Privacy Policy
Last updated: September 18, 2026
Table of contents
1. Information We Collect
Information you provide. When you create a provider account, book a service, or contact us, we collect information such as your name, email address, phone number, business name, service address, and the content of messages you send through Crowfly.
Careers inquiries. If you introduce yourself through our careers page, we collect your name and email address plus anything you choose to add (a LinkedIn or portfolio link, your location, a note). That goes to our careers inbox and is used only to consider you for work at Crowfly; it is not added to any customer or marketing list.
Authentication data. If you sign in with Google or Apple, we receive basic profile information (name, email, and a unique identifier) from those providers. We do not receive or store your Google or Apple password.
Booking and scheduling data. To calculate availability and drive times, we collect service addresses, appointment times, and provider schedules. Addresses are converted to coordinates ("geocoded") using Google Maps.
Payment data. If you make or accept a payment through Crowfly, payment card details are collected and processed by Stripe. We do not store full card numbers on our servers; we store only tokens and metadata (such as the last four digits and card brand) returned by Stripe.
Automatically collected information. When you use Crowfly, we collect limited device and usage information such as IP address, browser type, pages visited, and interactions with the product. This is used for security, debugging, and product analytics.
2. How We Use Your Information
We use the information we collect to:
- Provide and operate the Crowfly booking and scheduling platform;
- Calculate drive times, travel buffers, and available time slots between appointment locations;
- Send booking confirmations, reminders, and related transactional messages by email (via Resend) and SMS (via Twilio);
- Authenticate users and protect accounts from unauthorized access;
- Process payments and handle refunds or disputes;
- Respond to support requests and communicate about your account;
- Understand how the product is used so we can improve it, diagnose bugs, and prevent abuse;
- Comply with legal obligations.
We do not use your information to build advertising profiles, and we do not sell your personal information.
3. Location Data
Crowfly is location-aware: accurate addresses let us calculate drive times and schedule appointments efficiently. The location data we process comes only from addresses you (or your customers) enter — for example, a provider's home base or a customer's service address.
We do not collect real-time GPS or continuous location data from your device. We do not track where you are when you are not actively using Crowfly, and we do not share location data with advertisers.
4. How We Share Your Information
We share personal information only in the following circumstances:
- With service providers ("sub-processors") that help us run Crowfly, such as our hosting, database, email, SMS, payments, and analytics vendors. A current list is in the next section.
- Between providers and their customers as necessary to fulfill a booking (for example, sharing a customer's name, appointment address, and contact information with the provider they booked).
- To comply with law or respond to valid legal requests, and to protect the rights, property, or safety of Crowfly, our users, or others.
- In connection with a business transaction such as a merger, acquisition, or asset sale, in which case we will provide notice before personal information is transferred.
We do not sell your personal information.
5. Sub-processors
Crowfly relies on the following third parties to operate. Each receives only the data needed for its specific purpose.
- Vercel — application hosting and content delivery.
- Supabase — database, authentication, and file storage.
- Google (Sign in with Google, Google Maps Platform) — OAuth sign-in, address autocomplete, geocoding, and map display.
- Apple (Sign in with Apple) — OAuth sign-in.
- Stripe — payment processing.
- Resend — transactional email delivery (confirmations, reminders, password resets).
- Twilio — SMS delivery (booking notifications and reminders).
- PostHog — product analytics and error monitoring.
If we add or change a sub-processor in a way that materially affects how personal information is processed, we will update this page.
6. Data Security
We take reasonable steps to protect your information. All traffic between your browser and Crowfly is encrypted in transit using TLS. Data is stored in managed, access-controlled databases provided by Supabase, and administrative access is limited to the people who need it to operate the service.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.
7. Data Retention
We keep personal information for as long as your account is active. Records related to bookings, payments, invoices, and other financial transactions are retained for seven (7) years after the transaction to comply with U.S. federal and state tax, accounting, and recordkeeping requirements.
You may request deletion of your account at any time (see "Your Rights" below). When we delete an account, we remove or anonymize personal information except where we are required to retain it — for example, transaction records kept for the seven-year tax retention period described above.
8. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct information that is inaccurate or incomplete;
- Delete your account and associated personal information;
- Export a copy of your personal information in a portable format;
- Object to, or restrict, certain processing of your personal information;
- Opt out of non-essential communications at any time, using the unsubscribe link in emails or by replying STOP to SMS messages.
To exercise any of these rights, email us at [email protected]. We may need to verify your identity before fulfilling a request. You also have the right to lodge a complaint with your local data protection authority.
10. International Data Transfers
Crowfly is operated from the United States, and our primary hosting and database infrastructure (Vercel and Supabase) stores data in the United States. Other sub-processors listed above may process data in the United States or in other countries where they operate.
If you use Crowfly from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data protection laws than your country. For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland, see "European Economic Area, UK, and Switzerland (GDPR)" below.
11. Children's Privacy
Crowfly is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us at [email protected] and we will delete it.
12. California Residents (CCPA / CPRA)
This section provides additional disclosures required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), for California residents.
Categories of personal information collected. In the last 12 months, we have collected the following CCPA categories: identifiers (name, email, phone, IP address, account identifiers); customer records (billing and service address, payment tokens); commercial information (booking history, transaction records); internet or network activity (pages viewed, interactions with the product); geolocation information derived from addresses you provide; and inferences drawn from the above for product analytics.
Sources. We collect this information directly from you, automatically when you use Crowfly, and from our authentication providers (Google, Apple) when you sign in.
Purposes. We use this information for the purposes described in "How We Use Your Information" above, including providing the service, processing payments, communicating with you, preventing fraud, and improving the product.
Disclosure. We disclose personal information to the sub-processors listed in Section 5 for the business purposes described in this policy.
Sale or sharing of personal information. We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA.
Your California rights. Subject to certain exceptions, California residents have the right to: (i) know what personal information we collect, use, disclose, and retain; (ii) request deletion of personal information; (iii) correct inaccurate personal information; (iv) opt out of the sale or sharing of personal information; (v) limit the use of sensitive personal information; and (vi) not be discriminated against for exercising these rights.
To exercise any of these rights, email [email protected]. We will verify your request using information associated with your account. You may also designate an authorized agent to make a request on your behalf; we may require written authorization and identity verification.
13. European Economic Area, UK, and Switzerland (GDPR)
This section provides additional information for individuals in the European Economic Area, the United Kingdom, and Switzerland whose personal data is processed under the General Data Protection Regulation ("GDPR") or equivalent UK and Swiss law.
Data controller. The controller of your personal data is Upstairs Office Studio, LLC, 508 Lincoln St, Indianapolis, IN 46203, United States. You can reach us at [email protected].
Legal bases for processing. We process personal data on the following legal bases:
- Performance of a contract — to create and manage your account, process bookings, and deliver the service you have requested.
- Legitimate interests — to operate and secure the service, prevent fraud and abuse, debug issues, and improve the product. We balance these interests against your rights and freedoms.
- Legal obligation — to comply with tax, recordkeeping, and other applicable laws (including the seven-year retention described in Section 7).
- Consent — where we ask for it (for example, marketing communications). You can withdraw consent at any time without affecting the lawfulness of prior processing.
Your rights. You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing of your personal data. Where processing is based on consent, you have the right to withdraw consent. You also have the right to lodge a complaint with your local data protection authority.
International transfers. Your personal data will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards for such transfers, including the Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum, where applicable), and on sub-processors' certifications under the EU-U.S., UK, and Swiss- U.S. Data Privacy Framework where available.
Automated decision-making. We do not use your personal data to make decisions that produce legal or similarly significant effects on you through solely automated means.
14. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the "last updated" date at the top of this page and, where appropriate, notify you by email or through the product. Your continued use of Crowfly after a change takes effect means you accept the updated policy.
15. Contact Us
Crowfly is operated by Upstairs Office Studio, LLC. If you have questions about this policy or how we handle your information, contact us at:
Upstairs Office Studio, LLC
508 Lincoln St
Indianapolis, IN 46203
United States
[email protected]