1. Scope
This policy applies to the ShiftHub mobile app (currently iOS only) and related websites. By downloading, installing, or using the app, you confirm that you have read and agree to this policy.
2. Data we collect
2.1 Account and identity
- Email and password: collected when you register by email. Passwords are stored hashed in Firebase Authentication; we cannot read your plaintext password.
- Third-party sign-in: if you sign in with Google or Apple, we receive your email address and display name, not your third-party password.
- Name and phone number: used for store identification and staff management.
2.2 Location
- GPS: used to set clock-in locations and verify punches, only when you use clock-in.
- Wi-Fi information: SSID and BSSID as a secondary clock-in check.
- You can turn off location permission in device settings. GPS/location clock-in will then be unavailable.
2.3 Operations and attendance
- Schedules: shift assignments, shift labels, weekly rosters.
- Clock records: in/out times and method (GPS / Wi-Fi).
- Attendance exceptions: late, early leave, absence, and similar records.
- Staff records: name, store, invite code, pay settings.
2.4 Device and technical data
- Push token: for schedule updates, clock-in reminders, and similar notices.
- Device type and OS version: to keep the app compatible.
2.5 Photos, camera, and photo library
- Store logo and feedback screenshots: uploaded only when an admin or user chooses to do so. When you pick from the library or use the camera, we access them only for that action. We do not record video/audio in the background or keep camera/microphone access.
- Core features (scheduling, GPS/Wi-Fi clock-in, attendance) do not require camera or microphone. We do not request camera or full library access until you use an image-upload feature.
- Images are stored in Firebase Storage and are available only to members of that store.
3. How we use your data
| Purpose | Details |
|---|---|
| Core service | Scheduling, GPS/Wi-Fi clock-in, attendance stats |
| Account admin | Authentication, store and staff accounts |
| Push notices | Published schedules, clock-in reminders, system notices |
| Subscriptions | Pro plan status and entitlements |
| Improve the product | Usage analysis to improve features |
We do not use your data to:
- Show you ads
- Sell it to third parties
- Run marketing unrelated to this service
4. Storage and third parties
4.1 Third-party services we use
| Service | Provider | Use |
|---|---|---|
| Firebase Authentication | Sign-in | |
| Cloud Firestore | Data storage (schedules, punches, staff) | |
| Firebase Storage | Image storage | |
| Firebase Cloud Messaging | Push notifications | |
| RevenueCat | RevenueCat, Inc. | Subscriptions and payments |
| Geolocator | Open-source package | GPS (not sent to a third-party location vendor) |
4.2 Where data is stored
Your data is stored on Google Cloud infrastructure and protected under Google Cloud security standards.
4.3 Retention
- While the account exists: data is kept for the life of the account.
- After deletion: when you delete an account or store, related personal data is removed from our servers within 30 days.
- Attendance records: retention follows each store admin’s in-app setting, for payroll and attendance disputes.
5. Payments and subscriptions
- ShiftHub Pro and similar plans are billed through the Apple App Store (in-app purchase) (iOS only for now).
- We do not collect or store credit-card numbers, bank accounts, or other payment-instrument details.
- iOS: manage or cancel auto-renewal in Settings → Apple Account → Subscriptions.
- Price, billing period, and currency are those shown on the in-app purchase screen and the App Store when you complete the purchase.
6. Security
We protect your data by:
- HTTPS/TLS for all transfers
- Hashed passwords via Firebase Authentication
- Secure on-device storage for sensitive credentials
- Firestore security rules (only store members can access that store’s data)
7. Your rights
You may:
- Access your personal data in the app.
- Correct your account information.
- Delete:
- Staff can delete their personal account in Settings.
- Admins can close the whole store in Settings; related data will be deleted.
- Withdraw consent by stopping use of the app or turning off location/notification permissions.
- Data portability: contact us below if you need an export.
8. Children’s privacy
The app is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has given us data, contact us and we will delete it after confirmation.
9. Changes
We may update this policy. The new version will be posted here with a new “Last updated” date. If a change materially affects your rights or how we process data, we will notify you in the app or by push. Please check this page from time to time.
10. Contact
Questions about this policy, or to exercise your rights:
- Email: support@shiftshub.app
- Developer: ShiftHub team
© 2026 ShiftHub. All rights reserved.