ShiftFit ("the Service") helps independent restaurants build staff schedules. This policy explains what we collect, why, and your choices. "We"/"operator" means the party running this ShiftFit deployment.
Solely to provide the Service: authenticating you, generating and storing your schedules, and — where enabled — answering your Assistant requests. We do not sell your data.
Data for one restaurant is isolated from others. We share data only with infrastructure providers needed to run the Service (our hosting provider, and Anthropic for Assistant messages), or where required by law.
We keep your data while your account is active. Backups are retained for a limited rolling window. To access, correct, or delete your restaurant's data, contact us (below); we will act on verified requests within a reasonable period.
Passwords are hashed (PBKDF2, 200k iterations), sessions expire, and sign-in attempts are rate-limited. No system is perfectly secure, but we take reasonable measures to protect data.
The Service is for restaurant operators and staff and is not directed to children under 13.
We may update this policy; material changes will be reflected by the "Last updated" date.
Questions or data requests: shiftfit.inc@gmail.com