Privacy Policy
Effective [date — set on publish]
1. Who this applies to
ShiftSync (“ShiftSync”, “we”, “us”) is a multi-tenant operations platform for telemarketing and lead-generation agencies (“Agencies”, “Customers”). This policy covers three groups of people whose data passes through the platform: Agency staff (agents, team leads, QA, management roles), the Agency's own clients who are given read-only access via the client portal, and visitors to this website. Each Agency is the data controller for its own staff and client records; ShiftSync acts as the data processor operating the platform on the Agency's behalf, except for the account and billing data we hold directly as the merchant of record for the subscription itself.
2. Data we process
- Account & billing data — Agency owner name, work email, company details, and payment data. Card payments are handled by Kashier; we do not store full card numbers.
- Staff data — name, role, contact details, schedule and attendance records, call-disposition and QA-review outcomes, commission and payroll figures, and staff-advance records, entered by the Agency or its team leads.
- Call data — call metadata (duration, wrap time, disposition) ingested from the Agency's own dialer integration, and recordings where the Agency's dialer provider makes them available. ShiftSync does not place or record calls itself — it ingests what the Agency's own dialer produces.
- Client portal data — contact details of the Agency's clients, provisioned by the Agency, used solely to give that client a read-only view of their own contracts, campaigns, delivered leads, and invoices.
- Usage & device data — log-in activity, IP address, browser/device information, and product-usage analytics, collected automatically.
3. Why we process it
- To operate the platform — scheduling, attendance, QA, lead delivery, commission payroll, and the client portal.
- To bill and manage subscriptions.
- To secure the platform — authentication, tenant isolation, fraud and abuse prevention.
- To provide support and respond to requests.
- To improve the product, using aggregated or de-identified usage data wherever practical.
4. Who we share it with
We do not sell personal data. We share data only with the sub-processors needed to run the service: our database and hosting infrastructure (Supabase), our payment processor (Kashier), and, on Enterprise plans, transactional/bulk email delivery infrastructure used on the Agency's behalf. Call data flows from the Agency's own dialer provider into ShiftSync at the Agency's direction — we are not a party to the Agency's contract with its dialer provider, and any call-recording consent obligations under local telecom or wiretap law rest with the Agency and its dialer provider, not with ShiftSync.
5. Data isolation & security
Every Agency's data is isolated at the database layer by row-level security policies — no Agency can query or view another Agency's staff, leads, or clients. Data in transit is encrypted (TLS). Access to production data is limited to what's required to operate and support the platform. Enterprise plans add enhanced data-privacy controls and governance over outbound bulk/transactional email. No platform is unbreachable; if we become aware of an incident affecting your data we will notify the affected Agency without undue delay.
6. Retention
We retain data for as long as the Agency's account is active, and for a limited period afterward to allow account recovery and to meet legal, accounting, and audit-log obligations. An Agency can request deletion of its data on account closure, subject to records we're required to retain by law (e.g. billing history).
7. Your rights
If you are an Agency staff member or client-portal user, requests to access, correct, or delete your personal data should go to your Agency first, since the Agency controls that data — we act on the Agency's instructions. If you are an Agency itself, or your Agency is unresponsive, contact us at support@getshiftsync.app and we will assist directly.
8. International transfers
ShiftSync serves Agencies across regions and may process and store data outside the country where an Agency or its staff are located. Where required, we rely on our sub-processors' own safeguards for cross-border transfer.
9. Children
ShiftSync is a business tool for employers and is not directed at, or knowingly used by, children.
10. Changes to this policy
We'll update the effective date above when this policy changes, and where a change is material we'll tell Agency owners directly.
11. Contact
Questions about this policy: support@getshiftsync.app