Data Processing Addendum

Last updated: 2026-08-19 · Cut the Shift LLC (Ohio)

These terms are in effect for the public beta. A licensed attorney has not yet completed a review. We may update this page after counsel markup. Questions: contact us.

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between Cut the Shift LLC ("Processor," "we," "us") and the customer entity accepting the Terms ("Controller," "Customer," "you"). Version 2026-08-19.

If you need a wet-ink or PDF countersignature after attorney review, contact us. Accepting the Terms includes this DPA.

1. Roles and scope

For Customer Personal Data in Customer's tenant (primarily worker and manager data), Customer is the controller (or "business" under the CCPA) and we are the processor (or "service provider"). We act as an independent controller for account/billing contacts, product analytics and security data it determines the purposes for, and website visitor data, as described in the Privacy Policy — except that we will not use Customer Personal Data to train models for other customers and will not sell Customer Personal Data.

Subject matter: providing the Service (scheduling, timeclock including geofenced punches, tips/checkout when enabled, and related tools) via web and iOS. Duration: the term of the agreement plus post-termination retention/deletion below. Data subjects: Customer's workers, managers, and other individuals Customer invites.

Categories include identifiers; employment/timeclock data; precise geolocation at punch; tip ledger and optional payout-destination metadata; device/usage logs generated in the tenant; and files Customer stores.

2. Customer responsibilities

Customer is solely responsible for the lawfulness of processing, including notices and consents for timekeeping, precise location / geofencing, electronic monitoring, payouts, and inviting minors ages 14–17 where lawful. Customer will not submit biometric templates for face/fingerprint clock-in unless separately agreed — those are out of scope today.

3. Processor obligations

  • Process Customer Personal Data only on Customer's documented instructions, including this DPA and the Terms, unless required by law (in which case we notify Customer unless legally prohibited).
  • Ensure persons authorized to process Customer Personal Data are bound by confidentiality.
  • Implement the security measures in Annex II (see Privacy Policy §8 and this page).
  • Assist Customer with data-subject requests. Where a request is made directly to us and identifies Customer, we will notify Customer and not respond as controller except to redirect or as legally required.
  • Provide reasonable assistance for data-protection impact assessments regarding processing in the Service, including systematic location verification of workers.
  • Notify Customer without undue delay and in any event within 72 hours after becoming aware of a Security Incident affecting Customer Personal Data, and provide information reasonably available to assist Customer's notification obligations. Notification is not an admission of fault.
  • Not sell Customer Personal Data; not use it to train models for other customers; not combine it with personal data from other sources except as permitted for a service provider (for example security and debugging) or with Customer's direction.

4. CCPA service-provider terms

We will not: (a) sell or share Customer Personal Data (as those terms are defined under the CCPA); (b) retain, use, or disclose Customer Personal Data outside the business relationship or for any purpose other than the business purposes specified in the agreement, except as otherwise permitted for service providers; or (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Processor and Customer. We certify we understand these restrictions. Precise geolocation will be processed only for Service features Customer enables, not for unrelated secondary purposes.

5. Sub-processors

Customer authorizes us to engage sub-processors listed at /legal/subprocessors. We will impose written data-protection terms on each that are no less protective than this DPA in material respects, and we remain responsible for their performance of those obligations.

We will post updates to that list. For material new sub-processors we will provide at least 15 days' notice via the account-admin email or this page (emergency security replacements excepted, with notice as soon as practicable). Customer may object on reasonable data-protection grounds within 15 days. If unresolved, Customer may terminate the affected Service as its sole remedy.

We rely on each vendor's standard data-processing terms. Our signed copies of every vendor DPA are still being collected — that is a founder operations task, not a claim that they are already countersigned.

6. International transfers

Primary infrastructure is in the United States. We do not currently operate an EU/EEA/UK/Swiss transfer program. Customer will not onboard those worker populations without a written transfer plan (Standard Contractual Clauses and related addenda would be attached then).

7. Audit, government requests, return and deletion

Upon reasonable written request (not more than once per 12 months, unless a Security Incident or regulator asks), we will make available information reasonably necessary to demonstrate compliance, which may include questionnaires or summaries of security practices. On-site audits only if required by law or a supervisory authority, on reasonable notice, during business hours, subject to confidentiality and security policies, at Customer's expense unless material non-compliance is found.

If we receive a legally binding request to disclose Customer Personal Data, we will (unless legally prohibited) notify Customer before disclosure and disclose only the minimum required.

Upon termination or written request we will export Customer Data in CSV/JSON and, at Customer's choice, delete or return Customer Personal Data, except where retention is required by law or needed for reasonable backup cycles, dispute resolution, or financial records — in which case data remains protected until deletion. Deletion from active systems will occur within about 30 days after the 30-day export window; backups expire on a rolling schedule.

8. Liability, order of precedence, governing law

Liability under this DPA is subject to the limitations in the Terms, except where applicable data-protection law prohibits limitation of certain liabilities. If there is a conflict: this DPA controls over the Terms for data-protection subject matter; the Terms control otherwise. Governing law and venue match the Terms (Ohio).

Annex I — Sub-processors (summary)

  • VercelApplication hosting and edge deliveryUnited States
  • NeonManaged PostgreSQLUnited States
  • Cloudflare R2Object storage for files, photos, and receipts the restaurant uploadsUnited States
  • Upstash RedisOptional rate-limit mirror when configuredUnited States (optional / when configured)
  • StripeOrganization subscription billing (not live during public beta)United States (optional / when configured)
  • SquarePOS sales sync when the restaurant connects itUnited States (optional / when configured)
  • ResendTransactional emailUnited States (optional / when configured)
  • PostHogProduct analyticsUnited States (us.i.posthog.com)
  • SentryError monitoring when configuredUnited States (optional / when configured)
  • Apple (APNs)iOS push notifications when enabledUnited States (optional / when configured)

Not active: Twilio/SMS (parked); Google FCM / Android; Life360 or any third-party continuous-location vendor; AWS as storage vendor of record (R2 is Cloudflare).

Annex II — Security measures (summary)

  • Role-based access in product; org-scoped APIs (cross-org ids return 404, not 403)
  • Passwords hashed with bcrypt; session JWT in httpOnly cookie; Secure flag in production
  • HTTPS/TLS in transit; encryption at rest via Neon and Cloudflare R2 vendor defaults
  • No full payment-card PAN stored in the application database
  • Rate limiting on auth-sensitive routes
  • Sentry error monitoring when configured; PostHog analytics when not opted out
  • Neon point-in-time recovery; restore runbook exists
  • Location collected for punch-time geofence verification; no live staff map product

MFA for admins, pen-tests, and a named incident-response owner are not claimed here because they are not published as guaranteed controls.