Last updated July 13, 2026
This Privacy Notice for ShiftDispatch ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at shiftdispatchhq.com or any website of ours that links to this Privacy Notice
- Use our mobile-friendly staff and workspace experiences, or any other application of ours that links to this Privacy Notice
- Use ShiftDispatch. ShiftDispatch provides operational communications, coordination tools that help users create, publish, share, and manage staff schedules, updates, confirmations, open shifts, and related operational communications.
- Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services.
Summary of Key Points
This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? ShiftDispatch is not designed to request sensitive personal information, but some information you or your organization submit, such as account credentials, phone-based verification data, schedule notes, worker addresses, messages, invoice details, or uploaded spreadsheet contents, may be treated as sensitive under some laws or contexts. Please do not submit unnecessary sensitive information through the Services.
Do we collect any information from third parties? We may receive information from service providers and integrations that help operate the Services, such as Stripe for billing status, Twilio for SMS verification results, Google APIs for invoice connectors you authorize, Supabase for optional chat realtime features, analytics providers when enabled, error monitoring providers when enabled, and browser push services when you opt in to push notifications.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties.
How do we keep your information safe? We use organizational and technical measures designed to protect your personal information. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
How do you exercise your rights? The easiest way to exercise your rights is by emailing us at [email protected]. We will consider and act upon any request in accordance with applicable data protection laws.
Want to learn more about what we do with any information we collect? Review the Privacy Notice in full.
Table of Contents
- What information do we collect?
- How do we process your information?
- When and with whom do we share your personal information?
- Do we use cookies and other tracking technologies?
- How long do we keep your information?
- How do we keep your information safe?
- Do we collect information from minors?
- What are your privacy rights?
- Controls for Do-Not-Track features
- Do United States residents have specific privacy rights?
- Do we make updates to this Notice?
- How can you contact us about this Notice?
- How can you review, update, or delete the data we collect from you?
1. What Information Do We Collect?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
- names
- phone numbers
- job titles
- usernames
- passwords
- billing addresses
- mailing addresses
- email addresses
- tenant, workspace, organization, job site, address, and position information
- worker and staff profile information, including names, email addresses, phone numbers, tags, schedule colors, and addresses
- schedules, shifts, assignments, confirmations, reminders, open shift claims, published schedule snapshots, and related operational communications
- chat messages, conversation metadata, notification settings, push subscription information, and device or browser notification status
- spreadsheet imports, exported files, invoice connector settings, invoice run metadata, generated invoice details, and related customer or worker snapshots
- billing plan selections, Stripe customer and subscription identifiers, billing status, and checkout or customer portal metadata
Sensitive Information. ShiftDispatch is not intended to collect sensitive personal information such as government identifiers, health information, or precise geolocation. However, some account credentials, payment-related references, phone verification data, worker addresses, schedule notes, chat messages, invoice records, uploaded spreadsheet contents, and similar information may be considered sensitive depending on the context or jurisdiction. You are responsible for limiting the sensitive information you submit to what is necessary for using the Services.
Payment Data. If you choose to purchase a paid plan, Stripe processes payment details directly. ShiftDispatch stores billing-related references and status information, such as Stripe customer identifiers, subscription identifiers, selected price or tier, subscription status, checkout session metadata, and billing period information. We do not store full payment card numbers or card security codes in the application database. You may find Stripe's privacy notice here: https://stripe.com/privacy.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In Short: Some information -- such as your Internet Protocol (IP) address and/or browser and device characteristics -- is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information.
Like many businesses, we also collect information through cookies and similar technologies. You can find out more about this in our Cookie Policy.
The information we collect includes:
- Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files.
- Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services.
- Location Data. We may collect or infer imprecise location information from network data such as IP address. We do not intentionally collect precise device geolocation in the current application implementation.
Google API
If you connect a Google Drive/Docs invoice connector, we use Google APIs to create, copy, update, export, and manage invoice documents and folders as authorized by you. Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. ShiftDispatch may store encrypted Google refresh tokens, connected account email addresses, authorized scopes, Google file and folder identifiers, generated document URLs, and related invoice connector configuration.
2. How Do We Process Your Information?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To facilitate account creation and authentication and otherwise manage user accounts.
- To deliver and facilitate delivery of services to the user.
- To respond to user inquiries/offer support to users.
- To request feedback.
- To protect our Services.
- To identify usage trends.
- To create, publish, share, update, and manage schedules, staff profiles, shift assignments, confirmations, open shifts, reminders, chat, and related operational workflows.
- To authenticate workspace admins and staff, including password-based sign-in, phone-based SMS verification, staff access sessions, and workspace multi-factor authentication.
- To process billing events, maintain subscription status, and provide access to checkout or customer portal flows through Stripe.
- To process spreadsheet imports, invoice previews, generated invoice documents, exports, print/PDF workflows, and connected Google Drive/Docs invoice workflows.
- To send or facilitate service notifications, such as web push notifications, SMS verification codes, and schedule or chat-related notifications when configured and permitted.
3. When and With Whom Do We Share Your Personal Information?
In Short: We may share information in specific situations described in this section and/or with the following third parties.
We may need to share your personal information in the following situations:
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Service Providers and Integrations. We may share information with vendors and service providers that help us operate the Services, including Render for hosting and database infrastructure, Stripe for billing, Twilio for SMS verification codes, Google APIs for invoice connectors you authorize, Supabase for chat realtime features, Sentry for error monitoring, PostHog and Google Analytics for analytics, and browser push notification services when you opt in to push notifications.
- Workspace and Staff Users. Information you enter into a workspace may be visible to workspace admins, owners, staff users, or other authorized users according to their role and the product feature being used.
- Public Schedule Links. If you publish a free schedule or other public schedule link, the schedule snapshot may be accessible to anyone with the public link until it expires or is unpublished. Management tokens used to unpublish or republish free schedule links should be kept private.
4. Do We Use Cookies and Other Tracking Technologies?
In Short: We may use cookies and other tracking technologies to collect and store your information.
We may use cookies and similar tracking technologies to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.
We may permit third parties and service providers to use online tracking technologies on our Services for analytics when browser analytics is enabled and configured. Based on the current application implementation, browser analytics is disabled unless a public analytics setting is enabled and a browser provider key is configured. The current browser implementation may use Google Analytics 4 and/or PostHog for explicit page view and product analytics events. It does not enable PostHog autocapture or session recording, and it sanitizes analytics URLs and event payloads before sending them.
Server-side product analytics are separate from browser analytics. When a server-side PostHog key is configured, server-side product milestone events may be sent to PostHog even if browser analytics is disabled. These server events are used for retention and activation reporting and may include internal product identifiers, such as workspace, account, or worker identifiers.
To the extent these online tracking technologies are deemed to be a "sale"/"sharing" under applicable US state laws, you can opt out of these online tracking technologies by submitting a request as described below under section "Do United States Residents Have Specific Privacy Rights?"
Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy.
Google Analytics
If Google Analytics is enabled and configured, we may share limited usage information with Google Analytics to track and analyze use of the Services. The current implementation does not intentionally enable Google Analytics advertising features, demographic reporting, or interest reporting. To opt out of being tracked by Google Analytics across the Services, visit https://tools.google.com/dlpage/gaoptout.
5. How Long Do We Keep Your Information?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. Active workspace and account data is generally retained while the applicable account or workspace remains active. Some core records are soft-deleted so operational history and related records remain consistent. Expired rate-limit records and short-lived verification challenges are removed by scheduled cleanup processes. Service logs, database recovery data, logical backup exports, error-monitoring data, and analytics data follow the retention settings of the applicable configured provider and service plan. Billing and invoice records may be retained as needed for tax, accounting, legal, and compliance purposes. Contact [email protected] for a request concerning deletion or retention of your information.
Free schedule builder drafts may be stored locally in your browser until you clear them or the application clears them. Published free schedule snapshots are stored server-side, expire after the configured publication period, and may be unpublished using the management token. The application also includes cleanup processes for expired or unpublished public schedule snapshots, rate-limit records, and short-lived verification challenge records.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible, then we will securely store your personal information and isolate it from any further processing until deletion is possible.
6. How Do We Keep Your Information Safe?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.
7. Do We Collect Information From Minors?
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at [email protected].
8. What Are Your Privacy Rights?
In Short: You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.
Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
- Contact us using the contact information provided.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases.
Cookies and similar technologies
Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies.
9. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected.
At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.
10. Do United States Residents Have Specific Privacy Rights?
In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.
Categories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name | YES |
| B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information | YES |
| C. Protected classification characteristics under state or federal law | Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data | NO |
| D. Commercial information | Transaction information, purchase history, financial details, and payment information | YES |
| E. Biometric information | Fingerprints and voiceprints | NO |
| F. Internet or other similar network activity | Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements | YES |
| G. Geolocation data | Device location, including imprecise location inferred from IP address | YES |
| H. Audio, electronic, sensory, or similar information | Images and audio, video or call recordings created in connection with our business activities | NO |
| I. Professional or employment-related information | Business contact details, job title, work history, and professional qualifications | YES |
| J. Education Information | Student records and directory information | NO |
| K. Inferences drawn from collected personal information | Inferences drawn from any of the collected personal information listed above to create a profile or summary | YES |
| L. Sensitive personal Information | Account login information, payment account information, precise geolocation, or other data treated as sensitive under applicable law | YES |
We only collect sensitive personal information, as defined by applicable privacy laws, for the purposes allowed by law or with your consent. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.
Sources of Personal Information
Learn more about the sources of personal information we collect in "What Information Do We Collect?"
How We Use and Share Personal Information
Learn more about how we use your personal information in the section, "How Do We Process Your Information?"
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider.
We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration.
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:
- Right to know whether or not we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling
Depending upon the state where you live, you may also have the following rights:
- Right to access the categories of personal data being processed
- Right to obtain a list of the categories of third parties to which we have disclosed personal data
- Right to obtain a list of specific third parties to which we have disclosed personal data
- Right to review, understand, question, and correct how personal data has been profiled
- Right to limit use and disclosure of sensitive personal data
- Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature
How to Exercise Your Rights
To exercise these rights, you can contact us by emailing us at [email protected], or by referring to the contact details at the bottom of this document.
Request Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request.
Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at [email protected]. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision.
California "Shine The Light" Law
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information, if any, we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year.
11. Do We Make Updates to This Notice?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification.
12. How Can You Contact Us About This Notice?
If you have questions or comments about this notice, you may email us at [email protected]. Additional contact information is available upon request by emailing:
13. How Can You Review, Update, or Delete the Data We Collect From You?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information.
To request to review, update, or delete your personal information, please email [email protected].