in Annex I.

4. Confidentiality

crewmuster ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and access it only as needed to perform their duties.

5. Security

crewmuster implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs, and the risk. Current measures are summarized in Annex II.

6. Sub-processors

You give crewmuster general authorization to engage sub-processors to help provide the service. crewmuster will: (a) impose data protection obligations on each sub-processor that are no less protective than those in this DPA; (b) remain responsible for its sub-processors’ performance; and (c) maintain a current list of sub-processors (Annex III) and give you notice of intended additions or replacements — for example, by updating that list and notifying you by email or through the service. You may object to an intended change on reasonable data-protection grounds within 30 days of the notice, and the parties will work together in good faith to resolve the objection.

7. Assisting you (data-subject requests)

Taking into account the nature of the processing, crewmuster will assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, correction, deletion, portability, restriction, and objection). If crewmuster receives such a request directly, it will refer the data subject to you.

8. Personal data breaches

crewmuster will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your personal data, and will provide information reasonably available to help you meet your notification obligations.

9. Data protection impact assessments

crewmuster will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to crewmuster.

10. Return and deletion

On termination of the service, crewmuster will, at your choice, delete or return your personal data, and delete existing copies, unless law requires storage. You can also export your data while the service is active. crewmuster will complete deletion within 60 days of termination.

11. Audits

crewmuster will make available the information reasonably necessary to demonstrate compliance with the obligations in this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. crewmuster will satisfy audit requests primarily by providing relevant documentation and written responses to your reasonable questions. Where that information is insufficient to demonstrate compliance, an on-site or live inspection may be carried out, subject to the following: it is limited to once in any 12-month period; conducted at your expense; during normal business hours; under reasonable confidentiality and non-disclosure terms; on at least 30 days’ prior written notice; and remote-first where practical. An inspection may take place on shorter notice only where required following a confirmed personal data breach affecting your personal data or by a supervisory authority. This section bounds how audits are conducted; it does not remove your right, or that of an auditor you appoint, to verify crewmuster’s compliance.

12. International transfers

Where crewmuster transfers personal data across borders in a way that requires a transfer mechanism, it will use an appropriate one (for example, the EU standard contractual clauses and the UK addendum), incorporated by reference where applicable.

13. CCPA

To the extent the CCPA/CPRA applies, crewmuster acts as a “service provider.” crewmuster will not sell or share personal data, will not retain, use, or disclose it except to provide the service (or as permitted by the CCPA), and will not combine it with data from other sources except as the CCPA allows.

14. Order of precedence

If this DPA conflicts with the Terms regarding the processing of personal data, this DPA controls.


Annex I — Details of processing

Subject matterProvision of crewmuster’s scheduling, availability, and task service.
DurationFor the term of the service, plus the return/deletion period in section 10.
Nature and purposeHosting, storing, and processing personal data to operate scheduling, availability, tasks, and cross-location coverage on the controller’s behalf.
Types of personal dataNames, contact details, role/position, location assignment, availability, scheduled shifts, and task activity of the controller’s crew; account administrator details.
Categories of data subjectsThe controller’s employees, crew, and account administrators.
Special categoriesNone intended. The service is not designed to process special-category data; do not enter it.

Annex II — Security measures

crewmuster maintains the following measures:

  • Encryption in transit. Connections to the service and to our sub-processors are encrypted using TLS.
  • Tenant isolation enforced in the database. Customer data is separated using PostgreSQL row-level security keyed to each user’s store membership, enforced at the database layer rather than in application code alone.
  • Authentication. Accounts sign in with passwordless one-time codes sent by email and verified server-side; we do not store passwords. Authentication is single-factor.
  • Application access control. Role-based permissions (manager, employee, kiosk, and administrator) govern what each user can access within the service.
  • Incident response and breach notification. crewmuster maintains a documented internal incident-response procedure covering detection, triage, containment, a good-faith review of whether an incident may be a notifiable personal data breach, notification, and record-keeping. crewmuster keeps a durable, access-controlled record of security incidents and of the breach notifications it issues. If crewmuster becomes aware of a personal data breach affecting your personal data, it follows this procedure to notify you and to record that notification, as set out in section 8.

crewmuster also relies on measures provided by its infrastructure sub-processors that crewmuster does not itself operate — including encryption at rest and automated database backups (Supabase) and platform-level request logging (Vercel). These are the providers’ controls, described here for transparency.

Annex III — Sub-processors

The following sub-processors help crewmuster provide the service:

Sub-processorPurposeLocation
SupabasePrimary database and authenticationAWS us-east-1 (N. Virginia, United States)
VercelApplication hosting, serverless functions, and scheduled jobsFunctions: US East (iad1). Edge network and content delivery: global
ResendTransactional emailUnited States
Google (Firebase Cloud Messaging)Push notification delivery to mobile appsGlobal — no region selection is available
Apple, Google, and Mozilla push gatewaysPush notification delivery to browsersGlobal — determined by the recipient’s browser
OpenStreetMap Foundation (Nominatim)Geocoding of store addresses (business location only)Hosted by the OpenStreetMap Foundation
AnthropicReading an emailed sales report whose format crewmuster does not recognise, so the figures can be recorded. Applies only to stores that have enabled emailed sales reports, and only to the content of those reports. Scheduling, availability, rosters, tasks, wages, and time-card reports are never sent.United States. Reports are stored in the United States and crewmuster requests United States processing on every call. Anthropic states that limited internal processing, such as safety review, support, and incident response, may also occur in other countries where it operates
CloudflareMarketing-site hosting, content delivery, and site analyticsGlobal edge network
SquarespaceDomain email forwarding for inbound mailUnited States

Anthropic publishes the following commitments for the API crewmuster uses: inputs and outputs are deleted within 30 days of receipt or generation, and retained data is not used to train its models without express permission. These are that provider’s commitments, described here for transparency; crewmuster has not independently tested them.

The following are contracted for planned functionality and are not currently processing personal data. They are listed in advance so that enabling them does not require a change to this DPA.

Sub-processorPurposeLocation
StripeSubscription billingGlobal, including the United States
SentryError monitoringUnited States or European Union, determined at activation
SlackInternal operational alertsDetermined by account region

Contact

Questions about this DPA or to send data-protection notices, email hello@crewmuster.com.

crewmuster.

Scheduling, time off, and tasks for franchise stores. Built by a franchisee to run his own shop.

Features Pricing Switching Reporting Franchises Log in Terms Privacy DPA Data & account deletion Contact iPhone app Android app
© 2026 crewmuster. All rights reserved.