Skip to content
College Crew

Privacy Policy

How College Crew collects, uses, discloses, and safeguards personal information.

Effective date: July 29, 2026

College Crew LLC, an Illinois limited liability company ("College Crew," "we," "us," or "our"), operates a marketplace that connects customers with independent college-student service providers. This Privacy Policy applies to the College Crew website, accounts, booking and payment features, messaging, support, and related services (collectively, the "Platform").

This Policy explains the information we collect, where it comes from, how and why we use it, the parties to whom we disclose it, how disclosure occurs, the safeguards we use, and the choices available to you. Our Legal Terms govern your use of the Platform.

1. Information we collect

We collect the following categories of information:

Account and contact information

Name, email address, account role, authentication and account status, support contact information, and the content of account-recovery or support requests. Passwords are handled by our authentication provider and are stored in hashed form, not as readable passwords.

Address and location information

Home, business, student, service, and job addresses; city, state, postal code, and approximate coordinates derived from an address. We use this information for service-area matching, distance estimates, booking logistics, safety, and support. Exact home and job addresses are not displayed in the public provider directory.

Provider onboarding and verification information

Date of birth, school and .edu email information, school directory identifiers, government-issued identification images, provider type, business or display name, biography, profile and service photos, neighborhood, optional school-organization information, service offerings, rates, availability, and verification status. College Crew manually reviews government identification. We do not use facial-recognition technology or create biometric identifiers from identification images.

Booking and service information

Requested service, schedule and availability, job location, job instructions, photos and attachments, quotes, estimates, arrival and completion activity, cancellations, replacement requests, invoices, disputes, refunds, and related audit records. For services involving a minor, a customer may provide limited information such as allergies, medical considerations, emergency contacts, supervision expectations, or activity restrictions. Customers should provide only information that is necessary for the service and that they are authorized to provide.

Communications and user content

Messages between customers and providers, chat images and attachments, reviews, provider profile text and images, support submissions, moderation results, reports, and communications with College Crew. Messages and profile text are automatically scanned for safety, inappropriate content, and attempts to move contact or payment off the Platform. Flagged content may be redacted, logged, and reviewed by College Crew founders.

Payment and payout information

Transaction amounts and status, limited payment-method details supplied by Stripe (such as card brand and last four digits), Stripe customer and connected-account identifiers, payment, transfer, payout, refund, invoice, and dispute records. Stripe directly collects full card numbers, bank-account information, tax information, and additional identity information used for payment or provider onboarding. College Crew does not receive or store full card numbers or provider bank-account credentials.

Technical and usage information

IP address, browser and device information, request and error logs, timestamps, authentication sessions, security events, email-delivery status, webhook records, and cookies or similar identifiers needed to keep you signed in, preserve security, remember a selected booking location, and operate the Platform.

2. Sources of information

We receive information directly from you when you create or update an account, apply as a provider, upload content, make or manage a booking, send a message, pay, submit a review, or contact support.

We also receive information from the customer or provider on the other side of a marketplace interaction, from Stripe concerning payments and connected-account readiness, from the U.S. Department of Education College Scorecard concerning schools, from the U.S. Census Bureau geocoder concerning address coordinates, and automatically from the device, browser, and infrastructure used to access the Platform.

3. How we use information

We use personal information to:

  • Create, authenticate, secure, and administer accounts.
  • Verify provider age, student status, identity, and onboarding readiness.
  • Display provider profiles, services, rates, availability, and reviews.
  • Match customers and providers, calculate approximate distance, facilitate bookings, and share necessary job logistics.
  • Authorize and process payments, provider transfers and payouts, refunds, invoices, disputes, fraud controls, and financial reconciliation.
  • Deliver transactional emails and account, booking, payment, and safety notices.
  • Operate messaging and scan messages and profile text for safety, prohibited contact information, abuse, and policy violations.
  • Provide support, investigate reports, resolve disputes, enforce our agreements, and protect users, College Crew, and the public.
  • Debug, maintain, secure, measure, and improve the Platform.
  • Comply with legal, tax, accounting, reporting, and regulatory obligations and respond to lawful requests.

We do not sell personal information. We do not disclose personal information for cross-context behavioral advertising, and we do not currently use third-party advertising trackers.

4. Parties to whom we disclose information—and how

We disclose information only as reasonably necessary for the purposes described in this Policy. Disclosure generally occurs through encrypted web requests and authenticated application programming interfaces, restricted service dashboards, time-limited private-file links, or the marketplace interfaces visible to the people involved in a booking.

Customers and providers

Information disclosed
Profile and service information, names needed for a booking, messages, schedules, job instructions, service location when needed to perform an accepted job, photos, quotes, invoices, and booking status.
Why
To let the parties evaluate, arrange, perform, pay for, support, and resolve a service.
How
Through authenticated Platform pages, booking records, messaging, and restricted database access. Public provider information is disclosed through provider profiles as described below.

Stripe

Information disclosed
Account and contact details, transaction amounts, booking and payment metadata, connected-account information, and information entered directly into Stripe’s payment, identity, tax, bank, and payout interfaces.
Why
Payment authorization and processing, provider onboarding and payouts, refunds, disputes, fraud prevention, tax reporting, and financial compliance.
How
Through Stripe-hosted forms, Stripe.js, authenticated Stripe APIs, and signed webhook events.

Supabase

Information disclosed
Account records, database content, uploaded files, authentication sessions, realtime messages, request metadata, and operational logs.
Why
Authentication, database hosting, private and public file storage, realtime features, server functions, and access controls.
How
Through encrypted Supabase client and server APIs, database connections, Storage, Auth, Realtime, and Edge Functions.

Vercel

Information disclosed
Web requests, IP address, browser and device metadata, server logs, and information processed by the website’s server functions.
Why
Website hosting, delivery, security, reliability, and diagnostics.
How
Automatically through the infrastructure that serves the Platform.

Resend

Information disclosed
Email address, email content, delivery metadata, and identifiers needed to send and monitor account and transactional messages.
Why
Email verification, authentication, booking notices, payment notices, moderation alerts, and support communications.
How
Through authenticated email APIs and signed delivery webhooks.

OpenAI

Information disclosed
The message or provider-profile text being evaluated and limited surrounding conversation context when needed for moderation. We do not intentionally send payment credentials or government-identification images for this purpose.
Why
To assist with detecting prohibited contact channels, abusive or inappropriate content, and other safety concerns.
How
Through an authenticated server-to-server API. Automated results may cause redaction or a flag for founder review; they do not determine payment, credit, employment, or legal eligibility.

U.S. Census Bureau geocoder

Information disclosed
Street address, city, state, and postal code, without account credentials or payment information.
Why
To derive approximate coordinates for distance estimates and service-area matching.
How
Through a server-to-server request to the Census Geocoding Services API when an address is saved or selected.

U.S. Department of Education College Scorecard

Information disclosed
A school search term or selected public school identifier.
Why
To suggest and confirm recognized colleges and their public website domains.
How
Through a server-to-server request to the College Scorecard API.

Brandfetch

Information disclosed
A recognized school’s public website domain and ordinary web-request metadata such as IP address and browser information.
Why
To display a recognized school logo on provider profiles.
How
Your browser may request the logo directly from Brandfetch’s content-delivery network when a recognized-school logo is displayed.

We may also disclose information to professional advisers, insurers, auditors, tax preparers, and contractors subject to confidentiality and security obligations; to government authorities or other parties when required by law or reasonably necessary to protect rights, safety, and security; and in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate protections.

5. Public information

Approved provider profiles may publicly display the provider’s display or business name, profile and service photos, biography, provider type, general neighborhood, recognized school, school-organization information the provider chooses to add, offered services, rates or quote information, availability notes, completed-job counts, and ratings or reviews. Public review displays do not identify the customer or expose the underlying booking.

Blog posts and other content intentionally submitted for public publication are also public. Public information may be viewed, copied, indexed, or redistributed by search engines and other people outside College Crew. Do not include sensitive or unnecessary personal information in public fields.

6. Cookies and analytics

We use essential cookies and similar browser storage for authentication, security, password recovery, administrator preview controls, remembering a selected booking origin, and dismissing certain account notices. The booking-origin cookie can contain an address and derived coordinates selected by the user and expires after approximately 30 days unless replaced or deleted earlier. Authentication cookies have durations controlled by our authentication provider and account activity.

College Crew does not currently use third-party advertising cookies, behavioral advertising pixels, or third-party marketing analytics. Browser "Do Not Track" signals are not standardized; because we do not currently use cross-site behavioral advertising, we do not change Platform behavior in response to those signals.

7. How long we retain information

We retain information for as long as reasonably necessary to provide the Platform, maintain an account, complete bookings and payments, support users, resolve disputes, prevent fraud and abuse, enforce agreements, and satisfy legal, tax, accounting, insurance, and reporting obligations. Different records therefore have different retention periods.

Short-lived verification codes, payment drafts, session data, and operational leases expire or are cleaned up on shorter schedules. Account deletion removes the account and associated Platform records through our deletion workflow, but we or our service providers may retain limited transaction, legal-acceptance, dispute, fraud, backup, or security records when reasonably necessary or legally required. Information already made public or copied by another person may remain outside our control.

When information is no longer reasonably needed, we delete it, de-identify it, or securely isolate it until deletion is practicable.

8. Security practices

We use administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure. These practices include:

  • HTTPS encryption for data transmitted to the Platform.
  • Supabase database row-level security and role-based access controls that limit users to authorized records.
  • Private storage for government-identification images, job photos, and chat attachments, with owner-restricted access or time-limited signed links.
  • Restricted founder administration, server-only privileged credentials, environment-managed secrets, and audit records for sensitive booking and payment operations.
  • Stripe-hosted handling of full card numbers, bank credentials, and provider payout onboarding so those credentials are not stored in College Crew’s database.
  • Input validation, webhook signature verification, duplicate event protection, authentication controls, moderation, and operational monitoring.
  • Service providers selected to support appropriate confidentiality, integrity, and security of the information they process for us.

No system can guarantee absolute security. Please use a unique password, protect your email account and devices, and notify us promptly through Support if you believe your account or information has been compromised.

9. Your choices and privacy rights

You can review and update many account and provider-profile fields in the Platform. You can manage public profile content, message and booking information before submission, and certain browser cookies through your browser or Platform controls.

The account settings include an account-deletion workflow. Deleting an account can cancel active bookings and remove profile, message, review, and other associated Platform records, subject to the retention limitations above. You may also contact us to request access to, correction of, or deletion of personal information, or a portable copy where required by applicable law. We may need to verify your identity and may deny or limit a request where permitted by law, including to protect another person’s rights or preserve required financial, security, dispute, or legal records.

Depending on where you live, applicable law may provide additional rights, including rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of certain sales, targeted advertising, or profiling. College Crew does not sell personal information or use it for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable privacy right.

Submit a privacy request through our Support form and select the closest available account or payment category. State that your message is a privacy request and describe the request. An authorized agent may submit a request where allowed by law, but we may require proof of authority and direct identity confirmation from the account holder.

10. Children and information about minors

The Platform is a general-audience service intended for people who can arrange and pay for local services. It is not directed to children under 13, and we do not knowingly allow children under 13 to create accounts or directly submit personal information. Providers must be at least 18 years old.

An adult customer arranging babysitting, tutoring, youth sports coaching, or another service involving a minor may provide limited information about that minor when necessary for safety and performance of the service. The customer represents that they are authorized to provide that information. Do not submit a minor’s information unless it is necessary, and do not place highly sensitive information in public fields.

If you believe a child under 13 has directly provided personal information through the Platform, contact us through Support so we can investigate and delete it as appropriate.

11. Processing locations and third-party services

College Crew is based in Illinois and the Platform is intended for use in the United States. We and our service providers may process information in the United States and other locations where they operate. Those locations may have privacy laws that differ from the laws where you live.

Third-party services have their own privacy policies and security practices. This Policy describes College Crew’s use of those services but does not replace the privacy notices those parties provide when they collect information directly, including Stripe’s notices during payment and connected-account onboarding.

12. Changes to this Policy

We may update this Privacy Policy as the Platform, our practices, or legal requirements change. We will post the revised Policy on this page and update the effective date. If a change materially affects how we use or disclose personal information, we will provide additional notice when reasonably required, such as through the Platform or by email.

13. Contact us

College Crew LLC is responsible for the personal information described in this Policy. For privacy questions, requests, or complaints, contact us through our public Feedback & Support form. Include "Privacy request" in your message and provide the email address associated with your account so we can respond and verify the request.

Feedback