Privacy Policy
Last updated: 15 June 2026 · Version 2.0 — supersedes all prior versions.
How ShiftBuzz collects, uses, stores and protects personal data across our workforce-scheduling platform — written in plain language and aligned with the EU General Data Protection Regulation (GDPR).
Data controller
H Roark Holding
Reg. 14180796 · VAT EE102021330
Registered office
Pikk tn 7-17, 10123 Tallinn, Estonia
Privacy contact
[email protected]Scope
ShiftBuzz web app, iOS & Android apps, and the shiftbuzz.io website.
1. Who we are
ShiftBuzz is a workforce-scheduling platform for shift-based businesses — cafés, restaurants, bars, hotels, retail and multi-location operators. It is currently offered as an early-access pilot. The platform is owned and operated by H Roark Holding, a company registered in Estonia, which is the data controller responsible for the personal data described in this policy except where we act as a processor (see Section 12).
In this policy, "ShiftBuzz", "we", "us" and "our" refer to H Roark Holding. "You" refers to the individual whose personal data we process — whether you are an account holder, a member of staff added by a business customer, a website visitor, or someone who contacts us. We have not appointed a statutory Data Protection Officer, as we are not required to; all data-protection enquiries are handled at [email protected].
2. Information we collect
We collect only what we need to run the scheduling service and improve it. Most data is provided directly by you or by the business that employs you; some is generated automatically as you use the product.
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email address, role, optional phone number, profile photo, the company you belong to, authentication identifiers. | You, or your employer when inviting you |
| Workforce & employment | Position, location assignments, skills, certifications, training, performance reviews and work history. | You or your employer |
| Scheduling & operations | Shifts assigned, claimed, swapped or declined; availability and preferences; open-shift activity; coverage records. | You and your managers |
| Device & technical | Mobile push token (when you opt in), device type, operating system, app version, IP address, approximate region. | Automatic |
| Usage & product analytics | Features used, pages and screens viewed, in-app events, session activity and diagnostic/error data. | Automatic (see Section 5) |
| Communications | Messages to support, demo and contact-form submissions, newsletter sign-ups, notification settings. | You |
| Billing | Plan, billing contact and transaction records for paid subscriptions. Card details are handled by our payment provider, not stored by us. | You / payment provider |
Where staff data comes from (GDPR Art. 14)
If a business adds you to ShiftBuzz, we receive your details from your employer rather than directly from you. Your employer is the controller for that data; this notice and Section 12 explain your rights and who to approach.
Special category data. ShiftBuzz is not designed to collect special category data (such as health, religion or trade-union membership). Please do not enter such data into free-text fields. Where a certification or availability note might imply sensitive information, businesses are responsible for ensuring they have a lawful basis under GDPR Article 9 before entering it.
3. How we use information
We use personal data for the following purposes, and no others without telling you first:
- Deliver the service — create and manage accounts, build and publish schedules, run shift swaps and the open-shift marketplace, and keep teams in sync.
- Notify your team — send push notifications and emails about shifts, swaps, approvals and team activity.
- Support & account recovery — respond to requests, reset passwords and help recover accounts.
- Improve the product — understand how features are used (in aggregate where possible), fix bugs and improve reliability.
- Billing & administration — manage subscriptions, invoicing and our legitimate business records.
- Security & legal — protect the platform against abuse, and meet legal and regulatory obligations.
- Marketing — send our newsletter and product updates where you have asked to receive them (see Section 6).
What we never do. We do not sell or rent personal data, we do not share it with third parties for their own advertising, and we do not use staff scheduling data for any purpose beyond running the service for the employer who controls it.
4. Legal bases for processing
Under GDPR Article 6, we rely on one of the following legal bases for each purpose:
| Purpose | Legal basis (Art. 6) |
|---|---|
| Providing the service to account holders | Contract |
| Processing staff data on behalf of a business | Contract / Processor — on the customer's documented instructions (Section 12) |
| Notifications about shifts & swaps | Contract |
| Product improvement & non-essential analytics | Legitimate interest / Consent (consent where required for cookies/trackers — Section 5) |
| Security, fraud prevention & error monitoring | Legitimate interest |
| Marketing emails / newsletter | Consent — opt-in; withdraw any time (Section 6) |
| Billing, accounting & tax records | Legal obligation / Contract |
| Responding to legal requests | Legal obligation |
About legitimate interests. Where we rely on legitimate interests, we have weighed our interest in running and improving a reliable service against your rights and freedoms, and limited the data used accordingly. You can object at any time (Section 11), and we will stop unless we have compelling legitimate grounds.
5. Cookies and analytics
Our website and app use a small number of cookies and similar technologies. Strictly necessary cookies (for sign-in, security and core functionality) are always on. Non-essential analytics run only after you consent via our cookie banner, and you can change your choice at any time using the link in our footer.
| Provider | Purpose | Basis |
|---|---|---|
| Google Analytics 4 | Aggregate website traffic and usage trends. | Consent |
| PostHog | Product analytics — feature usage and funnels to improve the app. | Consent |
| Microsoft Clarity | Aggregated heatmaps and session replay (inputs masked) to study usability. | Consent |
| Sentry | Error and crash diagnostics to keep the product stable. | Legitimate interest (essential diagnostics) |
You can accept or reject non-essential cookies in the banner, change your choice via "Cookie settings", and control cookies in your browser. Microsoft Clarity session replay is configured to mask text inputs so that what you type is not captured. Sentry is kept to the minimum needed to identify and fix faults.
6. Marketing communications
We send two kinds of messages. Service messages (shift notifications, security alerts, billing and essential account notices) are part of the service and are not marketing. Marketing messages — such as our scheduling newsletter and product updates — are sent only where you have opted in.
- You can unsubscribe from marketing at any time using the link in every marketing email, or by emailing [email protected].
- Unsubscribing from marketing does not stop essential service messages, which are needed to operate your account.
- We do not share your contact details with third parties for their own marketing.
7. Sharing information
We share personal data only with the service providers ("sub-processors") that help us run ShiftBuzz, and only as needed. Each is bound by a contract requiring appropriate security and confidentiality.
| Provider | Role | Data involved |
|---|---|---|
| DigitalOcean | Cloud hosting, database and storage | All service data (encrypted) |
| Clerk | Authentication & account security | Identity & login data |
| Resend | Transactional & notification email | Email address, message content |
| Apple APNs / Google FCM | Mobile push notifications | Device push token, notification text |
| Google Analytics 4 · PostHog · Microsoft Clarity | Analytics (with consent) | Usage & device data |
| Sentry | Error monitoring | Diagnostic & technical data |
| Payment provider | Subscription billing | Billing contact & transaction data |
We may also share data within your own organisation (managers and colleagues see relevant scheduling information), to comply with the law or protect rights and safety, and in a business transfer (merger, acquisition or reorganisation), in which case we will notify you and this policy will continue to apply. A current list of sub-processors is available on request.
8. International transfers
We aim to host and process personal data within the European Economic Area (EEA). Some of our providers are based in, or transfer data to, countries outside the EEA — primarily the United States. Where data leaves the EEA, we ensure an appropriate safeguard is in place under GDPR Chapter V, such as:
- the European Commission's Standard Contractual Clauses (SCCs), with supplementary measures where needed; or
- transfers to providers certified under the EU–US Data Privacy Framework, where applicable; or
- an adequacy decision covering the destination country.
You can request information about the specific safeguards applied to a given provider, and a copy of the relevant clauses, by emailing [email protected].
9. Data retention
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it.
| Data | Retention |
|---|---|
| Account & workforce data | For the life of the account. Deleted or anonymised after account closure. |
| Scheduling records | Retained while the workspace is active; removed on the customer's instruction or account deletion. |
| Analytics data | Retained for a limited period per provider settings (for example, GA4 user-level data up to 14 months). |
| Diagnostic / error logs | Short-term, typically up to 90 days. |
| Billing & accounting records | Kept as long as required by applicable tax and accounting law. |
| Marketing contacts | Until you unsubscribe, then suppressed to honour your choice. |
Where ShiftBuzz acts as a processor, retention of staff data follows the customer's instructions and their own retention obligations (Section 12).
10. Security
We take a defence-in-depth approach to protecting personal data:
- Encryption in transit (TLS 1.2+) and at rest on hardened cloud infrastructure.
- Access controls — least-privilege access, role-based permissions and managed authentication via Clerk.
- Resilience — monitored, regularly updated cloud infrastructure.
- Monitoring — automated error and anomaly detection to detect and respond to issues.
In the event of a breach. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it — and inform affected individuals where the law requires. Where we act as a processor, we will notify the relevant customer-controller without undue delay. No system can be guaranteed perfectly secure, but we work continuously to protect your data and improve our safeguards.
11. Your rights
Subject to conditions in the GDPR, you have the following rights over your personal data:
| Right | What it means |
|---|---|
| Access (Art. 15) | Get a copy of the personal data we hold about you. |
| Rectification (Art. 16) | Correct inaccurate or incomplete data. |
| Erasure (Art. 17) | Ask us to delete your data where there is no overriding reason to keep it. |
| Restriction (Art. 18) | Limit how we use your data in certain circumstances. |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format. |
| Objection (Art. 21) | Object to processing based on legitimate interests, or to direct marketing. |
| Withdraw consent (Art. 7) | Withdraw consent at any time, without affecting prior processing. |
| Automated decisions (Art. 22) | Not be subject to a solely automated decision with legal or similarly significant effects — ShiftBuzz makes none. |
How to exercise your rights. You can view and edit much of your data directly in the app, including in-app account deletion. For anything else, email [email protected]. We respond within one month (extendable by two months for complex requests, with notice) and free of charge in normal cases. We may need to verify your identity first. If your data was added by an employer and we act as processor, please contact that employer first; we will support them in responding (Section 12). You also have the right to lodge a complaint with a supervisory authority (Section 15).
12. Data processor relationship
Because businesses upload information about their staff, it matters who is the controller and who is the processor for a given piece of data.
When ShiftBuzz is the controller. We decide the purpose and means of processing — so we are the controller — for: our own account holders' sign-up details, website visitors, marketing contacts, billing, product analytics and improvement, and platform security. This policy governs that processing.
When ShiftBuzz is the processor. When a business customer uploads and manages its employees' data to run schedules, that business is the controller and ShiftBuzz is the processor. We process that staff data only on the customer's documented instructions, under a Data Processing Agreement (DPA), and not for our own purposes.
As controllers of their staff data, business customers are responsible for:
- having a lawful basis to add and process their employees' data;
- informing their staff about the use of ShiftBuzz and providing their own privacy notice;
- responding to their employees' data-subject requests as the controller (with our support as processor);
- ensuring data entered is accurate and that no special category data is added without an appropriate Article 9 basis;
- configuring access and roles appropriately for their team.
A Data Processing Agreement is available to business customers on request at [email protected].
13. Children's privacy
ShiftBuzz is a workplace tool intended for users aged 16 and over. We do not knowingly collect personal data directly from anyone under 16. Where local law permits the lawful employment of young workers, the employing business is responsible for ensuring it has the appropriate consent and legal basis before adding a young person to the platform. If you believe a person under 16 has provided us personal data without the proper basis, contact [email protected] and we will take appropriate steps to delete it.
14. Changes to this policy
We may update this policy as the product, the law or our practices evolve. When we do, we will revise the "Last updated" date and version above and publish the new version at shiftbuzz.io/privacy. For material changes, we will give clear advance notice — for example by email to active customers or an in-app notice — before the changes take effect. Continued use of ShiftBuzz after a change takes effect means you accept the updated policy.
15. Contact information
For any privacy question, or to exercise your rights, contact us:
Data controller
H Roark Holding
Pikk tn 7-17, 10123 Tallinn, Estonia
Supervisory authority. If you are not satisfied with how we handle your data, you have the right to lodge a complaint with a data protection supervisory authority — in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, www.aki.ee, [email protected]), or the authority in your country of residence or work. We would, of course, appreciate the chance to address your concern first.
ShiftBuzz Privacy Policy · Version 2.0 · Last updated 15 June 2026. © 2026 H Roark Holding (Reg. 14180796, VAT EE102021330), Pikk tn 7-17, 10123 Tallinn, Estonia. This document supersedes all prior versions.