Privacy policy
Last updated: 10 July 2026
This policy explains how Shifty processes personal data. It takes account of Swiss data protection law and, where the GDPR applies, people in the European Union and European Economic Area.
Data controller
The data controller is Noé Henchoz. For any question or request concerning your data, write to henchoznoe@gmail.com.
Data we process
We process account and profile data (name, email address, image, language, time-zone and display preferences), authentication and session data (including IP address and user agent), data supplied by Google when OAuth sign-in is chosen, and planning, availability, hours, notes, member, link and guest-response data. We also process consent choices, technical data needed to operate the service and, with consent, analytics data.
Purposes and legal bases
This data is used to provide and secure the service, manage accounts and sharing, respond to requests, prevent abuse and comply with legal obligations. Processing required for the service relies on performance and our legitimate interests in security and improvement; analytics and session replay rely on your consent.
Hosting and recipients
Data is hosted and processed with Vercel and Prisma Postgres, whose database instance is located in Frankfurt, Germany. Google provides OAuth authentication when you choose it, Resend sends password-reset email and PostHog provides optional analytics. These providers access data only to deliver their services. Any international transfer is protected by the applicable safeguards.
Analytics and cookies
With your explicit consent, PostHog (European region) is used in the browser for analytics and session replay; form fields are masked. These features remain disabled without consent. Anonymous technical server errors may be sent to PostHog and aggregated measurements without marketing cookies to Vercel to protect the service and keep it reliable, based on our legitimate interests.
Retention and deletion
Account and planning data is retained while the account or planning exists. Deleting an account cascades to its related data; revoking a link removes public access. Backups are retained for the retention period configured with our providers, then deleted or replaced as they rotate.
Security
We apply reasonable technical and organisational safeguards, including access controls, protected session cookies and token-based links. No system can guarantee absolute security, so please do not include sensitive data in plannings or notes.
Your rights
You may request access to, correction, erasure, restriction of or objection to processing of your data and, where the GDPR applies, portability. You can export or delete your account in the app. For another request, use the email address above; you may also complain to the competent authority, including the Swiss Federal Data Protection and Information Commissioner.
Changes
This policy may change to reflect the service or legal requirements. The date at the top of the page identifies the applicable version.