ShiftPay: Shift Calculator (“ShiftPay”) is published by Ynoxa. This policy covers the Android app, package com.ynoxa.shiftpay, and its web dashboard.
The short version
ShiftPay is local-first: calculations and core features work offline without an account. If you choose Google sign-in, the work data you enter is stored in your private Firebase account so it can sync with your other devices and the web dashboard. We do not sell personal data or send your work data to advertisers. In the Android app, limited Firebase usage analytics is on by default and can be turned off during setup or later in Settings. The web dashboard uses limited Firebase Analytics for fixed feature and app-session events, the Android app embeds no remote crash reporter, and the free Android app uses Google AdMob.
1. Data you provide
- jobs, employer and role labels, pay rates and pay-rule settings;
- shift dates and times, breaks, statuses, notes, allowances and estimated earnings;
- profile and app settings, including your timesheet display name; and
- when you sign in, your Google display name, email address and Firebase user identifier.
Without sign-in, work data stays in the Android app’s private storage. With sign-in, supported work records—including jobs, shifts, shift types and templates, allowances, leave balances, payslip checks and roster patterns—are copied to Google Cloud Firestore under your authenticated user ID. The web dashboard reads and edits that same data. Pay calculations continue to run on your device.
If you deliberately create a schedule, shift-offer or swap link, ShiftPay uploads an expiring snapshot containing the selected dates, times and shift type and, when you choose that detail level, job labels. A shift type can reveal information such as sick leave to anyone with the link. Pay rates, earnings and shift notes are not included in those shared snapshots.
Friend calendars, alerts and visual exports
Friend sharing is optional. When you invite someone, we store your display name and verified email, their chosen sign-in email, invitation status and the schedule detail you select. Only that verified account can accept. You can enter the email or select one through the system contact picker; ShiftPay does not request access to your full address book. Accepting an invitation does not share a calendar back.
Accepted friends can see your next 30 days of availability, shift times, or optional job names according to your choice, including availability hours and travel/rest buffers. These projections refresh when your app syncs. They exclude pay, rates, notes and leave reasons. Either person can remove the connection. Colours and display preferences stay on the device. Offline copies may be retained by Firebase, but the app marks cached or stale schedules and requires a current server read for shared-calendar exports.
Optional change alerts periodically read calendars you select and store a comparison snapshot on this device. Quiet hours and Android notification settings apply, and Android may delay background checks. Notifications contain no friend names or shift times. Signing out clears alert comparison history. The home-screen month widget shows your own shifts only.
Visual calendar PDF and image exports exclude pay, notes and device-calendar events. Job names and visible friends are included only if you select them in the preview. You choose where files are saved and whether to send them. Saved or received copies cannot be revoked through ShiftPay.
2. Optional account and sync
An account is optional. ShiftPay uses Firebase Authentication with Google sign-in. Firestore security rules restrict personal sync documents to the signed-in account that owns them. Android also keeps an offline copy so the app remains useful without a connection. Signing out does not delete that device copy.
Sync uses a last-change-wins merge. Avoid editing the same item simultaneously on two offline devices. You can also export and import a JSON backup from the Android app.
3. Analytics controls and diagnostics
In the Android app, limited Firebase usage analytics is on by default. You can turn it off during setup or later at Settings → Privacy → Usage analytics. An opt-out is applied before app-authored events are allowed. Analytics may record limited feature, campaign and app-session events, such as onboarding completion, shift creation, exports, sign-in, Premium-screen views and whether sync succeeded. The web dashboard uses limited Firebase Analytics automatically for app-session and fixed feature events such as sign-in, dashboard, job, roster and shared-schedule activity. We deliberately do not put employer names, notes, shift times, schedules, rates, earnings or other work-content values in analytics events.
ShiftPay embeds no Firebase Crashlytics or other remote crash-reporting SDK. Release crashes and ANRs are reviewed through Google Play Android vitals, while app-authored diagnostics remain on the device. Firebase Analytics, when enabled, may process app-instance identifiers, device and operating-system information, app interactions and campaign attribution. The on-device ML Kit text recognizer may send limited usage and diagnostic metadata, but roster and payslip images and recognized text are not uploaded. Google handles this data under its Privacy Policy.
4. Advertising
The free Android app displays Google AdMob ads. Depending on your region and choices, Google may process advertising identifiers, IP-derived approximate location, device information, app and ad interactions, and diagnostic data for ad delivery, measurement, security and fraud prevention. Google’s User Messaging Platform presents privacy choices where required; you can reopen them from Settings → Privacy options. Jobs, schedules, notes, rates and earnings are not sent to AdMob.
5. Optional purchases
ShiftPay may offer an optional ad-removal purchase through Google Play. Google processes payment details; we do not receive your full payment-card or bank-account information. The App uses Google Play Billing to receive purchase status, product and transaction identifiers, acknowledgement state and entitlement status so it can remove ads, restore the purchase or restore ads when an entitlement ends. Product availability, purchase type and price are shown in the App before purchase.
Google handles purchase information under its Privacy Policy and Google Play terms. Jobs, schedules, notes, rates and earnings are not sent to Google Play Billing or attached to a purchase.
6. Permissions and security
- Internet and network state support sync, sign-in, analytics, diagnostics, ads and consent.
- Notifications are used for shift and weekly reminders and optional friend-calendar change alerts that you control.
- Optional calendar access lets ShiftPay create, update and remove only linked shift events in the primary writable calendar available on your device. With read access, device events can also be used locally to find time together; event contents are not uploaded. The local calendar event identifier is not uploaded, backed up or included in analytics. If you decline, one-time .ics export remains available.
- ShiftPay does not request contacts, SMS, call logs, precise location, camera or broad storage access.
Network traffic uses HTTPS. Production Android requests can additionally be protected with Firebase App Check and Google Play Integrity. No internet service is risk-free, so keep an export if the data is important.
7. Retention and deletion
- Local work data remains until you delete it in the app, clear app storage or uninstall.
- Synced work data remains while your account is active or until you delete the account/cloud data.
- Analytics, advertising, SDK diagnostic and purchase data follow Google’s applicable retention controls and policies.
In Android, open Settings, find Account & sync, then tap Delete account & cloud data. On the web, use Settings or our account deletion page. This removes your Firebase Authentication account and synced profile, jobs, shift types and templates, allowances, shifts, leave balances, payslip checks, roster patterns, owned schedule links and friend-sharing connections. Removing a connection prevents further access through the app; previously saved exports cannot be withdrawn. Delete the local Android copy separately with Delete all data.
Deleting your ShiftPay account does not cancel a Google Play subscription or delete a Google Play purchase. Manage or cancel subscriptions in Google Play.
8. Sharing and sale
We do not sell your personal information. Google processes data as our service provider for Firebase and as an independent provider for advertising, as described above. We may disclose information if required by law or to protect users, the service or our rights.
9. Children and your rights
ShiftPay is not directed to children under 13. Depending on your location, you may have rights to access, correct, delete or restrict processing of personal data. The in-app and web deletion controls are the fastest way to delete account data; you can also contact us.
10. Contact and changes
Privacy questions: support@ynoxa.com. We will update this page and its date when material practices change.