Privacy Policy

Last updated: 24 July 2026

ShiftFit ("the Service") helps independent restaurants build staff schedules. This policy explains what we collect, why, and your choices. "We"/"operator" means the party running this ShiftFit deployment.

What we collect

How we use it

Solely to provide the Service: authenticating you, generating and storing your schedules, and — where enabled — answering your Assistant requests. We do not sell your data.

Sharing

Data for one restaurant is isolated from others. We share data only with infrastructure providers needed to run the Service (our hosting provider, and Anthropic for Assistant messages), or where required by law.

Retention & deletion

We keep your data while your account is active. Backups are retained for a limited rolling window. To access, correct, or delete your restaurant's data, contact us (below); we will act on verified requests within a reasonable period.

Security

Passwords are hashed (PBKDF2, 200k iterations), sessions expire, and sign-in attempts are rate-limited. No system is perfectly secure, but we take reasonable measures to protect data.

Children

The Service is for restaurant operators and staff and is not directed to children under 13.

Changes

We may update this policy; material changes will be reflected by the "Last updated" date.

Contact

Questions or data requests: shiftfit.inc@gmail.com