Skip to content

Privacy Policy

Effective date: July 25, 2026 · Applies to: VeraCrew (“Veracrew,” “we,” “us”) web properties and SaaS services

Counsel action required: This page is an engineering-aligned draft. Have counsel rewrite Privacy and the customer DPA from the retention matrix in docs/data-retention-and-deletion.md and the jurisdiction packs in docs/legal-drafts/. Do not treat this page as final legal advice.

This policy describes personal and organizational information we process when you use Veracrew, including when you visit our marketing site or use the subscribed product. Customer organizations (employers) typically act as the primary controllers of worker data; Veracrew provides the multi-tenant SaaS platform.

Categories of information we collect

Why we process data

Cookies and analytics

We rely on strictly necessary cookies and similar storage for authentication, CSRF/session continuity, feature flags, analytics, or experimental insights. At minimum we may use PostHog for product instrumentation and Stripe.js or Turnstile iframes as required by those integrations. Detailed cookie tables should be finalized with counsel.

Processors and subprocessors

Representative infrastructure and software vendors powering Veracrew include:

A dedicated subprocessors ledger should be published with the customer DPA. Until then, requests for the latest disclosure should go through Veracrew support referenced in onboarding correspondence.

Retention and deletion

Soft-delete (marking a record deleted) is not the same as permanent erasure. Veracrew uses grace periods, anonymization, legal holds, and scheduled jobs. Current product behavior includes:

Exact schedules and exceptions for diligence are summarized for engineers and counsel in Veracrew’s internal retention matrix. Customer contracts must not promise shorter retention than legal holds encoded in the product.

Rights requests

Workers should generally start with their employer (the organization admin). Organization administrators can contact Veracrew through the onboarding or billing email on file to access, rectify, export, or request erasure of personal information subject to eligibility, employment-record exceptions, and legal holds. In-product audit export (where the plan includes it) helps admins review security-relevant events; it is not a complete substitute for every jurisdiction’s data-subject package. Regulatory timelines vary; we endeavor to respond within commercially reasonable periods after verification.

International transfers

Veracrew is operated using cloud infrastructure that may include United States regions and global edge networks. Organizations outside those regions authorize transfers pursuant to contractual clauses and Standard Contractual Clauses when required. Jurisdiction-specific drafts (Canada PIPEDA, Quebec Law 25, GDPR, US state privacy) are maintained for counsel in Veracrew’s legal-draft pack before publication.

Questions

Contact support@veracrew.com for privacy questions from organization administrators. Workers should generally start with their employer. Security-specific topics are also covered on the Security overview page.