Privacy policy

Published 2 August 2026, effective 16 August 2026.

InShift (“we”, “the service”) is a SaaS platform for shift scheduling, available as a web app and a mobile app. This policy explains what personal data we collect, how we use it, who we share it with and what rights you have. By using InShift you agree to this policy.

1. Who the data controller is

The controller of your personal data is the InShift team. For privacy enquiries: support@inshift.app.

For the data you create inside your organisation's workspace (schedules, employee profiles, requests and so on) the controller is your employer. InShift acts as a data processor on their instructions.

2. What data we collect

2.1 Account data

  • email address and an encrypted password;
  • first and last name, optionally an avatar and a phone number;
  • your role in the organisation, location, job title, department.

2.2 Work data

  • shift schedules and hours actually worked;
  • time off, sick leave and shift swap requests;
  • comments and messages inside those requests;
  • clock in, break and clock out records, if your organisation has turned on attendance tracking. Section 9 covers this in detail.

2.3 Technical data

  • device identifiers and push notification tokens (APNs, FCM);
  • device type, OS version, app version, interface language;
  • service logs (sign in time, IP address) for security and diagnostics.

We do not collect location data, contacts, photos from your library (other than an avatar you upload yourself), health data, users' payment details, browsing history or advertising data.

The app asks for camera access, but we collect nothing from the camera either: it reads the check-in code on your own device, and the frame is never stored or sent anywhere. The same applies to a photo you take for your profile or a support request: only what you deliberately send reaches us.

3. What we use the data for

  • running the service itself: schedules, requests, profiles, messages;
  • authentication and protection of your account;
  • sending push notifications about new shifts, requests, swaps and replies, only after you allow them at operating system level;
  • support and messages about important changes to the service;
  • stability analysis and finding bugs in the app;
  • tracking working time and calculating pay from check-ins, if your organisation has turned on attendance tracking;
  • meeting legal obligations.

4. Legal bases for processing

We process data on the basis of: (a) performance of the service contract with you or your organisation, (b) your consent, for example for push notifications and uploading an avatar, (c) legitimate interest, for security and diagnostics, (d) compliance with legal obligations, including an employer's duty to keep records of working time.

5. Who we share data with

We do not sell your data. We use only the processors we need:

  • Google Firebase Cloud Messaging (FCM) and Apple Push Notification service (APNs) to deliver push notifications to your device;
  • Our hosting provider (server infrastructure in the EU) to store the database and run the API;
  • Your organisation: administrators and managers can see work data within the limits of their permissions;
  • Public authorities, only on a valid legal request.

6. Storage and security

Data is stored on servers in the European Union. Traffic between your device and our servers goes over HTTPS/TLS. Passwords are stored as bcrypt hashes. Access by InShift staff is strictly limited and logged.

We keep your data while you use the service. After you delete your account, personal data is removed within 30 days, except where the law requires longer retention (accounting records, for example).

7. Your rights

  • get a copy of your data;
  • correct inaccurate data through your profile or through support;
  • delete your account and personal data: in the app under MoreDelete account, or by email to support@inshift.app. Step by step instructions are on the account deletion page;
  • withdraw consent for push notifications in your device settings;
  • withdraw camera access in your device settings;
  • lodge a complaint with a data protection authority.

Deleting your account also removes your employee record and everything attached to it: shifts, attendance check-ins, requests. If your employer needs those records to track working time or calculate pay, tell them before you delete: we cannot restore them afterwards.

8. Push notifications

Push notifications are sent only after you explicitly allow them. You can turn them off at any moment in your operating system settings. We use FCM (Android/Web) and APNs (iOS) for delivery and pass on the minimum needed: the device token and the content of the notification.

9. Attendance tracking

If your organisation has turned on attendance tracking, the app records when you clock in, take breaks and clock out. Your employer turns this feature on and is the controller of those records.

  • the time of the check-in, the location and the shift it belongs to;
  • how you checked in: the code on the tablet screen, or a staff number and PIN;
  • the device the check-in came from: the organisation's tablet or your phone.

The camera. It turns on only when you open the check-in screen yourself, and it reads the code on your device. The frame is not stored and is never sent anywhere: nothing reaches us from the camera except the check-in itself. You can refuse camera access: in that case use your staff number and PIN on the tablet instead.

We do not collect location data. The place is established by which tablet you walked up to, not by your phone's coordinates.

Your site manager and your organisation's administrator can see your check-ins. They are needed to track working time and calculate pay, so they are kept while you work at the organisation and disappear together with your employee record: if you delete your account, the check-ins go with it.

A single check-in cannot be deleted on request: a wrong one is corrected by a manager, and the correction stays visible in the history. That protects you too, because nobody can change your working time unnoticed.

10. Children

The service is not intended for people under 16. We do not knowingly collect children's data. If you believe a child has given us their data, contact us and we will delete it.

11. International transfers

Where a processor outside the EU is involved (APNs and FCM, for example), the transfer relies on standard contractual clauses or another legal mechanism provided for by the GDPR.

12. Changes to this policy

We may update this policy. We will announce material changes by email or in the app at least 14 days before they take effect. The current version is always available at https://inshift.app/en/privacy/.

13. Contact

For any privacy question write to support@inshift.app.