The two roles we play
This distinction decides which rules apply, so it comes first.
For venue and account data, we decide how it is used. When you sign up, contact us or pay us, EasyShift is the business responsible for that information.
For staff data inside an account, the venue decides. Names, phone numbers, shifts, hours, expense claims and documents are entered by the venue that employs those people. We only process them on that venue's instructions, as its service provider. We do not use staff data for our own purposes, and we never sell it.
If you are a member of staff and want your information corrected or removed, ask your employer first. They control it. We will help them act on your request.
What we collect
| Category | Examples | Why |
|---|---|---|
| Identifiers | Name, email, phone, business name, account ID | Creating and running your account |
| Commercial | Plan, staff count, invoices, payment status | Billing and support |
| Employment records | Roles, shifts, availability, hours, absence, expense claims, signed documents | Delivering the service to the venue that entered them |
| Internet activity | Log data, device and browser type, pages used, approximate location from IP | Security, troubleshooting, product improvement |
| Communications | Support messages and email you send us | Answering you and keeping a record |
We collect this from you directly, from your employer if you are a member of staff, and automatically from your device when you use the service.
We do not collect government identifiers, biometric data, or payment card numbers. Card details go straight to our payment provider and never reach our servers. Location is covered in its own section below, because it works differently.
We do not sell or share your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have not done so in the previous twelve months, including for anyone under 16.
We disclose information only to the service providers that make the product work, under contracts that stop them using it for anything else:
- Supabase for database and authentication hosting.
- Vercel for website hosting and delivery.
- Stripe, our payment processor, for card payments, invoicing and sales tax calculation. Stripe holds your card details; we never see the full number.
- Email and messaging providers for shift notifications and account email.
- Vercel Web Analytics, cookieless, for visit and page-view counts. It receives no identifier that could be tied back to you.
- Sentry for error monitoring, so we can fix what breaks. Passwords, tokens, phone numbers and social security numbers are stripped before anything is sent, and where a session recording is captured after an error, all text is masked and images are blocked.
We may also disclose information if the law requires it, to protect someone's safety, or as part of a merger or sale of the business, in which case this notice continues to apply.
Your rights
Privacy laws in California, Virginia, Colorado, Connecticut, Texas, Utah and other states give residents specific rights. Rather than treat people differently by postcode, we extend all of the following to every US resident.
- Know what we collect, use and disclose about you.
- Access a copy of it, in a portable format.
- Correct anything inaccurate.
- Delete it, subject to records we must keep by law.
- Opt out of sale, sharing, targeted advertising and profiling. We do none of these, so there is nothing to opt out of.
- Limit the use of sensitive information. The only category we may hold is precise location, and only if a venue turns it on and a person allows it.
- Appeal a decision, if we decline a request.
- No retaliation. Exercising a right never affects your price or your service.
How to exercise them
Email support@easyshift.team from the address on the account and say what you want. We verify identity before acting, because handing your data to the wrong person is the worse failure.
We respond within 45 days, and may extend once by another 45 days if the request is complex, telling you why. An authorised agent may act for you with written permission.
Location, and only if you turn it on
Location is off by default. Nothing starts until you answer a prompt on your own phone, and two separate features use it in two different ways. They are described separately because one of them runs while the app is closed.
1. The clock-in check. A venue can require that clocking in happens at the venue. We read a single position at the instant of a clock-in or clock-out, compare it to the venue's address, and store the result with that record. Declining the permission does not stop anyone from clocking in; the venue simply sees that the check was skipped.
2. Arrival detection, if you turn it on. The iPhone app can notice you arriving at your venue and offer to start your shift, so a forgotten clock-in does not cost you hours. This needs iOS "Always" location, the app asks for it in as many words, and it is the one part of EasyShift that works while the app is closed. Turning it down is a real choice, not a dead end: you get time-based reminders instead.
What that feature does and does not do:
- Your phone watches a circle, not you. It monitors the area around your venue and only during your scheduled shift windows. There is no continuous tracking, no location stream, and no regions at all outside those windows.
- Your coordinates never leave the phone. They are not read into the app, not stored, and not sent to us. When an arrival starts a shift, what reaches our servers is the venue and a coarse accuracy band, the same as any other clock-in.
- Nothing happens on its own. Arriving produces a notification with a button. A shift starts because you tap it.
- There is no trail. No history of where anyone went, between shifts or during them.
- It belongs to the employer. Under California law, precise location is sensitive personal information. You may ask us to limit its use at any time, and you may ask your employer to delete it. We never use it for advertising, profiling or any purpose of our own.
Until 26 August 2026 this section said the opposite of two of those things: that we only ever ask for "while using the app" and never "always", and that EasyShift never runs in the background. Both were written before arrival detection was built and neither was true of the app we ship. The behaviour described above is what the code does; the words were the part that was wrong, and they are the part that changed.
If you tap a physical EasyShift tag to start a shift, the tag's own signed code is the proof of attendance. Location, where enabled, is only a secondary check recorded alongside it.
For venues: switching this on makes you responsible for telling your staff, and several states require that notice in writing before you begin. Ask us and we will provide wording you can adapt.
Tracking, and why we do not ask
We do not track you across other companies' apps or websites. We do not use advertising identifiers, we do not build advertising profiles, and we do not share anything with data brokers.
Because of that, our apps will not show you Apple's "Allow tracking" prompt. That prompt exists for apps that follow you elsewhere, and ours does not. If that ever changes, we will ask for permission first and say plainly what changed, before any of it starts.
Inside EasyShift we do measure which screens are used and what errors occur, so we can fix what breaks. That stays within our own product and is never linked to advertising.
This notice used to say the same thing while a Meta advertising pixel and Google Analytics loaded on every page. Both were removed on 26 August 2026 and replaced with cookieless analytics. If we ever run advertising, the tracking that comes with it will arrive together with a consent banner, and this section will be rewritten before either goes live rather than after.
Artificial intelligence, and the automation that is not
No artificial intelligence or machine learning touches your data. EasyShift sends nothing to an AI provider, trains nothing on your information, and contains no model of any kind. There is no chatbot, no assistant and no generated content in the product.
What the product does have is ordinary automation, and it is worth naming because some of it is about people:
- It flags unusual hours. A clock-in far from a scheduled time, an unusually long shift, or hours that stand out against a person's own history are raised for a manager to look at.
- It refuses to assign someone a shift when a requirement the venue switched on is not met, such as an unverified email address or an incomplete profile.
- It notices when a week looks short of staff and when a shift nobody has taken is close.
None of this decides anything about a person on its own. Every one of them produces something a manager sees and acts on, or does not. There is no automated decision with a legal or similarly significant effect, and no profiling used to evaluate anyone's performance, reliability or conduct. If that ever changes we will say so here before it starts, and say what recourse you have.
How long we keep it
Account and venue data is kept while the account is open. After it closes we keep it for 90 days so an account can be restored by mistake-recovery, then delete it, except records we are required to retain for tax and accounting.
Deleted shifts, hours and expense records inside a live account are retained in our audit log so a venue can prove what happened, which is the point of keeping a record at all.
Security
Data is encrypted in transit and at rest. Passwords are hashed, never stored in readable form. Access to production data is limited to the people who need it. We keep an audit trail of changes to money-related records.
No system is perfect. If a breach affects your information, we will notify you and the relevant regulators as required by law, without unnecessary delay.
Children
EasyShift is a business tool and is not directed at children. We do not knowingly collect information from anyone under 13. If a venue enters records for a minor employee, that venue is responsible for having the consent that employment law in its state requires. Tell us if you believe a child's information reached us and we will remove it.
Where your data lives
Your data is stored in the European Union, in Amazon Web Services' Ireland region (eu-west-1). That is where the database lives and where your schedules, hours and staff records are held.
EasyShift is operated by a company based in Israel, so our staff access that data from Israel when supporting you. Israel is recognised by the European Commission as providing an adequate level of data protection. Some of the services we rely on process limited data elsewhere: card payments are handled by Stripe and email is sent through Resend, both of which operate internationally.
If your organisation needs its data held in a specific country, tell us before you start and we will say plainly whether we can do it.
Cookies
We use cookies that are necessary for the service to work: keeping you signed in, remembering your organisation, and holding a draft you have not submitted yet. Nothing more.
We do not use analytics or advertising cookies, so there is no consent banner. Our analytics is cookieless: it counts visits, sources and page views without storing an identifier on your device and without any way to recognise you on a later visit or on another site. There is nothing for you to refuse, which is why we do not interrupt you to ask.
Changes, and how to reach us
If we change this notice in a way that matters, we will say so on this page and, for material changes, email account holders. The date at the top always reflects the current version.
Questions, requests or complaints: support@easyshift.team.
California residents may also complain to the California Privacy Protection Agency or the state Attorney General. Residents of other states may complain to their own Attorney General.