SecureCrews is a job management platform built for roofing contractors and their teams. When we say “we” or “us,” we mean SecureCrews LLC. When we say “you,” we mean anyone who uses our website, app, or services, whether you are a contractor, a crew member, a subcontractor, a homeowner client, or an insurance agent.
What information do we collect?
The short answer: only what we need to run the platform. Here is a breakdown by the type of person using SecureCrews.
If you are a contractor or team member (owner, office admin, or field crew), we collect your name, email address, phone number, and a password you choose. We also collect your company name and business address. When you use the mobile app, we collect GPS location when you clock in, clock out, or take job site photos. Photos you upload may include GPS data embedded by your phone. We also look at your device information (like what browser or phone you use) so we can spot suspicious logins.
If you are a subcontractor, we collect your name, email, phone, company name, and address. If you upload W-9 tax forms, those contain your Social Security Number or Employer ID Number. We also store certificates of insurance (COIs) you upload and payment amounts tied to your work.
If you are a homeowner client, we collect your name, email, phone, and property address. If your contractor uses our insurance workflow, we may also collect your insurance policy number, adjuster contact information, and claim amounts. We store documents like Assignment of Benefits forms and adjuster estimates. We also collect digital signatures on estimates and invoices, and messages you send through the client portal.
If you are an insurance agent, we collect your name, email, phone number, agency name and address, and insurance license number and state when you create an Agent Portal account. We also track login activity (last login time, IP address, failed login attempts) for security purposes. Agent accounts are completely separate from contractor, crew, and homeowner accounts.
Information we collect automatically: your IP address and browser type when you visit our site, and which pages you visit. We use strictly necessary cookies to keep you logged in and the site secure. If you accept analytics in our cookie banner, we also use Google Analytics to understand how the site is used. We never use advertising cookies or sell your data. See the Cookies section for how to change your choice.
How do we use your information?
We use your information to do the things you would expect:
Run the platform. Create your account, manage jobs, send estimates and invoices, schedule crews, track time, and process payments.
Communicate with you. Send you text messages about job updates, email you invoices or estimates, and notify you about important account changes.
Keep things secure. Detect suspicious logins, prevent unauthorized access, and investigate potential security issues.
Improve the product. Understand how people use SecureCrews so we can make it better.
Meet legal requirements. Comply with tax laws (like generating 1099 forms), respond to legal requests, and follow state privacy laws.
Who do we share your information with?
We share your information only when there is a clear reason to do so.
Your contractor’s team. If you are a homeowner client, the contractor you hired (and their authorized staff) can see your contact information, job details, and documents. That is the whole point of the platform.
Referring insurance agents. If your contractor associates an insurance agent with your job and captures your explicit consent, that agent can see limited progress information: job status, milestone dates, claim status, carrier name, whether the deductible has been collected, your first name, and photo thumbnails. Agents cannot see your last name, contact information, financial details (estimates, invoices, amounts), adjuster information, or internal notes. Your contractor can revoke this sharing at any time, and you can ask your contractor to revoke it at any time, so access is removed immediately.
Service providers that help us run SecureCrews. These companies only see the data they need to do their specific job:
| Company | What they see | Why |
|---|---|---|
| Stripe | Billing name, email, payment card | Subscription payments |
| Twilio | Phone number, email, message text | Text messages and email delivery |
| AWS | Encrypted data, encryption keys | Servers and encryption key management |
| Cloudflare | Uploaded files (encrypted) | File storage and website protection |
| Google Maps | Property addresses | Map coordinates and address lookup |
| Anthropic | Review text only (no personal info) | AI-assisted review responses |
| Sentry | Error logs, device metadata (PII scrubbed) | Crash and error monitoring |
| Google Analytics | Anonymized usage data (only with your consent) | Website analytics |
We have data processing agreements with each of these companies.
Legal and safety reasons. We may share information if required to by law (like a subpoena or court order), or if we believe in good faith that sharing is necessary to prevent harm or protect rights.
With your permission. If you ask us to share something, for example sending a document to an insurance company, we will do that.
How do we protect your information?
We take security seriously. Here is what we do:
Encryption everywhere. All data moving between your device and our servers is encrypted using TLS 1.3, the latest standard. Sensitive fields in our database, like names, addresses, and phone numbers, are encrypted at rest using AES-256 encryption.
Extra protection for the most sensitive documents.W-9 tax forms, insurance claim documents, and other high-risk files get an additional layer of encryption. Each contractor’s documents are encrypted with their own unique key, managed through a dedicated key management service. Even if someone broke into our file storage, the files would be unreadable without the separate encryption keys.
Strict access controls. Every user can only see data that belongs to their company. This is enforced at the database level, not just the application level.
Two-factor authentication. We offer two-factor authentication (2FA) for all accounts and require it for our admin team. Logging in requires both your password and a code from an authenticator app.
Short-lived sessions. Login tokens expire after 15 minutes and refresh tokens rotate automatically, so a stolen token becomes useless quickly.
Audit logging. We record who accessed what and when. These logs are tamper-proof and help us investigate any suspicious activity.
How long do we keep your information?
We keep your data for as long as you have an active account, plus a grace period after you cancel:
| Data type | How long | Examples |
|---|---|---|
| Account data | While active + 90 days | Name, email, phone |
| Job photos | While active + 90 days | Originals and thumbnails |
| Insurance and claim docs | 7 years | W-9s, COIs, adjuster estimates, AOBs |
| Generated reports | 90 days | Can be regenerated anytime |
| Audit logs | As required by law | Security and access records |
If you ask us to delete your data, we will do so within 45 days unless we are legally required to keep it (for example, tax records).
What are your rights?
No matter where you live in the United States, we give everyone the same rights:
See your data. You can ask us for a copy of all the personal information we have about you.
Fix your data. If something is wrong, say a misspelled name or an old phone number, you can ask us to correct it.
Delete your data. You can ask us to delete your personal information. We will do so unless we are legally required to keep it.
Take your data with you. You can request your data in a portable format so you can move to another service.
Opt out of communications. You can unsubscribe from marketing emails with one click. You can opt out of text messages by replying STOP. Job-critical notifications (like a scheduled appointment reminder) will still come through while you have an active account.
Opt out of data sharing. We honor the Global Privacy Control (GPC) signal. If your browser sends it, we treat it as a request to opt out of any data sharing.
Cookies
We use two kinds of cookies, and you are in control of the second kind:
Strictly necessary cookies (always on). These keep you logged in, remember your theme and preferences, keep the site secure, and remember your cookie choice. The site cannot function without them, so they do not require consent.
Analytics cookies (only with your consent). If you accept, we use Google Analytics and limited error-performance monitoring to understand how the site is used so we can improve it. These do not load until you choose “Accept analytics” in our cookie banner, and we do not use advertising cookies or tracking pixels of any kind.
You can change your mind at any time — it is as easy to withdraw consent as it was to give it. Withdrawing consent stops future analytics and clears the analytics cookies from your browser.
International visitors (GDPR and UK GDPR)
SecureCrews is a United States business and our services are directed to customers in the United States. We do not target or market to people in the European Economic Area (EEA), the United Kingdom, or Switzerland. That said, if you visit our website from one of those regions, this section explains how we handle your information under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Data controller. SecureCrews LLC is the controller of the personal information described in this notice. You can reach us at [email protected].
Why we are allowed to process your information (legal bases). When the GDPR applies, we rely on one of these lawful bases:
• Contract— to create your account and provide the service you signed up for.
• Consent— for optional analytics cookies and any marketing messages. You can withdraw consent at any time.
• Legitimate interests— to keep the platform secure, prevent fraud, and improve the product, balanced against your rights.
• Legal obligation— to meet tax, accounting, and other legal requirements.
Your GDPR rights. In addition to the rights listed above, you have the right to access, correct, delete, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent at any time without affecting processing that already took place. To exercise any of these, email [email protected].
International data transfers.We and our service providers are located in the United States, so your information will be transferred to and processed there. Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) with our processors to protect that transfer.
Retention. We keep personal information only as long as needed for the purposes described in this notice, as set out in the retention table above, unless a longer period is required by law.
Children
SecureCrews is a business tool for adults. You must be at least 18 years old to create an account. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, please contact us and we will delete it.
Changes to this notice
If we make meaningful changes to this notice, we will email you at least 30 days before the changes take effect. We will also post the updated notice on this page with a new “last updated” date. Minor wording changes that do not affect your rights will be posted without advance notice.
Contact us
If you have questions about this privacy notice or want to exercise any of your rights:
If you are not satisfied with our response, you may file a complaint with your state’s Attorney General office.