← ShiftPay

Privacy Policy

Last updated: August 28, 2026

ShiftPay is a shift calendar and paycheck estimator for hourly workers. It knows where you work, when you work, and what you are paid — which is exactly why it was built to keep that information private. This policy explains what stays on the device, what can leave it when you enable an optional service, and how to erase your records.

The short version. There is no ShiftPay account and no developer-operated server for your work records. Your employers, shifts, wage rates, tips, pay stubs, and comparisons stay in the app's private database unless you explicitly enable private iCloud sync, in which case Apple stores a CloudKit copy in your private iCloud database. Schedule photos are read on-device and discarded after processing. Optional analytics and crash reporting are off unless you turn them on. We do not sell data, show ads, or track you across other apps or websites.

Your ShiftPay records

All of the following is written to ShiftPay's private, app-sandboxed database on your device and is never transmitted to the developer:

We have no ability to read this data and no way to restore it for you. If iCloud Backup is enabled on your device, Apple's device backup may include the app's local data under Apple's own terms.

Optional private iCloud sync

Pro users can enable Settings → Sync with iCloud. When enabled, ShiftPay uses Apple's private CloudKit database to keep the records listed above current across devices signed in to the same Apple Account. The developer cannot browse this private database. Apple processes and retains the synced copy under its iCloud terms and privacy policy.

Turning sync off stops this device from syncing and keeps a local working copy; it does not immediately erase the existing CloudKit copy. To delete synced ShiftPay records, leave sync enabled and use Delete all data so the deletions propagate through CloudKit. You can also manage app data through your Apple Account's iCloud settings.

Importing a schedule photo

When you import a posted schedule, ShiftPay reads the picture using Apple's Vision framework on the device itself. The image is not uploaded anywhere, and no third-party OCR service is involved. Once you confirm which shifts to keep, the source image is discarded — only the shifts you confirmed remain. Recognised text, employer names, wage values, and pay-stub values are never written to logs.

The app asks for photo access only when you choose to import, and only for the picture you pick.

Calendar access and exports

ShiftPay requests full Calendar access only after you enter Calendar export or Calendar overlay and choose to allow it. Export uses access to add your upcoming shifts and to find, update, or remove events ShiftPay previously created. Overlay reads events only from the calendars you select and displays them beside your shifts. Calendar data is processed on the device and is never sent to ShiftPay, Firebase, or RevenueCat. Exported events contain job, role, time, location, and notes, but never wage rates, tips, or calculated pay. Your calendar provider may sync those events under its own terms.

Optional analytics and crash reports

ShiftPay ships with Firebase Analytics and Firebase Crashlytics, and both stay switched off until you enable them in Settings → Share anonymous usage data. One toggle governs both, your choice persists across launches, and you can turn it back off at any time.

If you opt inWhat is sent
Product interaction events Coarse funnel event names — for example that an import was completed, an export was created, or a purchase attempt succeeded — with no app-supplied parameters. Firebase also receives standard app and device context such as app version, OS version, language, time zone, and an analytics app-instance identifier (disclosed as Device ID in Apple's privacy label). ShiftPay disables Firebase's IDFA and IDFV collection, ad-personalization signals, and automatic screen reporting. Events never include wage rates, employer names, schedules, recognised text, pay-stub values, or precise location, and are not linked to a ShiftPay account because none exists.
Crash diagnostics Crash and hang reports, stack traces, device/OS information, and redacted non-fatal reasons used to fix defects. Same consent, same opt-out.

If you never opt in, ShiftPay does not enable Analytics or Crashlytics event collection. Firebase's transport libraries may still send minimal, non-linked SDK health metadata such as dropped-event counts so Google can maintain the SDK itself. ShiftPay does not use Firebase Remote Config, advertising products, session replay, or user-ID features.

Purchases

ShiftPay Pro is sold by Apple through the App Store. Payment is handled entirely by Apple with StoreKit — we never receive or see your name, card number, billing address, or Apple Account details. Where the app is configured to use RevenueCat, an anonymous RevenueCat app-user identifier, an IDFV-derived device identifier, and your App Store purchase history are sent to RevenueCat to validate the purchase, prevent fraud, provide aggregate purchase analytics, and determine whether Pro is active. This does not contain your schedule, pay, employer, or name. If RevenueCat is not configured, the app validates entitlements directly with StoreKit on the device.

What we never do

Retention and deleting your data

Your rights

Depending on where you live — including under the GDPR/UK GDPR and U.S. state privacy laws such as the CCPA/CPRA — you may have the right to access, correct, delete, or port your personal information, and to opt out of sale or sharing. In ShiftPay most of these are immediate and self-service, because the data lives on your device or in your private iCloud database and you can view, edit, and erase it yourself; there is nothing to sell or share for advertising, so no sale/sharing opt-out is needed. For anything else, email us at the address below and we will respond within the period the applicable law requires.

Where consent is the legal basis (analytics and crash reporting), you may withdraw it at any time with the same toggle you used to grant it.

Service providers

These providers may process data outside your country. We use no other processors, and there is no developer-operated ShiftPay backend for your schedule or pay data to reach.

Children

ShiftPay is intended for working adults and is not directed at children under 13. We do not knowingly collect information from them.

Changes

If this policy changes, the updated version will be posted at this address with a new "last updated" date. If a change would ever expand what leaves your device, we will ask for your consent in the app before it takes effect.

Contact

Privacy questions and data requests: nvkhoe89@gmail.com. See also the Terms of Use and Support.