Privacy Policy
Effective August 7, 2026
1. Scope
This Privacy Policy explains how [LEGAL ENTITY NAME], operator of Krewly ("Krewly," "we," "us"), collects, uses, discloses, and protects information in connection with the Krewly platform, including data submitted by business owners who create accounts ("Providers") and data submitted by their customers through a Provider's hosted page, chat widget, quote form, or inbound email ("End Customers").
2. Information We Collect
From Providers: business name, trade type, contact email, password (stored as a salted hash, never in plain text), rate card and service details, business address, service area, timezone and availability, accepted payment methods, and Stripe account identifiers once you connect payments.
From End Customers, submitted by or through a Provider:name, email address, phone number, service address, and any details volunteered in a chat, email, or quote-form message, including answers to a Provider's configured intake questions.
Payment information: full payment card details are collected and stored directly by Stripe, our payment processor — Krewly does not receive or store full card numbers. We retain transaction metadata (amount, status, timestamps, and Stripe-issued identifiers).
Automatically collected: log data, IP address, device and browser information, and session/authentication cookies necessary to keep you signed in.
3. How We Use Information
- To operate the Service: matching customer requests to a Provider's rate card, computing prices and available time slots, and drafting reply text for a Provider to review and approve;
- To send transactional email: booking confirmations, reminders, invoices, and review requests to End Customers, and account and approval notifications to Providers;
- To process payments and deposits through Stripe;
- To maintain the security, integrity, and availability of the Service, including fraud prevention and abuse detection;
- To provide customer support and respond to inquiries; and
- To comply with legal obligations.
4. AI Processing Disclosure
Two narrow functions in the Service send limited data to a third-party AI provider (Anthropic): (a) matching an ambiguous customer message to a Provider's rate-card line item when a deterministic keyword match fails, and (b) drafting the natural-language text of a reply once price and scheduling facts have already been computed by non-AI logic. The data sent for these purposes may include the customer's message text, the Provider's rate card and FAQs, and recent previously-approved replies used as style examples. We do not use this data to train our own models, and rely on our AI provider's standard API terms, under which API inputs are not used to train their models by default. Every AI-assisted reply is held for the Provider's review and approval before it is ever sent to a customer.
5. How We Share Information
We share information with the following categories of third-party service providers, solely to operate the Service:
- Stripe — payment processing, Connect payouts, and subscription billing;
- Resend — outbound transactional email and inbound email parsing;
- Anthropic — AI-assisted service matching and reply drafting, as described above;
- Neon / Vercel (or their successor infrastructure providers) — database hosting and application hosting.
We do not sell personal information. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Krewly, our users, or the public. If Krewly is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy of at least equivalent protection.
6. Data Retention
We retain account and job-history data for as long as an account remains active and for a reasonable period afterward to satisfy legal, accounting, tax, and dispute-resolution obligations. A Provider may request deletion of their account; some records (e.g., completed transaction records) may be retained where required by law or legitimate business record-keeping needs.
7. Data Security
We use industry-standard technical and organizational measures — including encrypted connections, hashed passwords, and access controls — to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. Providers can access and update most of their own information directly from their dashboard settings. To exercise a data right not available in the dashboard, or if you are an End Customer with a request concerning your data, contact privacy@krewly.app; requests concerning an End Customer's data may also need to be directed to the relevant Provider, as they control the underlying customer relationship.
9. Cookies
We use strictly necessary cookies to maintain login sessions and protect account security. We do not use third-party advertising or cross-site tracking cookies.
10. Children's Privacy
The Service is not directed to, and we do not knowingly collect personal information from, children under 13 (or the minimum age required by applicable local law). If you believe a child has provided us personal information, contact us and we will take steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date. Material changes will be communicated through the Service or by email where required by law.
12. Contact
Questions about this Privacy Policy can be sent to privacy@krewly.app.