Privacy Policy
繁體中文OmyShift ("we", "us") provides the OmyShift shift schedule app (the "Service"). This policy explains what personal data we collect, why, where it is stored, how long we keep it, and how you can exercise your rights. It is written in accordance with the Personal Data Protection Act of Taiwan (R.O.C.). If this English version differs from the Traditional Chinese version, the Traditional Chinese version prevails.
1. Summary
- You can use the app without signing in. In guest mode your schedule stays on your phone and is never sent to us.
- Data is synced to the cloud only after you sign in. Only you can read and write your cloud data. Other people see part of it only when you choose to share it with them.
- We do not sell personal data, show ads, or track you across other apps or websites.
- You can delete your account in the app at any time, and your cloud data is permanently deleted.
2. Data we collect
2.1 Data that stays on your phone
Shift types, rotation patterns, schedule entries, leave, notes, pay settings, app settings, and any backups or images you export. When you are not signed in, none of this is sent to us. Shift reminders are scheduled on your phone and do not go through our servers.
2.2 When you sign in and sync
| Data | Purpose |
|---|---|
| Identifier and email address provided by Apple or Google (with Apple's "Hide My Email", we only receive the relay address) | To create and identify your account. Your email is never shown to other users. |
| Shift types, rotation patterns, schedule entries, leave and balance adjustments, notes | To sync between your devices. |
| Job names, hourly or monthly pay, overtime multipliers | To sync between your devices and calculate income. Synced to you only and never shared with anyone. |
| Display name (entered by you) | So people you share with know who you are. |
| Push token, device platform, language | To send push notifications (for example, when a shared schedule changes) in your language. |
2.3 Sensitive data: leave types
Some leave types (for example menstrual leave, prenatal checkup leave, pregnancy rest leave, or miscarriage leave) may reveal health, sex, or pregnancy status, and are special categories of personal data under Article 6 of Taiwan's Personal Data Protection Act. We store this data only at your direction when you sign in, to sync it between your devices. When you share a schedule, all leave is shown only as "Leave" by default, without its name or color. People you share with can see the leave type only if you explicitly turn on "Show leave names" in the app.
2.4 Analytics
We use Google Firebase Analytics to understand how the app is used, such as active users, retention, and which screens are used most.
- We do not collect advertising identifiers (IDFA on iOS or the advertising ID on Android) and do not use the data for advertising.
- We do not link analytics to your account, and events do not include schedules, names, or notes.
- You can turn off "Analytics" in the app's settings.
2.5 Pro purchases
Payments are processed by the Apple App Store or Google Play. We never receive your card or payment details. To verify and restore purchases, we receive transaction records (plan, time, subscription status) and an anonymous user identifier through RevenueCat.
2.6 Reports
If you report another user, or another user reports you, we keep the reason, the handling status, and a copy of the reported content (such as a display name) as it was at the time of the report, in order to handle violations.
2.7 Feedback
When you send feedback from the app, we receive what you write, any screenshots you upload, your email address if you choose to leave it, and the app version, OS version, device model, and language that the app attaches automatically. We use this to understand issues and reply to you. The feedback form is provided by Tally.
3. Sharing your schedule
You can invite specific people to view your schedule. They can view it but cannot edit it.
- They can see: the shift names, times, colors, and schedule of the jobs you choose to share, and your display name.
- They cannot see: your email, pay and overtime multipliers, overtime and leave hours, or jobs you have not shared. Leave types and notes are hidden by default and shown only if you turn on the corresponding setting.
- They can only see entries from 31 days ago onward.
- You can remove a member or stop sharing at any time, and they lose access immediately.
4. How we use data
Only to provide and maintain the Service (sync, sharing, push notifications, purchase verification), respond to your inquiries and reports, prevent abuse, and improve the app. We do not use your personal data for any other purpose, and we never sell or rent it to anyone.
5. Where data is stored and service providers
We use the following providers to process data. They may process it only on our instructions and not for their own purposes.
| Provider | Data processed | Location |
|---|---|---|
| Supabase | Account, synced and shared data | Japan (Tokyo) |
| Google Firebase (Cloud Messaging, Remote Config, Analytics) | Push tokens, app configuration, analytics | United States and other Google data centers |
| Apple, Google | Sign-in, payments | Per each company's policy |
| RevenueCat | Purchase records | United States |
| Tally | Feedback | European Union |
Apart from these providers, we disclose personal data only when required by law, such as a lawful request from a court or law enforcement.
6. Retention
- Cloud account and schedule data: until you delete your account.
- Individual items you delete: the deletion record is kept in the cloud for 90 days so your other devices can sync the deletion, then permanently deleted.
- Push tokens: deleted when you sign out, and automatically deleted if not updated for 90 days.
- Share invitations: deleted within 7 days after they expire or are used.
- Reports: deleted 180 days after they are resolved. Ban records are deleted when the ban ends.
- Firebase Analytics event data: kept for 2 months.
- Feedback: kept until no longer needed. You can ask us to delete it at any time by email.
7. Deleting your account
You can delete your account on the Account screen in the app. Your cloud account, schedules, sharing relationships, and push tokens are permanently deleted immediately and cannot be recovered. Schedules on your phone are kept, and you can continue using the app as a guest.
To prevent banned users from re-registering after deleting their account, if your account was banned or reported we keep a hash value that cannot be used to identify you, until the retention period above ends. For all other users, we keep nothing after account deletion.
8. Your rights
Under Article 3 of Taiwan's Personal Data Protection Act, you may ask us to:
- let you inquire about or review your personal data;
- provide a copy of it;
- supplement or correct it;
- stop collecting, processing, or using it;
- delete it.
Email us at support@omyshift.com from the email address of your account so we can verify your identity. We respond to requests to inquire or review within 15 days and to other requests within 30 days. You can also edit or delete most data directly in the app.
If you choose not to provide this data (for example, by not signing in), you can still use the app's local features, but not sync or sharing.
9. Security
All data is encrypted in transit (HTTPS). Cloud data is protected by database access rules so that only you and the people you share with can read it, and we test these rules regularly. No method of transmission over the internet is completely secure; if a personal data breach occurs, we will notify you as required by law.
10. Children
The Service is not designed for children. Users under 18 should use the Service and purchase Pro only with the consent of a parent or legal guardian.
11. Changes
We may update this policy when the Service or laws change, and we will update the effective date on this page. We will notify you in the app of significant changes.
12. Contact
OmyShift
Email: support@omyshift.com