ShiftQ Privacy Policy

Effective July 21, 2026.

Free beta. ShiftQ is currently provided free of charge and does not process payments. The operator's full registration details (sole proprietorship / FOP) will be added here before paid plans launch.

1. Who we are and what this Policy covers

This Privacy Policy ("Policy") is issued by the operator of ShiftQ — a private individual based in Ukraine (full sole-proprietor (FOP) registration details will be published before paid plans launch) — for the ShiftQ shift-scheduling service (app.shiftq.app, the "Service").

This Policy describes what data we process, why, where it's stored, and what rights you have — whether you're an organization account owner or an employee added to someone else's account.

2. Controller and processor — an important distinction

Data in ShiftQ is processed under two different roles, and this determines who you should contact with a request:

3. What data we process

CategoryDataSource
Organization accountOrganization name, owner's email, locationsEntered by the owner at signup
Employee dataName, email, phone, role/position, photo (optional)Entered by the organization's manager
Schedule dataShifts, swap requests, time-off/leave requests, open shiftsEntered by managers and employees using the Service
NotificationsNotification text about schedule changes (auto-deleted after 90–180 days)Generated by the Service
Push subscriptionTechnical browser push-subscription identifier (via OneSignal)Created when push notifications are enabled
Technical dataError and performance data (via Sentry), de-identified usage analytics (via PostHog, with UI text masking enabled)Automatically during use of the Service

We do not collect or store your card details — payment (once enabled) is processed directly by the payment provider.

4. Legal bases for processing

5. Who we share data with — subprocessors

We rely on the following companies (subprocessors) to run the Service, each processing data only to the extent needed to provide their service:

ProviderPurposeData location
SupabaseDatabase, authentication, file storage (photos)European Union (Ireland)
VercelApplication hostingGlobal edge network
SentryApplication error monitoringEuropean Union (Germany)
PostHogDe-identified usage analytics (UI text masking enabled)European Union
OneSignalPush notification deliveryUnited States
ResendTransactional email delivery (invites, password reset)United States
Subscription payment processing (not used during the free beta)

We do not sell your data to third parties and do not use it for ad targeting.

6. International data transfers

Your core business data (database, files, analytics, error monitoring) is processed within the European Union. Some technical subprocessors (push delivery, transactional email) are located in the United States — transfers to them rely on appropriate contractual safeguards (EU Standard Contractual Clauses or an equivalent mechanism), details available on request.

7. Cookies and similar technologies

The Service uses browser localStorage to save settings (color theme, interface language, a cached copy of your data for offline use) — this is strictly necessary for the app to function and does not require separate consent.

For usage analytics we use PostHog with UI text masking enabled (employee names and other visible text are not captured as part of analytics events), and no visitor profile is built before you log in to an account. We do not currently use advertising cookies or pixels (Google Ads, Meta Pixel, etc.).

Honest note on the current state: analytics currently activates automatically when the Service loads, without asking for visitor consent first. This is a temporary state — we are working on a consent banner for European Union visitors before analytics activates. Until then, you can block analytics yourself by enabling tracker-blocking in your browser or a privacy extension.

8. Retention and deletion

Your organization's data is kept for as long as the account is active. At any time you can:

Notifications are also automatically deleted after 90 days (once read) or 6 months (regardless of read status) even without manually deleting the account.

Deletion of data held by our subprocessors (e.g., historical analytics events in PostHog) follows their own retention schedules and may take additional time after account deletion in the Service.

9. Your rights

Whether GDPR applies to you (EU residents) or Ukrainian personal-data-protection law applies, you have the right to:

If you're an employee added to an organization's account, contact your employer (the account owner) first, since they are the controller of your data. If you're an organization account owner, or for any other question about this Policy, contact us directly: shiftqsupport@gmail.com.

10. Data security

Access to each organization's data is technically isolated at the database level (Row Level Security) — no user can access another organization's data through the normal Service interface. Sensitive actions (invitations, deletions, sending notifications) are rate-limited to prevent abuse.

11. Children

The Service is intended for use by adults within an employment relationship and is not intended for self-registration by children.

12. Changes to this Policy

We may update this Policy. We will notify you of material changes by email or via an in-Service notice at least 14 days before they take effect.

13. Contact

For questions about this Policy or to exercise your rights, contact: shiftqsupport@gmail.com.