Who processes your data
Shiftly’s operator handles account administration, subscriptions, technical support and service security. Your employer or organization determines how employee schedules and operational records are used. Their own privacy information also applies. The allocation of controller and processor responsibilities and the processing agreement must be finalized before release.
Information in the service
We process names, email addresses, optional phone numbers and avatars; companies, venues, roles, schedules and work groups; checklist answers, photos, measurements, incidents and comments; support messages; subscription identifiers and store status. Technical information includes app and OS versions, platform, installation identifiers, push tokens and security logs. Shiftly does not require advertising identifiers or continuous location tracking.
Why information is used
Data supports accounts, access control, work planning, evidence of completion, reminders, billing verification, support and reliability. Contract performance, applicable legal obligations and legitimate interests in security may apply to the operator’s processing. Workplace processing requires an appropriate basis determined by your organization; an employment relationship is not blanket consent.
Providers and access
Authorized company members see information according to their role and venue access. Platform administrators handle support and operations. Storage uses Contabo S3-compatible infrastructure; Apple and Google process store payments; Firebase and Apple services support push delivery when configured. The selected email provider delivers account messages. Telegram receives only ticket, company and message identifiers plus an admin link, not the conversation text. Final provider agreements, hosting locations and any international transfer safeguards must be confirmed before release.
Diagnostics and website storage
The internal error monitor records exception types, code locations, app releases, occurrence counts and timestamps. It excludes passwords, message contents and request bodies. Standard server security logs are separate. The public pages do not include advertising trackers; account deletion and administration use essential session and security cookies.
Retention and deletion
Operational records remain while needed for the organization’s use of the service. Deleting an owner account deletes the entire company; other users delete their own account with the history treatment explained on the deletion screen. Support conversations belonging to the deleted account are deleted. Error groups expire after 30 days without recurrence. Encrypted backup copies are retained for 14 days and are not used for normal operations. Any legally required retention and precise retention periods for other records must be finalized before release.
Your choices and rights
You can edit your profile, language and notification preferences. Contact support about access, correction, deletion, restriction, portability or objections where applicable; workplace requests may need your organization’s involvement. You may complain to the competent data protection authority. We may verify identity before disclosing or changing data. Withdrawing an optional permission does not make earlier lawful processing unlawful.
Updated: 2026-09-23