Skip to content

Privacy Policy

Effective: September 7, 2026

This Privacy Policy explains how OnShift HQ ("OnShift HQ", "we", "us") handles information on the public website and in the OnShift HQ application. It is written in plain language so owners, managers, and employees can understand what is collected and why.

What information we collect

Public website. The website does not include contact or lead forms and does not ask you for personal information. We collect anonymous, first-party usage events (such as which pages are viewed and which buttons are clicked) to understand how the site is used. These events are not linked to a name, email address, or phone number.

Account information. When a company creates an OnShift HQ account, we collect the details needed to run the service: company name, the account owner's name and email address, employee names and roles added by the company, and settings the company configures.

Time and attendance data. The app records punch events (clock in, clock out, break start, break end) with the time, the employee, the punch type, and—where the company enables geofencing and the employee grants permission—a location stamp for that punch event. OnShift HQ does not continuously track employee location.

Work content. Tasks, calendar events, chat messages, announcements, shift notes, action-log records, and the photos or files attached to them are stored so the company can use those features.

Pay assumptions. Companies may enter hourly or salary assumptions used only to calculate estimated labor cost. OnShift HQ does not process payroll and does not collect bank, tax, or benefits information.

How we use information

We use information to provide and operate OnShift HQ, including clock-ins, tasks, events, chats, notifications, live labor visibility, reports, and employee profiles; to keep the service secure and prevent abuse; to provide in-app support; to understand aggregate website and product usage; and to meet legal obligations.

We do not sell personal information and we do not use workforce data (such as punch records, messages, or action logs) for advertising.

Location and geofencing

Geofencing is optional and controlled by each company. When enabled, the app checks an employee's location at the moment of an eligible punch against the company's configured work address and radius. The employee's device asks for location permission and explains what happens if permission is denied. Location context is stored with the punch record so managers can review whether a punch met the company's rule.

Communications, photos, and files

Messages, photos, and files stay attached to the chat, task, or record where they were shared. Access follows the same role and membership permissions as that conversation or record. Attachments are validated for type and size and are served through protected access rather than public, guessable links.

Website analytics and cookies

The website uses a small set of first-party analytics events to measure traffic and navigation. Events never include names, email addresses, message contents, exact geolocation, or disciplinary information. Campaign parameters (such as utm_source) may be kept for your browsing session so that a free-trial signup can be attributed to the campaign that brought you here. See the Cookie Policy for details about storage used by the website.

When information is shared

We share information only with service providers that help us run OnShift HQ (such as hosting and infrastructure providers) under agreements that restrict how they may use it; when required by law or to protect the rights, safety, and security of OnShift HQ, our customers, or others; and as part of a merger, acquisition, or similar transaction, with notice where required.

Retention and deletion

Company data is retained while the company account is active. Companies can delete records they no longer need from within the app where permissions allow. When an account is closed, we delete or de-identify company data within a reasonable period, except where we must keep it to meet legal, security, or accounting obligations.

Security practices

OnShift HQ is designed to protect workforce information with role-based access enforced on the server, least-privilege defaults, encrypted connections, hashed passwords, session expiry and revocation, and audit context for important changes. No system can be guaranteed to be perfectly secure; if you believe you have found a security issue, please report it through the in-app support option.

Your choices and rights

Employees can review the attendance information their company has made visible to them inside the app. Company administrators control most settings, including geofencing, visibility, and notifications. Depending on where you live, you may have rights to access, correct, or delete personal information, or to object to certain processing. Requests can be made through the in-app support option, and we will respond as required by applicable law.

Children

OnShift HQ is a business tool and is not directed to children under 16. Companies are responsible for ensuring that the employees they add are legally eligible to work and use the service.

Changes to this policy

We may update this Privacy Policy as the product evolves. The effective date at the top of this page shows when it was last changed. Material changes will be communicated inside the app or on this website.

Related policies: Terms of ServiceCookie PolicyAccessibility