1. Data Controller
Emirhan Şahin, who operates Shiftrio ("we", "our", "us"), is the data controller for personal data processed through the Shiftrio mobile application (formerly Shifter). This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding your personal data.
Contact: support@shiftrio.com
2. Data We Collect
2.1 Account Data
- Full name
- Email address (used for login via Firebase Authentication, including Google Sign-In)
- Profile photo (optional; stored in Firebase Storage)
2.2 Business & Operational Data
- Restaurant and branch names and information you enter
- Your role (admin or employee) within a branch
- Department membership
- Shift schedules assigned to or created by you
- Leave requests you submit or manage
- Shift swap requests you submit or manage
- Availability you declare
2.3 Device & Notification Data
- Firebase Cloud Messaging (FCM) device token — used exclusively to send you push notifications
- Device platform (iOS/Android) and app version — standard metadata for compatibility
2.4 Subscription Data
- Subscription plan and status (active, expired, trial)
- Anonymous purchase transaction IDs from Apple App Store or Google Play
- This data is processed by RevenueCat, Inc. on our behalf. We never store payment card details.
2.5 Data We Do Not Collect
- Payment card numbers or banking information
- Precise GPS location
- Contacts, microphone, or camera data (camera is used only to let you choose a profile photo; no image is captured without your action)
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the Shiftrio service (shift scheduling, team management, requests) | Art. 6(1)(b) — performance of a contract |
| Sending push notifications about schedule updates and request decisions | Art. 6(1)(b) — contract; Art. 6(1)(a) — consent (notification permission) |
| Managing your subscription plan and enforcing team-size limits | Art. 6(1)(b) — performance of a contract |
| Improving and securing the application | Art. 6(1)(f) — legitimate interest |
| Complying with legal obligations | Art. 6(1)(c) — legal obligation |
4. Third-Party Services
We use the following third-party services to operate Shiftrio:
| Service | Provider | Purpose |
|---|---|---|
| Firebase Authentication | Google LLC | User login and identity management |
| Cloud Firestore | Google LLC | Storage of operational data (shifts, requests, team data) |
| Firebase Storage | Google LLC | Profile photo storage |
| Firebase Cloud Functions | Google LLC | Server-side business logic (invite redemption, notifications) |
| Firebase Cloud Messaging | Google LLC | Push notification delivery |
| RevenueCat | RevenueCat, Inc. | Subscription and in-app purchase management |
| Apple App Store | Apple Inc. | iOS app distribution and in-app purchases |
| Google Play | Google LLC | Android app distribution and in-app purchases |
All Firebase services process data on Google Cloud infrastructure under Google's data processing terms. RevenueCat processes purchase data under its own privacy policy. We recommend reviewing the privacy policies of each third-party service.
5. Data Sharing
We do not sell, rent, or trade your personal data. We share data only in the following circumstances:
- Within your team: Your name, profile photo, role, and shift data are visible to admins and other members of the same branch. This is necessary to provide the scheduling service.
- Service providers: We share data with the third parties listed in Section 4 strictly to the extent needed to operate the service.
- Legal requirements: We may disclose data if required by law or to protect our legal rights.
6. Data Retention & Deletion
We retain your personal data for as long as your account is active. You can delete your account at any time from Settings → Account → Delete Account.
Upon account deletion:
- Your personal data (name, email, profile photo) is permanently and irreversibly deleted.
- FCM device tokens associated with your account are removed.
- Operational records (e.g., historical shift records) where your identity has been removed may be retained for up to 30 days before permanent deletion from all backups.
If you are the owner of a restaurant, account deletion is blocked until ownership is transferred or the restaurant is deleted, in order to prevent disruption to your team.
7. Your Rights (GDPR — EU/EEA users)
If you are located in the EU or EEA, you have the following rights under the GDPR:
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to restriction — request that we limit processing of your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to lodge a complaint — contact your national data protection authority (e.g., Türkiye Kişisel Verileri Koruma Kurumu, or the supervisory authority in your country)
To exercise any of these rights, contact us at support@shiftrio.com. We will respond within 30 days.
8. Your Rights (KVKK — Turkish users)
6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamında Türkiye'deki kullanıcılarımız aşağıdaki haklara sahiptir:
- Kişisel verilerinizin işlenip işlenmediğini öğrenme
- Kişisel verileriniz işlenmişse buna ilişkin bilgi talep etme
- Kişisel verilerinizin işlenme amacını ve bunların amacına uygun kullanılıp kullanılmadığını öğrenme
- Yurt içinde veya yurt dışında kişisel verilerinizin aktarıldığı üçüncü kişileri bilme
- Kişisel verilerinizin eksik veya yanlış işlenmiş olması hâlinde bunların düzeltilmesini isteme
- KVKK'nın 7. maddesi çerçevesinde kişisel verilerinizin silinmesini veya yok edilmesini isteme
- Düzeltme ve silme işlemlerinin kişisel verilerin aktarıldığı üçüncü kişilere bildirilmesini isteme
- İşlenen verilerin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme
- Kişisel verilerinizin kanuna aykırı olarak işlenmesi sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme
Bu haklarınızı kullanmak için support@shiftrio.com adresine yazılı başvuru yapabilirsiniz.
9. Data Security
- All data in transit is encrypted via TLS/HTTPS.
- Data at rest is encrypted by Firebase (Google Cloud AES-256).
- Access to data is controlled by Firebase Security Rules — users can only access data they are authorized for.
- Authentication is required for all data operations.
- We regularly review access controls and security configurations.
10. Children's Privacy
Shiftrio is a business operations tool intended for adults working in the restaurant industry. We do not knowingly collect personal data from children under the age of 16. If we become aware that a child has provided us with personal data, we will delete it immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through the app or by email at least 7 days before the changes take effect. Continued use of Shiftrio after the effective date constitutes acceptance of the updated policy.
12. Contact
For any privacy-related questions, requests to exercise your rights, or to report a concern:
Emirhan Şahin (Shiftrio)
Email: support@shiftrio.com