← Back

CI Crew Tracker Privacy Policy

Effective date: July 27, 2026
Last updated: July 27, 2026

CI Crew Tracker is an internal crew scheduling and time-tracking application operated by CI Management ("CI Management," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, and disclose information when authorized crew members and production managers use CI Crew Tracker.

CI Crew Tracker is intended only for authorized CI Management personnel, workers, contractors, and administrators. It is not a public consumer application.

1. Information We Collect

Account and profile information

We may collect and store:

  • Email address
  • Full name
  • Optional phone number
  • Account role, such as administrator or worker
  • Account status
  • Account creation and update timestamps

Authentication is provided through Supabase Auth. CI Crew Tracker does not store plaintext passwords. Password credentials are processed and secured through the authentication provider.

Event and scheduling information

We may collect and store:

  • Event names, dates, start and end times, time zones, statuses, and notes
  • Event location labels and addresses
  • Event latitude and longitude, when configured
  • Geofence radius
  • Worker assignments
  • Assigned role or responsibility
  • Scheduled call time and end time
  • Assignment notes and instructions
  • Custom worker roles

Time-tracking and location information

When a worker chooses to clock in or clock out, CI Crew Tracker may collect:

  • Clock-in and clock-out timestamps
  • Device GPS coordinates at the time of the action
  • Reported location accuracy
  • Calculated distance from the event location
  • Whether the device was within the event's configured geofence
  • The event location associated with the time entry
  • Optional clock-in or clock-out notes
  • Time-entry status, such as open, closed, needs review, or approved

CI Crew Tracker does not continuously track a worker's location. Location is requested when the worker initiates a clock-in or clock-out action.

Audit and administrative information

We may collect and store records concerning:

  • Changes made to time entries
  • The administrator who made a change
  • The field that was changed
  • The previous and updated values
  • The reason for an adjustment
  • Dates and times of administrative activity

These records help CI Management investigate discrepancies, maintain accountability, and support operational and payroll-related review.

Device and local-storage information

The application may use browser local storage to maintain an authenticated session. The browser and hosting infrastructure may also process standard technical information required to deliver and secure the application, such as IP address, browser type, device type, request time, and security logs.

CI Crew Tracker does not currently use advertising trackers, marketing pixels, or third-party analytics tools.

2. How We Use Information

We use information collected through CI Crew Tracker to:

  • Create and administer authorized user accounts
  • Schedule and manage events
  • Assign workers to events
  • Communicate work assignments and responsibilities
  • Verify that a worker is at the assigned event location when clocking in or out
  • Record and review work time
  • Prepare staffing lists and time reports
  • Support payroll, billing, operational, compliance, and recordkeeping activities
  • Investigate timekeeping discrepancies
  • Document administrative changes
  • Protect the application, users, and CI Management from unauthorized access, misuse, fraud, or security threats
  • Comply with legal obligations and enforce workplace or contractor policies

We do not use location information for advertising or marketing.

3. Location Information and Geofencing

CI Crew Tracker uses the browser or device geolocation feature when a worker initiates a clock-in or clock-out action. The coordinates are sent to the application server, which calculates the approximate distance between the device and the assigned event location.

If an administrator has configured a geofence and the device appears to be outside the allowed radius, the application may prevent the clock-in or clock-out and display an error. Device location can be affected by signal quality, device settings, buildings, network conditions, and other technical factors.

Location information collected during clock-in or clock-out is stored with the time entry and may be viewed by authorized administrators in timekeeping records and reports.

Workers should contact an administrator if:

  • Location permission is unavailable
  • The reported location is inaccurate
  • A geofence incorrectly blocks a clock action
  • A time entry does not accurately reflect time worked

CI Management may review the circumstances and correct a time entry when appropriate. Nothing in this policy is intended to prevent a worker from reporting or correcting hours actually worked.

4. Camera and QR-Code Scanning

Camera access is optional and is used only when a worker chooses to scan an event-specific QR code.

QR-code video frames are processed locally in the browser using the jsQR library. CI Crew Tracker does not upload, transmit, or store camera images or video through the QR scanner.

The QR code opens the relevant event clock-in screen. Scanning a QR code does not itself complete a clock-in or clock-out.

CI Crew Tracker does not request microphone access, and microphone access is disabled by application policy.

5. How Information Is Shared

CI Management does not sell personal information. We do not share crew data with third-party advertisers or use it for targeted advertising.

Information may be disclosed as follows:

Authorized CI Management users

  • Workers can access their own profile information, assignments, and time entries.
  • Administrators can access worker profiles, events, assignments, time entries, operational reports, and audit logs as needed to perform authorized duties.

Service providers

We use service providers to operate the application:

  • Lovable Cloud and Supabase: Database hosting, authentication, backend functions, and related infrastructure
  • Google Fonts: Delivery of the Inter font. When the font loads from Google's servers, the user's browser may send standard request information, including an IP address, to Google.
  • jsPDF: Local PDF generation in an administrator's browser
  • jsQR: Local QR-code processing in a worker's browser

Supabase processes application data on CI Management's behalf as a service provider. jsPDF and jsQR perform the described functions in the browser and are not used by CI Management to upload PDF content, camera images, or video to those library providers.

Legal, safety, and business purposes

We may disclose information when reasonably necessary to:

  • Comply with law, regulation, court order, subpoena, or other valid legal process
  • Protect the rights, safety, property, or security of CI Management, its personnel, users, or others
  • Investigate suspected fraud, misuse, security incidents, or violations of applicable agreements or policies
  • Complete a merger, acquisition, reorganization, financing, sale of assets, or similar business transaction, subject to appropriate safeguards

6. PDF Exports

Authorized administrators may export staffing lists and clock-in reports as PDF files. These PDFs are generated locally in the administrator's browser and saved to the administrator's device.

Once downloaded, the file is controlled by the administrator and CI Management. Administrators must protect exported files, share them only for authorized business purposes, and delete them when they are no longer needed.

7. Data Retention

The application does not currently apply an automatic deletion schedule. Account, event, assignment, timekeeping, location, and audit information is generally retained until an authorized administrator deletes the relevant account or event.

Some information may be retained longer when reasonably necessary for payroll, tax, accounting, dispute resolution, legal compliance, security, or other legitimate business-record purposes. Deletion of an account or event may be limited when retaining associated records is required by law or needed to preserve accurate timekeeping and audit history.

CI Management should periodically review retained information and securely delete information that is no longer reasonably needed.

8. Data Security

CI Management uses administrative, technical, and organizational safeguards designed to protect information. These safeguards include:

  • Email and password authentication through Supabase Auth
  • Password requirements and breached-password screening
  • Row Level Security policies that restrict database access according to role and ownership
  • Role-based access within the application
  • Security-related browser headers and permissions policies
  • Audit records for administrative time-entry changes

No method of electronic storage or transmission is completely secure. Users must protect their login credentials, use a secure device, sign out of shared devices, and promptly report suspected unauthorized access.

9. Your Choices and Requests

Workers can view their assignments and time entries and can update their own phone number through the application.

To request access, correction, account deactivation, or deletion of information, contact an authorized CI Management administrator or use the contact information below. CI Management may need to verify the requester's identity.

Certain requests may be limited when information must be retained for payroll, tax, legal, security, dispute-resolution, or other legitimate business purposes. Workers may report inaccurate time or location records and request review without waiving any rights they may have under applicable law.

Users can deny browser location or camera permission. Denying location permission may prevent use of the standard clock-in and clock-out feature. Camera permission is optional because workers may access an event without scanning its QR code.

10. Children's Privacy

CI Crew Tracker is a restricted workforce application and is not directed to children. Users must be legally eligible and authorized to perform work for CI Management. If CI Management authorizes a minor to work, the account and data must be handled in accordance with applicable employment and privacy requirements.

11. Changes to This Privacy Policy

We may update this Privacy Policy when the application, our practices, or applicable requirements change. The revised policy will display a new "Last updated" date. When a change materially affects how worker information or location data is handled, CI Management may provide additional notice through the application, by email, or through another appropriate workplace communication.

12. Contact Us

Questions, privacy requests, timekeeping concerns, or security reports may be directed to an authorized CI Management administrator or:

CI Management
Email: info@ci-mgt.com

Before publishing this policy, CI Management must replace the bracketed contact field with an actively monitored email address.