ShiftQ Privacy Policy
1. Who we are and what this Policy covers
This Privacy Policy ("Policy") is issued by the operator of ShiftQ — a private individual based in Ukraine (full sole-proprietor (FOP) registration details will be published before paid plans launch) — for the ShiftQ shift-scheduling service (app.shiftq.app, the "Service").
This Policy describes what data we process, why, where it's stored, and what rights you have — whether you're an organization account owner or an employee added to someone else's account.
2. Controller and processor — an important distinction
Data in ShiftQ is processed under two different roles, and this determines who you should contact with a request:
- For the account owner's own data (email, organization name, billing data) — ShiftQ is the data controller. If you have questions about this data, contact us directly (Section 9).
- For employee data entered by the account owner (name, email, phone, photo, schedule) — the employer organization that added you is the data controller, and ShiftQ acts only as a processor operating on its instructions. If you're an employee with a question about your own data in the Service, contact your employer first; we fulfill access/erasure requests on their behalf.
3. What data we process
| Category | Data | Source |
|---|---|---|
| Organization account | Organization name, owner's email, locations | Entered by the owner at signup |
| Employee data | Name, email, phone, role/position, photo (optional) | Entered by the organization's manager |
| Schedule data | Shifts, swap requests, time-off/leave requests, open shifts | Entered by managers and employees using the Service |
| Notifications | Notification text about schedule changes (auto-deleted after 90–180 days) | Generated by the Service |
| Push subscription | Technical browser push-subscription identifier (via OneSignal) | Created when push notifications are enabled |
| Technical data | Error and performance data (via Sentry), de-identified usage analytics (via PostHog, with UI text masking enabled) | Automatically during use of the Service |
We do not collect or store your card details — payment (once enabled) is processed directly by the payment provider.
4. Legal bases for processing
- Contract performance — processing the data needed to provide the Service's functionality (scheduling, notifications) under the terms you agreed to.
- Legitimate interest — keeping the Service secure and preventing abuse (rate limiting, error monitoring).
- Consent — where required by law (e.g., for optional analytics cookies for EU visitors) — see Section 7.
5. Who we share data with — subprocessors
We rely on the following companies (subprocessors) to run the Service, each processing data only to the extent needed to provide their service:
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication, file storage (photos) | European Union (Ireland) |
| Vercel | Application hosting | Global edge network |
| Sentry | Application error monitoring | European Union (Germany) |
| PostHog | De-identified usage analytics (UI text masking enabled) | European Union |
| OneSignal | Push notification delivery | United States |
| Resend | Transactional email delivery (invites, password reset) | United States |
| — | Subscription payment processing (not used during the free beta) | — |
We do not sell your data to third parties and do not use it for ad targeting.
6. International data transfers
Your core business data (database, files, analytics, error monitoring) is processed within the European Union. Some technical subprocessors (push delivery, transactional email) are located in the United States — transfers to them rely on appropriate contractual safeguards (EU Standard Contractual Clauses or an equivalent mechanism), details available on request.
7. Cookies and similar technologies
The Service uses browser localStorage to save settings (color theme, interface language, a cached copy of your data for offline use) — this is strictly necessary for the app to function and does not require separate consent.
For usage analytics we use PostHog with UI text masking enabled (employee names and other visible text are not captured as part of analytics events), and no visitor profile is built before you log in to an account. We do not currently use advertising cookies or pixels (Google Ads, Meta Pixel, etc.).
Honest note on the current state: analytics currently activates automatically when the Service loads, without asking for visitor consent first. This is a temporary state — we are working on a consent banner for European Union visitors before analytics activates. Until then, you can block analytics yourself by enabling tracker-blocking in your browser or a privacy extension.
8. Retention and deletion
Your organization's data is kept for as long as the account is active. At any time you can:
- delete an individual employee — their shifts, notifications, swap requests, account, and photo are permanently deleted;
- delete the entire organization (Settings → Organization) — after email confirmation and typing the exact organization name, all organization data is deleted: locations, employees, schedules, requests, notifications, photos, and every employee's login account.
Notifications are also automatically deleted after 90 days (once read) or 6 months (regardless of read status) even without manually deleting the account.
Deletion of data held by our subprocessors (e.g., historical analytics events in PostHog) follows their own retention schedules and may take additional time after account deletion in the Service.
9. Your rights
Whether GDPR applies to you (EU residents) or Ukrainian personal-data-protection law applies, you have the right to:
- confirm whether your data is being processed and obtain a copy of it;
- request correction of inaccurate data;
- request erasure of your data ("right to be forgotten");
- receive your data in a machine-readable format (data portability);
- object to processing in certain cases or withdraw consent you've given.
If you're an employee added to an organization's account, contact your employer (the account owner) first, since they are the controller of your data. If you're an organization account owner, or for any other question about this Policy, contact us directly: shiftqsupport@gmail.com.
10. Data security
Access to each organization's data is technically isolated at the database level (Row Level Security) — no user can access another organization's data through the normal Service interface. Sensitive actions (invitations, deletions, sending notifications) are rate-limited to prevent abuse.
11. Children
The Service is intended for use by adults within an employment relationship and is not intended for self-registration by children.
12. Changes to this Policy
We may update this Policy. We will notify you of material changes by email or via an in-Service notice at least 14 days before they take effect.
13. Contact
For questions about this Policy or to exercise your rights, contact: shiftqsupport@gmail.com.
ShiftQ