Privacy Policy
How College Crew collects, uses, discloses, and safeguards personal information.
Effective date: July 29, 2026
College Crew LLC, an Illinois limited liability company ("College Crew," "we," "us," or "our"), operates a marketplace that connects customers with independent college-student service providers. This Privacy Policy applies to the College Crew website, accounts, booking and payment features, messaging, support, and related services (collectively, the "Platform").
This Policy explains the information we collect, where it comes from, how and why we use it, the parties to whom we disclose it, how disclosure occurs, the safeguards we use, and the choices available to you. Our Legal Terms govern your use of the Platform.
1. Information we collect
We collect the following categories of information:
Account and contact information
Name, email address, account role, authentication and account status, support contact information, and the content of account-recovery or support requests. Passwords are handled by our authentication provider and are stored in hashed form, not as readable passwords.
Address and location information
Home, business, student, service, and job addresses; city, state, postal code, and approximate coordinates derived from an address. We use this information for service-area matching, distance estimates, booking logistics, safety, and support. Exact home and job addresses are not displayed in the public provider directory.
Provider onboarding and verification information
Date of birth, school and .edu email information, school directory identifiers, government-issued identification images, provider type, business or display name, biography, profile and service photos, neighborhood, optional school-organization information, service offerings, rates, availability, and verification status. College Crew manually reviews government identification. We do not use facial-recognition technology or create biometric identifiers from identification images.
Booking and service information
Requested service, schedule and availability, job location, job instructions, photos and attachments, quotes, estimates, arrival and completion activity, cancellations, replacement requests, invoices, disputes, refunds, and related audit records. For services involving a minor, a customer may provide limited information such as allergies, medical considerations, emergency contacts, supervision expectations, or activity restrictions. Customers should provide only information that is necessary for the service and that they are authorized to provide.
Communications and user content
Messages between customers and providers, chat images and attachments, reviews, provider profile text and images, support submissions, moderation results, reports, and communications with College Crew. Messages and profile text are automatically scanned for safety, inappropriate content, and attempts to move contact or payment off the Platform. Flagged content may be redacted, logged, and reviewed by College Crew founders.
Payment and payout information
Transaction amounts and status, limited payment-method details supplied by Stripe (such as card brand and last four digits), Stripe customer and connected-account identifiers, payment, transfer, payout, refund, invoice, and dispute records. Stripe directly collects full card numbers, bank-account information, tax information, and additional identity information used for payment or provider onboarding. College Crew does not receive or store full card numbers or provider bank-account credentials.
Technical and usage information
IP address, browser and device information, request and error logs, timestamps, authentication sessions, security events, email-delivery status, webhook records, and cookies or similar identifiers needed to keep you signed in, preserve security, remember a selected booking location, and operate the Platform.
2. Sources of information
We receive information directly from you when you create or update an account, apply as a provider, upload content, make or manage a booking, send a message, pay, submit a review, or contact support.
We also receive information from the customer or provider on the other side of a marketplace interaction, from Stripe concerning payments and connected-account readiness, from the U.S. Department of Education College Scorecard concerning schools, from the U.S. Census Bureau geocoder concerning address coordinates, and automatically from the device, browser, and infrastructure used to access the Platform.
3. How we use information
We use personal information to:
- Create, authenticate, secure, and administer accounts.
- Verify provider age, student status, identity, and onboarding readiness.
- Display provider profiles, services, rates, availability, and reviews.
- Match customers and providers, calculate approximate distance, facilitate bookings, and share necessary job logistics.
- Authorize and process payments, provider transfers and payouts, refunds, invoices, disputes, fraud controls, and financial reconciliation.
- Deliver transactional emails and account, booking, payment, and safety notices.
- Operate messaging and scan messages and profile text for safety, prohibited contact information, abuse, and policy violations.
- Provide support, investigate reports, resolve disputes, enforce our agreements, and protect users, College Crew, and the public.
- Debug, maintain, secure, measure, and improve the Platform.
- Comply with legal, tax, accounting, reporting, and regulatory obligations and respond to lawful requests.
We do not sell personal information. We do not disclose personal information for cross-context behavioral advertising, and we do not currently use third-party advertising trackers.
4. Parties to whom we disclose information—and how
We disclose information only as reasonably necessary for the purposes described in this Policy. Disclosure generally occurs through encrypted web requests and authenticated application programming interfaces, restricted service dashboards, time-limited private-file links, or the marketplace interfaces visible to the people involved in a booking.
Customers and providers
- Information disclosed
- Profile and service information, names needed for a booking, messages, schedules, job instructions, service location when needed to perform an accepted job, photos, quotes, invoices, and booking status.
- Why
- To let the parties evaluate, arrange, perform, pay for, support, and resolve a service.
- How
- Through authenticated Platform pages, booking records, messaging, and restricted database access. Public provider information is disclosed through provider profiles as described below.
Stripe
- Information disclosed
- Account and contact details, transaction amounts, booking and payment metadata, connected-account information, and information entered directly into Stripe’s payment, identity, tax, bank, and payout interfaces.
- Why
- Payment authorization and processing, provider onboarding and payouts, refunds, disputes, fraud prevention, tax reporting, and financial compliance.
- How
- Through Stripe-hosted forms, Stripe.js, authenticated Stripe APIs, and signed webhook events.
Supabase
- Information disclosed
- Account records, database content, uploaded files, authentication sessions, realtime messages, request metadata, and operational logs.
- Why
- Authentication, database hosting, private and public file storage, realtime features, server functions, and access controls.
- How
- Through encrypted Supabase client and server APIs, database connections, Storage, Auth, Realtime, and Edge Functions.
Vercel
- Information disclosed
- Web requests, IP address, browser and device metadata, server logs, and information processed by the website’s server functions.
- Why
- Website hosting, delivery, security, reliability, and diagnostics.
- How
- Automatically through the infrastructure that serves the Platform.
Resend
- Information disclosed
- Email address, email content, delivery metadata, and identifiers needed to send and monitor account and transactional messages.
- Why
- Email verification, authentication, booking notices, payment notices, moderation alerts, and support communications.
- How
- Through authenticated email APIs and signed delivery webhooks.
OpenAI
- Information disclosed
- The message or provider-profile text being evaluated and limited surrounding conversation context when needed for moderation. We do not intentionally send payment credentials or government-identification images for this purpose.
- Why
- To assist with detecting prohibited contact channels, abusive or inappropriate content, and other safety concerns.
- How
- Through an authenticated server-to-server API. Automated results may cause redaction or a flag for founder review; they do not determine payment, credit, employment, or legal eligibility.
U.S. Census Bureau geocoder
- Information disclosed
- Street address, city, state, and postal code, without account credentials or payment information.
- Why
- To derive approximate coordinates for distance estimates and service-area matching.
- How
- Through a server-to-server request to the Census Geocoding Services API when an address is saved or selected.
U.S. Department of Education College Scorecard
- Information disclosed
- A school search term or selected public school identifier.
- Why
- To suggest and confirm recognized colleges and their public website domains.
- How
- Through a server-to-server request to the College Scorecard API.
Brandfetch
- Information disclosed
- A recognized school’s public website domain and ordinary web-request metadata such as IP address and browser information.
- Why
- To display a recognized school logo on provider profiles.
- How
- Your browser may request the logo directly from Brandfetch’s content-delivery network when a recognized-school logo is displayed.
We may also disclose information to professional advisers, insurers, auditors, tax preparers, and contractors subject to confidentiality and security obligations; to government authorities or other parties when required by law or reasonably necessary to protect rights, safety, and security; and in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate protections.
5. Public information
Approved provider profiles may publicly display the provider’s display or business name, profile and service photos, biography, provider type, general neighborhood, recognized school, school-organization information the provider chooses to add, offered services, rates or quote information, availability notes, completed-job counts, and ratings or reviews. Public review displays do not identify the customer or expose the underlying booking.
Blog posts and other content intentionally submitted for public publication are also public. Public information may be viewed, copied, indexed, or redistributed by search engines and other people outside College Crew. Do not include sensitive or unnecessary personal information in public fields.
7. How long we retain information
We retain information for as long as reasonably necessary to provide the Platform, maintain an account, complete bookings and payments, support users, resolve disputes, prevent fraud and abuse, enforce agreements, and satisfy legal, tax, accounting, insurance, and reporting obligations. Different records therefore have different retention periods.
Short-lived verification codes, payment drafts, session data, and operational leases expire or are cleaned up on shorter schedules. Account deletion removes the account and associated Platform records through our deletion workflow, but we or our service providers may retain limited transaction, legal-acceptance, dispute, fraud, backup, or security records when reasonably necessary or legally required. Information already made public or copied by another person may remain outside our control.
When information is no longer reasonably needed, we delete it, de-identify it, or securely isolate it until deletion is practicable.
8. Security practices
We use administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure. These practices include:
- HTTPS encryption for data transmitted to the Platform.
- Supabase database row-level security and role-based access controls that limit users to authorized records.
- Private storage for government-identification images, job photos, and chat attachments, with owner-restricted access or time-limited signed links.
- Restricted founder administration, server-only privileged credentials, environment-managed secrets, and audit records for sensitive booking and payment operations.
- Stripe-hosted handling of full card numbers, bank credentials, and provider payout onboarding so those credentials are not stored in College Crew’s database.
- Input validation, webhook signature verification, duplicate event protection, authentication controls, moderation, and operational monitoring.
- Service providers selected to support appropriate confidentiality, integrity, and security of the information they process for us.
No system can guarantee absolute security. Please use a unique password, protect your email account and devices, and notify us promptly through Support if you believe your account or information has been compromised.
9. Your choices and privacy rights
You can review and update many account and provider-profile fields in the Platform. You can manage public profile content, message and booking information before submission, and certain browser cookies through your browser or Platform controls.
The account settings include an account-deletion workflow. Deleting an account can cancel active bookings and remove profile, message, review, and other associated Platform records, subject to the retention limitations above. You may also contact us to request access to, correction of, or deletion of personal information, or a portable copy where required by applicable law. We may need to verify your identity and may deny or limit a request where permitted by law, including to protect another person’s rights or preserve required financial, security, dispute, or legal records.
Depending on where you live, applicable law may provide additional rights, including rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of certain sales, targeted advertising, or profiling. College Crew does not sell personal information or use it for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable privacy right.
Submit a privacy request through our Support form and select the closest available account or payment category. State that your message is a privacy request and describe the request. An authorized agent may submit a request where allowed by law, but we may require proof of authority and direct identity confirmation from the account holder.
10. Children and information about minors
The Platform is a general-audience service intended for people who can arrange and pay for local services. It is not directed to children under 13, and we do not knowingly allow children under 13 to create accounts or directly submit personal information. Providers must be at least 18 years old.
An adult customer arranging babysitting, tutoring, youth sports coaching, or another service involving a minor may provide limited information about that minor when necessary for safety and performance of the service. The customer represents that they are authorized to provide that information. Do not submit a minor’s information unless it is necessary, and do not place highly sensitive information in public fields.
If you believe a child under 13 has directly provided personal information through the Platform, contact us through Support so we can investigate and delete it as appropriate.
11. Processing locations and third-party services
College Crew is based in Illinois and the Platform is intended for use in the United States. We and our service providers may process information in the United States and other locations where they operate. Those locations may have privacy laws that differ from the laws where you live.
Third-party services have their own privacy policies and security practices. This Policy describes College Crew’s use of those services but does not replace the privacy notices those parties provide when they collect information directly, including Stripe’s notices during payment and connected-account onboarding.
12. Changes to this Policy
We may update this Privacy Policy as the Platform, our practices, or legal requirements change. We will post the revised Policy on this page and update the effective date. If a change materially affects how we use or disclose personal information, we will provide additional notice when reasonably required, such as through the Platform or by email.
13. Contact us
College Crew LLC is responsible for the personal information described in this Policy. For privacy questions, requests, or complaints, contact us through our public Feedback & Support form. Include "Privacy request" in your message and provide the email address associated with your account so we can respond and verify the request.