Privacy Policy & Data Protection
ShiftShield is engineered from the ground up on the principle of worker confidentiality, cryptographic evidence integrity, and absolute zero data monetization. We never sell, rent, or trade your shift logs, evidence photos, or workplace grievance records to employers, insurers, or advertising brokers.
01. Data Controller & Organization Identity
The Data Controller responsible for your personal information is ShiftShield Legal Technologies Ltd (“ShiftShield”, “we”, “us”, or “our”), registered in the United Kingdom under the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
02. Lawful Bases for Processing (GDPR Articles 6 & 9)
Under Article 6 and Article 9 of the UK and EU GDPR, we process your personal data solely under the following strict lawful grounds:
- Contract Performance (Article 6(1)(b)): To provide you with contemporaneous shift recording, statutory breach calculation, automated rest deficit auditing, and Court Evidence Package generation pursuant to your subscription agreement.
- Legal Obligation & Evidentiary Defence (Article 6(1)(c) & Article 9(2)(f)): Processing workplace directives, harassment incidents, and statutory rest deficit chronologies for the explicit establishment, exercise, or defence of legal claims before Employment Tribunals, civil courts, and labor arbitrations.
- Legitimate Interests (Article 6(1)(f)): Protecting the integrity and security of our cryptographic infrastructure against fraud, unauthorized intrusion, and evidence tampering.
03. Categories of Data We Collect & Generate
Full legal name, email address, cryptographically hashed passwords (via Bcrypt/Argon2ID), preferred timezone, and selected statutory jurisdiction (UK, US, AU, CA, SE, NO, or EU).
Clock-in and clock-out timestamps accurate to the second, meal break durations, active work hours, site locations, employer notes, and automated statutory breach audit scores (e.g. 11-hour daily rest deficits, 48-hour weekly rolling averages, missed statutory pauses).
Records of manager requests to work during statutory rest, coercive instructions, harassment incident timestamps, harasser identifiers, incident narratives, and statutory reprisal / retaliation flags.
Uploaded shift rosters, photographic timecard proofs, text message screenshots, and employment contracts. All images undergo client-side EXIF stripping prior to server storage to erase unintended GPS coordinate leakage while computing immutable SHA-256 digital checksums.
04. Cryptographic Security & Storage Architecture
ShiftShield operates bank-grade technical and organizational safeguards:
- Encryption in Transit: TLS 1.3 protocol enforced across all web, PWA, and native mobile network communications with HSTS preloading.
- Encryption at Rest: Database records and evidentiary document vaults are encrypted with AES-256 algorithms.
- Cryptographic Hashing: Every evidence file and generated court package produces a verifiable SHA-256 checksum at ingestion to legally defeat employer claims of document spoliation or post-facto modification.
- Tenant Isolation: Data rows and file directories are strictly partitioned by cryptographic tenant identifiers (`tenant_id`), preventing multi-tenant data contamination or unauthorized horizontal privilege escalation.
05. In-App Payments & Subscriptions
ShiftShield does not process, store, or have access to your personal debit or credit card information. Subscriptions (£4.99 for Basic 6 Months or £9.99 for 12 Month Rolling Contract in your local currency) are processed exclusively by:
Processed under Apple Inc.’s Privacy Policy. We only receive an anonymous cryptographic transaction token and subscription expiry date.
Processed under Google LLC’s Privacy Policy. We only receive an encrypted purchase token to verify entitlement.
06. Your Rights Under GDPR, CCPA & Global Privacy Laws
Under the UK GDPR, EU GDPR, and applicable international privacy legislation, you have the following rights:
07. Data Retention & Expiry Policies
In strict compliance with Apple App Store Guideline 3.1.2 and Google Play Billing Policies:
- Active Subscriptions: Data is actively maintained in real-time with full recording, auditing, and export capabilities.
- Expired Subscriptions: If your subscription period ends, your records are NEVER deleted or locked away. You retain perpetual read-only access to review past shifts, inspect statutory breaches, and generate/download your official Court Evidence Package (PDF and CSV) at no additional charge. You simply cannot append new shifts until renewed.
08. Self-Service Permanent Account Deletion
In accordance with Apple Guideline 5.1.1(v) and Google Play user data rules, users have complete autonomy to destroy their account at any time:
To prevent accidental or coerced deletion, we require you to type I CONFIRM and confirm your current password in Account Settings.
Once submitted, our backend executes an irreversible cryptographic cascade: all shifts, manager requests, harassment grievance records, email notification logs, and disk-stored evidentiary documents are purged immediately.
09. Supervisory Authorities & Complaints
If you have concerns regarding our processing of your personal information, you have the statutory right to lodge a complaint with your supervisory authority: