1Who we are
Crewbase is operated by ‹registered company name›, a company incorporated in Nigeria with registration number ‹RC number› and its registered office at ‹registered address› (“Crewbase”, “we”, “us”). We run the service at crewbase.africa and app.crewbase.africa.
For the personal data described in this policy we are the data controller under the Nigeria Data Protection Act 2023 (the NDPA). Where an operator uses Crewbase to find and contact people, that operator is a separate controller for what it does with the data afterwards — see clause 6.
Our Data Protection Officer is ‹DPO name› and can be reached at privacy@crewbase.africa. Our registration with the Nigeria Data Protection Commission (the NDPC) is ‹NDPC registration number›.
2What this policy covers
Two kinds of account use Crewbase, and what we hold differs sharply between them:
- Professionals — pilots, engineers, apprentices and aviation office staff who build a dossier and are found by operators. Crewbase is free for professionals.
- Operators — airlines, MROs and ground handlers whose team members search, post work and pay for a subscription.
It also covers visitors to our public pages who have no account at all. It does not cover what an operator does with your details once they have contacted you — at that point the operator is answerable to you directly, and to the NDPC.
3What we collect
In short — from professionals: who you are, what you are licensed to do, the document proving it, and how to reach you. From operators: the company, the team, and what they did on the platform. From everyone: the technical minimum needed to serve a page securely.
3.1 From professionals
- Identity — your full name, work email address, and a profile photo if you add one.
- Profile — profession, base city and base location, availability, years of experience, and an optional short bio.
- Contact — an optional phone number, and separately recorded consent for whether you may be sent SMS or telephoned about grounded-aircraft (AOG) work, including whether you accept critical calls outside normal hours.
- Credentials — for each licence, rating or certificate: its type, licence number, issuing authority, issue date and expiry date, plus the document you upload as evidence.
- Type ratings — the aircraft you are rated on, your rating class, and optionally your hours on each type.
- Logbook figures — total, pilot-in-command, night and instrument hours. These are self-reported by you. NCAA verification covers your licence, not your logbook, and we label them that way everywhere they appear.
- Ad-hoc eligibility — whether you are freelance, retired, employed and cleared, or employed and training-bonded; and, each time you apply for ad-hoc work, a timestamped attestation that you are contractually free to accept it.
- Activity — the requests you open, the requests you respond to or apply for, the stage your application has reached, any note you attach to it, and whether you withdrew it.
- Device — a push notification token if you use a mobile app and enable push.
3.2 From operators
- Company — name, type (airline, MRO or handler), base airport, fleet, logo and location.
- Team — each member’s name and work email, their role in the workspace, their permissions, and their notification preferences.
- Activity — requests posted, applicants received and the stage each was moved to, shortlists created, private notes written about professionals, contact reveals used, and messages received in the company inbox.
- Billing — subscription tier and status, and the payment reference returned by Paystack. Card numbers are handled entirely by Paystack and never reach our servers.
3.3 From everyone, automatically
- Your IP address, browser and device type, and the pages you request — collected by our hosting provider as part of serving the site and kept in access logs.
- A session cookie that keeps you signed in, and a preference cookie remembering light or dark mode. See clause 10.
- The fact and time of each sign-in, held in our authentication system.
3.4 What we deliberately do not collect
- No password. Sign-in is a one-time code sent to your email, or an optional Google sign-in — there is no password for us to store or lose.
- No card or bank details. Payment happens on Paystack’s systems.
- No date of birth, national identity number, BVN, next of kin, marital status, religion or ethnicity. We have never needed them, so we do not ask.
- No advertising or cross-site tracking identifiers, and no data bought from third parties.
4Medical certificates and other sensitive data
In short — your aviation medical certificate is health data. We treat it as the most protected thing on the platform, we ask for your explicit consent before storing it, and no operator ever sees the certificate itself.
A Class 1 or Class 2 aviation medical certificate is a record about your health. Under section 30 of the NDPA that makes it sensitive personal data, which may only be processed on a narrower set of grounds and with heightened protection.
- We ask for your explicit, separate consent before you upload a medical certificate, and we tell you why we need it. You can decline; you simply will not carry a verified medical on your dossier.
- We record only the certificate class, its number, the issuing authority and its issue and expiry dates. We do not record, extract or store any clinical finding, diagnosis, limitation or restriction from the certificate.
- The uploaded document is stored in a private bucket and is readable only by you and by the Crewbase verification staff performing the check. No operator can open it on any plan.
- To operators on paid Pro or Enterprise plans, a verified medical appears as a class and an expiry date — the fact that you are current — and nothing more.
- You may withdraw consent at any time by writing to privacy@crewbase.africa. We will delete the document and the record, and the medical will disappear from your dossier.
We do not knowingly collect any other category of sensitive personal data — race, religion, political opinion, trade union membership, sexual orientation, genetic or biometric data. Please do not put any of it in your bio, your application note, or a document you upload.
5Why we process it, and on what legal basis
Section 25 of the NDPA requires a lawful basis for every processing activity. Ours are set out below, purpose by purpose.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account | You cannot use Crewbase without one | Performance of a contract |
| Verify a licence or certificate against the issuing authority’s record | Verification is the entire point of the service | Performance of a contract; legitimate interests in a trustworthy register |
| Store and check a medical certificate | To show operators you hold a current medical | Explicit consent (sensitive data — clause 4) |
| Show your verified dossier to operators searching | So that operators can find you, which is why you signed up | Performance of a contract |
| Match and alert you to AOG work near your base | Grounded aircraft are filled in hours, not weeks | Performance of a contract; consent for SMS and voice calls |
| Record a contact reveal and tell you it happened | You are entitled to know who obtained your details; the operator is entitled to a record that they paid for them | Legitimate interests; performance of a contract with the operator |
| Take subscription payments and keep accounting records | We are paid by operators and taxed on it | Performance of a contract; legal obligation |
| Send service notifications about your account and activity | You asked for the service; these are part of it | Performance of a contract |
| Send optional product news | Only if you opt in | Consent, withdrawable at any time |
| Detect fraud, fake credentials and misuse | A single forged licence would destroy the platform’s value | Legitimate interests; legal obligation |
| Respond to a regulator, court or lawful request | We have to | Legal obligation |
Where we rely on legitimate interests we have weighed those interests against your rights and concluded they do not override them. You can ask us for that assessment, and you can object — see clause 16.
6Who can see what
In short — the licence scan you upload is seen by you and our verification staff, and by nobody else — ever, on any plan. Everything an operator can see is listed below.
6.1 Your uploaded documents
The licence, rating or medical scan you upload is the most sensitive thing you give us and it is treated as such. It is held in a private storage bucket, reachable only through short-lived signed links, and access is enforced by the database itself: you can read files in your own folder, and platform verification staff can read them to perform the check. Nobody else can, including our own engineers working through the application.
No operator can see your uploaded document, on any subscription tier. Operators see the outcome of verification and, on paid tiers, the record it produced — never the paperwork itself. The reason a submission was rejected is shown to you and to our reviewers, and to nobody else: a rejection is between you and the person who reviewed it, and we will not let a failed attempt follow you around the market.
6.2 What operators can see about you
You appear in operator search only once you hold at least one NCAA-verified credential. Until then you are invisible to every operator on the platform.
| Information | Free / Starter | Pro / Enterprise |
|---|---|---|
| Name, photo, profession, base city | Yes | Yes |
| Availability, years of experience, bio | Yes | Yes |
| Type ratings and hours on type | Yes | Yes |
| Self-reported logbook hours, labelled as self-reported | Yes | Yes |
| That you are NCAA-verified | Yes | Yes |
| Licence number and issuing authority | No | Yes |
| Issue date, expiry date, date verified, currency | No | Yes |
| Your email address | Only via a contact reveal | Only via a contact reveal |
| Your phone number | Never listed | Never listed |
| Your uploaded document | Never | Never |
| Rejected or pending credentials, and rejection reasons | Never | Never |
6.3 If you apply for a job or a training place
Recruitment and on-the-job-training posts are open to people who have no verified credential yet — an apprentice legitimately has none. If you apply to one, you make yourself visible to that operator even if you would not otherwise appear in search. The operator sees your name, photo, profession, base city, years of experience, how many verified credentials you hold, your note, when you applied, your ad-hoc eligibility category and your attestation. Only the operator that posted the request, and platform admins, can see this. You can withdraw an application.
6.4 What operators record about you
Operators can add you to a private shortlist and write private notes against your name. Those notes belong to the operator and are not shown to you by the product — but they are personal data about you, so the operator must disclose them if you exercise your right of access against that operator. We will tell you which operators hold a shortlist entry for you if you ask us.
We also record when you open a request, so the operator that posted it can see how far its alert reached — as counts of who was alerted, who viewed and who responded. An operator sees these as aggregate coverage figures for its own request.
6.5 What Crewbase staff can see
Platform administrators can read profiles, credentials and uploaded documents, because somebody has to perform verification. Every verification decision is written to an append-only log recording who acted, what they did and why. Access is limited to staff who need it for verification, support or safety, and is subject to confidentiality obligations that survive their leaving.
7Contact reveals
An operator cannot see your email address by browsing. To obtain it, a team member with the right permission must spend a contact reveal from their plan. When they do:
- A record is written server-side identifying the company, the professional, the team member who acted and the time. It cannot be edited or deleted by the operator, and operators cannot write these records themselves.
- You are notified that it happened.
- The operator may use your details only to discuss the work they found you for. Passing them on, or adding you to a marketing list, breaches our Terms and the NDPA.
Your phone number is never released through this route. It is used by us to send AOG alerts you have consented to receive, and is not listed to operators.
The reveal record is kept even if you later close your account — see clause 13. An operator who paid to reach you is entitled to a record that they did, and you are entitled to a record of who reached you.
8Email, SMS, push and AOG calls
We contact you on four channels, and you control three of them.
| Channel | What it carries | Your control |
|---|---|---|
| Sign-in codes, verification results, applications, contact reveals, AOG alerts | Sign-in codes cannot be switched off. Operator team members manage the rest in settings; professionals do not yet have those controls, so ask us and we will stop non-essential email | |
| In-app | The same events, in your notifications feed | Always on while you have an account |
| Push | Urgent matches, if you use a mobile app | Turn off in your device settings; we delete the token |
| SMS and voice | AOG alerts near your base, and escalations on unanswered critical work | Off unless you opt in. Separate switch for critical calls outside normal hours |
Withdrawing AOG call consent takes effect immediately and is as easy as giving it, as the NDPA requires. Operators also receive an inbox: if you email a company through Crewbase, your name, address and message are stored in that company’s inbox and are readable by its team.
9Ranking, matching and automated processing
In short — software decides the order you appear in and who gets an AOG alert. No software decides whether you get hired — a person at the operator does that.
The platform makes three kinds of automated decision about you:
- Search ranking. Results are ordered using your profession, type ratings, hours on type, total hours, availability and base city.
- A profile completeness score. The system computes a 0–100 score from how much of your dossier you have filled in and uses it in ranking. You cannot set it yourself, and neither can anyone else — it is derived.
- AOG matching. When an operator posts a grounded-aircraft request, we select professionals within a radius of the affected airport who are available, hold at least one verified credential, and where relevant hold the right type rating. If nobody responds in time, the alert escalates to a wider group and to SMS.
None of this produces a legal or similarly significant effect on you by itself: it affects the order in which a human being sees you, not whether they engage you. Hiring decisions are made by operators, off the platform. Even so, you may object to this processing, ask us to explain how a ranking was reached, or ask for human review — write to privacy@crewbase.africa. We do not use your data to train machine learning models, and we do not sell or license it for that purpose.
11Who else handles your data
We do not sell your personal data, and we do not share it for advertising. We use a small number of service providers to run the platform. Each is bound by a written contract that limits them to our instructions, as the NDPA requires.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Everything in clause 3, including uploaded documents | ‹hosting region› — outside Nigeria |
| Vercel | Application hosting and delivery | IP address, request metadata, access logs | Global edge network — outside Nigeria |
| Resend | Sign-in codes and notification email | Name, email address, message content | United States |
| Termii | AOG SMS alerts | Phone number, message content | Nigeria |
| Paystack | Subscription payments for operators | Operator billing contact and payment details; we never see card numbers | Nigeria |
| Mapbox | Maps in the operator dashboard | IP address and map viewport of the browser loading tiles | United States |
| Optional “sign in with Google” | Only used if you choose it; Google learns you signed in to Crewbase | United States |
We also disclose personal data in these situations, and no others:
- To the Nigerian Civil Aviation Authority or another issuing authority, to confirm that a licence or certificate you submitted is genuine and current.
- To an operator, exactly as described in clause 6.
- To our professional advisers — lawyers, auditors, insurers — under a duty of confidence.
- Where the law requires it: a court order, a regulator exercising its powers, or the investigation of a serious offence.
- To protect life. If we believe disclosure is necessary to prevent serious harm, including to flight safety, we will make it and record why.
- To a buyer, if the business is sold or merged. We will tell you before your data moves, and the buyer will be bound by this policy until it lawfully changes it.
12Transfers outside Nigeria
Some of the providers above operate outside Nigeria, so your personal data is transferred out of the country. The NDPA permits this only where there is an adequate level of protection or a recognised safeguard.
- We rely on written contracts with each provider containing data protection terms equivalent to the standard contractual clauses recognised by the NDPC, together with the provider’s own security commitments.
- We transfer only what the provider needs to do its job, and no provider is permitted to use your data for its own purposes.
- Your uploaded documents and credential records are held in our database and storage, which sit with a single provider — they are not copied to any other overseas service.
- Payments and AOG SMS stay in Nigeria, with Paystack and Termii respectively.
You can ask us for a copy of the safeguards that apply to any particular transfer by writing to privacy@crewbase.africa.
13How long we keep it
In short — your dossier lives as long as your account does. A few records — proof that an operator paid to contact you, and who verified your licence — outlive it, because they exist to protect you as much as us.
The GAID requires that where no statute sets a retention period, personal data is deleted within six months of the purpose being fulfilled. Where we hold something longer, the reason is stated.
| Record | Kept for | Why |
|---|---|---|
| Account, profile and type ratings | While your account is open, then 6 months after you close it | Recovery of an account closed in error; then deletion |
| Uploaded credential and medical documents | Deleted within 30 days of you closing your account or withdrawing consent | They serve no purpose once verification cannot be relied on |
| Verified credential records (number, authority, dates) | 6 years from account closure | Defence of a claim that we verified something we did not — the limitation period for contract claims in Nigeria |
| Verification decision log | 6 years | Audit of who verified what, and regulator enquiries |
| Contact reveal records | 6 years | Billing integrity and dispute resolution; both sides are entitled to the record |
| Requests, applications and responses | 24 months after the request closes | Operator hiring records and dispute resolution |
| Request view records | 12 months | Reporting on how far an alert reached |
| Notifications and inbox messages | 24 months | So you can look back at what you were told |
| Payment and accounting records | 6 years | Nigerian tax and company law record-keeping |
| Authentication and access logs | 12 months | Security investigation |
| Backups | Rolling, overwritten within 30 days | Deleted data disappears from backups within this window |
Records kept after account closure are reduced to the minimum that serves the stated purpose. Where we no longer need to identify you, we anonymise rather than keep.
14How we protect it
The NDPA requires appropriate technical and organisational measures. Ours are specific and enforced by the database rather than by convention:
- Row-level security on every table. Access rules live in the database, so a bug in the application cannot widen what a user can read.
- Uploaded documents sit in a private bucket, reachable only through short-lived signed links, restricted to your own folder and to verification staff.
- Credential detail is served through functions that return only the safe columns, so there is no query an operator can write that reveals a document path or a rejection reason.
- Audit records — contact reveals, verification decisions — are written by the server only. Neither operators nor professionals can create or alter them.
- No passwords exist to be stolen. Sign-in is a one-time code or a Google sign-in.
- Payment webhooks are verified by cryptographic signature before anything changes.
- Data is encrypted in transit and at rest by our infrastructure providers.
- Staff access follows least privilege, is limited to those performing verification, support or safety work, and is logged.
No system is perfectly secure, and we do not claim otherwise. What we do claim is that the sensitive parts of Crewbase are protected at the layer that is hardest to get wrong.
15If something goes wrong
If a personal data breach occurs, we will report it to the NDPC within 72 hours of becoming aware of it, as section 40 of the NDPA requires, describing what happened, how many people are affected and what we are doing about it.
Where the breach is likely to result in a high risk to your rights — for example if uploaded licence documents were exposed — we will tell you directly and without undue delay, in plain language, and tell you what to do about it. We will not wait for certainty about scope before warning you.
16Your rights
Under the NDPA you have the following rights over your personal data. They are free to exercise, and using them will never disadvantage your standing on the platform.
- To be informed — this policy, kept accurate.
- Access — a copy of the personal data we hold about you, including which operators revealed your contact details and which hold a shortlist entry for you.
- Rectification — correction of anything inaccurate. Most of your profile you can correct yourself, immediately.
- Erasure — deletion of your data where we no longer have a good reason to hold it. See clause 17.
- Restriction — to have us pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability — your data in a structured, machine-readable format, or sent directly to another controller where technically feasible.
- Objection — to processing based on legitimate interests, including your appearance in operator search, and to any direct marketing. An objection to marketing is absolute and takes effect at once.
- Withdrawal of consent — for AOG SMS and calls, for your medical certificate, and for optional email. Withdrawal does not undo processing already carried out lawfully.
Write to privacy@crewbase.africa from the address on your account. We will acknowledge within 7 days and respond within 30 days. If a request is unusually complex we may take a further 30 days and will tell you why. We may ask you to confirm your identity, but only as much as is needed to be sure we are not handing your dossier to someone else.
If we refuse a request we will say so plainly, explain why, and tell you how to challenge it.
17Closing your account
In short — the “delete account” button in settings signs you out today; it does not yet erase your data. To have your data actually deleted, email us and we will do it within 30 days.
We would rather tell you this than let you believe otherwise. The delete-account control in the operator settings screen currently signs you out and returns you to the sign-in page. It does not remove anything. Full self-service erasure is being built.
Until it ships, email privacy@crewbase.africa from your account address and ask us to delete your account. We will:
- Remove your profile, dossier, type ratings, logbook figures and applications, so that you disappear from operator search immediately.
- Delete your uploaded documents within 30 days.
- Retain only what clause 13 lists as outliving the account — principally verified credential records, the verification log and contact reveal records — and nothing else.
- Confirm to you in writing when it is done.
If you are an operator team member, closing your own account does not close your company’s workspace or cancel its subscription. A workspace administrator must do that.
18Age
Crewbase is for working aviation professionals and the companies that engage them. You must be at least 18 to hold an account. We do not knowingly collect data about children, and if we learn that we have, we will delete it.
19Changes to this policy
When the product changes what it does with data, this page changes with it — it is maintained as part of the codebase, not separately from it.
For material changes — a new category of data, a new recipient, a new purpose, or a transfer to a new country — we will give you at least 14 days’ notice by email before they take effect. If a change requires your consent, we will ask for it rather than assume it. Minor corrections take effect on publication, and the version and date at the top of this page always tell you which version you are reading.
20Contact and complaints
For anything in this policy, or to exercise a right, write to privacy@crewbase.africa, or by post to ‹registered company name›, ‹registered address›, for the attention of the Data Protection Officer.
If you are not satisfied with how we have handled your data or your request, you can complain to the Nigeria Data Protection Commission, No. 5 Gambia Street, Wuse Zone 5, Abuja — info@ndpc.gov.ng — which can investigate and order us to put things right. You do not have to come to us first, though we would like the chance to fix it.
Our Terms of Service govern your use of the platform and should be read alongside this policy.