Privacy
This is the first-version privacy notice for Shifts (theshifts.app). A lawyer should review it before you take paying customers. Hosting is intended to be in the EU.
Who we are
Shifts is a multi-tenant web app. Each company (tenant) has its own portal. We are the platform operator; the company you work for is the controller of your rota, clock, and holiday data.
What we store
- Account email, name, Employee ID, home site and other assigned sites
- Shifts, holiday requests, availability, skills, and clock in/out times
- Authenticator secrets (hashed) and backup codes (hashed)
- Audit events (for example HQ support login, PIN reset, 2FA reset)
Why
To run scheduling, the site tablet clock, holiday balances, billing for the company, and security. Legal bases are typically contract and legitimate interests. Companies may have their own policies on top.
Sharing
We do not sell personal data. Processors (email, payments, EU hosting) will be listed here when they are contracted. HQ support login is time-limited and audit-logged.
Retention and rights
If you work for a customer company, ask them first. You may request access, correction, or deletion where the law allows. A company admin can deactivate you; a full erase is a separate admin/HQ action.
Contact
Use the email on your company invite, or the operator contact published when Shifts is in production.