Shiftie pilot privacy notice

The house gets its record. Your career stays yours.

Effective August 4, 2026 · Production pilot

What we collect

Shiftie stores the information needed to operate a venue-controlled perk: account email, display name, venue and role memberships, benefit eligibility, manager actions, short-lived QR presentation records, redemptions, approved item and cost snapshots, invitations, and security/audit events.

The QR itself contains an opaque rotating token. It does not contain an employee name, email, benefit price, schedule, or trusted authorization claim.

How it is used

We use pilot data to authenticate users, enforce venue roles, issue and redeem one-time benefits, prevent replay and cross-venue use, create the venue ledger, troubleshoot incidents, and improve the pilot. We do not sell employee identities or private venue operating data.

Who can see it

  • Employees can see their own available benefits and redemption history.
  • Authorized redeemers can see only the information needed to validate and complete a current redemption at their venue.
  • Venue managers and owners can see their scoped team, outstanding benefits, policy, and venue redemption record.
  • Shiftie platform administrators may access limited records when required to operate, secure, or support the service.

Partner boundary

Partners may receive aggregate campaign reporting only when a venue has approved a sponsored program. They do not receive employee names, emails, schedules, individual answers, drink choices, or personal redemption histories. Small cohorts are suppressed. Alcohol-funded reward structures remain inactive unless separately approved.

Retention and requests

Active pilot records are retained while needed for venue reconciliation, security, dispute handling, and the pilot relationship. Original schedule files are not part of the manager-release pilot. Future imports will use private storage and a documented short-retention policy.

To request access, correction, account deactivation, or deletion review, email info@shiftie.me. Some ledger and audit records may need to be retained for venue, security, or legal reasons; we will explain any limitation.

Security and incidents

Shiftie uses passwordless authentication, venue-scoped roles, database row-level security, no-store headers on authenticated surfaces, hashed QR tokens, and one-time redemption controls. No internet service is risk-free. Report suspected exposure immediately through the incident process.

Changes

This notice describes the production pilot. Material changes will be dated here and communicated to participating venues before they take effect.