Legal · Data Protection

Privacy Policy

Last updated: 15 June 2026 · Version 2.0 — supersedes all prior versions.

How ShiftBuzz collects, uses, stores and protects personal data across our workforce-scheduling platform — written in plain language and aligned with the EU General Data Protection Regulation (GDPR).

Data controller

H Roark Holding

Reg. 14180796 · VAT EE102021330

Registered office

Pikk tn 7-17, 10123 Tallinn, Estonia

Privacy contact

[email protected]

Scope

ShiftBuzz web app, iOS & Android apps, and the shiftbuzz.io website.

1. Who we are

ShiftBuzz is a workforce-scheduling platform for shift-based businesses — cafés, restaurants, bars, hotels, retail and multi-location operators. It is currently offered as an early-access pilot. The platform is owned and operated by H Roark Holding, a company registered in Estonia, which is the data controller responsible for the personal data described in this policy except where we act as a processor (see Section 12).

In this policy, "ShiftBuzz", "we", "us" and "our" refer to H Roark Holding. "You" refers to the individual whose personal data we process — whether you are an account holder, a member of staff added by a business customer, a website visitor, or someone who contacts us. We have not appointed a statutory Data Protection Officer, as we are not required to; all data-protection enquiries are handled at [email protected].

2. Information we collect

We collect only what we need to run the scheduling service and improve it. Most data is provided directly by you or by the business that employs you; some is generated automatically as you use the product.

Category Examples Source
Account & identity Name, email address, role, optional phone number, profile photo, the company you belong to, authentication identifiers. You, or your employer when inviting you
Workforce & employment Position, location assignments, skills, certifications, training, performance reviews and work history. You or your employer
Scheduling & operations Shifts assigned, claimed, swapped or declined; availability and preferences; open-shift activity; coverage records. You and your managers
Device & technical Mobile push token (when you opt in), device type, operating system, app version, IP address, approximate region. Automatic
Usage & product analytics Features used, pages and screens viewed, in-app events, session activity and diagnostic/error data. Automatic (see Section 5)
Communications Messages to support, demo and contact-form submissions, newsletter sign-ups, notification settings. You
Billing Plan, billing contact and transaction records for paid subscriptions. Card details are handled by our payment provider, not stored by us. You / payment provider

Where staff data comes from (GDPR Art. 14)

If a business adds you to ShiftBuzz, we receive your details from your employer rather than directly from you. Your employer is the controller for that data; this notice and Section 12 explain your rights and who to approach.

Special category data. ShiftBuzz is not designed to collect special category data (such as health, religion or trade-union membership). Please do not enter such data into free-text fields. Where a certification or availability note might imply sensitive information, businesses are responsible for ensuring they have a lawful basis under GDPR Article 9 before entering it.

3. How we use information

We use personal data for the following purposes, and no others without telling you first:

  • Deliver the service — create and manage accounts, build and publish schedules, run shift swaps and the open-shift marketplace, and keep teams in sync.
  • Notify your team — send push notifications and emails about shifts, swaps, approvals and team activity.
  • Support & account recovery — respond to requests, reset passwords and help recover accounts.
  • Improve the product — understand how features are used (in aggregate where possible), fix bugs and improve reliability.
  • Billing & administration — manage subscriptions, invoicing and our legitimate business records.
  • Security & legal — protect the platform against abuse, and meet legal and regulatory obligations.
  • Marketing — send our newsletter and product updates where you have asked to receive them (see Section 6).

What we never do. We do not sell or rent personal data, we do not share it with third parties for their own advertising, and we do not use staff scheduling data for any purpose beyond running the service for the employer who controls it.

4. Legal bases for processing

Under GDPR Article 6, we rely on one of the following legal bases for each purpose:

Purpose Legal basis (Art. 6)
Providing the service to account holdersContract
Processing staff data on behalf of a businessContract / Processor — on the customer's documented instructions (Section 12)
Notifications about shifts & swapsContract
Product improvement & non-essential analyticsLegitimate interest / Consent (consent where required for cookies/trackers — Section 5)
Security, fraud prevention & error monitoringLegitimate interest
Marketing emails / newsletterConsent — opt-in; withdraw any time (Section 6)
Billing, accounting & tax recordsLegal obligation / Contract
Responding to legal requestsLegal obligation

About legitimate interests. Where we rely on legitimate interests, we have weighed our interest in running and improving a reliable service against your rights and freedoms, and limited the data used accordingly. You can object at any time (Section 11), and we will stop unless we have compelling legitimate grounds.

5. Cookies and analytics

Our website and app use a small number of cookies and similar technologies. Strictly necessary cookies (for sign-in, security and core functionality) are always on. Non-essential analytics run only after you consent via our cookie banner, and you can change your choice at any time using the link in our footer.

Provider Purpose Basis
Google Analytics 4Aggregate website traffic and usage trends.Consent
PostHogProduct analytics — feature usage and funnels to improve the app.Consent
Microsoft ClarityAggregated heatmaps and session replay (inputs masked) to study usability.Consent
SentryError and crash diagnostics to keep the product stable.Legitimate interest (essential diagnostics)

You can accept or reject non-essential cookies in the banner, change your choice via "Cookie settings", and control cookies in your browser. Microsoft Clarity session replay is configured to mask text inputs so that what you type is not captured. Sentry is kept to the minimum needed to identify and fix faults.

6. Marketing communications

We send two kinds of messages. Service messages (shift notifications, security alerts, billing and essential account notices) are part of the service and are not marketing. Marketing messages — such as our scheduling newsletter and product updates — are sent only where you have opted in.

  • You can unsubscribe from marketing at any time using the link in every marketing email, or by emailing [email protected].
  • Unsubscribing from marketing does not stop essential service messages, which are needed to operate your account.
  • We do not share your contact details with third parties for their own marketing.

7. Sharing information

We share personal data only with the service providers ("sub-processors") that help us run ShiftBuzz, and only as needed. Each is bound by a contract requiring appropriate security and confidentiality.

Provider Role Data involved
DigitalOceanCloud hosting, database and storageAll service data (encrypted)
ClerkAuthentication & account securityIdentity & login data
ResendTransactional & notification emailEmail address, message content
Apple APNs / Google FCMMobile push notificationsDevice push token, notification text
Google Analytics 4 · PostHog · Microsoft ClarityAnalytics (with consent)Usage & device data
SentryError monitoringDiagnostic & technical data
Payment providerSubscription billingBilling contact & transaction data

We may also share data within your own organisation (managers and colleagues see relevant scheduling information), to comply with the law or protect rights and safety, and in a business transfer (merger, acquisition or reorganisation), in which case we will notify you and this policy will continue to apply. A current list of sub-processors is available on request.

8. International transfers

We aim to host and process personal data within the European Economic Area (EEA). Some of our providers are based in, or transfer data to, countries outside the EEA — primarily the United States. Where data leaves the EEA, we ensure an appropriate safeguard is in place under GDPR Chapter V, such as:

  • the European Commission's Standard Contractual Clauses (SCCs), with supplementary measures where needed; or
  • transfers to providers certified under the EU–US Data Privacy Framework, where applicable; or
  • an adequacy decision covering the destination country.

You can request information about the specific safeguards applied to a given provider, and a copy of the relevant clauses, by emailing [email protected].

9. Data retention

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it.

Data Retention
Account & workforce dataFor the life of the account. Deleted or anonymised after account closure.
Scheduling recordsRetained while the workspace is active; removed on the customer's instruction or account deletion.
Analytics dataRetained for a limited period per provider settings (for example, GA4 user-level data up to 14 months).
Diagnostic / error logsShort-term, typically up to 90 days.
Billing & accounting recordsKept as long as required by applicable tax and accounting law.
Marketing contactsUntil you unsubscribe, then suppressed to honour your choice.

Where ShiftBuzz acts as a processor, retention of staff data follows the customer's instructions and their own retention obligations (Section 12).

10. Security

We take a defence-in-depth approach to protecting personal data:

  • Encryption in transit (TLS 1.2+) and at rest on hardened cloud infrastructure.
  • Access controls — least-privilege access, role-based permissions and managed authentication via Clerk.
  • Resilience — monitored, regularly updated cloud infrastructure.
  • Monitoring — automated error and anomaly detection to detect and respond to issues.

In the event of a breach. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it — and inform affected individuals where the law requires. Where we act as a processor, we will notify the relevant customer-controller without undue delay. No system can be guaranteed perfectly secure, but we work continuously to protect your data and improve our safeguards.

11. Your rights

Subject to conditions in the GDPR, you have the following rights over your personal data:

Right What it means
Access (Art. 15)Get a copy of the personal data we hold about you.
Rectification (Art. 16)Correct inaccurate or incomplete data.
Erasure (Art. 17)Ask us to delete your data where there is no overriding reason to keep it.
Restriction (Art. 18)Limit how we use your data in certain circumstances.
Portability (Art. 20)Receive your data in a structured, machine-readable format.
Objection (Art. 21)Object to processing based on legitimate interests, or to direct marketing.
Withdraw consent (Art. 7)Withdraw consent at any time, without affecting prior processing.
Automated decisions (Art. 22)Not be subject to a solely automated decision with legal or similarly significant effects — ShiftBuzz makes none.

How to exercise your rights. You can view and edit much of your data directly in the app, including in-app account deletion. For anything else, email [email protected]. We respond within one month (extendable by two months for complex requests, with notice) and free of charge in normal cases. We may need to verify your identity first. If your data was added by an employer and we act as processor, please contact that employer first; we will support them in responding (Section 12). You also have the right to lodge a complaint with a supervisory authority (Section 15).

12. Data processor relationship

Because businesses upload information about their staff, it matters who is the controller and who is the processor for a given piece of data.

When ShiftBuzz is the controller. We decide the purpose and means of processing — so we are the controller — for: our own account holders' sign-up details, website visitors, marketing contacts, billing, product analytics and improvement, and platform security. This policy governs that processing.

When ShiftBuzz is the processor. When a business customer uploads and manages its employees' data to run schedules, that business is the controller and ShiftBuzz is the processor. We process that staff data only on the customer's documented instructions, under a Data Processing Agreement (DPA), and not for our own purposes.

As controllers of their staff data, business customers are responsible for:

  • having a lawful basis to add and process their employees' data;
  • informing their staff about the use of ShiftBuzz and providing their own privacy notice;
  • responding to their employees' data-subject requests as the controller (with our support as processor);
  • ensuring data entered is accurate and that no special category data is added without an appropriate Article 9 basis;
  • configuring access and roles appropriately for their team.

A Data Processing Agreement is available to business customers on request at [email protected].

13. Children's privacy

ShiftBuzz is a workplace tool intended for users aged 16 and over. We do not knowingly collect personal data directly from anyone under 16. Where local law permits the lawful employment of young workers, the employing business is responsible for ensuring it has the appropriate consent and legal basis before adding a young person to the platform. If you believe a person under 16 has provided us personal data without the proper basis, contact [email protected] and we will take appropriate steps to delete it.

14. Changes to this policy

We may update this policy as the product, the law or our practices evolve. When we do, we will revise the "Last updated" date and version above and publish the new version at shiftbuzz.io/privacy. For material changes, we will give clear advance notice — for example by email to active customers or an in-app notice — before the changes take effect. Continued use of ShiftBuzz after a change takes effect means you accept the updated policy.

15. Contact information

For any privacy question, or to exercise your rights, contact us:

Data controller

H Roark Holding

Pikk tn 7-17, 10123 Tallinn, Estonia

Supervisory authority. If you are not satisfied with how we handle your data, you have the right to lodge a complaint with a data protection supervisory authority — in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, www.aki.ee, [email protected]), or the authority in your country of residence or work. We would, of course, appreciate the chance to address your concern first.

ShiftBuzz Privacy Policy · Version 2.0 · Last updated 15 June 2026. © 2026 H Roark Holding (Reg. 14180796, VAT EE102021330), Pikk tn 7-17, 10123 Tallinn, Estonia. This document supersedes all prior versions.

Request a demo