DRAFT — REQUIRES LEGAL REVIEW BEFORE COMMERCIAL LAUNCH. Not legal advice.

Version: draft-2026-08-11

Privacy Policy

Last updated: August 11, 2026 (draft). Based on current product data flows.

1. Who we are

Shift Resource (“we”) provides B2B workforce scheduling software at shiftresource.com. Contact: hello@shiftresource.com.

2. What we collect

Depending on Customer configuration and use, we may process:

  • Account information: email, username, name fields, authentication identifiers (via Supabase Auth), organization membership and roles.
  • Workforce information: employee records, numbers, assignments to sites/departments/crews/ positions, qualifications, restrictions, status.
  • Schedules and staffing: shift definitions, assignments, vacancies, staffing requirements.
  • Leave / PTO: leave types, requests, approvals, balances and adjustments where enabled.
  • Overtime: groups, offers, responses, records, and related lists/overrides.
  • Permits: permit metadata, activity history, and uploaded permit document files stored in Supabase Storage when the permits module is used.
  • Notifications: in-app notification records; email delivery depends on configured mail providers.
  • Configuration: organization modules, roles/permissions, rules, Builder build configurations linked to the Customer.
  • Audit logs: security and operational audit events for the organization.
  • Billing metadata: organization commercial status, negotiated amounts, billing contact information, invoice tracking records, and optional external billing references. Payment card numbers are not stored in Shift Resource application databases.
  • Technical / error data: when Sentry is configured, selected application error events and related technical context may be sent to Sentry. Hosting/runtime logs may exist on Vercel and Supabase infrastructure.

3. What we do not intentionally collect today

Based on the current product: we do not operate a separate marketing analytics pixel suite in-app, and we do not store full payment card numbers in our database. If additional trackers are added later, this policy should be updated.

4. How we use information

We use information to provide the Service to Customer organizations, authenticate users, enforce permissions and tenancy, support invoice-based billing operations, monitor errors, secure the platform, and support Customers.

5. Processors / infrastructure

  • Supabase — authentication, PostgreSQL database, file storage
  • Vercel — application hosting
  • External invoicing / accounting tools as used by Shift Resource operations (invoices are typically emailed; not hosted as an in-app payment portal)
  • Sentry — optional error monitoring when configured

6. Cookies

The application uses authentication session cookies required to keep users signed in. Optional short-lived operational cookies may be used for one-time UX flashes (for example temporary password display to an administrator). We do not currently rely on third-party advertising cookies in the product.

7. Retention and deletion

Customer data is retained while the organization is active or suspended. After cancellation, data is preserved until intentional export and controlled deletion according to the Customer agreement and our retention model (business/legal retention periods to be finalized). Database backups follow Supabase Pro backup retention.

8. Customer / employee rights

Because this is B2B software, employee personal data is typically controlled by the Customer organization. Individuals should contact their employer/Customer administrator for access or correction requests relating to workplace data. Platform privacy inquiries may be sent to hello@shiftresource.com.

9. Changes

We may update this Privacy Policy. The version identifier will change when material updates are published.

10. Related

See also Terms of Service (draft) and Contact.