Skip to content

Security & privacy

Workforce data deserves serious handling.

OnShift HQ is designed to keep employee, attendance, location, communication, and accountability information controlled by role and purpose.

Permissions in practice

  • Owner / adminCompany settings, pay assumptions, all reports, audit history
  • ManagerTeam live labor, tasks, events, action logs for their team
  • EmployeeOwn time, tasks, events, chats, permitted attendance history

Illustrative demo roles. Exact permissions are configured per company.

How OnShift HQ approaches workforce data

Measured language on purpose: these are the controls the product is designed around, described without guarantees or badges we have not earned.

Role-based access by design

Owners/admins, managers, and employees see only the features and records their permissions allow.

Server-side authorization
Permission checks are enforced on the backend/API, not only by hiding UI elements.
Least-privilege defaults
New roles and settings default to the least access required for normal work.

Account access

Account security follows standard, well-understood practices.

Password handling
Passwords are never stored in plain text; OnShift HQ uses a standard secure identity and authentication architecture.
Session security
Sessions use secure cookies/tokens with expiry, logout, and revocation.

Location context with a specific purpose

Optional geofence and location context relate to punch events and the work rules a company configures.

No continuous tracking
OnShift HQ records location context only at punch-related events. It is not always-on employee GPS tracking.
Permission transparency
The employee app explains when location permission is required and what happens if it is denied.

Files and photos stay permission-aware

Attachments inherit the access rules of the conversation or task they belong to and are protected from unauthorized enumeration.

File validation
File types and sizes are restricted, validated where supported, and served through signed/protected access rather than public, predictable URLs.

Important changes keep context

Time edits, action logs, sensitive profile changes, and relevant administrative settings preserve who changed what and when.

Collect only what the product needs

OnShift HQ avoids collecting employee financial, medical, payroll, or unrelated HR data.

Retention and deletion
Data retention and deletion workflows are defined in the Privacy Policy and applied consistently.
Customer control
Company administrators control their workforce data, settings, and account inside the app.

Operational security practices

Security controls include encrypted connections, patched dependencies, access logging, and monitored infrastructure.

Reporting a concern
If you believe you have found a security issue, report it through the in-app support option so it reaches the right people quickly.

OnShift HQ does not display compliance certifications it has not earned and does not describe any system as "100% secure". Questions about security are answered on the FAQ and Help pages.

Ready when you are.

Start a free trial, or read how the site and app handle information.