Privacy Policy
CrowdSense measures crowds without identifying anyone. This policy explains what we collect from you, what our sensing technology collects at a site, and what we do with both.
Last updated: August 2026
The short version
- We measure crowds, not people. Our sensors count and classify — they do not identify.
- No facial recognition, no number-plate recognition, no biometric identification. Ever.
- Where imagery is kept it is rendered as anonymised silhouettes, and retention is set by the site owner.
- We never sell your personal information.
Who We Are and What This Covers
CrowdSense (crowdsense.events) is an Australian business operated by Artefact Group. This policy covers this website, the CrowdSense platform, and the sensing hardware we deploy at customer sites. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For customers and visitors in the EU or UK we additionally commit to handling personal data consistently with the GDPR.
There is an important split in our role. For website visitors and customer contacts, we decide how information is handled — we are the controlling entity. When we operate sensing on a customer's site, the customer decides why it is deployed and what it is used for; we handle that data on their behalf, under contract. Questions about sensing at a particular venue, site or event are best directed to the organisation running it.
Information You Give Us
If you contact us we collect what you choose to tell us — typically your name, work email, company, phone number, and whatever you type into an enquiry, sign-up or quote form.
Forms on this website are relayed to us by email through a third-party form-relay service. That service passes your submission to our inbox; it is not used to build a profile of you. Please do not include sensitive information in a web form.
What Our Sensing Technology Actually Collects
This is the section most people want, so we will be specific.
- Sense Nodes read anonymous Bluetooth (BLE) signals already present in a crowd to measure presence, density and movement. They do not identify a person, do not capture content, and are not linked to any account, ticket or customer record.
- Vision Nodes and camera analytics run detection on the device itself. What leaves the device is structured data — counts, object classes, zone events and timestamps — not a video stream. Analytics applied to a customer's existing IP or CCTV cameras work the same way: the output is numbers, not footage.
- We do not perform facial recognition, number-plate recognition or any form of biometric identification, and we make no attempt to identify individuals, match a person between sites, or re-identify anonymous readings.
- Off-Grid Communications carry these measurements between nodes over a self-healing LoRa mesh. The mesh moves counts and status, not personal information.
Images and Retrospective Review
Two features keep imagery: Timelapse, which assembles scheduled keyframes into video over weeks or months, and X-Ray Vision, which lets an operator scrub back to a past moment and see keyframes alongside the metrics that were live at that second.
- These capture periodic keyframes, not continuous video.
- Keyframes render "frosted" by default — anonymised silhouettes with no readable faces or number plates, and no biometric identification applied to them at any point.
- Retention is configurable per site and is set by the customer who operates that site.
- Metrics can outlive imagery. A site may keep counts and trends long after the keyframes behind them have been deleted.
Crew and Workforce Data
Crew data is different from attendee data, and we treat it that way. The Companion App and Travla use named accounts so a crew member can check in and receive tasking, and where a customer enables it, they can show live crew position during a shift.
This is workforce data about identified people. It is the employing customer's responsibility to inform their crew about what is collected and why, and to meet their obligations as an employer. We recommend disclosure at induction, before anyone is issued an account. We hold this data on the customer's behalf and do not use it for any other purpose.
Digital Signage
CrowdSense Signage plays content on screens. Players connect over wifi, Ethernet or mobile data using a SIM we supply on a managed data plan. Signage playback does not collect any information about the people who look at a screen — there is no camera in the player, no audience detection and no device tracking.
Where a screen sits near a node, the node's anonymous counts are the audience measure. That measure stays anonymous and is never tied to an individual viewer.
Platform Access, APIs and AI Agents
The Brain is the indexed record of what happened at a site, and it can be reached three ways: an MCP server for AI agents, a REST API, and webhooks.
- Access uses scoped tokens, with read and write permissions separated.
- Calls are logged and auditable.
- Tokens are revocable at any time by the customer who issued them.
- An AI agent a customer connects only ever sees what that customer's token permits. It cannot reach another customer's data, and it cannot widen its own scope.
Cookies and Website Analytics
This website uses a small number of cookies to keep the site working and to understand, in aggregate, which pages people find useful. We use analytics to count visits and see how people arrive — not to build advertising profiles. Your browser can block or delete cookies; the site will still work, though some preferences will not be remembered.
How We Use Information
- To answer your enquiry, prepare a quote and stay in touch about it.
- To deliver, support and improve the platform and the hardware.
- To operate deployments and provide reporting to the customer who commissioned them.
- To keep systems secure, investigate faults and maintain audit records.
- To meet legal and safety obligations.
We do not use sensing data to profile individuals, and we do not combine anonymous crowd measurements with contact records.
Disclosure and Third Parties
We do not sell personal information, and we do not trade or rent it. We share it only where it is needed to run the service or where the law requires it.
We use a small number of sub-processors — cloud hosting, email delivery, mobile connectivity and the form relay described above. Each acts under contract, is limited to what it needs, and is not permitted to use the data for its own purposes. Where our site links to another organisation's site, their privacy policy applies once you leave ours.
Where Data Is Stored and Sent
Platform data is hosted on secure infrastructure and is encrypted in transit and at rest. Some of our providers may store or process data outside Australia. Where that happens we take reasonable steps to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles, as required by APP 8.
How Long We Keep It
- Enquiry and contact records: kept while there is an active relationship and for a reasonable period afterwards, then deleted.
- Platform metrics: anonymous counts and trends are retained for the life of the customer's account so historical comparison remains possible.
- Keyframe imagery: retained for the window the customer configures for that site, then automatically deleted.
- Decision and audit logs: the Control Room's timestamped decision log and our API access logs are retained as an operational and safety record, and may be kept longer where a customer or the law requires it.
Your Rights
Under the Australian Privacy Principles you can ask us for access to the personal information we hold about you, and ask us to correct it if it is wrong. Emailprivacy@crowdsense.events and tell us what you need. We will respond within a reasonable period and may ask you to verify your identity first. There is normally no charge.
If your request relates to data captured at a specific customer's site — a venue, council area, construction site or event — we will direct you to that customer, because they are the controlling entity for that deployment. We will help them respond. If you are in the EU or UK, you may also have rights to erasure, restriction, portability and objection, and we will honour those requests where they apply.
Children
Our website and platform are intended for business users. We do not knowingly collect personal information from children. Our sensing technology counts people without identifying them, so it does not distinguish or record a child as an individual. If you believe a child has given us personal information, contact us and we will delete it.
Security
We protect information with encryption in transit and at rest, scoped and revocable access tokens, separated read and write permissions, audited API calls, and access limited to personnel who need it. Processing on the device — counting at the edge rather than shipping video — is itself a security control: data that is never captured cannot be exposed. If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Changes to This Policy
We update this policy as our products change. The current version always lives on this page with the date it was last updated. Where a change materially affects how we handle your information, we will tell affected customers directly.
Contact Us
For any privacy question, request or complaint, emailprivacy@crowdsense.events. We would rather hear from you first and put things right.
If you are not satisfied with our response, you can escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.