Privacy policy

Last updated 9 September 2026

Crewmark holds employment records for the organisation that invited you. This page says exactly what is stored, why, how long it stays, and what you can ask for.

Who is responsible for your data

Crewmark is operated by InfoKrafts. Where Crewmark is used by your employer, your employer decides what goes in it and why — they are the controller of your personal data, and InfoKrafts acts as a processor on their instructions. Requests about your own data are usually fastest through your employer’s HR contact, but you may also write to us.

Contact: no-reply@mehro.ch. Despite the name, that mailbox is read and forwarded to a person — it is the address to use for anything in this policy, and you will get a reply.

What Crewmark stores

Only what the product needs to do its job. Specifically:

  • Identity and contact. Name, work email address, employee number, optional phone number, work location and timezone.
  • Employment. Job title, department, team, who you report to, employment type and status, start and end dates, and your contracted working pattern. These are kept as dated records, so past reports stay accurate when something changes.
  • Work. Hours you record, which project they were for, whether they were billable, and any description you wrote. Timesheet submissions, approvals and rejections with their reasons.
  • Leave. Requests, dates, type, decisions and any note attached.
  • Skills. Skills you or your manager record, proficiency levels, experience and certifications.
  • Money. Internal cost rate and billing rate, where your employer uses those features. Visible only to people holding financial permission — not to your manager by default.
  • Account and security. A hash of your password, an encrypted second-factor secret, hashes of recovery codes, and session records with the address and browser used.
  • Activity. An audit trail of significant actions: who changed what and when, sign-ins, and report downloads.

Crewmark does not track your activity on your computer. There is no screenshotting, no keystroke or mouse monitoring, no idle detection, and no reading of your files, email or code. Hours are entered by hand, by you.

Why, and on what basis

  • Running the employment relationship — recording time, leave, assignments and organisation structure. Lawful basis: performance of a contract, and your employer’s legitimate interests in administering work.
  • Billing clients and managing projects — cost, revenue and margin. Lawful basis: legitimate interests.
  • Keeping the system secure — sign-in records, rate limiting, the audit trail. Lawful basis: legitimate interests, and legal obligation where records must be retained.
  • Meeting legal obligations — employment and accounting records that law requires be kept for a period.

We do not use your data for advertising, we do not sell it, and we do not use it to train machine-learning models.

Who can see what

Access is decided by role and by where you sit in the organisation, and it is checked on our servers for every request rather than by hiding buttons.

  • You always see your own records.
  • Your manager sees the people who report to them, directly or through others — and not colleagues in other parts of the organisation.
  • Your manager does not see what you cost. Rates are a separate permission held by finance and executives.
  • HR sees employment records company-wide, and by default no financial data.
  • Your phone number is visible to you and to whoever may edit employee records.

Where it is held

Crewmark runs on servers in Switzerland, hosted by Infomaniak. Transactional email is sent through Infomaniak’s mail service, also in Switzerland. Backups are stored on the same infrastructure. No personal data is transferred outside Switzerland or the EEA in the ordinary running of the service.

How long it is kept

  • While you are employed — everything above, for as long as the account is in use.
  • After you leave — your account is disabled and its sessions ended immediately. Your employment record, recorded hours and approvals are retained, because they are the basis of invoices already issued and reports already made.
  • Audit and sign-in records — retained as a security record.
  • Expired sessions and rate-limit counters — cleared automatically.

Your employer sets the retention period that applies to them, within what the law requires of them. Business records that have to exist — hours behind an invoice, an approval in an audit trail — are not deleted on request, and no honest system would promise otherwise.

Your rights

Under the GDPR and the Swiss Federal Act on Data Protection you may ask to:

  • See the personal data held about you.
  • Correct anything inaccurate.
  • Receive a copy in a portable format. You can do this yourself: your account page has an export of everything Crewmark holds about you, as a file you can open in a spreadsheet.
  • Have data erased, where no legal or contractual reason requires keeping it.
  • Restrict or object to certain processing.
  • Complain to a supervisory authority — in Switzerland the FDPIC, or your national authority in the EEA.

Ask your employer’s HR contact first, since they are the controller. If that fails, write to no-reply@mehro.ch — it is monitored despite the name — and we will respond within one month.

Cookies

Crewmark sets one cookie: a session cookie that keeps you signed in. It contains a random value and nothing else — no name, no identifier, nothing readable. It is HttpOnly, Secure and SameSite=Lax, and it is deleted when you sign out.

There are no analytics cookies, no advertising cookies and no third-party trackers, which is why there is no cookie banner. A cookie that is strictly necessary to deliver a service you asked for does not require consent, and we have no others.

Security

Described in detail on the security page. In short: two-factor authentication is compulsory, passwords are hashed with Argon2id, second-factor secrets are encrypted at rest, all traffic is encrypted in transit, permissions are enforced on the server, and the audit trail cannot be altered even by us.

Changes

If this policy changes in a way that affects you, you will be told through the application before it takes effect. The date at the top always reflects the current version.