How we handle your data
Last updated: 4 August 2026
1. Who we are
ShiftPriority ("we", "us", "our") is a restaurant scheduling and tip-management platform. Our product is available at app.shiftpriority.com. For all data-protection matters contact us at [email protected].
2. What data we collect and why
2.1 Account and organisation data
When you sign up we collect your name, email address, and business name to create your workspace and deliver the service. Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.2 Employee data
Within your workspace you may enter employee names, roles, contact details, birth dates, and hourly rates. This data is stored on your behalf and processed solely to deliver scheduling and tip-management functionality. Legal basis: Art. 6(1)(b) GDPR.
2.3 Operational data
Shift schedules, tip entries, POS sales events, and payout records are stored to provide the core service. This data belongs to your organisation and is deleted when you close your account.
2.4 Billing data
Payments are processed by Stripe, Inc. We store only a Stripe customer ID and subscription status — we never see or store full card numbers. Stripe's privacy policy →
2.5 Essential cookies
We use Supabase session storage to keep you signed in, PWA/version storage to deliver the app reliably, and local storage to remember your privacy choice for up to 180 days. These operations are strictly necessary to provide the requested service or remember your refusal and do not require separate consent (§ 25(2) no. 2 TDDDG). Google Analytics cookies are not essential and are covered separately below.
2.6 AI Import (optional)
If you use the optional AI Import feature, the roster or schedule you submit (which may contain employee names) is sent to Anthropic, PBC to extract structured data. It is processed only to return the import result and is not used to train AI models. Legal basis: Art. 6(1)(b) GDPR.
2.7 Early-access waitlist
If you join our early-access list, we retain your email address and optional venue name only to contact you about ShiftPriority. Legal basis: Art. 6(1)(a) GDPR — consent. You can withdraw at any time by emailing us.
2.8 Plausible Analytics (cookieless)
Our marketing site and the app use Plausible Analytics for aggregate reach statistics. Plausible is EU-hosted, sets no cookies and stores nothing on your device, so no device-storage consent under § 25 TDDDG is required. Legal basis for the limited aggregate measurement is Art. 6(1)(f) GDPR — our legitimate interest in understanding whether the service is useful.
2.9 Google Analytics 4 (consent only)
Only after you enable Website analytics, our marketing site and app load Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (measurement ID G-2DHZB6S27V). We use it to understand aggregate page and interaction usage and improve the product. Google may receive the page path and title, approximate location derived from connection data, browser/device information, session information and a pseudonymous client identifier. Enhanced Measurement may additionally report 90% scroll depth, outbound-link domains and URLs, site-search terms derived from supported URL parameters, form-start/submission status and form identifiers, YouTube video engagement, and downloaded-file metadata. Form field contents are not collected. We do not add names, email addresses, organisation or employee IDs, schedules, tips, POS data or other business-domain values to Analytics events. Our manual app page reports remove query strings, fragments, invite/verification tokens and OAuth state; automatic page reporting from browser-history changes is disabled.
After consent, Google may set the first-party cookies _ga (distinguishes a pseudonymous browser) and _ga_<container-id> (maintains session state). We configure both for at most 180 days without extending the expiry on later visits. Google advertising storage, advertising user data, advertising personalisation and Google Signals remain disabled. Before consent—or after rejection—the Google tag is not requested and no cookieless measurement ping is sent.
Legal bases: your consent under § 25(1) TDDDG for storage/access on your device and Art. 6(1)(a) GDPR for the subsequent processing. You may withdraw at any time through Privacy choices on every page or Settings → Privacy in the app; accessible Analytics cookies are then removed. Withdrawal does not affect processing before withdrawal. Google processes Analytics data under its data-processing terms; transfers outside the EEA are protected by Google's applicable safeguards, including Standard Contractual Clauses. See Google's Privacy Policy.
2.10 Crash and performance diagnostics (consent only)
If — and only if — you allow it in the consent banner, the app sends crash reports and a small sample of performance traces to Sentry (Functional Software, Inc., USA) so we can find and fix bugs. Session replays are recorded only around errors, with all text and inputs masked and all media blocked; we disable Sentry's collection of IP addresses and request headers. Nothing is sent unless you opt in, and you can withdraw at any time under Settings → Privacy — withdrawal is as easy as granting (Art. 7(3) GDPR). Legal basis: Art. 6(1)(a) GDPR — consent; transfer to the US covered by Standard Contractual Clauses.
2.11 Optional lifecycle emails and in-app review prompt
If you separately opt in and confirm your choice by email, ShiftPriority may send optional onboarding and product-help emails. Seven days after onboarding, we use only existing workspace records to determine whether the workspace has had a genuine product experience—for example, whether an employee or shift was created, a POS connection was activated, or tip/revenue data was stored. We do not add page-view, clickstream or generic last-active tracking for this purpose. If there is no such activity and there is no real paid or trialing Stripe subscription, we may send one personal inactivity email. Legal basis: your consent under Art. 6(1)(a) GDPR.
If an owner has had a genuine product experience and at least seven days have passed since onboarding, we may display a neutral in-app prompt asking for an honest Trustpilot review. Eligibility uses the same limited existing workspace records described above; it does not depend on whether feedback is expected to be positive or critical. We store when the prompt was shown, snoozed or completed. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in obtaining fair product feedback.
ShiftPriority does not send Trustpilot your name, email address, preferred language, workspace data or eligibility signal. Only if you choose Review ShiftPriority does your browser open Trustpilot's public review page. Trustpilot then processes your visit and any review under its own privacy policy. Optional ShiftPriority emails remain consent-based and contain an unsubscribe link.
3. Third-party processors
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, edge functions | EU (Frankfurt, DE) |
| Stripe, Inc. | Payment processing | US (SCC — Art. 46 GDPR) |
| Resend, Inc. | Transactional email | US (SCC — Art. 46 GDPR) |
| Anthropic, PBC | AI roster/schedule import — only when you use AI Import | US (SCC — Art. 46 GDPR) |
| Cloudflare, Inc. | Hosting, CDN, DNS | EU + US (SCC — Art. 46 GDPR) |
| Plausible Analytics | Cookieless website statistics (marketing site) | EU-hosted |
| Google Ireland Limited | Website and app analytics — only with your consent | EU + US (SCC — Art. 46 GDPR) |
| Functional Software, Inc. (Sentry) | Crash & performance diagnostics — only with your consent | US (SCC — Art. 46 GDPR) |
| POS providers (Square, SumUp, Lightspeed, ready2order) | Sales & tip sync — only if you connect a POS | EU / US per provider |
All transfers outside the EU are covered by Standard Contractual Clauses (SCC) under Art. 46 GDPR.
4. Retention
- Account and workspace data — until account deletion.
- Billing records — 10 years (§ 147 AO, German tax law).
- Server logs — 30 days, then automatically purged.
- Google Analytics user and event data — 2 months; consent and Analytics cookies — up to 180 days.
- Email-consent evidence, lifecycle classification, suppression and in-app review-prompt state, and delivery identifiers — while the workspace exists; deleted when the workspace is deleted.
5. Your rights (Art. 15–22 GDPR)
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — delete your account and all associated data.
- Portability — export your data in machine-readable format.
- Restriction — limit processing of your data.
- Objection — object to processing based on legitimate interest.
To exercise any right, email [email protected]. We respond within 30 days. You may also lodge a complaint with the German federal supervisory authority: Bundesbeauftragte für den Datenschutz (BfDI).
6. Security
All data is encrypted in transit (TLS 1.3) and at rest. Access is controlled through row-level security and JWT-based authentication. We conduct regular security reviews.
7. Changes
Material changes will be communicated by email or in-app notice at least 14 days before taking effect.