Krew60
Legal

Privacy Policy

Effective 13 January 2025 · Last updated 5 October 2026
Shine to Success Collective Pty Ltd ABN 54 684 627 058 trading as Krew60

Shine to Success Collective Pty Ltd ABN 54 684 627 058 trading as Krew60 ("Krew60", "we", "us", "our") builds and runs AI front offices for trade and service businesses in Australia, the United States, and the United Kingdom. Our service, The Front Office Foundation, covers five front-office roles (the Core Five): Receptionist, Sales & Follow-Up, Admin & Ops, Reviews, and Marketing ("the Service"). We also operate the website krew60.com.

We are committed to handling personal information openly, securely, and lawfully, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where they apply to you, we also comply with the UK GDPR and the Data Protection Act 2018 (UK), the EU GDPR, and United States federal and state privacy laws.

This policy explains what personal information we collect, why, who we share it with, how long we keep it, and the choices you have.

On this page
  1. Who This Policy Applies To
  2. Information We Collect
  3. How We Collect It
  4. How We Use Your Information
  5. AI, Recordings, and Automated Decisions
  6. Information We Handle for Our Clients
  7. Marketing and Outreach
  8. Cookies and Tracking
  9. Disclosure of Your Information
  10. International Data Transfers
  11. Data Security
  12. Data Retention
  13. Your Privacy Rights
  14. Children
  15. Changes to This Policy
  16. Contact Us

1. Who This Policy Applies To

This policy applies to everyone whose personal information we handle, including:

  • Visitors to krew60.com and our order and booking pages
  • Prospective clients: business owners and staff we contact by phone, email, or social media, and anyone who books or attends a Front Office Audit with us
  • Clients: businesses that buy The Front Office Foundation, and their owners, staff, and nominated contacts
  • Our clients' customers: people who call, message, book with, or are followed up by a client's business through the Service (see section 6)
  • Sales contractors and applicants: people who apply to sell for Krew60 or work with us as independent sales contractors
  • People who engage with our content: people who comment on, message, or interact with our social media accounts

If you are in the United Kingdom, the European Union, or a US state with its own privacy law (such as California), you may have extra rights. We note these where relevant.

2. Information We Collect

Depending on how you deal with us, we may collect:

  • Contact and business details: name, job title, business name, email address, phone number, business address, website, ABN or company number, trade, and service area
  • Business information we use for prospecting: information about your business that is publicly available, such as your website, online directory and marketplace listings, reviews, and professional profiles
  • Front Office Audit information: what you tell us about how your business handles calls, enquiries, quotes, bookings, reviews, and follow-up, and your answers during the audit
  • Account and onboarding information: logins, onboarding form answers, business knowledge, pricing, scripts, and the access and decisions you give us so we can build the Service
  • Payment information: billing name, billing address, and transaction records. Card details are handled by our payment processor. We do not store full card numbers.
  • Client Data: the information the Service creates or handles for a client, including contact records, call recordings, transcripts, call summaries, message history (SMS, email, web chat, Facebook, Instagram, and WhatsApp), bookings, job updates, invoices and reminders, review requests, and reviews
  • Owner channel messages: messages and voice notes a client sends to their Krew by WhatsApp, Slack, Microsoft Teams, or text, and the preferences the Krew remembers from them
  • Recordings and testimonials: recordings of audit, onboarding, or support calls where you have been told the call is recorded, and testimonials, photos, or videos you agree to give us
  • Sales contractor information: name, email, phone, ABN (for Australian contractors), bank or payment details for commission, signed agreements, and sales activity records
  • Website and device data: IP address, browser and device type, pages visited, and referring links, collected through cookies and similar tools (see section 8)
  • Communications and preferences: messages you send us, and your marketing and cookie choices, including any request to stop contacting you

We do not ask for sensitive information (such as health information) and ask that you do not give it to us or to the Service. If a caller volunteers it, it is handled as part of Client Data under section 6.

You can deal with us without giving your name where that is practical, for example when browsing our website. We cannot provide the Service, run a Front Office Audit, or pay a contractor without identifying you.

3. How We Collect It

  • From you: when you visit our website, book or attend a call, fill in a form, pay, complete onboarding, message us, or sign an agreement
  • From public sources: business websites, online trade directories and marketplaces, review sites, and professional networking sites, sometimes gathered using data and research tools
  • From our clients: when a client loads its customer records into the Service, or the Service handles a call or message for that client
  • From service providers: payment, e-signature, analytics, and social media platforms that report back to us about transactions and engagement

If we collect your information from someone other than you, we take reasonable steps to let you know, for example by telling you who we are and how we found your details when we first contact you.

4. How We Use Your Information

We use personal information for the following purposes. Where the UK or EU GDPR applies, the lawful basis is shown in brackets.

  • Building, operating, supporting, and improving the Service for our clients (contract; legitimate interests)
  • Running Front Office Audits, preparing proposals, and responding to enquiries (steps before a contract; legitimate interests)
  • Processing payments, managing accounts, and handling cancellations and refunds (contract)
  • Sending service messages, such as onboarding steps, build updates, billing confirmations, and support replies (contract)
  • Contacting businesses about Krew60 by phone, email, and social media (legitimate interests, or consent where the law requires it; see section 7)
  • Engaging, paying, and managing our sales contractors (contract; legal obligation)
  • Publishing testimonials and case studies (consent)
  • Measuring and improving our website, content, and advertising (legitimate interests, or consent for non-essential cookies)
  • Keeping our systems secure, preventing fraud and misuse, and enforcing our agreements (legitimate interests)
  • Meeting legal, tax, and regulatory obligations (legal obligation)

We will not use your personal information for a purpose unrelated to the one we collected it for unless you consent or the law allows it.

5. AI, Recordings, and Automated Decisions

The Service uses artificial intelligence to answer calls, reply to messages, book jobs, follow up leads, request reviews, and draft content, around the clock. This means:

  • When you call or message a business that uses Krew60, you may be speaking with an AI rather than a person.
  • Calls handled by the Service may be recorded and transcribed, and summaries are created so the business can follow up. The business is responsible for giving any notice or getting any consent its local recording laws require, and we help configure this.
  • AI models from our technology partners process the content of calls and messages in order to produce responses, transcripts, and summaries.

The Service makes some automated decisions, such as sorting an enquiry by urgency, sending an urgent call to a person, offering available booking times, or choosing which follow-up message to send. These decisions help a business respond quickly. They are not used to make decisions with legal or similarly significant effects on individuals, such as decisions about credit, employment, or access to essential services. A business owner or their team can review and change the outcome at any time. If you want a person to review a decision made about you, contact the business you dealt with, or us.

6. Information We Handle for Our Clients

When the Service handles calls, messages, bookings, and records for a client's customers, we do so on behalf of that client. The client owns its Client Data and decides how it is used. We act as its service provider (a "processor" under the GDPR) and use Client Data only to provide the Service, in line with the client's instructions and our Service Agreement.

If you are a customer of one of our clients and want to access, correct, or delete your information, please contact that business first. If you contact us, we will pass your request to the business and help it respond.

Clients are responsible for having a lawful basis to collect their customers' information, for giving their own privacy notices, and for complying with the telemarketing, spam, and recording laws in the places they operate.

We do not sell Client Data, use it to market to our clients' customers, or share it with other clients.

7. Marketing and Outreach

We find new clients by contacting trade and service businesses directly, by phone, email, and social media message. Our sales team includes independent sales contractors who contact businesses on our behalf. When we contact you:

  • We identify Krew60 and the person contacting you.
  • We send commercial emails to business addresses only where you have consented, or where consent can be inferred under the Spam Act 2003 (Cth) because your address is published for your business and our message relates to your business role.
  • Every commercial email includes a working way to unsubscribe. We honour unsubscribe requests within 5 business days.
  • If you ask us not to call you again, we will add you to our do-not-contact list and stop.
  • We follow the telemarketing and spam laws of the country we contact you in, including the Do Not Call Register Act 2006 (Cth) and the Telemarketing and Research Industry Standard in Australia, the CAN-SPAM Act and the Telephone Consumer Protection Act in the United States, and the Privacy and Electronic Communications Regulations in the United Kingdom.

Clients also receive service messages about their account and the Service. These are not marketing and do not need consent, but we will not use them to promote unrelated products.

We will never sell, rent, or trade your email address or phone number.

To stop all marketing from us, reply "stop" or "unsubscribe" to any message, or email [email protected].

8. Cookies and Tracking

We use cookies and similar technologies on krew60.com and our order and booking pages to:

  • Keep sessions and order forms working securely
  • Measure website traffic and performance
  • Measure the results of our advertising, where we use advertising tools

Where the law requires it, we ask for your consent before setting non-essential cookies. You can change your choices at any time using your browser settings. To ask about the cookies we use, email [email protected].

9. Disclosure of Your Information

We share personal information only as needed for the purposes in this policy, with:

  • Platform and infrastructure providers: the CRM, telephony, messaging, and automation platform the Service runs on, and our hosting and workspace providers
  • AI providers: providers of the AI language, voice, and transcription models used by the Service
  • Payment processors: to take and verify payments in AUD, USD, and GBP
  • E-signature, email, and communication providers: to send agreements and messages
  • Our sales contractors: who contact prospective clients and run Front Office Audits for us, under written agreements that require them to keep information confidential
  • Social media and scheduling platforms: when we publish content, or reply to comments and messages
  • Professional advisers: such as accountants, lawyers, and insurers
  • A buyer or successor: if all or part of our business is sold or restructured, under confidentiality obligations
  • Regulators, courts, and law enforcement: where the law requires or allows it

Our providers may only use personal information to provide their services to us, under contracts that require them to protect it. We will never sell your personal information.

10. International Data Transfers

Many of our technology partners store and process data in the United States, and some may process it in other countries where they operate. Some of our sales contractors may be located outside Australia. We work with clients in Australia, the United States, and the United Kingdom, so information may move between those countries.

Before we disclose personal information to an overseas recipient, we take reasonable steps to make sure it is handled in a way consistent with the APPs (APP 8.1), including through contracts and data processing terms. Where we transfer personal data of people in the UK or EU, we rely on appropriate safeguards, such as the International Data Transfer Agreement or Addendum, Standard Contractual Clauses, or an adequacy decision.

11. Data Security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, change, or disclosure. These include:

  • Encryption of data in transit using TLS/SSL
  • Access limited to the people who need it, with access removed when they no longer do
  • Strong passwords and multi-factor authentication where available
  • Using established platforms that hold recognised security certifications
  • Confidentiality obligations in our contractor agreements

If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme. Where the UK or EU GDPR applies, we will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If a breach affects Client Data, we will tell the client promptly so it can meet its own obligations.

12. Data Retention

We keep personal information only as long as we need it:

  • Client Data: for as long as the client's engagement is active. When an engagement ends, the client has 7 days from the end date to export its Client Data (including contact records, call logs, and message history), either itself or by asking us, as set out in the Service Agreement. After that 7-day window, operational data is deleted or de-identified.
  • Financial and transaction records, including contractor commission records: 7 years from the transaction, to meet Australian tax and accounting obligations, even where operational data has been deleted.
  • Prospect records: up to 2 years from our last contact with you, unless you become a client.
  • Do-not-contact list: if you ask us to stop contacting you, we keep the minimum details needed to make sure we do not contact you again.
  • Communications, support records, and call recordings we make: 2 years from the date of the communication, or longer if needed to resolve a dispute.
  • Sales contractor records: for the length of the engagement, then 7 years for agreements and payment records.

When we no longer need personal information and no law requires us to keep it, we take reasonable steps to destroy or de-identify it (APP 11.2).

13. Your Privacy Rights

Depending on where you are, you may have the right to:

  • Access the personal information we hold about you
  • Correct information that is wrong, out of date, or incomplete
  • Ask us to delete your information, subject to the records we must keep by law
  • Withdraw your consent where we rely on it
  • Opt out of marketing at any time
  • Receive a portable copy of your information (UK and EU)
  • Object to, or ask us to restrict, certain processing, including processing based on our legitimate interests (UK and EU)
  • Know what we collect and how we use it, and opt out of the sale or sharing of personal information (California and other US states with privacy laws). We do not sell personal information.

To use any of these rights, email [email protected]. We may need to confirm your identity first. We will respond within 30 days, and we do not charge for making a request. If we refuse a request, we will tell you why and how to complain.

If you are a customer of one of our clients, please see section 6.

If you are not satisfied with how we handle a complaint, you can contact the Office of the Australian Information Commissioner at www.oaic.gov.au. In the UK you can contact the Information Commissioner's Office at ico.org.uk, and in the EU your local data protection authority.

14. Children

Krew60 is a business service and is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe we have collected information about a child, please contact us so we can delete it.

15. Changes to This Policy

We may update this policy when our services, technology, or legal obligations change. When we do, we will update the "Last updated" date at the top of this page. If a change is significant, we will tell clients by email or put a clear notice on our website.

16. Contact Us

For questions, requests, or complaints about this policy or how we handle your personal information, contact our privacy contact:

Shine to Success Collective Pty Ltd

Trading as: Krew60

ABN: 54 684 627 058

Registered Address: Shell Cove NSW 2529, Australia

Email: [email protected]

Website: krew60.com

This Privacy Policy should be read with our Terms & Conditions, Service Agreement, and Payment Terms.

© Copyright 2026 Krew60 - All rights reserved. Privacy Policy  |  Terms & Conditions