an honest document
The short version: we use your data to schedule rotas. Nothing else. We don't train AI on it. We don't sell it. We collect only what we need to make Shiftly work.
Last updated 1 May 2026
Shiftly is a staff scheduling tool for UK hospitality and retail businesses. This Privacy Policy explains what information we collect when you use Shiftly, how we use it, and the rights you have over it.
Shiftly is a product of Seedcraft Ventures Ltd, a company registered in Scotland, trading as Shiftly. Throughout this document “Shiftly”, “we”, “us”, or “our” refers to Seedcraft Ventures Ltd. “You” means anyone who visits the site, holds a Shiftly account, or has staff data added by a Shiftly customer.
We aim to comply with the UK GDPR, the EU GDPR, and to honour the broader privacy rights of people wherever they're working from. If anything here confuses or concerns you, the contact card is at the bottom.
The way we handle data depends on whose data it is. Shiftly is used by businesses to manage their staff, which means we hold data on two distinct groups of people, and our role is different for each.
Account holders
We are the controller
When you sign up for a Shiftly account as a business owner or manager, we decide how your personal data (email, name, payment info) is processed. We are the data controller.
Staff members
We are the processor
When a business adds staff to Shiftly, the business decides how that staff data is used. Shiftly processes it on their behalf. The business is the data controller; we are the processor.
Data Controller
Seedcraft Ventures Ltd
Registered in Scotland
Trading as Shiftly
Contact: shiftly@seedcraft.co
Staff who want to exercise their data rights should contact their employer first, as the employer is the controller. We'll assist where required by law and have a Data Processing Agreement (DPA) available to any business customer on request.
We try to collect as little as possible, and only what's needed to make Shiftly work. Here's everything:
Account
Account holder information
Your email, name, and a password (handled by our auth provider, hashed — we never see the plaintext). If you sign in with a third party, we receive only the basic profile fields they send us.
Business
Business details
Your company name, sections (Kitchen, Bar, Front of House), operating hours, and any settings you configure. Used solely to run your account.
Staff
Staff data you add
Names, contact details, contracted hours, max hours, role/section, availability windows, and any time-off requests. The business that signed up is the controller for this data; Shiftly processes it on their behalf.
Schedules
Rotas and shift records
The shifts your team works, generated rotas, manual edits, and history. Used for reports, payroll exports, and to keep your past schedules accessible.
Tech
Technical data
Basic log data your browser sends us: IP address, browser type, pages visited, and timestamps. Kept short-term to diagnose problems and spot abuse.
Payments
Payment information
If you pay for Shiftly, our payment processor (Stripe) handles your card details. We receive confirmation that a payment was made and the basic billing info needed for invoicing. We never see or store your card number.
What we don't collect: we don't track you across other websites, we don't use advertising cookies, we don't fingerprint your device, and we don't ask for your phone number or address unless you choose to provide it.
We use the information we collect to:
Core commitment
No AI. No training. No exceptions.
Shiftly's scheduling engine is a deterministic constraint satisfaction solver — the same kind of maths used for airline crew scheduling. It is not AI, and it never will be. We do not use your data to train, fine-tune, or improve any AI or machine learning model, ours or anyone else's. We do not sell, license, or transfer your data to AI companies or data brokers.
No AI training
Your staff data, schedules, and business information will never be used to train any AI model — ours or anyone else's.
No selling to vendors
We will never sell, license, or otherwise transfer your data to AI companies, advertisers, or data brokers.
Used for scheduling only
Your staff data exists in Shiftly to schedule rotas. That's it. It is not aggregated, anonymised, and resold.
No silent changes
If we ever need to revisit any of the above, we will tell you first, clearly, with time to leave if you disagree.
Under the UK GDPR and EU GDPR, we rely on the following lawful bases:
We don't sell your data. We don't rent it. We share personal data only with a small set of infrastructure providers that help us run Shiftly, each bound by a data processing agreement.
Stripe
Payments
Processes subscriptions and one-time payments. We never see your card details.
Privacy policy →We may also disclose information if required by law or to protect the rights, safety, or property of Shiftly or its users. If we're ever compelled to hand something over, we will push back where we lawfully can and notify the person affected where we're allowed to.
If we add a new infrastructure vendor, we'll update this list before that vendor starts handling your data.
Your data is stored on servers located in the UK and European Union where possible. Some of our infrastructure providers (such as Clerk and Stripe) are based in the United States and may process data there.
When personal data leaves the UK or EEA, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent safeguard to ensure your data keeps the same level of protection wherever it goes.
Your account and the data inside it stick around for as long as your subscription is active. If you cancel and delete your account, we delete your personal data within 30 days, with the exception of:
Technical logs are rotated out automatically, typically within 30 days.
We take reasonable technical and organisational measures to protect your data: encryption in transit (TLS), encryption at rest, hashed passwords (handled by Clerk), and access controls on our infrastructure. Payroll data is protected by an additional password layer.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours (as UK GDPR requires) and, where the risk is significant, we will notify you directly as soon as we reasonably can.
Depending on where you live, you have a set of rights over the personal data we hold about you. We honour these globally where we reasonably can.
Access
Ask for a copy of the personal data we hold about you.
Rectification
Ask us to correct anything that's wrong or out of date.
Erasure
Ask us to delete your account and the data we hold on you.
Restriction
Ask us to pause processing while a dispute is being sorted out.
Portability
Receive your data in a portable, machine-readable format.
Object
Object to processing based on our legitimate interests.
Withdraw consent
Pull back any consent you've given, at any time.
Complain
Lodge a complaint with your local data protection authority.
To exercise any of these rights as an account holder, write to shiftly@seedcraft.co. We'll respond within 30 days with no charge and no need to justify your request.
If you're a staff member added to Shiftly by a business, your employer is the data controller. Please contact them first. We'll support them in responding to your request.
UK users
You can complain to the Information Commissioner's Office at ico.org.uk. In the EEA, contact your local data protection authority.
Shiftly accounts are for businesses, and account holders must be 18 or older.
We recognise that hospitality and retail employ workers from age 16 in many UK roles. Where a business adds a 16- or 17-year-old staff member to Shiftly, the business must ensure their participation complies with UK employment and data protection law, and that the staff member (or their parent/guardian where appropriate) is informed about how their data is used.
We don't knowingly process data on anyone under 16. If you believe a child under 16 has been added to Shiftly, please contact us and we'll investigate.
We use a small number of cookies to keep you signed in, remember your preferences, and measure basic site performance. We don't use advertising cookies, cross-site trackers, or third-party analytics tools that build profiles on you.
You can block or delete cookies through your browser settings. If you do, some parts of Shiftly may stop working properly.
When we make material changes, we'll notify active users by email or in-app before the change takes effect. Minor updates will just show a new “last updated” date.
If Shiftly is ever incorporated separately, sold, or restructured, we will tell you before any personal data moves and give you the chance to delete your account first.
This policy is governed by the laws of Scotland. Any disputes shall be subject to the exclusive jurisdiction of the Scottish courts, without prejudice to your rights as a consumer under the laws of your own country.
Get in touch
Write to us. Emails don't go into a black hole — a real person on the team reads every one.
shiftly@seedcraft.coShiftly is fair rotas, generated in seconds.
A product of Seedcraft Ventures Ltd, registered in Scotland.