1. Who we are
ShiftInOut ('we', 'us', 'our') provides mobile attendance tracking and an admin dashboard for teams that work on-site. This policy explains what personal data we collect, why we collect it, and the choices you have.
Last updated: 11 August 2026
How ShiftInOut handles personal data for employees, managers, and account admins — written in plain language.
ShiftInOut ('we', 'us', 'our') provides mobile attendance tracking and an admin dashboard for teams that work on-site. This policy explains what personal data we collect, why we collect it, and the choices you have.
Account details (name, email, phone, company role), attendance events (clock-in/out times, status), location data when you check in (GPS coordinates used for geofence validation), optional selfie photos for identity verification, device and log data needed to run the app securely, and support messages you send us.
We use this data to operate ShiftInOut: authenticate users, record and display attendance, validate geofences, sync offline check-ins, send transactional notifications (reminders, leave approvals), generate reports for your organization, and improve reliability and security. We do not sell personal data.
GPS is captured only in connection with check-in/out or related attendance features your organization enables. Optional selfie capture is used for verification and stored according to your company's retention settings. These features can be configured by your admin; contact them if you have workplace-specific questions.
Within your organization, admins and authorized managers can see attendance and related records needed to run payroll and operations. We use infrastructure providers such as Firebase (Google) for authentication, database, storage, and hosting. Payment processors (if billing is enabled) receive only what is required to charge your organization — not employee attendance histories.
We use necessary cookies and similar storage for signed-in sessions on the dashboard and website. We may use basic analytics to understand how the marketing site is used. Disabling essential session storage will prevent sign-in.
We keep account and attendance records for as long as your organization maintains an active ShiftInOut workspace, or as required for legal, tax, or fraud-prevention purposes. Admins may request export or deletion of organization data subject to those obligations.
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to certain processing. Employees should usually start with their employer/admin. See our delete account page for the exact steps, or email privacy@shiftinout.com and we will respond within 30 days.
We use industry-standard safeguards including HTTPS, access controls, and encrypted storage with our cloud providers. No system is perfectly secure. Report suspected vulnerabilities to security@shiftinout.com.
ShiftInOut is built for workplace attendance and is not directed at children under 16. We do not knowingly collect personal information from children.
We may update this policy from time to time. When we do, we will revise the 'Last updated' date below and, for material changes, notify account admins by email when practical.
Questions about privacy? Email privacy@shiftinout.com or use our contact page. For product setup questions, your organization admin is usually the fastest path.