Last updated: April 19, 2026
Shift-Right ("we", "our", or "us") operates the Shift-Right mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our App. By using the App, you agree to the practices described here.
1. Information We Collect
We collect the following types of information:
- Account information: Name, email address, and role (manager or worker) provided during registration.
- Profile photo: Optionally uploaded by you. Stored securely via Cloudflare R2.
- Organizational data: Shift schedules, availability, swap requests, and coverage blocks created within your organization.
- Billing information: Subscription plan and payment status. Payment transactions are processed by Lemon Squeezy — we never store your card details.
- Device information: Push notification token, device type, and OS version, collected to deliver notifications.
- Usage data: App activity logs collected via Sentry for error monitoring and crash reporting.
2. How We Use Your Information
- To provide and operate the Shift-Right service
- To send shift reminders and scheduling notifications
- To process subscription payments via Lemon Squeezy
- To send transactional emails (invites, password resets) via Resend
- To detect and fix errors via Sentry crash reporting
- To respond to your support requests
3. Information Sharing
We do not sell your personal data. We share data only with the following trusted service providers, solely to operate the App:
- Lemon Squeezy — payment processing and subscription management
- Cloudflare — CDN, media storage (R2), and DDoS protection
- Expo / EAS — push notification delivery
- Resend — transactional email delivery
- Sentry — error and crash monitoring
- Railway — cloud infrastructure and database hosting
Each provider is bound by their own privacy policy and data processing agreements.
4. Data Retention
- Account data is retained while your account is active.
- Shift and scheduling data is retained for 12 months after creation, then automatically deleted.
- After account deletion, all personal data is removed within 30 days.
5. Data Security
We use industry-standard security measures including:
- TLS/HTTPS encryption for all data in transit
- Encrypted storage for authentication tokens on your device (via Expo SecureStore)
- HMAC-SHA256 verification for all webhook payloads
- JWT access tokens with short expiry and rotating refresh tokens
No method of transmission over the internet is 100% secure. We strive to use commercially acceptable means to protect your data but cannot guarantee absolute security.
6. Children's Privacy
Shift-Right is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Object to or restrict certain processing
To exercise any of these rights, contact us at support@shiftright.app.
8. International Transfers
Shift-Right is operated from Israel. Your data may be processed in countries where our service providers operate (including the United States). By using the App, you consent to this transfer.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the App or by email. Continued use of the App after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Shift-Right
Israel
support@shiftright.app