Privacy policy

Last updated 2026-08-09.

What we collect

Account and organization data (name, email, role) via Clerk; time & attendance data you or your team enter (clock in/out times, breaks, shift patterns, and an optional GPS location captured only if you allow it on clock-in/out); and billing details, handled directly by Stripe, we never see or store your card number.

Why

Solely to run the product: authenticate you, record and report on time worked, bill your organization's subscription, and send transactional email (invites, billing notices). We don't sell data or use it for advertising.

Subprocessors

Services that process data on our behalf, and each one's own Data Processing Agreement:

  • Clerk, Sign-in, organization/team membershipDPA
  • Supabase, Database (organizations, memberships, time entries, timesheets)DPA
  • Stripe, Billing and payment processingDPA
  • Resend, Transactional email (invites, notifications)DPA
  • Vercel, Application hostingDPA

Retention

Time & attendance records are kept for as long as your organization is subscribed, plus a reasonable period after cancellation in case of a payroll or legal dispute. One exception: audit log entries (who corrected which time entry, when, and why) are kept permanently and can't be edited or deleted by anyone, including us, that's what makes them trustworthy as a record.

Your rights

You can request an export of your organization's data, or request that your organization's account and data be deleted, from Account settings (Owner/Admin), look for "Data & privacy." These are handled by a person, not instantly: we'll follow up by email, typically within a few business days. Deletion doesn't remove audit log entries, for the reason above.

Contact

Questions about this policy or a data request: get in touch. That form is for privacy and data only, not product demos (Request a demo).

This page describes what Aerta Shift actually does, in plain language. It is not a substitute for legal advice, before real customer data is processed at scale, have this reviewed by a qualified privacy/data-protection lawyer for your jurisdiction.