Privacy Policy
Last updated: 23 July 2026
CREVO (“CREVO”, “we”, “us”) provides a business operating system for project-based small and medium enterprises. This policy explains what personal data we handle, why, and the choices you have. It applies to the CREVO web application at crevo.tech and the CREVO mobile companion apps for iOS and Android. This is a draft prepared for launch and does not constitute legal advice.
Who controls your data
CREVO is a multi-tenant platform. Your employer or the organisation that invited you (the “Organisation”) is the data controller for the staff, HR, attendance, payroll, claims and project records created inside its workspace. CREVO acts as the data processor, operating the platform on the Organisation’s behalf. For the public marketing site and sales enquiries, CREVO is the controller.
Information we collect
- Account & profile: name, work email, role, department, phone, and (where the Organisation records them) bank details for payroll and claims reimbursement.
- Operational records: tasks, projects, attendance check-in/out times, leave, claims, quotations, invoices and related notes you or your Organisation create.
- Location & media (mobile): if you enable them, GPS coordinates for attendance geofencing and mileage, and photos you capture (attendance selfies, claim receipts). These are only captured when you take the action, and location is used at the moment of check-in — we do not track you in the background.
- Device & usage: device model, app version, push notification token, and security/audit events (sign-ins, 2FA) used to keep accounts safe.
How we use it
To provide and secure the service: authentication and two-factor security, delivering notifications you have opted into, calculating attendance/payroll/claims, and letting your Organisation run its operations. We do not sell your personal data, and we do not use your Organisation’s operational data to train third-party advertising models.
Permissions on mobile
The mobile app asks for camera, photo library, location and notification permissions only in the context where they are used, and explains why first. You can decline any of them and continue to use the rest of the app; you can change them any time in your device settings.
Storage, security & retention
Data is stored on Supabase infrastructure with row-level security so each Organisation can only access its own records. Sessions are held in the device secure enclave (iOS Keychain / Android Keystore) and cached operational data is encrypted at rest and scoped to the signed-in user. Media such as receipts and selfies is kept in private storage and served through short-lived signed links. We retain records for as long as your Organisation’s account is active or as required by Malaysian law (e.g. payroll and tax records), then delete or anonymise them.
Your rights
Subject to your Organisation’s policies and applicable law (including Malaysia’s Personal Data Protection Act 2010), you may request access to, correction of, or deletion of your personal data. Because most accounts are created and administered by your Organisation’s HR/Admin, start with them; you can also contact us and we will route the request. See Access, correction & deletion.
Changes & contact
We may update this policy as the platform evolves; material changes will be posted here with a new date. Questions or requests: support@crevo.tech.
Questions about this policy, your account, or your data? Email support@crevo.tech. We aim to respond within 5 business days.
