Privacy Policy for ShiftWake Alarm
Last updated: June 7, 2026
This Privacy Policy explains how we collect, use, share, and protect your personal data when using the ShiftWake Alarm mobile application (hereinafter referred to as the "App"). These rules are designed to comply with global privacy standards, including the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the US.
If you do not agree with this policy, please do not use our App.
Short Version
- ShiftWake Alarm does not sell personal data.
- ShiftWake Alarm does not use third-party advertising SDKs or cross-app tracking.
- The Android and iOS apps are designed to store alarms, tasks, preferences, selected sounds, and selected images locally on your device or in your Google account (e.g., via Firebase services) if syncing is enabled.
- The website collects only the information you submit to the registration or beta form. It uses no analytics or tracking tools whatsoever.
- Google handles App Store/Play Store billing, subscriptions, refunds, notifications, and other platform services.
1. What Data We Collect
When using the App, we may collect and process the following categories of data:
- Account Data: Email address and your chosen name or nickname. This data is obtained during registration or in the app settings.
- App and Usage Data: Your alarm settings, work schedules, shift types, and time-off records.
- Shared Data: If you choose to share your schedule or request a shift swap, the App generates a code. Users with whom you voluntarily share this code will see your name, email address, and details of your schedule/alarms.
- Analytics and Technical Data: Through Google Analytics for Firebase and Crashlytics, we automatically collect IP addresses (in anonymized form), device type, operating system version, unique device identifiers (e.g., Firebase Cloud Messaging token for delivering notifications), App usage data (interactions, screens visited), and app crash/error diagnostic data.
- Payment Data: The App may offer subscriptions or trials. All payments are processed exclusively by third parties (Google Play Store or Apple App Store). We do not collect, store, or have access to your payment card numbers.
Device Permissions and Local Data:
- Biometric Data: If you use biometric authentication (e.g., fingerprint or face recognition) to unlock the App or dismiss alarms, this data is processed strictly locally on your device. We do not collect, access, store, or transmit your biometric data to our servers or any third parties.
- Local Storage and Media: The App requests access to your device's external storage and audio files solely to allow you to select a custom alarm sound. These files are not uploaded to our servers.
2. How We Use Your Data & Legal Basis
We use your personal data exclusively for the following purposes, relying on the specified legal bases under the GDPR:
- Providing and maintaining core functionality (syncing alarms, shift management): Performance of a contract.
- Enabling user interaction (sharing schedules, swapping shifts): Performance of a contract.
- Sending service and push notifications (e.g., notification of a received shift swap request): Performance of a contract.
- Verifying and managing subscriptions or trial periods: Performance of a contract.
- Analyzing technical errors, App crashes, and usage behavior (via Firebase Analytics) to improve the App: Legitimate interest (to ensure App stability and enhancement) and/or Consent (where required by local law).
3. Data Sharing with Third Parties
We do not sell your personal data to any third parties for marketing or other purposes. We share data exclusively with reliable service providers who ensure the technical operation of the App:
- Google LLC / Google Ireland Limited (Firebase services): We use Firebase Authentication, Cloud Firestore (database), Firebase Cloud Messaging (notifications), Crashlytics (crash analysis), and Google Analytics for Firebase (usage analytics).
- App Stores (Google Play, Apple App Store): To verify the status of your payments and subscriptions.
- Other Users: Data may be disclosed to other App users only based on your explicit action (e.g., if you provide another user with your secure schedule-sharing code).
4. International Data Transfer
Because we use Google cloud services to operate the App, your data may be transferred to and stored on servers located outside your state, province, or country (including the US). These transfers are protected and subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission.
5. Data Retention Period
We retain personal data only for as long as necessary to provide our services.
- Account and Schedule Data: Retained until you delete your account.
- Shared Requests (Shift Swaps): Automatically deleted from our servers after the expiration period (e.g., 90 days from the proposed date).
- Technical Logs and Analytics: Typically retained for a maximum of 90 days.
6. Your Rights (GDPR and Global Rights)
Depending on your place of residence, you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data directly in the App.
- Erasure (Right to be Forgotten): Permanently delete your account and all associated data at any time directly through the App settings ("Settings" -> "Delete Account").
- Data Portability: Request a copy of your data in a structured, commonly used, and machine-readable format.
- Withdrawal of Consent: Opt out of receiving push notifications or analytics tracking in your device settings.
- Right to Lodge a Complaint: If you believe your privacy rights have been violated, you have the right to lodge a complaint with the data protection authority in your country of residence.
7. Additional Rights for California Residents (CCPA)
In compliance with the CCPA, we explicitly state that we do not sell your personal data ("Do Not Sell My Personal Information"). You can exercise your rights to access or deletion directly in the App or by contacting us via email.
8. Children's Privacy (COPPA / GDPR-K)
Our App serves as a tool for managing work shifts and alarms and is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently obtained data from a person under 16, we will take steps to immediately delete such information from our servers.
9. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes directly in the App or by updating the "Last updated" date at the top of this document.
Data Retention After Deletion
Upon account deletion, all your personal data, schedules, and settings are permanently erased. However, we securely retain a minimal technical log (such as the cryptographically hashed email address, timestamp, and IP address) regarding your acceptance of our Terms of Service and Privacy Policy. This isolated log is kept solely for the purpose of demonstrating compliance and defending against legal claims, as permitted by GDPR Article 17(3)(e).
10. Contact Us
If you have any questions, requests, or concerns regarding this Privacy Policy, you can contact us:
- By email: info@shiftwake.com
- Operator: Registra SK s. r. o.
Registered office: Predmier 280, 013 51 Predmier, Slovak Republic
Company ID (IČO): 55376886
Tax ID (DIČ): 2121961072
Registered in the Commercial Register of the District Court Žilina, Section: Sro, Insert No. 81819/L