Scope and data responsibility
This Policy explains how Shiftaam collects and processes information when you use our website, web application, and workforce scheduling services at shiftaam.com.
Where an organization enters employee and scheduling information into Shiftaam, that organization determines certain purposes of the work-related processing, while Shiftaam processes the information to provide the service.
Information we collect
- Account and identity data: name, mobile number, email address, profile image, user role, and account identifiers.
- Organization and work data: organization, department and position, schedules, shift or leave requests, preferences, tasks, messages, and service activity records.
- Subscription and transaction data: subscription status, payment status, and transaction identifiers needed for reconciliation. Shiftaam does not receive or store full bank-card details.
- Technical and security data: IP address, device and browser type, login times, security events, technical errors, session cookies, and data required to prevent abuse and operate the service.
- Information you voluntarily provide in support requests, feedback, or other communications.
Google data and Google Calendar
Google sign-in and Google account connection are optional and occur only after you choose them and grant consent. Shiftaam may receive your Google account identifier and the basic profile information shown on the consent screen, such as your name and email, to identify your account and complete sign-in.
If you connect Google Calendar, Shiftaam uses only the permission you approve to create, update, or delete calendar events for finalized work shifts. To continue synchronization, we store the Google identifier, calendar identifier, identifiers of created events, and an encrypted long-lived access token.
We do not use Google user data for advertising, advertising profiling, sale, credit decisions, or training artificial-intelligence models. Humans do not read this data except with your explicit consent for support, to investigate security or abuse, or where legally required.
How we use information
- Create and manage accounts, authenticate users, and provide manager or employee functionality.
- Create, publish, and display schedules and process requests, notifications, messages, and organization reports.
- Synchronize finalized shifts with Google Calendar when enabled by the user.
- Process payments, administer subscriptions, provide support, and send necessary service messages.
- Maintain security, prevent fraud and abuse, troubleshoot errors, and improve reliability and usability.
- Meet legal obligations and respond to disputes or valid requests from competent authorities.
Data retention and deletion
We retain information only as long as needed to provide the service, preserve required organization records, maintain security, resolve disputes, and meet legal obligations. The period depends on the type of data, account status, organization settings, and applicable law. Backups and security logs may remain in a protected deletion cycle for a limited period before being deleted or anonymized.
To request deletion of your account or related data, submit a request through in-account support or email support@shiftaam.com. After verifying the requester and considering organization rights and legal duties, we delete or anonymize eligible data. Records required for law, security, or transaction evidence are retained only for the necessary period.
Your Google access controls
You may revoke Shiftaam's access at any time from the third-party connections page at myaccount.google.com/connections. Revocation stops future access through Google APIs. Calendar events already created may remain until you delete them.
To remove the encrypted token and Google connection identifiers from Shiftaam, contact in-account support or support@shiftaam.com. Deleting your Shiftaam account does not delete your Google account.
Information security
We use proportionate technical and organizational safeguards, including HTTPS encryption in transit, password hashing, encryption of Google tokens, role-based access controls, security logging, and backups. No internet transmission or storage system, however, can be guaranteed completely risk-free.
Users must keep passwords and access methods confidential and promptly report suspected unauthorized access.
Your choices and rights
- View and correct available profile information and account settings.
- Revoke Google access and request deletion of connection data.
- Request access to, correction of, or deletion of personal information, subject to law and the relevant organization's rights.
- Manage optional notifications and sign out on available devices.
- Object or ask questions about processing through our support channels.
Younger users
Shiftaam is designed for workplace management and is intended for people legally permitted to work and use the service in their location. Information about a younger person may be entered only with any legally required authorization and under the organization's responsibility.
Changes to this Policy
We may update this Policy to reflect changes in the service, technology, or law. We will publish the revised version and its update date at this URL and provide appropriate notice of material changes. Continued use after changes take effect is governed by the revised Policy.
Contact us
For privacy questions, rights requests, or security concerns, use in-account support or email support@shiftaam.com. We may verify your identity before acting on a request to protect your information.