Introduction
Vizlume Inc., operating as Shift Terminal (“Shift Terminal,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our website at shiftterminal.com (the “Site”), use our web application, or use our mobile applications for iOS and Android (collectively, the “Service”).
By accessing or using the Service, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal information as described in this Privacy Policy, our Terms of Service, and our Cancellation & Refund Policy.
“You” or “Your” refers to any user of the Service, which may be an individual, an employer (organization), an employee associated with an organization account, or any other authorized user.
1. Our Role: Data Controller and Data Processor
As a Data Processor: When we collect and process personal information on behalf of our business customers (“Organizations”) in connection with providing the Service, the Organization is the data controller and we act as the data processor. This includes personal information that Organizations upload about their employees, managers, supervisors, and contractors (“Organization Data”). If you have questions about Organization Data, please contact your Organization administrator directly. For details on our data processing obligations, see our Data Processing Agreement.
As a Data Controller: When we process personal information of prospective customers, account owners, and users in their direct interactions with us (e.g., account registration, website visits, support requests), we are the data controller.
2. Information We Collect
2.1 Information You Provide
- Account Registration: When you create an account, we collect your full name, email address, phone number, and password. If you register an Organization, we also collect your organization name and business information.
- Profile Information: Job title, position, profile photo, and any other information you choose to add to your profile.
- Employee Data: If you are an Organization administrator, you may provide information about your employees, including names, email addresses, phone numbers, hourly rates, positions, and employment details.
- Scheduling and Attendance Data: Shift schedules, availability preferences, time clock records (clock-in/clock-out times), break records, time-off requests, and attendance data.
- Communications: Messages sent through team chat features, shift notes, broadcast messages, and any communications between you and Shift Terminal support.
- Payment Information: When you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details. We receive only the last four digits of your card number, card brand, expiration date, and billing address. We do not store full payment card numbers on our servers.
- Support Requests: Information you provide when contacting us for support, including descriptions of issues and any attachments.
2.2 Information Collected Automatically
- Device and Browser Information: IP address, browser type and version, operating system, device type, screen resolution, language preferences, and unique device identifiers.
- Usage Data: Pages visited, features used, actions taken within the Service, date and time of access, session duration, and referring/exit pages.
- Location Data: If you enable geofencing or GPS clock-in features, we collect precise geolocation data (latitude and longitude) from your device. This data is used to verify clock-in/clock-out locations relative to designated job sites. Location data is only collected when you actively use these features, and you can disable location services through your device settings at any time.
- Cookies and Similar Technologies: We use cookies, local storage, and similar technologies to maintain your session, remember preferences, and understand how the Service is used. See Section 8 (Cookies and Tracking Technologies) for details.
2.3 Information from Third Parties
- Invitation Referrals: If another user invites you to join an Organization on Shift Terminal, we receive your name and email address or phone number as provided by the inviting user.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and Operate the Service: To create and manage accounts, process scheduling and attendance data, enable team communication, generate reports, and deliver all features of the Service.
- Process Payments: To process subscription payments, manage billing cycles, and handle billing-period changes, cancellations, and refunds through our payment processor.
- Communicate with You: To send service-related notifications including shift assignments, schedule changes, time-off approvals, clock-in reminders, and system alerts via email, push, and in-app notifications. To respond to your support requests and inquiries.
- Verify Location: To validate clock-in and clock-out events against designated job site geofences, where this feature is enabled by your Organization.
- Maintain Security: To detect and prevent fraud, unauthorized access, and other security incidents. To enforce our Terms of Service and protect the rights and safety of our users.
- Improve the Service: To analyze usage patterns, diagnose technical issues, and improve the reliability, performance, and functionality of the Service.
- Comply with Legal Obligations: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Aggregate Analytics: To compile anonymized, aggregate statistics about Service usage that do not identify any individual user.
We do not sell your personal information. We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.
4. How We Share Your Information
We may share your personal information in the following circumstances:
- Within Your Organization: Your name, profile information, schedule, availability, and attendance data are visible to other members of your Organization based on role-based access controls set by your Organization administrator. Administrators and managers can view employee data necessary for workforce management. Privacy settings may allow you to hide contact information from coworkers.
- Service Providers: We share information with third-party service providers who process data on our behalf to provide the Service. These providers are contractually obligated to use your information only as directed by us and in accordance with this Privacy Policy. Our current service providers include:
- Supabase — Database hosting, authentication, and real-time infrastructure
- Stripe — Payment processing and subscription management
- Resend — Transactional email delivery
- Vercel — Web application hosting and content delivery
- Cloudflare — Bot protection (Turnstile) and security
- OpenWeatherMap — Weather data for scheduling features
- Apple / Google — Push notification delivery for mobile applications
- Intuit (QuickBooks Online) — Optional accounting integration for timesheet synchronization (optional; requires explicit administrator authorization via OAuth 2.0)
- Legal Requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to (a) comply with a legal obligation; (b) protect and defend the rights, property, or safety of Shift Terminal, our users, or the public; (c) prevent or investigate possible wrongdoing; or (d) enforce our Terms of Service.
- Business Transfers: If Shift Terminal is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service of any change in ownership or use of your personal information.
- With Your Consent: We may share your information for other purposes with your explicit consent.
We do not share your mobile phone number with third parties for their marketing purposes.
5. Communications
5.1 Service Communications
We send transactional and operational communications related to the Service, including shift assignment notifications, schedule changes, time-off request updates, clock-in reminders, system alerts, and account security notices. These communications are necessary for the operation of the Service and cannot be opted out of while you maintain an active account.
5.2 Notification Channels
Service notifications may be delivered through the following channels, depending on your Organization’s subscription plan and your notification preferences:
- Email — Available on all plans
- Push Notifications — Available on all plans via web browser and mobile app
- In-App Notifications — Available on all plans
You can manage your notification preferences in your profile settings. You may opt out of specific notification types while keeping others active. Our email communications comply with Canada’s Anti-Spam Legislation (CASL), and you may withdraw consent to receive them by adjusting your notification preferences or by using the unsubscribe link included in those emails.
5.3 Marketing Communications
We may occasionally send product updates or feature announcements. You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email or by contacting us at support@shiftterminal.com. Opting out of marketing communications does not affect service-related transactional messages.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. Specifically:
- Account Data: Retained for the duration of your account. If your account is deactivated or your Organization account is closed, we may retain account data for a limited period to support reactivation, data export, billing reconciliation, security, and legal compliance, after which it may be deleted, anonymized, or archived as required by applicable law.
- Scheduling and Attendance Records: Retained for the duration of the Organization’s account plus an additional period as required by applicable employment and labour laws (typically 3–7 years depending on jurisdiction).
- Payment Records: Retained as required by applicable tax and financial regulations.
- Communications Data: Team chat messages and shift notes are retained for the duration of the Organization’s account.
- Location Data: Geolocation records associated with clock-in/clock-out events are retained as part of attendance records and related audit history. This may include clock-in and clock-out coordinates captured to verify attendance against configured location controls.
- Usage and Log Data: Retained for up to 12 months for security, debugging, and analytics purposes, then deleted or anonymized. Administrative and settings audit records (who changed what, and when) are retained for up to 24 months.
When personal information is no longer needed, we securely delete or anonymize it. We may retain anonymized, aggregate data indefinitely for analytical purposes.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
- Encryption at Rest: Personal information stored in our database is encrypted at rest using AES-256 encryption.
- Row-Level Security: Our database enforces row-level security policies that ensure users can only access data belonging to their Organization.
- Role-Based Access Controls: Access to personal information within the Service is governed by role-based permissions (admin, manager, supervisor, employee).
- Authentication Security: We use secure password hashing and session management, and may provide additional authentication controls where available.
- Infrastructure Security: Our infrastructure providers maintain SOC 2, ISO 27001, and other industry-standard security certifications.
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents in accordance with applicable breach notification laws.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Service:
- Essential Cookies: Required for the Service to function, including authentication tokens, session management, and security cookies. These cannot be disabled.
- Preference Cookies: Remember your settings and preferences (e.g., selected view, date range, notification preferences).
We do not use analytics cookies, advertising cookies, or tracking technologies for targeted advertising. We do not participate in ad networks or sell data to advertisers.
Most web browsers allow you to control cookies through their settings. Disabling essential cookies may prevent you from using certain features of the Service.
9. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
9.1 General Rights (All Users)
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of your personal information, subject to legal retention obligations. See how to delete your account.
- Data Portability: Request your personal information in a structured, commonly used, machine-readable format.
- Withdraw Consent: Where processing is based on consent, withdraw your consent at any time.
- Notification Preferences: Manage your email, push, and in-app notification preferences through your profile settings.
- Account Deactivation: Request deactivation of your account by contacting your Organization administrator or us directly.
9.2 Canadian Residents (PIPEDA)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, Canadian residents have the right to:
- Know what personal information we hold about you and how it is used
- Access your personal information
- Challenge the accuracy and completeness of your personal information and have it amended
- Withdraw consent to the collection, use, or disclosure of your personal information (subject to legal or contractual restrictions)
- Complain to the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated
9.3 European Economic Area Residents (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including:
- Right to object to processing based on legitimate interests
- Right to restriction of processing
- Right to lodge a complaint with your local data protection authority
Our legal bases for processing include: performance of a contract (providing the Service), legitimate interests (security, improvement), consent (marketing communications, location data), and compliance with legal obligations.
9.4 California Residents (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt out of the sale or sharing of personal information (we do not sell your personal information)
- Right to non-discrimination for exercising your privacy rights
- Right to correct inaccurate personal information
- Right to limit the use and disclosure of sensitive personal information
9.5 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@shiftterminal.com. We will respond to your request within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before processing your request. If your personal information is managed by an Organization using the Service, we may direct your request to that Organization.
10. International Data Transfers
Shift Terminal is based in Canada, and our database and file storage are hosted in Canada (AWS Canada Central, Montréal). Some personal information may be transferred to, stored, and processed in countries other than your country of residence, including the United States, where certain service providers (such as payment processing, e-mail delivery, and error monitoring) maintain infrastructure.
Where personal information is transferred outside of your jurisdiction, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions where applicable
- Contractual obligations requiring service providers to protect personal information to standards equivalent to applicable law
Canada has been recognized by the European Commission as providing an adequate level of data protection under the GDPR.
11. Children’s Privacy
The Service is designed for use by businesses and their workforce and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe that we have inadvertently collected information from a child under 16, please contact us at privacy@shiftterminal.com.
12. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to third-party websites or services. We encourage you to review the privacy policies of any third-party websites or services that you access through or in connection with the Service. We are not responsible for the privacy practices or content of third-party websites or services.
13. QuickBooks Online Integration
The Service offers an optional integration with Intuit QuickBooks Online (“QuickBooks”) that allows Organization administrators to synchronize employee timesheet data from Shift Terminal to their QuickBooks Online company. This section describes how we handle data in connection with this integration.
13.1 Authorization and Connection
The QuickBooks integration is initiated exclusively by Organization administrators and requires explicit authorization through Intuit’s OAuth 2.0 authentication protocol. During authorization, you are redirected to Intuit’s website where you grant Shift Terminal permission to access your QuickBooks Online company. We do not receive or store your QuickBooks login credentials.
13.2 Data We Access from QuickBooks
When connected, Shift Terminal accesses the following data from your QuickBooks Online company:
- Company name and identifier (Realm ID)
- Employee names and QuickBooks employee identifiers (for mapping purposes)
We do not access your QuickBooks financial reports, bank accounts, bank feeds, invoices, bills, payroll data, tax information, social insurance numbers, or any data beyond what is necessary for the timesheet synchronization feature.
13.3 Data We Send to QuickBooks
When an Organization administrator initiates a timesheet sync, we transmit the following data as TimeActivity entries in QuickBooks:
- Employee name (mapped to the corresponding QuickBooks employee)
- Shift date, start time, and end time
- Break duration
- Position or job role
- Tips (if recorded)
- Shift notes (if present)
13.4 Purpose Limitation
We use QuickBooks data solely to provide the timesheet synchronization feature to you. We do not use QuickBooks data for advertising, analytics, profiling, marketing, or any purpose other than delivering the Service. We do not sell, rent, or share your QuickBooks data with any third party.
13.5 Data Isolation
QuickBooks data for each Organization is strictly isolated. One Organization’s QuickBooks data is never accessible to, visible to, or shared with any other Organization or user outside of that Organization.
13.6 Token Security
OAuth access tokens and refresh tokens issued by Intuit are stored encrypted at rest in our database. Access tokens are short-lived (one hour) and are automatically refreshed as needed. We do not store your QuickBooks login password.
13.7 Disconnection and Data Deletion
You may disconnect the QuickBooks integration at any time from Settings > Integrations within the Service, or from the QuickBooks App Center. Upon disconnection:
- All OAuth tokens are immediately revoked at Intuit and deleted from our systems
- We cease all access to your QuickBooks Online company
- Employee mapping data and sync history logs are retained for your reference but can be deleted upon request
- TimeActivity entries previously synced to QuickBooks remain in your QuickBooks account under your control
To request deletion of all QuickBooks-related data (including mapping and sync logs), contact us at privacy@shiftterminal.com.
13.8 Intuit’s Privacy Practices
Your use of QuickBooks Online is governed by Intuit’s own Privacy Statement and Terms of Service. We encourage you to review Intuit’s privacy practices independently.
14. Organization Responsibility
If you use the Service as an employee, contractor, or other personnel of an Organization, please note:
- Your Organization controls the personal information it provides to the Service and is responsible for obtaining any necessary consents from you.
- Your Organization determines the settings that apply to your account, including privacy settings, notification preferences, and feature access.
- Your Organization administrator can access your scheduling, attendance, and communication data within the Service.
- Questions about how your Organization uses the Service or handles your data should be directed to your Organization administrator.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by posting the updated Privacy Policy on the Service with a revised “Last updated” date and, where required by law, by sending you an email notification. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
- Email: privacy@shiftterminal.com
- General Support: support@shiftterminal.com
- Website: shiftterminal.com
If you are a Canadian resident and are not satisfied with our response to your privacy concern, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
