Privacy
What we collect, why, who sees it, and how to get it back or have it deleted. No cookie banner, because this site does not set any.
Last updated 12 September 2026
The short version. We collect what you type into the enquiry form and what you email us. We use it to answer you and to do work you have engaged us for. We do not sell it, we do not profile you, and this website sets no cookies and runs no tracking. Ask us and we will show you what we hold, or delete it.
- Who we are
- The standard we hold ourselves to
- What we collect
- What we do not collect
- Cookies and tracking
- Why we collect it
- Who else sees it
- Information going overseas
- Your systems during an engagement
- How we protect it
- How long we keep it
- Seeing and correcting your information
- Marketing and unsubscribing
- If something goes wrong
- Making a complaint
- Changes to this policy
1Who we are
ABN 51 702 111 591 · ACN 702 111 591
Level 1, 63-73 Ann Street, Surry Hills NSW 2010, Australia
Privacy contact: admin@crew22.com.au
We are an automation and systems-integration firm working with businesses in earthmoving, civil, mining, main roads and construction. Adam Perry is our privacy contact. Email the address above and it reaches him.
2The standard we hold ourselves to
The Privacy Act 1988 (Cth) binds organisations with an annual turnover above $3 million, and some others regardless of size. Crew22 Pty Ltd is a new company and is not yet above that threshold. We are telling you that rather than implying a legal obligation we do not currently carry.
We comply with the Australian Privacy Principles anyway, as though we were bound by them, and we will be bound as a matter of law once we pass the threshold or take on work that carries the obligation, for example a Commonwealth government contract. The practical effect for you is the same: the rights described on this page are real and we will honour them.
3What we collect
- When you send an enquiry
- Your name, your business name, your email address, and your phone number if you choose to give it. Anything you write in the message box. The figures you set on the hours tool travel with the enquiry: jobs per week, number of systems, minutes per entry. That is the whole point of it.
- When you apply for work with us
-
Your name, your email address, what you write about the projects you have worked on and
the stacks and platforms you have used, and a link if you choose to give one.
We do not ask for a date of birth, an address or a resume upload, and the careers
form has no field for any of them.
One optional question asks whether you are of Aboriginal or Torres Strait Islander origin. It is the only sensitive information anywhere on this website, and section 4 explains exactly how it is handled. - When you email us
- Whatever is in the email, including your address and signature block.
- When we work for you
- Business contact details for the people we deal with, and whatever we necessarily see inside your systems while building and testing. See section 9.
- Automatically
- Our host keeps standard server logs: IP address, the page requested, time, browser type. They are kept for security and troubleshooting. We do not combine these with anything that identifies you, and we do not look at them unless something has gone wrong.
Giving us your details is voluntary. You can deal with us without giving a phone number. If you do not give a name, a business and an email we cannot answer you, which is the only reason those three are required.
4What we do not collect
- No date of birth, no government identifiers, no financial account details through this website.
- No sensitive information, with one exception, and it is opt in. No health, no religion, no union membership, no political views. We do not want any of it and there is nowhere on this site to give it to us.
- No advertising profiles and no data bought from anyone else.
The one exception: the careers form
The careers form asks, optionally, whether you are of Aboriginal or Torres Strait Islander origin. Under the Privacy Act that is sensitive information, so here is exactly how it works.
Why we ask. Crew22 is Aboriginal-owned and we want Aboriginal and Torres Strait Islander people building this with us. That is the only reason, and it is the only thing the answer is used for.
It is genuinely optional. There is no default answer, "prefer not to say" is one of the choices, and leaving it blank has no effect on your application. It is never used to screen anybody out.
What happens to it. It goes to one Crew22 mailbox with the rest of your application and nowhere else. It is not published, not passed to a recruiter, not used for statistics, and not attached to anything else we hold. Ask us and we delete it, either on its own or with your whole application, and we will tell you when it is done.
The wording of the question is the standard one used across Australia by the Australian Bureau of Statistics, so that it asks what it means to ask and nothing more.
5Cookies and tracking
This website sets no cookies. There is no analytics script, no advertising pixel, no session tracking and no third-party tag. That is why you are not being asked to consent to anything.
The site loads web fonts from Google Fonts, which means your browser requests a font file from Google's servers and Google will see the request. It does not set a cookie for it.
If we ever add analytics, this page changes first and the change will be visible in the date above.
6Why we collect it
- To answer your enquiry, and to answer it usefully. The numbers you send mean our first reply is about your business rather than a list of questions.
- To quote, scope and carry out work you engage us for.
- To consider you for work with us, if you send the careers form, and to reply to you either way. We do not use it for anything else, and we delete it on request. The optional question about Aboriginal or Torres Strait Islander origin is used for hiring and for nothing else. See section 4.
- To send you invoices and keep the business records the law requires us to keep.
- To keep the website and our systems secure.
That is the complete list. We do not use it for anything else without asking you first.
7Who else sees it
We do not sell personal information, and we do not disclose it for anyone else's marketing. We use a small number of service providers to run the business:
- Website hosting
- Vercel Inc., which serves this site and keeps the server logs described above.
- Email delivery
- Resend, which takes the enquiry form and delivers it to our inbox.
- Email and business records
- The provider of our email mailboxes, and our accounting software for invoicing.
Each of them sees only what it needs to do its job. We may also disclose information where the law requires it, or to our own professional advisers under a duty of confidentiality.
If we ever sell or restructure the business, personal information may transfer with it, and the buyer would be bound by a policy at least as protective as this one.
8Information going overseas
Some of the providers in section 7 store data outside Australia, mainly in the United States. We are telling you that plainly because you are entitled to know before you press send.
We choose providers that publish their security and privacy commitments, and we take reasonable steps to make sure your information is handled consistently with this policy. An overseas provider is not bound by Australian privacy law in the same way we are, and we cannot promise otherwise.
If your organisation requires Australian-only data handling for a piece of work, tell us at the scoping stage and we will design for it or tell you we cannot.
9Your systems during an engagement
- We ask for the least access that does the job, on our own named accounts. Never a shared password.
- We do not copy data out of your systems except where the workflow requires it, or to reproduce a fault.
- Where your systems hold personal information about your employees or customers, you are the one responsible for it and we handle it only on your instructions.
- You can revoke our access at any time, without asking and without explaining.
10How we protect it
- The site is served over HTTPS.
- Accounts that hold your information use multi-factor authentication.
- Credentials are kept in a password manager, never in a spreadsheet, a note or a message.
- Access is limited to the people who need it, which today is the two founders.
No system is perfectly secure, and we will not claim ours is. What we can say is what we do, and what we do when something goes wrong. That is section 14.
11How long we keep it
- Enquiries that go nowhere
- Two years, then deleted. Long enough that we remember the conversation if you come back.
- Client records
- Seven years after the last piece of work, because tax and corporate law require us to keep business records for that long.
- Server logs
- As long as our host keeps them, which is a short rolling window.
Ask us to delete something sooner and we will, unless the law says we have to keep it.
12Seeing and correcting your information
Email admin@crew22.com.au and ask. We will tell you what we hold about you and give you a copy, normally within 30 days, and we do not charge for it.
If something is wrong, tell us and we will correct it. If we decide not to give access or make a correction, which would be unusual, we will tell you why, in writing, and how to complain about that decision.
13Marketing and unsubscribing
Sending us an enquiry does not put you on a list. We have no newsletter and we do not run email sequences.
If that ever changes, any commercial message we send will identify us, will only go to people who agreed to receive it or who are existing customers with a reasonable expectation of it, and will carry a working unsubscribe that we action promptly, as the Spam Act 2003 (Cth) requires. Unsubscribing never affects work we are doing for you.
14If something goes wrong
If personal information we hold is lost, or accessed or disclosed without authorisation, we will investigate immediately and contain it.
Where that is likely to result in serious harm, we will tell the people affected and the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme. We will do that whether or not the scheme technically binds us at the time. If your business is affected because we were working in your systems, you hear from us first, not from someone else.
15Making a complaint
- Tell us first. Email admin@crew22.com.au with "Privacy complaint" in the subject. We will acknowledge it within 5 business days and give you an answer within 30 days.
- If you are not satisfied, you can take it to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.
You do not need our permission to go to the OAIC, and we will not hold it against you.
16Changes to this policy
The current version always sits on this page with the date it was last updated. If we make a change that materially affects how we handle information you have already given us, we will email you rather than rely on you noticing.
Email admin@crew22.com.au. One person reads it, and you will get a real answer.