What we hold, why we hold it, and what you can make us do about it.
Before you publish this. This is a complete, accurate draft written against what ShiftWren actually does — but it is not legal advice, and the items marked in red are facts only you can supply. Have a qualified lawyer in each of India, Canada and the United States review it before launch.
ShiftWren runs the working day — schedules, clock-ins, leave, payroll and the invoices that follow — on one record. That means we handle information about real people: your staff, your clients, and you. This policy explains exactly what we hold, why, and what you can make us do about it.
01The two roles we play
This distinction decides who you talk to about what, so it comes first.
We are the controller for information about our own customers and visitors: the person who signs up, the billing contact, anyone who fills in a form on this site. We decide why and how that is used, and this policy governs it.
We are a processor for the employee and client records you put into the product — names, hours worked, pay rates, leave balances, payslips, customer invoices. That data is yours. You are the controller; we act on your instructions under our Terms of Service and only to provide the service. If you are an employee of a business that uses ShiftWren and you want to see, correct or delete your record, ask your employer, not us — we are not permitted to act on your data without their instruction, though we will always help them respond to you.
02What we collect
When you visit this website
This marketing site sets no cookies. It stores five small values in your own browser, which never leave your device and are never sent to us:
| Key | Store | What it is for |
|---|---|---|
wc_pt, wc_pt_x, wc_pt_y | Session | Lets a page-to-page transition resume from the point you clicked. Cleared when you close the tab. |
wc_cta_dismissed | Session | Remembers you dismissed the trial banner, so it stays dismissed. |
wc_sound | Local | Remembers whether you turned interface sound on. |
If we have enabled website analytics, that is described separately and in full in our Cookie Policy, including how to refuse it. Our web host also writes standard server logs (IP address, user agent, page requested, timestamp) which we use to keep the site up and to investigate abuse.
When you contact us or start a trial
- Identity and contact: your name, work email, company name, and anything you choose to write in a message to us.
- Account: your login credentials (passwords are stored only as a salted hash — we cannot read yours), business details, locations, and the working-week and holiday settings you configure.
- Billing: plan, seat count, invoices and payment status. We do not store card or bank numbers on our servers — payments are handled by our payment processor, and we keep only a token and the last four digits.
- Product usage: which features you use and when, plus an immutable audit log of changes to pay records, which exists so that a payroll figure can always be explained.
What your business puts in (we process, you control)
Employee names and contact details, roles and locations, rosters, clock-in and clock-out times, leave requests and balances, pay rates, pay runs, payslips, and your customers, catalog, estimates and invoices. Some of this may be sensitive in your jurisdiction. You decide what to upload; we ask that you upload only what you actually need.
Two categories are worth naming separately, because they are more sensitive than the rest and we hold them for one narrow purpose each:
- Date of birth — optional, and used for exactly one thing: working out statutory pension contributions that depend on age. Canada Pension Plan and Québec Pension Plan contributions begin the month after an employee turns 18 and stop at 70, so without a birth date payroll cannot tell whether a contribution is owed. It is never shown on a payslip, never used to profile anyone, and leaving it blank costs you nothing but that age check.
- Tax identifiers and filed tax elections — a Social Insurance Number, Social Security Number or PAN where you enter one, along with the claim amounts and exemptions an employee has filed on a TD1, W-4 or equivalent. These exist so that the right amount of tax is withheld and so that you can file. A tax identifier is stored for filings and is never shown on a payslip.
03Why we are allowed to
- To perform our contract with you — running your account, processing your payroll, taking payment.
- Our legitimate interests — keeping the service secure and available, preventing fraud and abuse, and improving the product. We balance these against your rights and do not use them as a catch-all.
- Your consent — for optional analytics and for marketing email. You can withdraw it at any time, and refusing costs you nothing in the product.
- Legal obligation — tax, employment and accounting records we are required to retain.
04Who else sees it
We do not sell personal information, and we never have. We do not share it for cross-context behavioural advertising. We disclose it only to:
- Sub-processors who run parts of the service for us under written contract — The complete list today is short, and we would rather print it than link a page that drifts: Neon (managed PostgreSQL, running on Amazon Web Services) holds the application database, Resend delivers transactional email — reminders, password resets and account notices — and so sees the recipient’s name, email address and the contents of that message, and Render runs the application itself — the server, and the disk that holds every file you upload — and Vercel serves this marketing site. That is all of them. We do not currently use a third-party service for error monitoring or customer support tooling, and no payment processor holds your data yet because card payments are not live. We will give you 30 days’ notice before adding a sub-processor, and update this list when we do.
- Authorities, where we are legally compelled. We will tell you first unless we are prohibited from doing so.
- An acquirer, if the business is sold or merged — under the same obligations, and we will notify you.
05Where it lives
ShiftWren operates in India, Canada and the United States, and data may be processed in any of them. Our primary hosting region is AWS us-east-2 (Ohio, United States), and backups are held in that same region. This means data belonging to a Canadian or Indian business is stored in the United States, and is subject to United States law while it is there. Where data leaves its country of origin we rely on Standard Contractual Clauses with our sub-processors, and on your consent to the transfer as described in this policy. If you need your data kept in one region only, tell us before you sign up — we would rather say no up front than fail you later.
06How long we keep it
| What | Kept for |
|---|---|
| Enquiries and support messages | 24 months from the last exchange |
| Live account and product data | For as long as your account is open |
| A trial that never became a subscription | 14 days after the trial ends, then the workspace and everything in it is permanently deleted |
| A subscription that ended and was not restarted | 45 days after the paid term ends, then the workspace and everything in it is permanently deleted |
| Payroll, tax and invoicing records | Held only while your account is live, and removed on the schedule above. Your own statutory retention — typically 6–7 years — is yours to meet: export before the window closes |
| Backups | Rolling 6 hours, after which deletions propagate |
| Server logs | 90 days |
Deletion after a lapse is automatic, permanent and unattended. A daily job removes workspaces whose window has closed; there is no recycle bin and we cannot restore one afterwards. The rule is the same either way — a trial that never became a subscription is deleted 14 days after it ends, and a subscription that ended is deleted 45 days after the last day you paid for. Starting a subscription at any point before that stops the clock and changes nothing about your data.
We tell you the exact date on the locked-account screen every time somebody signs in during that window, and a user who is left belonging to no workspace at all is deleted with it. We keep one record of the deletion afterwards — the workspace id, its name, the reason and the date — which contains no personal data and exists so we can answer for what we removed.
Export first. You can export everything in open formats at any time while the account is open, and you should do so before the window closes if you have your own tax, payroll or employment-record obligations. We hold this data on your behalf; meeting those obligations is yours, and once we delete our copy we cannot give it back.
07Your rights
Wherever you are, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider in a portable format. You can withdraw consent at any time, and you can complain to a regulator.
- India (DPDP Act 2023): access, correction, erasure, grievance redressal and nomination. Grievances reach our privacy contact at support@shiftwren.com, who will respond within 30 days.
- Canada (PIPEDA): access and correction, and a complaint to the Office of the Privacy Commissioner of Canada.
- United States (including CCPA/CPRA): know, delete, correct, and opt out of sale or sharing — we do neither. We will not discriminate against you for exercising any right.
- EU/UK, if applicable: the full set of GDPR rights, and a complaint to your supervisory authority.
Email support@shiftwren.com and we will respond within 30 days. We may need to verify who you are first. Exercising a right is always free unless a request is manifestly excessive.
08How we protect it
Every connection is encrypted in transit with TLS, and data is encrypted at rest. Access inside ShiftWren is role-based and least-privilege, and every route is scoped to the business that owns the record. Changes to money records are written to an append-only audit log. Passwords are salted and hashed; changing security-critical account settings requires re-authentication. Card and bank numbers never reach our servers.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant regulator without undue delay, and within 72 hours of becoming aware of it, with what we know and what we are doing about it.
09Children
ShiftWren is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16 as a visitor or account holder. Where you employ people under the age of majority and hold their records in ShiftWren, you are responsible for having the lawful basis and any parental consent your jurisdiction requires.
10Changes
If we change this policy we will update the version and date at the top. For changes that materially affect your rights we will email account holders at least 30 days in advance rather than quietly reposting the page. Previous versions are available on request.
11Contact us
Email support@shiftwren.com, or use the contact form and choose “Privacy & data”. Our entity is ShiftWren Inc.; write to us at the email above. No Data Protection Officer is appointed: we do not carry out large-scale systematic monitoring, and special-category data is not a core activity of the service, so the threshold in Article 37 of the UK/EU GDPR is not met. Privacy questions go to the same address and are answered by a person, not a queue.