1. Who we are
Shiftzilla is operated by 2842192 Alberta Ltd., Edmonton, Alberta, Canada. This notice explains how we handle personal information in our website, apps, and restaurant workspaces. Contact our privacy team at privacy@shiftzilla.ca.
Your employer or the organization running your workspace decides which workplace records to create, who may access them, and how they are used for its business. We process those records to provide the service. We are also responsible for our own account administration, support, security, and business records. Your organization's workplace privacy notice applies to its use of your information.
2. Information we handle
The information depends on the features you and your organization use:
- Account and profile: name, email, account identifier, sign-in and verification details, birth date and other profile information, phone number, emergency contacts, invitations, organization and store memberships, and access level.
- Workplace records: shifts, availability, time-off requests, hourly pay rates, tasks, training, form responses, applications, interview responses, employment documents, evaluations, and operational records supplied by you or your organization.
- Content you provide: messages, comments, support requests, selected photos, recordings, documents, and other attachments. Content can identify you or other people. Only provide information you are authorized to share and need for the task.
- Service and security information: IP address, browser or device information, session identifiers, request times, bounded error details, access and security events, and notification registration identifiers when that feature is used.
- Business enquiries and transactions: demo requests, business contact details, correspondence, and applicable organization subscription, order, or reimbursement records. The mobile app does not collect card details for an in-app purchase.
Clerk handles sign-in credentials and authentication. Do not put passwords, authentication codes, payment-card details, or unrelated sensitive information into messages or ordinary uploads.
3. Why we use it
We use this information to sign you in, check workplace access, provide the features you use, deliver requested communications, answer enquiries, maintain service security, investigate misuse, resolve faults, handle privacy requests, and meet applicable legal obligations.
We do not sell personal information or use identifiable workplace content for third-party advertising. The app does not use an advertising identifier. Optional AI or connected-service access requires a separate feature-specific explanation and authorization; this notice does not authorize transferring everyone's workplace records to an AI service. The mobile release does not enable third-party AI recommendations without the required consent controls.
4. Who receives information
Workspace information is available to its authorized audience according to organization, store, role, and record permissions. Your organization administers that access. Messages and shared records are visible to their authorized recipients; they are not a private conversation with Shiftzilla support.
If you submit post-shift feedback, the rating, tags, comment and shift details identify you to Level 3 and Level 4 in that store. Other team members cannot read your answers. Feedback responses are kept for up to 365 days, and expired prompt state is removed after seven days. You can request access or deletion through the account privacy process; authorized exports held by your organization are subject to its own responsibilities.
Your optional birth date stays in your private account profile. Birthday sharing defaults to off. If you explicitly enable it in My Hub, Zilla can post a deterministic greeting and mention you in the public Birthdays channel of each store you currently belong to. Members can infer the birthday's month and day from the post; your birth year and age are not included or sent to OpenAI. Disabling sharing stops future greetings, and clearing your birth date also disables sharing. Previous greetings remain shared message history and are handled through the account privacy and shared-history review process.
You can choose a messaging presence and optionally share a short custom status with authorized colleagues in stores you currently belong to. Choices sync through your private account profile. Invisible hides your online activity and last-active time from colleagues; messages you post remain visible to their authorized audience. Custom status expiry uses server time and the store's time zone. Clearing a status removes it from future presence projections. Account erasure removes the private status preferences.
Application traffic uses HTTPS. Server-side access checks protect workplace records and private file access. We limit access according to the task and apply request validation, rate limits, and security monitoring. See our security page for reporting concerns.
We use these providers to operate the service:
- Clerk: account authentication, verification, invitations, and session management.
- Cloudflare: website and app hosting, server processing, D1 workspace data, protected R2 file storage where enabled, Stream video where enabled, security infrastructure, and email routing.
- Google email services: correspondence sent to our support, privacy, security, and demo contact addresses after routing through Cloudflare.
- Apple and Google notification services: device notification delivery when configured and enabled for your device.
- MET Norway: weather forecasts using the configured restaurant location. This request comes from our server and uses store coordinates, not your phone's GPS location.
- OpenAI: optional Zilla text and voice processing when you use Zilla (in the iOS and Android apps, after you choose Allow on Zilla's one-time consent screen). Audio or chat messages, recent messages of the current chat (and, when you refer to an earlier chat, short excerpts of your own earlier Zilla chats) and the authorized workspace information needed to answer your requests are sent to OpenAI. The app never receives Shiftzilla's provider API key.
Zilla
When you use Zilla, by text or voice, your message and the authorized workplace information needed to answer it are sent through OpenAI's API to OpenAI, which processes them as our service provider. OpenAI does not use API data to train its models. It may keep API data for up to 30 days to monitor for abuse, then deletes it. On the web, using Zilla is your choice to send it; there is no separate in-app screen. In the iOS and Android apps, before you first use Zilla, the app shows a screen titled Zilla uses OpenAI and asks you to choose Allow or Not now. It says: "What you say to Zilla is sent to OpenAI to answer you. OpenAI doesn't train its models on your conversations. It keeps them for up to 30 days only to prevent abuse, then deletes them." In the apps, nothing is sent to OpenAI, and the microphone is not requested, until you choose Allow; if you choose Not now, the app asks again the next time you use Zilla. We ask once, and again only if this disclosure changes or after you withdraw. In the apps you can withdraw at any time in My Hub, under Profile & Settings (Zilla & AI); Zilla then stops sending your requests to OpenAI until you allow it again. On the web, simply don't use Zilla. Choosing Not now or withdrawing does not affect other app features. During a voice call you can also mute the microphone or end the call. OpenAI may process the information outside Canada. Its processing is also subject to OpenAI's privacy policy.
Shiftzilla does not save voice-call audio or speech captions. Information you ask Zilla to save, such as an authorized workplace update, becomes an ordinary workplace record under that feature's permissions and retention rules. Avoid passwords, payment details and unrelated sensitive information. AI can make mistakes; check proposed changes before confirming them.
Zilla text chat shares one private history across the Schedule Builder and Messages surfaces for your selected account and restaurant. Shiftzilla keeps completed chat messages, short tool-status summaries and proposal references for up to 30 days. Use Clear chat history (in the Chats menu of the Zilla chat) to remove that history from both surfaces. Schedule proposals expire after 20 minutes and require an explicit Apply action in the Schedule Builder; a typed chat instruction does not apply or publish them. Text requests are sent with OpenAI's response storage turned off, so OpenAI keeps no retrievable copy of the generated response; the up-to-30-day abuse-monitoring retention described above still applies. Text chat never starts a microphone session.
Shiftzilla keeps one consent receipt for you: the consent version, your account and the time you allowed or withdrew consent. A current receipt is kept until you withdraw or the disclosure changes; withdrawn or replaced receipts are deleted after 90 days. Receipts contain no audio, captions, chat messages or provider credentials and are included in account privacy processing.
Use Report Zilla in the voice or chat controls to report an incorrect answer, unsafe content or a privacy concern. Reporting during voice ends the call. Only your selected reason and optional written details are saved for Shiftzilla support; audio, captions and chat history are not attached. Reports are private to Shiftzilla support, included in account privacy processing, and removed by the scheduled cleanup after 90 days.
If you choose a supported external integration, its connection screen identifies the service and requested access. Information you choose to send to it is also subject to that provider's terms and privacy notice. We may disclose limited information when legally required or necessary to investigate misuse and protect people's rights and security.
Providers can process information outside Canada, where local laws may permit government access. A Canadian domain does not mean all information stays in Canada. Contact us for information about the providers relevant to your account.
5. Device permissions and local storage
Camera, microphone, and selected-photo access support actions such as adding evidence or recording an interview when those features are available. Calendar access adds shifts at your request. Notifications are optional. You can change device permissions in system settings; denying one may prevent the related action.
The app does not request device location or address-book access. Sign-in sessions and necessary preferences are stored by the app or authentication provider. Your language choice and choice to hide a store setup checklist can be saved to your account so they follow you across devices. Cookies and similar storage support authentication and site operation. Signing out or uninstalling the app does not by itself delete your server-side account or workplace records.
6. Retention and deletion
Account information and workplace records remain while needed to provide the service and administer the workspace. Removing workplace access does not automatically erase employment records or information shared with other people.
You can request account deletion through account privacy, including after workplace access ends. In the app, open My Hub → Profile → Delete account. We verify account ownership before processing a request. See account deletion for the steps. Contact privacy@shiftzilla.ca if you cannot sign in.
A submitted request starts a review; it is not a confirmation that every copy has been erased. After verification, we remove the account identity, sign-in access, memberships, invitations, and private profile information. Shared workplace operational history may remain when the organization needs the record; we remove direct account attribution and show Deleted user instead. Employment, transaction, dispute, security, or other records may need to be retained for a specific purpose or legal requirement. We explain any applicable retention and its duration in the response; we do not treat all workplace records as permanently exempt from deletion. An organization may need to transfer ownership or close its workspace before its sole owner's account can be removed.
Encrypted recovery copies expire 30 days after verified deletion is completed. They are restricted to disaster recovery and are not used in the active service. If a recovery copy is restored during that period, deletion restrictions and anonymization must be reapplied. We keep a minimal deletion-security tombstone for 31 days after verified deletion is completed so a restored recovery copy cannot reactivate the deleted account. The tombstone contains the former authentication subject, deletion request reference, status, and expiry controls; it is not available in an active workspace. Copies exported by your organization or other authorized recipients are subject to their own responsibilities. Contact us about the retention or deletion of a particular record.
7. Your choices and rights
You may ask to access or correct your information, withdraw consent where processing relies on consent, or request deletion, subject to applicable law. Optional permissions and integrations can be turned off without granting them access to other features. Necessary account information is required to use a private workspace.
We may need to verify identity and involve the organization responsible for workplace records. We will not ask for your password by email. If you disagree with our response, contact our privacy team; you may also raise a concern with the privacy regulator responsible for your jurisdiction.
Shiftzilla is a workplace service, not a service directed to children. Organizations must ensure their use is appropriate and lawful for their workforce, including young workers.
8. Changes and contact
We update this notice when our practices change and show the effective date above. Material new uses require the notice or consent applicable to that change. For privacy questions, contact 2842192 Alberta Ltd. at privacy@shiftzilla.ca. For account help, use support@shiftzilla.ca.
Back to top