This Privacy Policy explains how Handoff Shifts LLC("Handoff Shifts," "we," "us") handles information when you use the Handoff Shifts mobile app, website, and related services (the "Service"). Handoff Shifts is a workplace operations platform that employers (restaurant operators and their organizations) provide to their employees. This policy is written for both: the employers who administer accounts and the employees who use the Service day-to-day.
1. Our role and your employer's role
Handoff Shifts is provided to employers under a separate agreement with each employer. When you use the Service as an employee, your employer decides what features are enabled, what information is entered about you, and how long records are kept. Your employer is the "data controller" for that information, and Handoff Shifts acts as their "processor" — we handle data on their instructions.
If you have questions about why specific information was entered about you, how long it is retained, or want a copy or deletion, the fastest path is usually to ask your employer first. You can also write to us at privacy@handoffshifts.com and we will route your request appropriately.
2. Information we collect
Account information
When your employer adds you to the Service, we receive your name, email address, and role. When you sign in, our authentication provider (Clerk) collects a password or sign-in code, optional multi-factor authentication factors, and (if you provide one) a profile photo. Clerk also records sign-in events for security purposes.
Work and operational information
Depending on which features your employer uses, the Service stores information about your work, including: position assignments, schedules, time-punch entries (clock-in and clock-out timestamps), completed checklists, training records and certifications, recognition and coaching notes, writeups, shift notes, food and warehouse orders, and related operational records.
Content you create
The Service includes features for posting shift notes, completing checklists, and uploading photos (for example, store-item images or checklist evidence). We store this content so it can be displayed to authorized members of your workplace.
Device and notification information
If you install our mobile app and grant notification permission, your device provides us with a push notification token from Apple Push Notification service (APNs) or Google's Firebase Cloud Messaging (FCM). We use this token only to deliver the notifications you have opted into. We do not collect your phone number, contacts, or location.
Cookies and session information
The Service uses cookies and similar storage to keep you signed in and to remember your preferences. Authentication cookies are set by Clerk; we do not use third-party advertising cookies or web tracking pixels.
3. Information we do not collect
To be explicit, because the major app stores ask:
- We do not collect your precise or coarse location (no GPS or network-based location).
- We do not access your camera or microphone in real time. File uploads go through the standard system file picker.
- We do not collect payment, credit-card, or other financial information from individual users.
- We do not collect health, medical, biometric, or sensitive demographic information.
- We do not use third-party advertising networks, analytics SDKs (such as Google Analytics, Mixpanel, Segment, Amplitude, or PostHog), or behavioral tracking tools.
- We do not sell your information. We do not share information for cross-context behavioral advertising.
4. How we use information
- To provide the Service to you and your employer: displaying schedules, delivering notifications, running checklists, and the other features described above.
- To send transactional emails (sign-in codes, password resets, notification alerts your employer configures).
- To produce daily operational summaries for your employer. These summaries are generated by an AI service (Anthropic's Claude API) using aggregated operational data and may reference employee names where the underlying records include them.
- To keep the Service secure, including detecting abuse, troubleshooting errors, and protecting accounts.
- To comply with legal obligations and enforce our terms.
5. Service providers
We rely on a small set of third-party services to operate the platform. Each receives only the data needed for its specific function:
- Clerk — user authentication, sign-in security, and identity management.
- Neon — managed PostgreSQL database (hosted on Amazon Web Services). Stores the operational records described above.
- Vercel — application hosting and file storage (Vercel Blob) for uploaded images.
- Resend — sending transactional email (sign-in codes, notification digests).
- Anthropic — AI weekly operational summaries. We do not use this service to make decisions about individual employees.
- Firebase Cloud Messaging (Google) — push notification delivery to Android devices. Receives the FCM token and the notification payload only.
- Apple Push Notification service — push notification delivery to iOS devices. Receives the APNs token and the notification payload only.
These providers are contractually required to use information only as instructed by us. We do not authorize them to sell information or use it for their own marketing.
6. Children and minors
Handoff Shifts is a workplace tool, not a consumer app, and it is not directed to children under 13. We do not knowingly accept registrations or collect information from anyone under 13. If your employer adds a worker who is under 13, that account should be removed immediately and you can request its deletion by writing to privacy@handoffshifts.com.
We recognize that some employees are minors aged 13 to 17, since federal and state child-labor laws allow some workers as young as 14 to be employed in restaurant settings with restrictions. Where applicable law requires parental or guardian consent before a minor's personal information is collected, the employer is responsible for obtaining and documenting that consent before adding the minor to the Service. A parent or guardian may contact us at privacy@handoffshifts.com to request access to or deletion of a minor's information on the Service.
7. Data retention
We retain personal information for as long as your account is active and for a reasonable period afterward to support your employer's record-keeping and to satisfy legal, tax, audit, and dispute-resolution obligations. Push notification tokens are deleted when they become invalid or when you uninstall the app. Aggregated and de-identified information may be retained for longer to support analytics about the Service itself.
8. Your rights
You can ask us to access, correct, delete, or export your personal information by writing to privacy@handoffshifts.com. Because Handoff Shifts holds most employee information on behalf of an employer, we will forward applicable requests to your employer and follow their instructions consistent with law. We do not sell personal information or share it for cross-context behavioral advertising.
9. Security
We protect information using industry-standard practices: HTTPS for all network traffic, encrypted database backups, scoped access controls, and security review of third-party providers. No system is perfectly secure, but if we become aware of a breach that affects you, we will notify your employer and, where required, you directly.
10. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, for significant changes, notify you through the Service or by email.
11. Contact us
For any privacy question, request, or concern, write to us at privacy@handoffshifts.com.