Privacy Policy
Last updated: August 28, 2026
ShiftPay is a shift calendar and paycheck estimator for hourly workers. It knows where you work, when you work, and what you are paid — which is exactly why it was built to keep that information private. This policy explains what stays on the device, what can leave it when you enable an optional service, and how to erase your records.
Your ShiftPay records
All of the following is written to ShiftPay's private, app-sandboxed database on your device and is never transmitted to the developer:
- Employers and job details, wage rates, differentials, and overtime rule settings.
- Shifts, shift templates, rotations, breaks, notes, and time off.
- Tips, earnings history, and pay-period calculations.
- Pay stubs you enter and the saved comparisons made from them.
- App preferences, including your analytics choice and the free-tier import counter.
We have no ability to read this data and no way to restore it for you. If iCloud Backup is enabled on your device, Apple's device backup may include the app's local data under Apple's own terms.
Optional private iCloud sync
Pro users can enable Settings → Sync with iCloud. When enabled, ShiftPay uses Apple's private CloudKit database to keep the records listed above current across devices signed in to the same Apple Account. The developer cannot browse this private database. Apple processes and retains the synced copy under its iCloud terms and privacy policy.
Turning sync off stops this device from syncing and keeps a local working copy; it does not immediately erase the existing CloudKit copy. To delete synced ShiftPay records, leave sync enabled and use Delete all data so the deletions propagate through CloudKit. You can also manage app data through your Apple Account's iCloud settings.
Importing a schedule photo
When you import a posted schedule, ShiftPay reads the picture using Apple's Vision framework on the device itself. The image is not uploaded anywhere, and no third-party OCR service is involved. Once you confirm which shifts to keep, the source image is discarded — only the shifts you confirmed remain. Recognised text, employer names, wage values, and pay-stub values are never written to logs.
The app asks for photo access only when you choose to import, and only for the picture you pick.
Calendar access and exports
ShiftPay requests full Calendar access only after you enter Calendar export or Calendar overlay and choose to allow it. Export uses access to add your upcoming shifts and to find, update, or remove events ShiftPay previously created. Overlay reads events only from the calendars you select and displays them beside your shifts. Calendar data is processed on the device and is never sent to ShiftPay, Firebase, or RevenueCat. Exported events contain job, role, time, location, and notes, but never wage rates, tips, or calculated pay. Your calendar provider may sync those events under its own terms.
Optional analytics and crash reports
ShiftPay ships with Firebase Analytics and Firebase Crashlytics, and both stay switched off until you enable them in Settings → Share anonymous usage data. One toggle governs both, your choice persists across launches, and you can turn it back off at any time.
| If you opt in | What is sent |
|---|---|
| Product interaction events | Coarse funnel event names — for example that an import was completed, an export was created, or a purchase attempt succeeded — with no app-supplied parameters. Firebase also receives standard app and device context such as app version, OS version, language, time zone, and an analytics app-instance identifier (disclosed as Device ID in Apple's privacy label). ShiftPay disables Firebase's IDFA and IDFV collection, ad-personalization signals, and automatic screen reporting. Events never include wage rates, employer names, schedules, recognised text, pay-stub values, or precise location, and are not linked to a ShiftPay account because none exists. |
| Crash diagnostics | Crash and hang reports, stack traces, device/OS information, and redacted non-fatal reasons used to fix defects. Same consent, same opt-out. |
If you never opt in, ShiftPay does not enable Analytics or Crashlytics event collection. Firebase's transport libraries may still send minimal, non-linked SDK health metadata such as dropped-event counts so Google can maintain the SDK itself. ShiftPay does not use Firebase Remote Config, advertising products, session replay, or user-ID features.
Purchases
ShiftPay Pro is sold by Apple through the App Store. Payment is handled entirely by Apple with StoreKit — we never receive or see your name, card number, billing address, or Apple Account details. Where the app is configured to use RevenueCat, an anonymous RevenueCat app-user identifier, an IDFV-derived device identifier, and your App Store purchase history are sent to RevenueCat to validate the purchase, prevent fraud, provide aggregate purchase analytics, and determine whether Pro is active. This does not contain your schedule, pay, employer, or name. If RevenueCat is not configured, the app validates entitlements directly with StoreKit on the device.
What we never do
- No sale or sharing of personal information — there is nothing collected to sell, and we do not share data with data brokers.
- No tracking. ShiftPay does not use the advertising identifier, does not ask for App Tracking Transparency permission, and does not link activity to you across other companies' apps or websites. Its privacy manifest declares tracking as false.
- No advertising SDKs and no ads.
- No profiling or automated decision-making about you.
Retention and deleting your data
- Local records are kept until you delete them. If private iCloud sync is enabled, Apple also retains a CloudKit copy under your iCloud account.
- Delete all data: open Settings in ShiftPay and tap Delete all data. It erases every employer, shift, rotation, template, pay stub, and comparison on the device. When sync is active, those deletions also propagate to the private CloudKit database.
- Deleting the app removes its container and everything in it.
- Opting out of analytics stops future Analytics and Crashlytics collection. Previously submitted records are retained and deleted according to the Firebase retention settings and Google's policies. Because ShiftPay has no account and does not attach your identity, we may not be able to locate an anonymous installation's individual records.
- Purchase records held by Apple and RevenueCat are governed by their own retention policies, because they are financial records rather than app content.
Your rights
Depending on where you live — including under the GDPR/UK GDPR and U.S. state privacy laws such as the CCPA/CPRA — you may have the right to access, correct, delete, or port your personal information, and to opt out of sale or sharing. In ShiftPay most of these are immediate and self-service, because the data lives on your device or in your private iCloud database and you can view, edit, and erase it yourself; there is nothing to sell or share for advertising, so no sale/sharing opt-out is needed. For anything else, email us at the address below and we will respond within the period the applicable law requires.
Where consent is the legal basis (analytics and crash reporting), you may withdraw it at any time with the same toggle you used to grant it.
Service providers
- Apple — App Store distribution and purchases; optional private CloudKit sync and iCloud backup; on-device frameworks such as Vision and notifications.
- Google Firebase — opt-in Analytics and Crashlytics, plus minimal SDK transport diagnostics described above.
- RevenueCat — receipt validation and subscription status, when configured.
These providers may process data outside your country. We use no other processors, and there is no developer-operated ShiftPay backend for your schedule or pay data to reach.
Children
ShiftPay is intended for working adults and is not directed at children under 13. We do not knowingly collect information from them.
Changes
If this policy changes, the updated version will be posted at this address with a new "last updated" date. If a change would ever expand what leaves your device, we will ask for your consent in the app before it takes effect.
Contact
Privacy questions and data requests: nvkhoe89@gmail.com. See also the Terms of Use and Support.