ShiftHQ Privacy Policy
Effective date: 2026-07-14
Last updated: 2026-07-14
This Privacy Policy describes how Refael Dabush ("ShiftHQ," "we," "us," or "our") collects, uses, discloses, and protects information when you use the ShiftHQ shift-scheduling platform, including our website at shifthq.app, our iOS apps, and related backend services (together, the "Service").
If you are a business administrator, you are the Controller of your employees' data and enter into a Data Processing Agreement with us (see §12). We act as the Processor for employee data submitted by your business, and as the Controller for account, billing, and diagnostic data.
1. Who we are
- Legal entity: Refael Dabush, sole trader (English) / רפאל דבוש, עוסק פטור
- Registered address: Dvora Omer 5, Ra'anana, Israel / דבורה עומר 5, רעננה, ישראל
- Registration / company number: 200353530
- Contact for privacy inquiries: privacy@shifthq.app (or dabush001@gmail.com)
2. Data we collect
2.1 Information you give us
- Account details: email address, full name, phone number (optional), preferred language.
- Business details (business accounts): business name, business type, address, employee roster, employee roles and pay rates you configure.
- Employee availability & scheduling data: availability windows, shift preferences, swap requests, time-off requests.
- Payment details: we do not store card numbers. Stripe processes payments and returns a customer ID and subscription state that we store.
- Support communications: any email or in-app message you send us.
2.2 Information we collect automatically
- Authentication tokens: short-lived access tokens (in memory) and refresh tokens (secure HttpOnly cookie on web; Keychain on iOS via Capacitor secure storage).
- Device identifiers for push notifications: APNs device tokens, associated to your user account so we can send you notifications you have opted in to receive. This qualifies as a Device ID under Apple's App Privacy taxonomy.
- Diagnostic logs: IP address, user-agent, timestamps, endpoint accessed, and error traces, for the purposes of security, rate-limiting, and debugging. Retained per §6.
- Cookies: an HttpOnly; Secure refresh-token cookie scoped to
/api/v1/authonshifthq.app. No third-party advertising cookies, no analytics cookies at present.
2.3 What we do NOT collect
- We do not collect precise device location.
- We do not use tracking pixels, ad IDs, or third-party analytics SDKs on device.
- We do not sell personal data. We do not "share" it for cross-context behavioral advertising (CCPA meaning).
3. How we use your data
We use personal data to:
- Provide the Service — authenticate you, restore your session, run the scheduling engine, deliver push notifications you opted in to.
- Bill and manage your subscription via Stripe.
- Send transactional email (OTP codes, receipts, account notices) via Resend.
- Provide optional AI-assisted features (schedule suggestions, natural-language rule parsing) via Google Gemini. Content sent to Gemini is limited to the specific request; Gemini's data handling is governed by Google's terms (see §5).
- Protect the Service against abuse: rate-limiting, fraud detection, audit logs.
- Comply with legal obligations (tax invoices, lawful requests).
3.1 Legal bases (GDPR / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service to you | Contract (Art. 6(1)(b)) |
| Billing & subscription management | Contract + legal obligation |
| Push notifications | Consent (opt-in), withdrawable at any time from iOS settings or in-app |
| Security, fraud prevention, audit logs | Legitimate interests (Art. 6(1)(f)) |
| AI-assisted features | Consent + contract |
| Legal compliance (tax, lawful requests) | Legal obligation (Art. 6(1)(c)) |
3.2 Automated scheduling
The Service includes an automated scheduling solver that suggests shift assignments based on rules, employee availability, and priority settings you configure. All suggested assignments are reviewed and published by a human manager before becoming visible to employees — no shift assignment is made solely by automated means. Accordingly, GDPR Article 22 (automated individual decision-making) does not apply.
4. Push notifications
Push notifications are opt-in. On first login on iOS, we show an in-app pre-prompt explaining what notifications you will receive before triggering the system permission dialog. You can withdraw consent at any time from your device's Settings → Notifications → ShiftHQ, or by signing out. Withdrawal revokes the device token on our servers.
Notifications you will receive if you opt in:
- A manager publishes a schedule that includes you.
- An employee submits a swap request (managers only).
- A swap request you submitted is approved or declined.
We do not send marketing push notifications.
5. Third-party sub-processors
The following third parties process data on our behalf. Each is bound by contract to process data only as instructed by us and to maintain appropriate security.
| Sub-processor | Purpose | Data categories | Location | More info |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing, subscription billing | Email, name, business name, subscription state (no card numbers stored by us) | US, EU | Stripe Privacy |
| Resend | Transactional email (OTP, receipts, notices) | Email address, message content | US | Resend Privacy |
| Cloudflare R2 / Cloudflare, Inc. | File storage (e.g., business logos, exported schedules) | Uploaded files, associated metadata | Global CDN | Cloudflare Privacy |
| Google LLC — Gemini API | Optional AI-assisted scheduling features | Prompt text (may include shift/rule descriptions) | US, EU | Google Privacy |
| Apple Inc. — APNs | Push notification delivery to iOS | Device token, notification payload | US | Apple Privacy |
| Render Services, Inc. | Application hosting & database | All Service data at rest | Frankfurt, Germany (EU Central) | Render Privacy |
A current list of sub-processors is available on request at privacy@shifthq.app.
6. Data retention
- Active account data: retained for the life of your account.
- Deleted accounts: hard-deleted from our production database within 30 days of deletion request. Backups are purged within 90 days.
- Diagnostic logs: retained for 30 days, then deleted or aggregated beyond identification.
- Billing records: retained for the period required by applicable tax law (typically 7 years in Israel; 6 years in most EU jurisdictions).
- Push device tokens: deleted when you sign out, revoke notification permission, or delete your account.
7. International transfers
We are based in Israel. Personal data may be transferred to and processed in the United States and other countries where our sub-processors operate. Where such transfers involve personal data of EU/UK/Swiss residents, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, and, where applicable, the EU–US Data Privacy Framework certification of the sub-processor.
8. Your rights
Depending on where you live, you may have the following rights. To exercise any of them, email privacy@shifthq.app from the address associated with your account. We will respond within 30 days (GDPR/UK GDPR) or 45 days (CCPA).
8.1 GDPR / UK GDPR (EEA, UK, Switzerland)
- Access — receive a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure ("right to be forgotten") — see §9.
- Restriction — limit our processing.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — for consent-based processing (e.g., push notifications, AI features).
- Lodge a complaint — with your local Data Protection Authority.
8.2 CCPA / CPRA (California)
- Right to know what personal information we collect and how it is used and shared.
- Right to delete personal information (subject to legal exceptions).
- Right to correct inaccurate information.
- Right to opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information — we do not process sensitive personal information for purposes that would trigger this right.
- Right to non-discrimination for exercising these rights.
8.3 Israeli Privacy Protection Law (חוק הגנת הפרטיות)
- Right to review your personal data in our database (§13, Privacy Protection Law).
- Right to correct or delete inaccurate data (§14).
- Data controller: Refael Dabush, Dvora Omer 5, Ra'anana, Israel.
- Sources of data: directly from you (registration, in-app entry) and, for employee accounts, from the business account that invited you.
- Lodge a complaint with the Israeli Privacy Protection Authority (הרשות להגנת הפרטיות) — gov.il/he/departments/the_privacy_protection_authority.
9. Account deletion
You can delete your account at any time from Settings → Account → Delete account inside the app. Deletion:
- Hard-deletes your users row and cascades to all owned records (business, employees, shifts, etc.) on our production database.
- Wipes the refresh token from your device's secure storage.
- Revokes your push device token.
- Cancels any active Stripe subscription (business accounts).
Some records may be retained where required by law (e.g., tax invoices — see §6).
Alternatively, you can email privacy@shifthq.app with the subject "Account deletion" from your registered email address.
10. Security
- All traffic to our API is over TLS 1.2 or later.
- Access tokens are short-lived (15 minutes) and held only in memory. Refresh tokens are stored in HttpOnly; Secure cookies (web) or the iOS Keychain (mobile).
- Passwords, where used, are hashed with bcrypt.
- Every backend query is scoped to the requesting user's
business_idto prevent cross-tenant access. - We maintain audit logs of authentication and administrative events.
- No system is perfectly secure; we cannot guarantee absolute security.
- If you discover a vulnerability, please email privacy@shifthq.app. Please do not disclose publicly until we have had a reasonable opportunity to remediate.
11. Children
The Service is not directed to children under 16 (or 13 in the US). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact privacy@shifthq.app and we will delete it.
12. Business (B2B) customers — DPA
If you are a business administrator, our Data Processing Agreement (DPA) forms part of your subscription. Employee data you upload to the Service is processed on your behalf under that DPA. To request a signed DPA copy, please contact privacy@shifthq.app.
13. Changes to this policy
We will post any changes to this Privacy Policy on this page and, for material changes, notify you by email or in-app notice before the change takes effect. The "Last updated" date at the top reflects the most recent revision.
14. Contact us
For questions, requests, or complaints:
- Email: privacy@shifthq.app
- Postal address: Refael Dabush, Dvora Omer 5, Ra'anana, Israel