Privacy Policy
Last updated: January 2026
1. Introduction
Qrew (“we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our time-tracking SaaS platform and related services.
We process personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable Italian data protection legislation.
2. Data Controller
The data controller is Qrew S.r.l. You can contact us at [email protected].
3. Data We Collect
- Account data: name, email address, phone number, company name.
- Worker data: phone number, clock-in/out timestamps, GPS coordinates (only during active sessions), device identifiers.
- Technical data: IP address, browser type, device fingerprint (for fraud prevention), WebAuthn credentials.
- Usage data: session durations, location assignments, payroll calculations.
4. Legal Basis for Processing
- Contract performance: processing necessary to provide the time-tracking service.
- Legitimate interest: fraud prevention, security, service improvement.
- Consent: push notifications, optional photo verification.
- Legal obligation: compliance with employment law record-keeping requirements.
5. Data Retention
We retain personal data for the duration of your account plus 10 years (to comply with Italian employment record-keeping obligations). Audit logs are retained for 10 years. You may request earlier deletion where permitted by law.
6. Your Rights (GDPR)
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
To exercise your rights, contact [email protected].
7. Data Processors & Transfers
We use the following processors: Stripe (payments), our mailcow email server (transactional email). All data is stored within the EU. We do not transfer data to third countries without appropriate safeguards.
8. Security
We implement appropriate technical and organisational measures including encryption at rest and in transit, CSRF protection, audit logging with chain-of-custody verification, and regular security reviews.
9. Changes
We may update this policy. Material changes will be communicated via email or in-app notification at least 30 days before they take effect.