Privacy Policy

Effective and last updated: 19 August 2026

1. Controller and contact

ElShift is operated by Private Entrepreneur OYENIRAN MICHAEL TEMITOPE, registered in Ukraine (RNOKPP 3589611556), at 39730, УКРАЇНА, ПОЛТАВСЬКА ОБЛАСТЬ, КРЕМЕНЧУЦЬКИЙ РАЙОН, С. БОНДАРІ, ВУЛ. ПЕРЕМОГИ, БУД. 9. For website visitors, purchasers, and organization administrators, we generally act as data controller. For workforce data entered by a customer organization, that organization generally acts as controller and ElShift acts as its processor or service provider.

Privacy requests can be sent to support@elshift.com.

2. Data we collect

We collect purchase and account details such as name, email, organization name, organization website, country, selected plan, subscription references, policy acceptance, and support correspondence. When a prospective customer starts a sales or product inquiry through our website, we ask for their name, work email, organization, country, and the scheduling needs or use case they choose to share. Organizations may add employee names, contact details, roles, availability, work patterns, leave, shifts, locations, departments, timesheet entries, schedule logs, and exports. We also process security and diagnostic data such as IP address, device and browser information, timestamps, authentication events, and application errors. Paddle collects payment-card and billing information directly; ElShift does not receive full card details.

3. Why and on what basis we use data

We process data to take pre-contract steps, respond to product and sales inquiries, understand where prospective customers are contacting us from, provide and administer subscriptions, create organizations, authenticate users, generate schedules and exports, send service messages, provide support, protect ElShift, prevent fraud, keep required financial and legal records, and improve reliability. Depending on the context, our legal bases are performance of a contract, steps taken at your request before entering a contract, compliance with legal obligations, legitimate interests in operating and securing the service, and consent where the law requires it.

4. Providers and recipients

We use Paddle as reseller and Merchant of Record for self-service billing; Supabase for EU-region database, authentication, and storage services; Resend for transactional email delivery through Supabase; Google for optional Google authentication and related infrastructure; and Lovable and its hosting or deployment infrastructure to operate the application and website. These providers process only the information required for their role and may also act as independent controllers for their own compliance, security, and billing obligations. We may disclose data when required by law or to protect legal rights.

5. Where data is processed

ElShift’s active Supabase project uses the EU Ireland region for its primary database, authentication, and storage. Paddle, Resend, Google, Lovable, and their subprocessors may process data in other countries. Where required, transfers are supported by adequacy decisions, standard contractual clauses, or another lawful transfer mechanism.

6. Retention and deletion

Active account and organization data is kept while needed to provide ElShift. Purchase, tax, fraud-prevention, and legal records may be retained for the period required by law. Sales and product inquiry correspondence is retained only as long as reasonably needed to respond, follow up, and maintain an appropriate business record. Verified deletion or organization-closure requests are completed within 30 days unless a legal exception applies. Residual encrypted backup copies are removed within 90 days through the backup cycle and are not restored for ordinary business use. An organization administrator may need to submit requests concerning workforce data controlled by that organization.

7. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also complain to the Ukrainian Parliament Commissioner for Human Rights or the competent data-protection authority where you live or work. We may verify identity and authority before acting on a request.

8. Security

We use access controls, organization-based authorization, encrypted transport, managed hosting, backups, logging, and restricted administrative credentials. No internet service can promise absolute security, so please report suspected misuse promptly.

9. Cookies and authentication

ElShift uses essential storage and cookies needed for security, sessions, language choices, and checkout operation. Optional Google authentication is used only when selected. We do not sell personal data or use workforce data for targeted advertising.

10. Children and policy changes

ElShift is a workforce-management service and is not directed to children. Customers must have a lawful basis before entering information about younger workers. We may update this policy when services or legal requirements change and will update the date above; material changes will receive reasonable notice where appropriate.