an honest document

Your data, your business.

The short version: we use your data to schedule rotas. Nothing else. We don't train AI on it. We don't sell it. We collect only what we need to make Shiftly work.

Last updated 1 May 2026

Shiftly is a staff scheduling tool for UK hospitality and retail businesses. This Privacy Policy explains what information we collect when you use Shiftly, how we use it, and the rights you have over it.

Shiftly is a product of Seedcraft Ventures Ltd, a company registered in Scotland, trading as Shiftly. Throughout this document “Shiftly”, “we”, “us”, or “our” refers to Seedcraft Ventures Ltd. “You” means anyone who visits the site, holds a Shiftly account, or has staff data added by a Shiftly customer.

We aim to comply with the UK GDPR, the EU GDPR, and to honour the broader privacy rights of people wherever they're working from. If anything here confuses or concerns you, the contact card is at the bottom.

01

Who is responsible for your data

The way we handle data depends on whose data it is. Shiftly is used by businesses to manage their staff, which means we hold data on two distinct groups of people, and our role is different for each.

Account holders

We are the controller

When you sign up for a Shiftly account as a business owner or manager, we decide how your personal data (email, name, payment info) is processed. We are the data controller.

Staff members

We are the processor

When a business adds staff to Shiftly, the business decides how that staff data is used. Shiftly processes it on their behalf. The business is the data controller; we are the processor.

Data Controller

Seedcraft Ventures Ltd

Registered in Scotland

Trading as Shiftly

Contact: shiftly@seedcraft.co

Staff who want to exercise their data rights should contact their employer first, as the employer is the controller. We'll assist where required by law and have a Data Processing Agreement (DPA) available to any business customer on request.

02

What we collect

We try to collect as little as possible, and only what's needed to make Shiftly work. Here's everything:

Account

Account holder information

Your email, name, and a password (handled by our auth provider, hashed — we never see the plaintext). If you sign in with a third party, we receive only the basic profile fields they send us.

Business

Business details

Your company name, sections (Kitchen, Bar, Front of House), operating hours, and any settings you configure. Used solely to run your account.

Staff

Staff data you add

Names, contact details, contracted hours, max hours, role/section, availability windows, and any time-off requests. The business that signed up is the controller for this data; Shiftly processes it on their behalf.

Schedules

Rotas and shift records

The shifts your team works, generated rotas, manual edits, and history. Used for reports, payroll exports, and to keep your past schedules accessible.

Tech

Technical data

Basic log data your browser sends us: IP address, browser type, pages visited, and timestamps. Kept short-term to diagnose problems and spot abuse.

Payments

Payment information

If you pay for Shiftly, our payment processor (Stripe) handles your card details. We receive confirmation that a payment was made and the basic billing info needed for invoicing. We never see or store your card number.

What we don't collect: we don't track you across other websites, we don't use advertising cookies, we don't fingerprint your device, and we don't ask for your phone number or address unless you choose to provide it.

03

How we use your data

We use the information we collect to:

  • Run the service. Generate rotas, sync data across devices, keep your account secure.
  • Generate fair schedules. Run our deterministic OR-Tools solver against your staff data, contracted hours, and rules to produce balanced rotas.
  • Keep things working. Fix bugs, prevent abuse, improve features based on what's actually being used.
  • Talk to you when we must. Important account notices, billing receipts, security alerts, or material changes to this policy. No marketing spam.
  • Meet legal obligations. Respond to lawful requests, resolve disputes, and enforce our terms.
04

Our commitment to your data

Core commitment

No AI. No training. No exceptions.

Shiftly's scheduling engine is a deterministic constraint satisfaction solver — the same kind of maths used for airline crew scheduling. It is not AI, and it never will be. We do not use your data to train, fine-tune, or improve any AI or machine learning model, ours or anyone else's. We do not sell, license, or transfer your data to AI companies or data brokers.

No AI training

Your staff data, schedules, and business information will never be used to train any AI model — ours or anyone else's.

No selling to vendors

We will never sell, license, or otherwise transfer your data to AI companies, advertisers, or data brokers.

Used for scheduling only

Your staff data exists in Shiftly to schedule rotas. That's it. It is not aggregated, anonymised, and resold.

No silent changes

If we ever need to revisit any of the above, we will tell you first, clearly, with time to leave if you disagree.

05

Our legal bases for processing

Under the UK GDPR and EU GDPR, we rely on the following lawful bases:

  • Contract. Running your account, generating rotas, processing payments — necessary to deliver the service you signed up for.
  • Legitimate interests. Basic logging, security monitoring, and fraud prevention. We've weighed this against your privacy and kept collection minimal.
  • Consent. Where we ask for something optional, we only act on it if you say yes. You can withdraw consent at any time.
  • Legal obligation. When we have to respond to a lawful request from a court or regulator, or to keep records as the law requires.
  • Processor instructions. For staff data, we process under the documented instructions of the business that signed up — not our own decisions.
06

Who we share it with

We don't sell your data. We don't rent it. We share personal data only with a small set of infrastructure providers that help us run Shiftly, each bound by a data processing agreement.

V

Vercel

Hosting

Serves the Shiftly website and handles request logging.

Privacy policy →
S

Supabase

Database

Stores your account, staff records, and rotas. EU-hosted.

Privacy policy →
C

Clerk

Authentication

Manages user sign-up, sign-in, and account security.

Privacy policy →
$

Stripe

Payments

Processes subscriptions and one-time payments. We never see your card details.

Privacy policy →
R

Railway

Solver hosting

Runs the OR-Tools scheduling engine that generates your rotas.

Privacy policy →

We may also disclose information if required by law or to protect the rights, safety, or property of Shiftly or its users. If we're ever compelled to hand something over, we will push back where we lawfully can and notify the person affected where we're allowed to.

If we add a new infrastructure vendor, we'll update this list before that vendor starts handling your data.

07

International data transfers

Your data is stored on servers located in the UK and European Union where possible. Some of our infrastructure providers (such as Clerk and Stripe) are based in the United States and may process data there.

When personal data leaves the UK or EEA, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent safeguard to ensure your data keeps the same level of protection wherever it goes.

08

How long we keep things

Your account and the data inside it stick around for as long as your subscription is active. If you cancel and delete your account, we delete your personal data within 30 days, with the exception of:

  • Backups. Encrypted backups may retain your data for up to 60 days before rotation.
  • Financial records. We keep records of payments for as long as UK tax law requires (currently six years).
  • Legal holds. If we're under a legal obligation to retain something, we'll keep only what's strictly required and for no longer than necessary.

Technical logs are rotated out automatically, typically within 30 days.

09

How we protect your data

We take reasonable technical and organisational measures to protect your data: encryption in transit (TLS), encryption at rest, hashed passwords (handled by Clerk), and access controls on our infrastructure. Payroll data is protected by an additional password layer.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours (as UK GDPR requires) and, where the risk is significant, we will notify you directly as soon as we reasonably can.

10

Your rights

Depending on where you live, you have a set of rights over the personal data we hold about you. We honour these globally where we reasonably can.

a

Access

Ask for a copy of the personal data we hold about you.

b

Rectification

Ask us to correct anything that's wrong or out of date.

c

Erasure

Ask us to delete your account and the data we hold on you.

d

Restriction

Ask us to pause processing while a dispute is being sorted out.

e

Portability

Receive your data in a portable, machine-readable format.

f

Object

Object to processing based on our legitimate interests.

g

Withdraw consent

Pull back any consent you've given, at any time.

h

Complain

Lodge a complaint with your local data protection authority.

To exercise any of these rights as an account holder, write to shiftly@seedcraft.co. We'll respond within 30 days with no charge and no need to justify your request.

If you're a staff member added to Shiftly by a business, your employer is the data controller. Please contact them first. We'll support them in responding to your request.

UK users

You can complain to the Information Commissioner's Office at ico.org.uk. In the EEA, contact your local data protection authority.

11

Young workers

Shiftly accounts are for businesses, and account holders must be 18 or older.

We recognise that hospitality and retail employ workers from age 16 in many UK roles. Where a business adds a 16- or 17-year-old staff member to Shiftly, the business must ensure their participation complies with UK employment and data protection law, and that the staff member (or their parent/guardian where appropriate) is informed about how their data is used.

We don't knowingly process data on anyone under 16. If you believe a child under 16 has been added to Shiftly, please contact us and we'll investigate.

12

Cookies & similar things

We use a small number of cookies to keep you signed in, remember your preferences, and measure basic site performance. We don't use advertising cookies, cross-site trackers, or third-party analytics tools that build profiles on you.

You can block or delete cookies through your browser settings. If you do, some parts of Shiftly may stop working properly.

13

Changes to this policy

When we make material changes, we'll notify active users by email or in-app before the change takes effect. Minor updates will just show a new “last updated” date.

If Shiftly is ever incorporated separately, sold, or restructured, we will tell you before any personal data moves and give you the chance to delete your account first.

14

Governing law

This policy is governed by the laws of Scotland. Any disputes shall be subject to the exclusive jurisdiction of the Scottish courts, without prejudice to your rights as a consumer under the laws of your own country.

Get in touch

Questions?

Write to us. Emails don't go into a black hole — a real person on the team reads every one.

shiftly@seedcraft.co

Shiftly is fair rotas, generated in seconds.

A product of Seedcraft Ventures Ltd, registered in Scotland.