ShiftInOut
Legal

Privacy Policy

Last updated: 11 August 2026

How ShiftInOut handles personal data for employees, managers, and account admins — written in plain language.

1. Who we are

ShiftInOut ('we', 'us', 'our') provides mobile attendance tracking and an admin dashboard for teams that work on-site. This policy explains what personal data we collect, why we collect it, and the choices you have.

2. Information we collect

Account details (name, email, phone, company role), attendance events (clock-in/out times, status), location data when you check in (GPS coordinates used for geofence validation), optional selfie photos for identity verification, device and log data needed to run the app securely, and support messages you send us.

3. How we use your information

We use this data to operate ShiftInOut: authenticate users, record and display attendance, validate geofences, sync offline check-ins, send transactional notifications (reminders, leave approvals), generate reports for your organization, and improve reliability and security. We do not sell personal data.

4. Location and biometric-style data

GPS is captured only in connection with check-in/out or related attendance features your organization enables. Optional selfie capture is used for verification and stored according to your company's retention settings. These features can be configured by your admin; contact them if you have workplace-specific questions.

5. Who we share data with

Within your organization, admins and authorized managers can see attendance and related records needed to run payroll and operations. We use infrastructure providers such as Firebase (Google) for authentication, database, storage, and hosting. Payment processors (if billing is enabled) receive only what is required to charge your organization — not employee attendance histories.

6. Cookies and similar tech

We use necessary cookies and similar storage for signed-in sessions on the dashboard and website. We may use basic analytics to understand how the marketing site is used. Disabling essential session storage will prevent sign-in.

7. Data retention

We keep account and attendance records for as long as your organization maintains an active ShiftInOut workspace, or as required for legal, tax, or fraud-prevention purposes. Admins may request export or deletion of organization data subject to those obligations.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to certain processing. Employees should usually start with their employer/admin. See our delete account page for the exact steps, or email privacy@shiftinout.com and we will respond within 30 days.

9. Security

We use industry-standard safeguards including HTTPS, access controls, and encrypted storage with our cloud providers. No system is perfectly secure. Report suspected vulnerabilities to security@shiftinout.com.

10. Children

ShiftInOut is built for workplace attendance and is not directed at children under 16. We do not knowingly collect personal information from children.

11. Changes

We may update this policy from time to time. When we do, we will revise the 'Last updated' date below and, for material changes, notify account admins by email when practical.

12. Contact

Questions about privacy? Email privacy@shiftinout.com or use our contact page. For product setup questions, your organization admin is usually the fastest path.

© 2026 ShiftInOut. See also our about and contact pages.