Shiftelix legal

Privacy Policy

This Privacy Policy explains how Shiftelix handles information across our public website, workforce scheduling web application, and mobile apps.

Last updated: March 12, 2026

Overview

Shiftelix is a scheduling, workforce, and workspace operations product used by organizations to plan shifts, manage access, coordinate employees, and support related operational workflows. This Privacy Policy applies to information collected through our public website, authenticated web application, mobile apps, and direct support interactions.

The data entered into Shiftelix is often provided and managed by the organization that invited you to its workspace. We use that information to operate the service, secure accounts, and support the workflows your organization enables. We do not sell personal information.

Information we collect

  • Account and profile information. Name, work email, role, workspace association, and sign-in details needed to provide secure access.
  • Workspace and operations data. Shifts, assignments, availability, time-off records, attendance activity, permissions, department information, and related workforce records created or uploaded in the product.
  • Support and communications data. Information you submit through support forms, contact requests, and product communications with Shiftelix.
  • Usage, device, and log data. IP address, browser or device details, request timestamps, error logs, and feature-usage metadata used for security, troubleshooting, and service reliability.
  • Optional integration data. If you connect Google Calendar, we store the information needed to maintain the integration, including your Google account email, an encrypted refresh token kept server-side, and event-mapping data used to keep schedules in sync.
  • Mobile feature data. When product features require it, the mobile apps may process while-in-use location for location-required check-ins, media you choose to upload, microphone input for supported recording flows, and push-notification tokens for alerts.

How we use information

  • Provide, secure, and improve the Shiftelix service.
  • Authenticate users, enforce permissions, and maintain workspace access.
  • Run scheduling, attendance, messaging, and operational workflows requested by your organization.
  • Send product notices, account alerts, and push or email notifications related to service use.
  • Respond to support requests, review incidents, and troubleshoot technical issues.
  • Detect abuse, investigate security concerns, and protect the integrity of the platform.

Sharing and processors

We share information only as needed to operate Shiftelix, including with service providers that support hosting, databases, storage, notifications, email delivery, and optional integrations you enable. Current product flows also rely on infrastructure and service providers such as Render for hosted application infrastructure and Google Calendar when a user explicitly enables calendar sync.

We may also share information within a workspace at your organization’s direction, or when disclosure is reasonably necessary to comply with law, enforce our terms, prevent fraud, or protect users and Shiftelix.

Retention and security

We retain information for as long as needed to provide the service, maintain workspace records, satisfy legal obligations, resolve disputes, and protect the platform. Some payroll, attendance, tax, fraud-prevention, and audit records may be retained when required by law or legitimate business needs.

We use reasonable administrative, technical, and physical safeguards to protect data. For example, Google Calendar refresh tokens used for optional sync are stored encrypted at rest and are not exposed to the client application.

Mobile permissions

The Shiftelix mobile apps request access only when a product feature needs it. Location access is requested while in use for location-required check-ins. Camera, microphone, and media-library permissions are tied to the specific capture or upload actions you initiate. The current mobile implementation does not rely on continuous background location tracking for routine use.

Your choices and rights

  • Workspace administrators and authorized users can update much of their account and workspace data inside the product.
  • Users can disconnect optional integrations such as Google Calendar.
  • Users can manage supported device permissions through the operating system and the app’s settings surfaces.
  • Request account deletion in the mobile app under Settings > Account & Security > Request Account Deletion, or use /account-deletion if you cannot sign in.
  • If you need help locating the right workflow or understanding retained-record limits, visit /support.

International transfers

If you access Shiftelix from outside the United States, your information may be processed and stored in the United States or other jurisdictions where our service providers operate.

Changes to this policy

We may update this Privacy Policy from time to time as the product evolves or legal requirements change. We will update the “Last updated” date when changes are posted. Material updates may also be communicated through the product or by other appropriate notice.

Contact

If you have questions about this Privacy Policy, contact us at support@shiftelix.com.

For operational help, reviewer questions, or launch-readiness requests, use /support.