Private workspaces
A signed-in workspace stores the information needed to build schedules, such as employee names, roles, availability, time off, staffing rules, schedules and any optional cost figures you enter. Exact wages are not required; a relative cost signal can be used instead. Employee email addresses are optional.
Files and AI interpretation
Uploaded files are read for the requested interpretation; the original image or spreadsheet is not kept as an uploaded file. To support review and troubleshooting, Shiftly stores the text you submitted or text extracted from a file, its filename, the structured interpretation and any error details in an encrypted audit record. If cloud interpretation is selected, the submitted content needed for that request is sent to the currently configured AI provider. Do not upload information that is not needed for scheduling.
Anonymous demo
The demo uses an HTTP-only browser cookie to keep each visitor's sample workspace separate. The demo cookie expires after 24 hours. Basic traffic records can include the IP address, browser user-agent, page or endpoint, response status, referring site and campaign tags so the team can diagnose failures and understand how people find the product. These records are not shown to other visitors.
Product learning and improvement notes
The admin learning view summarizes first-party demo-session activity, AI outcomes and core API errors from records Shiftly already keeps. Per-action demo audit details used by this view are deleted after 180 days when the learning data is next read. Funnel percentages use one cohort of newly created demo sessions; AI and API rates count attempts or requests, not people, and may include signed-in use. The summary does not copy IP addresses, browser strings, employee details, wages, schedules, uploaded content or typed requests. Crawler detection is a browser-string heuristic and cannot verify a person. An administrator may add a sanitized summary of customer or manager feedback, then track a testable hypothesis, owner role and success measure. Improvement hypotheses and review notes are encrypted and admin-only; records are deleted 365 days after creation the next time the learning data is read. Do not include names, contact details or private information.
AI assistant connections
An MCP-compatible assistant can connect only after a signed-in manager approves the requested access and explicitly selects one or more store workspaces. The manager can review and disconnect approved assistants in Connection settings; after disconnection, the service rejects that assistant’s access token. The assistant may receive staff names, roles, availability, time off, rules and schedule context from only the selected stores as needed for the task; exact hourly pay rates are omitted, although a draft may include an aggregate cost estimate. Usage events are linked internally to the signed-in account for aggregate counts and include the assistant-client label, tool name, outcome and time. This separate usage view does not copy prompts, tool results, rosters or uploaded content, and records are removed after 180 days when the admin panel is next refreshed. General operational access logs may still record IP address, browser user-agent, endpoint and status. A separate, optional permission allows the assistant to send a generalized feedback note. Feedback is encrypted, visible only to platform administrators, and removed after 180 days when the admin panel is next refreshed. Do not include employee names, contact details, wage amounts, exact shift contents, uploaded text or private store details. An assistant cannot change saved settings, confirm or publish a schedule.
Public demo for AI assistants
No account is needed, and only fictional sample teams are used. The signed demo ID contains a sample-industry identifier and expiry, not a merchant identity; it is signed, not encrypted. Shiftly reconstructs the sample workspace when needed instead of saving it on the server. The ID expires after two hours. Demo instructions and generated schedules are returned to the calling assistant and are not stored in the demo workspace or MCP usage metrics. Aggregate tool and outcome counts and a daily count of natural-language demo requests may be recorded without their contents. Natural-language instructions and relevant fictional setup are sent to Shiftly’s configured scheduling parser, which may use a cloud AI provider; that provider’s privacy practices also apply. Standard operational access logs may separately include IP address, browser user-agent, endpoint and response status. Do not send real staff, customer or store information.
Contact and billing
If you submit the contact form, your name, email and any optional phone, store name or message are stored so the team can respond. The first and most recent source, campaign, referring site and entry page are also attached to the request to understand how people find Shiftly. New contact requests are not linked to anonymous demo sessions by an IP-derived visitor code; older requests may still contain a pseudonymous visitor code from the previous setup. Billing choices and subscription events are recorded to operate checkout and understand which plan was selected. First- and last-visit campaign details are kept in this browser for up to 180 days; billing funnel events are retained for 180 days. Submitted contact requests, including their source labels, do not yet have a published deletion schedule. Card details are entered in Stripe Checkout; Shiftly does not ask you to send card numbers by email.
What to avoid entering
- Do not upload identity documents, bank details or unrelated personal conversations.
- Use employee names only when needed; employee email is optional.
- Use relative cost levels if you do not want to enter actual pay.
- Check extracted text and rules before applying them to a schedule.
Retention and questions
The anonymous demo cookie expires after 24 hours. Access logs, billing attribution and funnel events have a 180-day limit; access logs are cleaned when a new access is recorded or an administrator opens the access-log view. Demo action details and MCP usage/feedback records are deleted after 180 days when their admin panel is next read, and product-improvement notes are deleted 365 days after creation when the learning data is next read. Other contact, workspace, demo-session and audit records do not yet have a published, product-wide deletion schedule. If you need information about a record or want to discuss a data request, contact [email protected]. We will review requests manually.