Privacy Policy

Last updated: 2025-10-20

MyShiftSheet ("we", "our", "us") provides tools to record work shifts, generate timesheets, and share them with agencies. This policy explains how we handle your information when you use our website and services.

Who controls your data

The data controller is MyShiftSheet. If you have questions, contact us at support@myshiftsheet.com.

Information we collect

  • Account data: username, password (stored as a one-way hash), and optional name and email.
  • Profile data: full name, phone number, SIA/licence number.
  • Company/agency data: company names and contact details you store.
  • Bank details you enter: account name, bank name, sort code, account number, IBAN, SWIFT/BIC, and payment reference for inclusion on timesheets.
  • Shift data: dates, times, sites/projects, notes, hourly rates.
  • Usage and device data: log and diagnostic information; cookies or similar technologies as described below.

How we use your information

  • To provide and improve the service (create timesheets, exports, dashboards).
  • To authenticate you and keep your account secure.
  • To communicate service updates and respond to support requests.
  • To comply with legal obligations and enforce our terms.

Legal bases (UK GDPR/EU GDPR)

  • Contract: processing necessary to deliver the service you request.
  • Legitimate interests: service improvement, security, fraud prevention.
  • Consent: where required for optional features or communications (you can withdraw at any time).
  • Legal obligation: where law requires retention or disclosure.

Sharing and disclosure

  • Service providers: trusted vendors (e.g., hosting, email) under contracts that protect your data.
  • Legal and safety: to comply with law, requests from authorities, or to protect rights and safety.
  • Business transfers: as part of a merger, acquisition, or asset sale. We will notify you if required by law.

We do not sell your personal information.

International transfers

If we transfer data outside the UK/EEA, we use appropriate safeguards (e.g., standard contractual clauses) where required.

Security

  • Passwords are stored using industry-standard one-way hashing.
  • Data is transmitted over TLS (HTTPS).
  • Access to production systems is restricted to authorised personnel.

No method of transmission or storage is 100% secure; we work to protect your data but cannot guarantee absolute security.

Retention

We keep information for as long as your account is active or as needed to provide the service. You can request deletion of your account; some records may remain in backups for a limited period.

Your rights

Subject to law, you may have rights to access, correct, delete, or export your data, and to object to or restrict processing. You can also withdraw consent where processing relies on it. To exercise these rights, contact support@myshiftsheet.com. You have the right to complain to the ICO (UK) or your local authority.

Cookies

We use essential cookies to keep you signed in and operate the site. Your browser provides controls to manage cookies. Blocking essential cookies may affect service functionality.

Children

Our service is not intended for children under 16, and we do not knowingly collect their personal data.

Changes to this policy

We may update this policy to reflect changes in our practices. We will update the "Last updated" date and, where appropriate, provide additional notice.

Contact

Email: support@myshiftsheet.com