Privacy policy
1. Controller
The controller responsible for processing personal data is Imad Sookoor, Shiftheld, Donaustr. 44, 12043 Berlin, Germany. You can contact us at info@shiftheld.de or by phone at +49 15563 752871.
2. Data we process
Depending on how you use Shiftheld, we process contact details such as your name, email address and phone number; account and session information; details about your business; and staff, shift, absence, availability and communication data that you enter. This may include names, phone numbers, roles, shift times, and the status and time of requests or replies. Please do not enter information about reasons for illness or other special-category data unless it is necessary for your use of the service. When you visit the website, technical access data such as your IP address, the time of access and the page requested may also be processed.
3. Waitlist and contact requests
When you join the waitlist, we process your email address, selected language and, where applicable, a source or campaign identifier so that we can manage your request and tell you when access to Shiftheld is available. We process this information to handle your request and take steps at your request before entering into a contract (Art. 6(1)(b) GDPR). Where that basis does not apply, we rely on our legitimate interest in responding to a request you have made (Art. 6(1)(f) GDPR). If you contact us directly, we process your message and contact details only to handle and reply to your enquiry.
4. Use of the Shiftheld service
When you register, we process details including your name, email address and business information to create your account and provide the software. Within the service, business owners or authorised users can manage staff and shift data and organise notifications and replies. We use this information to provide the agreed features, operate and secure the service, and provide support. The legal basis is generally Art. 6(1)(b) GDPR. Where we process data to prevent misuse, diagnose errors or protect the service, we rely on our legitimate interest in secure and reliable operation (Art. 6(1)(f) GDPR). A business that enters data about its own staff remains responsible for the lawfulness of that data and for informing the people concerned.
5. Recipients and service providers
We use technical service providers to provide the service. Supabase supports authentication and storage of application data. Resend may be used to send emails. If a business uses the WhatsApp integration, data required for the relevant message, such as a phone number and message content, is sent to Meta through the WhatsApp Cloud API. These providers process data only as needed to provide their respective services. We disclose data to other parties only where necessary to perform a contract, required by law or authorised by you.
6. Cookies and session data
We use technically necessary session cookies to support sign-in and the secure operation of the protected area. They are not used to build advertising profiles or deliver personalised advertising. Based on the current implementation, we do not use analytics or advertising cookies on the website.
7. Retention
We keep waitlist and contact data only for as long as needed to handle your request. Account and business data stored in the service is processed for the duration of the customer relationship and then deleted unless statutory retention duties or the need to establish, exercise or defend legal claims require otherwise. Technical log data is kept only as long as needed for security, troubleshooting and reliable operation.
8. Your rights
Subject to the legal requirements, you have the right to access your personal data, have it corrected or erased, restrict its processing, and receive it in a portable format. Where processing is based on legitimate interests, you may object for reasons relating to your particular situation. You may withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority. If data is processed on behalf of a business, please first contact that business about your rights; we will assist it in handling your request.
9. Security and updates
We use appropriate technical and organisational measures to protect personal data against loss, unauthorised access and disclosure. We update this privacy policy when our processing or legal requirements change. The version published on this website is the current version.
10. Privacy contact
For questions about our processing of personal data or to exercise your rights, contact info@shiftheld.de or write to the address in the Impressum.
