Privacy Policy
Last updated: 29 July 2026
This policy explains what personal data Skiftly (the "Service", "we", "us") collects, why we collect it, how long we keep it, and what rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR) and the Belgian Data Protection Act.
1. Who is the controller
The data controller is Skiftly, contact hello@skiftly.com. Full company details are available on the Legal Notice page.
2. What data we collect
2.1 Account data
- Email address, used to create your account, send transactional emails (leave requests, decisions, invitations), and sign you in.
- Display name and job role, that you enter yourself. Used to show who you are inside your team.
- Password (hashed) if you set one. We never see or store your password in clear text; it is hashed and stored by our authentication provider.
2.2 Team and planning data
- Team membership, role (admin or member), and location.
- Planning entries, that is, dates and half-days you mark as leave, present, remote, on-site, closed, or other custom categories your team configures.
- Leave and overtime balances, and audit entries when balances are edited.
- Leave requests, including the status (pending, approved, rejected) and any rejection reason.
- Team-wide bulletins that admins post, if any.
2.3 Technical data
- Login session tokens, stored in a first-party cookie by Supabase Auth (our authentication provider) so you stay signed in.
- Aggregated, anonymous page-view stats via Vercel Analytics. No cookies, no cross-site tracking, no personal identifiers.
- Server logs, kept for up to 30 days, containing your IP address and request timing. Used solely to debug and to defend against abuse.
2.4 What we do not collect
- We do not sell data to third parties.
- We do not run advertising trackers or fingerprinting.
- We do not use third-party analytics cookies. See Cookie Policy.
3. Why we process this data (legal bases under Article 6 GDPR)
- Performance of a contract (Art. 6(1)(b)), for account, team, and planning data, because we cannot deliver the Service without it.
- Legitimate interests (Art. 6(1)(f)), for security logs and aggregated analytics, balanced against your reasonable expectations.
- Legal obligation (Art. 6(1)(c)), for tax and accounting records if you become a paying customer.
- Consent (Art. 6(1)(a)), only in cases where consent is explicitly requested (for example, non-essential cookies if we ever introduce them).
4. Where the data lives (sub-processors)
Skiftly stores and processes personal data using the following sub-processors:
- Supabase (Supabase Inc.), for the primary database and authentication. EU region.
- Vercel (Vercel Inc.), for application hosting, edge routing, and cookieless analytics.
- Resend (Resend Inc.), for transactional email delivery.
- Nager.Date (public API), for national public-holiday lookups. Only country codes are sent, no personal data.
Each sub-processor is bound by a Data Processing Agreement. When data leaves the EU (for example, if a sub-processor operates a US-based control plane), the transfer is covered by Standard Contractual Clauses (SCC) as approved by the European Commission.
5. How long we keep data
- Account and team data: as long as your account exists.
- Planning entries: as long as the team exists, or until you delete them.
- Server logs: up to 30 days.
- Notification history: 60 days, then automatically purged.
- After account deletion (see below): all personal data is deleted within 30 days, except tax records where retention is legally required.
6. Your rights (GDPR chapter III)
You can exercise the following rights at any time by emailing hello@skiftly.com:
- Access, receive a copy of the personal data we hold on you.
- Rectification, correct data that is wrong or incomplete. Most of it you can edit yourself in Settings.
- Erasure, delete your account and all personal data. Available in-app under Settings, Danger Zone.
- Portability, get your data in a machine-readable format. Calendar entries already export via iCal.
- Restriction and objection, ask us to stop processing your data in certain cases.
- Withdraw consent, where processing was based on consent.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
7. Security
- All traffic is served over HTTPS (TLS 1.2 or higher).
- Database access is protected by row-level security. Team data is isolated so one team cannot read another's records.
- Passwords are hashed using industry-standard algorithms by our auth provider.
- Point-in-time backups let us restore recent state if a database incident occurs.
8. Children
Skiftly is a workplace tool and is not directed at children under 16. We do not knowingly collect data from them.
9. Automated decision-making
Skiftly does not make decisions with legal or similarly significant effects about you based solely on automated processing. The auto-approval rule engine only approves leave requests based on rules that an admin has explicitly configured, and the outcome is auditable.
10. Changes to this policy
If we change this policy in a way that materially affects you, we will notify signed-in users by email and by an in-app banner at least 30 days in advance.