Skip to content
Launch special: 50% off your first 2 months· 50% off for 2 months

Legal

Data Processing Addendum

Effective October 1, 2026

This Data Processing Addendum (“DPA”) is part of the Terms of Service between RepeatCrew (“we”, “us”) and the business that uses RepeatCrew (“you”). It explains how we handle personal data about your customers and contacts on your behalf. It applies automatically when you accept the Terms; no separate signature is needed.

Roles

For personal data about your customers, leads, and contacts that you or they put into RepeatCrew (“Customer Personal Data”), you are the controller (you decide why and how the data is used) and we are your processor. Under U.S. state privacy laws such as the California Consumer Privacy Act (CCPA), you are the “business” and we are your “service provider” or “processor”. Information about your own account and team is handled as described in our Privacy Policy.

Scope of processing

  • Purpose: to provide RepeatCrew to you, including messaging, calls, AI features, booking, estimates, invoicing, payments, reviews, and support.
  • Types of data: names, phone numbers, email and postal addresses, messages, call recordings and transcripts, appointment and job details, photos, payment records (not full card numbers), consent and opt-out records, and other information you or your customers provide.
  • People concerned: your customers, leads, and other contacts, and anyone who communicates with your business through RepeatCrew.
  • Duration: for as long as you use RepeatCrew, plus the deletion period described below.

Your instructions

We process Customer Personal Data only on your documented instructions. The Terms, this DPA, and the way you configure and use RepeatCrew are your instructions. If we are required by law to process data in another way, we will tell you first unless the law forbids it. We will tell you if we believe an instruction violates the law. You are responsible for having a lawful basis and any required notices and consents for the data you give us.

Confidentiality

Our staff and contractors who can access Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide, support, and secure the service.

Security

We maintain technical and organizational measures designed to protect Customer Personal Data, including:

  • Encryption of data in transit (TLS) and at rest.
  • Row-level tenant isolation in the database, so each business can access only its own data.
  • Multi-factor authentication (MFA) options and role-based access controls for accounts and staff.
  • Encryption of secrets, such as integration access tokens.
  • Least-privilege access, logging, and monitoring of our systems.

See our Security page for more detail. We may update these measures as long as the overall level of protection is not reduced.

Subprocessors

You authorize us to use subprocessors to help provide RepeatCrew. Our current subprocessors are listed in the Privacy Policy under “Service providers we share information with”. We bind each subprocessor to data protection terms at least as protective as this DPA, and we remain responsible for their performance. We will update that list before adding or replacing a subprocessor. If you have a reasonable, data-protection-based objection to a new subprocessor, contact us; if we can’t address it, you may stop using the affected feature or close your account.

Helping with requests from individuals

RepeatCrew lets you view, export, correct, and delete most Customer Personal Data yourself. Taking into account the nature of the processing, we will provide reasonable help so you can respond to requests from individuals to access, correct, delete, or port their data, or to opt out. If we receive a request directly, we will direct the person to you, or forward it to you, rather than respond ourselves, unless the law requires otherwise. We will also give reasonable help with data protection assessments and consultations with regulators where required by law.

Security incidents

If we become aware of a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, we will notify you without undue delay. We will share the information you reasonably need to understand the incident and meet your own notification duties, and we will take reasonable steps to contain and fix it.

Deletion and return

You can export your data at any time while your account is active. When your account closes, we delete or anonymize Customer Personal Data within a reasonable period, except where we must keep it to meet legal, tax, or accounting obligations, or to show compliance (for example consent records). Data in backups is removed as backups roll off on their normal schedule and is protected in the meantime.

Audits

On reasonable written request, no more than once a year (or after a security incident), we will provide documentation, such as security summaries and answers to a reasonable security questionnaire, to show our compliance with this DPA. Any further audit must be agreed in advance in writing, be at your expense, be conducted with reasonable notice during business hours, and be subject to confidentiality.

International transfers

RepeatCrew is operated from the United States and our subprocessors may process data in the United States and other countries. Where the law requires a transfer mechanism for personal data leaving the European Economic Area, the United Kingdom, or Switzerland, the applicable Standard Contractual Clauses (or another approved mechanism) apply and are incorporated by reference.

CCPA service provider terms

For personal information covered by the CCPA and similar U.S. state laws, we will not:

  • Sell or share the personal information (including for cross-context behavioral advertising).
  • Keep, use, or disclose it for any purpose other than providing the service to you, or as otherwise permitted by law for service providers.
  • Keep, use, or disclose it outside our direct business relationship with you.
  • Combine it with personal information we receive from others, except as the law permits.

We will comply with applicable obligations under those laws, provide the same level of privacy protection they require, and tell you if we can no longer meet them. You may take reasonable steps to stop and fix any unauthorized use. We certify that we understand and will comply with these restrictions.

General

If this DPA conflicts with the Terms, this DPA controls for the processing of Customer Personal Data. The limits of liability in the Terms apply to this DPA. We may update this DPA as described in the Terms. Questions? Reach us through our contact page.