CrewShift Landing Page Privacy Policy
Last updated: 30 May 2026 Version: 2.21. Scope
This policy applies only to the CrewShift landing page available at https://crewshift-app.com and the Polish Zmianowo version available at https://zmianowo-app.pl.
It does not describe processing in the production application. The application, accounts, checkout, payments, employee data and training data are covered by separate documents available in the application and presented before checkout.
2. Data controller
The controller of personal data is:
Brillnet Piotr Adamskiul. Sienkiewicza 73/6
90-057 Lodz, Poland
Tax ID (NIP): PL7321779060
REGON: 101551294
Privacy contact: hello@crewshift-app.com
The controller does not list a separate Data Protection Officer for this landing page. If such contact is formally appointed, this document will be updated.
3. Data we process
Depending on how the page is used, we may process:
- technical request data, including IP address, source domain, HTTP headers, browser, device and event time,
- data submitted in the contact or demo form: full name, e-mail address, optional company name, subject and message,
- readiness assessment data: e-mail address, score, readiness tier, page language and source domain,
- form security data, including Cloudflare Turnstile token, IP address and anti-bot verification result,
- cookie and similar technology preferences stored in the browser,
- analytics data from Google Analytics 4, only after analytics consent,
- Crisp chat data, only after functional consent and only if the chat widget is enabled.
The landing page itself does not create accounts, provide login, accept payments or store training content, learner progress or test results. Registration buttons redirect to the separate application, whose privacy documents apply after the user enters its domain.
4. Purposes and legal bases
| Purpose | Data categories | Legal basis |
|---|---|---|
| Displaying and technically operating the page | technical request data, logs, source domain | Art. 6(1)(f) GDPR - legitimate interest |
| Security, spam prevention and abuse prevention | IP, headers, Turnstile token, verification result, rate limiting | Art. 6(1)(f) GDPR |
| Handling a contact or demo request | full name, e-mail, company, subject, message | Art. 6(1)(b) GDPR, including pre-contractual steps requested by the person |
| Handling the readiness assessment and follow-up | e-mail, score, readiness tier, language, source domain | Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR, depending on the request |
| Website analytics | GA4 identifiers, page events, device data | Art. 6(1)(a) GDPR - consent |
| Optional chat | chat session data, conversation content, device metadata | Art. 6(1)(a) GDPR to load the widget, then Art. 6(1)(b) or 6(1)(f) GDPR to handle the conversation |
| Establishing or defending claims | correspondence, logs, security metadata | Art. 6(1)(f) GDPR |
5. Forms
The contact form and readiness assessment are voluntary. Providing an e-mail address is necessary to respond to a request or continue the conversation after the assessment.
Forms are protected by:
- request rate limiting,
- a hidden honeypot field,
- Cloudflare Turnstile, if service keys are configured for the environment.
Form messages are delivered by e-mail through Resend / Plus Five Five, Inc. to the Brillnet contact mailbox. Resend acts as Brillnet's processor for form messages and Brillnet-owned contact lists.
6. Cookies, localStorage and similar technologies
Detailed information about browser storage technologies is available in the Cookie Policy.
Cookie settings are stored locally in the browser under the cookie-consent key. The record includes selected categories and the date of the choice. The page reads this record to avoid asking again on every visit and to load or block optional scripts.
The e-mail address provided in the readiness assessment may be stored locally under the quiz_email key to make the contact form easier to complete. This record stays in the user's browser and can be removed in browser settings.
7. Recipients and processors
For this landing page, we use only providers needed for hosting, security, e-mail delivery, optional analytics and optional chat.
| Provider | Role on the landing page | Data scope |
|---|---|---|
| Cloudflare Inc. | Workers hosting, server functions, infrastructure logs and metrics, request rate limiting and Turnstile | request data, IP, headers, source domain, error and availability logs, rate-limit counter, verification token, browser and device signals |
| Resend / Plus Five Five, Inc. | e-mail delivery for forms and Brillnet-owned contact-list handling | full name, e-mail, company, subject, message content, assessment result, subscription source, consent or unsubscribe status, technical delivery metadata |
| Google Ireland Ltd. / Google LLC | Google Analytics 4, only with analytics consent | cookie identifiers, page events, device data |
| Crisp IM SAS | chat widget, only with functional consent | chat session data, conversation content, IP and device metadata |
For this page we do not use payment processors, application login, the production application database or tools that manage training content, learner progress or tests.
8. Transfers outside the EEA
Some providers may process data outside the European Economic Area or use subprocessors outside the EEA. Resend / Plus Five Five, Inc. is a US-based provider. Where such transfer occurs, it relies on GDPR-compliant mechanisms such as a data processing agreement, Standard Contractual Clauses, the EU-US Data Privacy Framework or other appropriate safeguards.
We do not use open tracking or link-click tracking in messages from these forms or contact lists unless that feature is separately disclosed and has an appropriate legal basis.
Transfers related to Google Analytics or Crisp may occur only if the user consents to the relevant optional category and the service is configured on the page.
9. Retention periods
| Data category | Retention |
|---|---|
| Contact and demo requests | for the time needed to handle the request, then up to 3 years for contact history and claims |
| Readiness assessment data submitted by form | for the time needed to handle the follow-up, no longer than 3 years unless a further relationship justifies longer retention |
| Technical and security logs | according to hosting and provider configuration, usually for a limited technical period |
| Rate limiting data | for the rate-limit window and technical provider retention |
| Browser cookie preferences | up to 180 days or until removed by the user |
| Google Analytics data | according to provider settings and user consent |
| Crisp chat data | according to Crisp settings and conversation history |
10. Data subject rights
You have the right to:
- access your data,
- rectify your data,
- erase your data,
- restrict processing,
- data portability where applicable,
- object to processing based on legitimate interest,
- withdraw consent at any time, without affecting processing before withdrawal,
- lodge a complaint with a competent supervisory authority.
Requests can be sent to: hello@crewshift-app.com.
11. Automated decisions
The landing page does not make automated decisions about users that produce legal effects or similarly significant effects.
The readiness assessment is informational and marketing-oriented. Its result is not legal, HR or audit advice.
12. Changes
This policy may be updated if the page scope, provider list, form operation, law or cookie configuration changes.
The current version is available at: https://crewshift-app.com/en/privacy-policy.
13. Contact
Brillnet Piotr AdamskiE-mail: hello@crewshift-app.com
Address: ul. Sienkiewicza 73/6, 90-057 Lodz, Poland
Effective date: 23 July 2026
