Privacy policy
Last updated: 21 September 2026 · Version 1.1
Crew Pass is a workforce platform used two ways, and this policy explains both, because the answer to "who is responsible for my information" is different for each one.
- If a security company (or another employer) uses Crew Pass to run its own workforce (inductions, rostering, time and attendance, licence and compliance records), that company is the one collecting and controlling that information. Crew Pass provides the platform they use to do it, in the same way any software provider does.
- If you hold a Crew Pass wallet (the free, personal, portable licence wallet a worker can set up for themselves, independent of any one employer), Crew Pass is the one collecting and controlling that information.
The rest of this policy is organised around that split.
Who operates Crew Pass
Crew Pass is operated by Crew Pass, ABN 27 740 322 170, of 10/89-97 Jones Street, Ultimo NSW 2007. General enquiries, including privacy enquiries, can be sent to [email protected].
If your employer uses Crew Pass to manage your work
Your employer collects things like your name and contact details, licence and ticket numbers and details, induction and training records and quiz results, certificates, roster and shift assignments, time and attendance (including clock on/off location where geofenced sites are used), and documents you upload (for example a photo of a licence card). This is your employer's data, held in their own account, used to run their business and meet their own workplace and licensing obligations. Crew Pass processes it on their instructions, as their service provider, and does not use it for its own separate purposes.
Questions about this data, or requests to access, correct or delete it, should go to your employer first. See "Access, correction and deletion" below for how that works inside Crew Pass.
If you create a Crew Pass wallet
The wallet is a separate, worker-owned identity, not scoped to any employer. Setting one up needs only an email address; there's no password to remember, since sign-in is a one-time code emailed to you. In your wallet you can add licences and tickets (type, number, state, expiry) and upload the evidence file for each one (for example a scan or photo of the card or certificate). Nobody but you can open an evidence file you've uploaded to your wallet unless you actively choose to share it, as described below.
If you're a worker inside an employer's Crew Pass account, "Save to my Crew Pass" lets you copy your own submitted licence or ticket details into your personal wallet. This only ever copies what you yourself submitted; it never copies an admin's private notes or the employer's own check result against a register.
Sharing your wallet with an employer
Sharing sends a copy of the items you choose to the employer you're sharing with. That employer then keeps its own copy as its own compliance record, separate from your wallet; changing or deleting the item in your wallet afterwards doesn't change what that employer already has. The employer runs its own check against the relevant licence register rather than simply trusting your wallet's own check result.
You can unlink from an employer at any time from your wallet's "Linked employers" page. Unlinking stops any future renewal from being pushed to that employer; records already shared with them stay with them as their own compliance record.
Exporting and deleting your wallet
From your wallet's privacy page you can, at any time and after a fresh email verification code:
- Export a copy of everything stored in your wallet, as a downloadable file.
- Delete your wallet permanently, removing every item and evidence file. This only affects the copy you control in Crew Pass; records an employer already holds in their own system, from a share you made earlier, are theirs to keep.
Licence and ticket register checks
Where a licence or ticket is checked against a State Government licensing register (for example Queensland's security-provider register, or the equivalent registers in New South Wales and Victoria), Crew Pass sends only the licence or ticket number to the register. Your name is never included in that request. The register's own recorded holder name is then compared, inside Crew Pass, against the name on file, so a mismatch can be flagged for a human to review rather than assumed to be a match. The result of a check (register holder name, licence type, any conditions shown, expiry date and when it was checked) is stored against the employer's own compliance record when the check was run inside an employer's account, or against your wallet's own record when it was run there.
Cookies
Crew Pass uses a small number of cookies, all first-party and used only to run the service, never for advertising or tracking across other sites:
- Sign-in sessions for company/admin accounts, workers, client users, and Crew Pass wallet holders, so you stay signed in between requests.
- In-progress course attempts, so a worker's place in an induction is remembered on that device.
- Bot and spam protection on public forms (a short-lived cookie tied to a security check, used only to confirm a form submission followed a real page load).
Sharing with third parties
Crew Pass uses a small number of service providers to run the platform:
- Twilio, to send SMS messages where an employer or worker has opted into SMS.
- Email delivery over SMTP, to send account, induction and notification emails.
- Stripe, to process subscription billing for employer accounts. Crew Pass does not store full card details itself.
- Cloudflare, in front of the app, for bot protection (Turnstile) on public forms and as a reverse proxy/CDN.
- Hosting infrastructure in Amazon Web Services' Sydney (Australia) region.
These providers only receive the information needed to perform their function and are not permitted to use it for their own purposes.
Access, correction and deletion
Employer-side data. Admin and team members can request account closure or data erasure from /account; workers can do the same from their company's worker portal (/{company}/portal/account). Both require confirming your current password. Requests are reviewed by platform administrators. Submitting a request does not itself deactivate an account or delete records; a review and, where approved, a completion step follows.
Wallet data. Use the export and delete tools on your wallet's privacy page at any time, described above under "Exporting and deleting your wallet". No review step is needed for these, since they act only on data you control directly.
Retention
Employer-side records are kept for as long as the employer's account is active and as required for their own workplace and licensing record-keeping obligations, then in line with the outcome of any closure or erasure request reviewed as above. Wallet records are kept until you delete them yourself or your wallet is otherwise erased following a request.
Overseas disclosure
Crew Pass is hosted in Australia. Some of the service providers listed above (for example Twilio, Stripe and Cloudflare) operate infrastructure outside Australia as part of their global service, which can mean information is processed or stored overseas as a normal part of using them.
Complaints
If you have a concern about how your information has been handled, contact us first at [email protected] so we can try to sort it out directly. If you're not satisfied with the response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes to this policy
We may update this policy from time to time. The version number and "last updated" date at the top of this page will change when we do.