Privacy Policy
Last updated: 2026-08-19 · Cut the Shift LLC (Ohio)
These terms are in effect for the public beta. A licensed attorney has not yet completed a review. We may update this page after counsel markup. Questions: contact us.
Cut the Shift LLC ("we," "us") provides the CutTheShift scheduling and operations software for restaurants on web and iOS (cuttheshift.io). CutTheShift is a product name, not a registered DBA. This policy describes how we handle personal data.
Privacy requests: contact form (topic: privacy). We aim to acknowledge requests within 2 business days and to complete verified requests within 45 days where that timeline applies (subject to permitted extensions). A dedicated privacy@ inbox will be published only when that mailbox is monitored. Mailing address: 10130 Sleepy Ridge Dr, Loveland, OH 45140.
1. Roles: controller vs processor
For staff and operations data in a restaurant's account, the restaurant is the employer/controller and we act as a processor. See our Data Processing Addendum. We act as a controller for its own account/billing contacts, website visitors, and product analytics/security data it determines the purposes for.
If you are a worker using CutTheShift through your employer, we may route privacy requests about workplace data to your employer as the controller.
2. Personal data we collect
- Identifiers — names, emails, phone numbers when provided; account and billing contacts.
- Employment / timeclock — roles, schedules, time punches, wages, tips, checkout and payout-related fields your organization uses.
- Precise geolocation (sensitive) — when geofenced timeclock is enabled: latitude/longitude, accuracy, distance, geofence status at punch; optionally venue Wi-Fi/BLE identifiers if configured. Optional arrive-near-work reminders use operating-system region monitoring (not a live staff map). We do not offer continuous background staff tracking as a product feature. Geofencing is built in-house; Life360 is not a vendor.
- Commercial / payment — subscription billing via Stripe when enabled; tip ledger amounts; debit brand + last4 if a worker registers a card; USDC wallet destination if that rail is enabled. We do not store full payment-card PAN in the CutTheShift application database.
- Internet / device — IP address, device/app info, timestamps, usage logs for security, reliability, and analytics.
- Files — photos, receipts, or other files the restaurant uploads (including inventory count-sheet photos if that feature is used).
- Audio — if a restaurant uses hands-free inventory counting, the iOS app may capture short voice recordings for that feature.
We do not create significant inference profiles about workers. We do not use precise geolocation for advertising.
3. How we use it
- Operate the product for your organization (schedule, timeclock integrity, coverage, tips)
- Authenticate users and prevent abuse
- Provide support and troubleshoot issues
- Process subscription billing when enabled
- Monitor reliability (Sentry) and product usage (PostHog; Vercel Analytics on the marketing site)
- Comply with law and enforce agreements
- Send transactional email when configured (Resend). SMS product features are parked; we do not send routine SMS alerts today
We do not sell your personal data. We do not use customer or worker data to train models for other customers. You own the data your organization submits.
4. Sensitive personal information
Precise geolocation is sensitive personal information under California law. We use it only for timeclock integrity and optional arrive-near-work reminders the restaurant enables — not to infer unrelated characteristics.
You may request that we limit use and disclosure of sensitive personal information to what is necessary to perform the services reasonably expected, via the privacy contact form. Where we act as a processor, we will coordinate with the restaurant.
5. Who we share with
We disclose personal data to vendors that help us run the product. The current list is at /legal/subprocessors. In summary: Vercel (Application hosting and edge delivery); Neon (Managed PostgreSQL); Cloudflare R2 (Object storage for files, photos, and receipts the restaurant uploads); Upstash Redis (Optional rate-limit mirror when configured); Stripe (Organization subscription billing (not live during public beta)); Square (POS sales sync when the restaurant connects it); Resend (Transactional email); PostHog (Product analytics); Sentry (Error monitoring when configured); Apple (APNs) (iOS push notifications when enabled).
We also disclose data to the restaurant's authorized admins; to professional advisors under confidentiality; if required by law or to protect rights and safety; and in a merger, acquisition, or asset sale, subject to continued protection.
We do not sell personal data. We do not disclose personal data for cross-context behavioral advertising as a business model. See Do Not Sell or Share.
6. Retention
We retain personal data as needed to operate the Service, including legal, accounting, and dispute-resolution needs. There is no automated geo-redaction job today. Current practice:
| Data | Retention |
|---|---|
| Account / billing contacts | Life of the customer relationship, then up to 7 years for financial records |
| Schedules, time punches, tip/wage ledger amounts | Life of the restaurant tenant. We export on request. Typical wage-hour recordkeeping is multi-year; the restaurant (employer) should export if they need a longer archive after offboarding |
| Precise geolocation / geofence fields on punches | Stored with the punch record (same life as the punch). There is no separate auto-redact job today |
| Optional Wi-Fi BSSID / BLE identifiers at punch | Same as geolocation fields on that punch |
| Payout destination metadata (debit brand + last4, or USDC wallet if enabled) | Until the worker is removed from the org, plus about 30 days |
| Session / auth logs | About 90 days, plus vendor hosting logs on their schedules |
| PostHog product analytics | PostHog project default |
| Sentry errors | About 90 days or the Sentry plan default |
| Files on Cloudflare R2 | Life of the tenant, or until the restaurant deletes them |
| Database backups (Neon PITR) | Rolling window (production target at least 7 days) |
| Contact / privacy-request records | Up to 3 years so we can show we handled the request |
After a restaurant ends service, we export data on request (CSV/JSON) for 30 days and delete from active systems within about 30 days, except where law, backups, or financial records require a longer hold, consistent with the DPA.
7. Cookies, SDKs, and GPC
See our Cookie Policy. If your browser sends a Global Privacy Control (GPC) signal, we treat that as a request to opt out of analytics capture (best-effort). You can also choose Essential only on the cookie banner or Cookie Policy.
8. Security
We use administrative, technical, and organizational measures designed to protect personal data, including role-based access in the product, org-scoped APIs, passwords hashed with bcrypt, httpOnly session cookies with the Secure flag in production, TLS in transit to the app, and hosted infrastructure (Vercel, Neon, Cloudflare R2). Encryption at rest is provided by those vendors' defaults. No method of transmission or storage is 100% secure.
Report security issues via the contact form (topic: security) or see security.txt.
9. Children and minors
The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13.
Restaurant workforces may include minors ages 14–17. The restaurant is responsible for child-labor compliance and for any parental/guardian notices the law requires. CutTheShift does not currently collect date of birth or enforce an in-product age gate for invited workers. Arrive-near-work reminders that request Always location are optional operating-system permissions the worker can deny.
10. Your privacy rights
Depending on where you live (especially California and other U.S. states with comprehensive privacy laws), you may have rights to know/access, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, non-discrimination for exercising rights, and appeal a denied request where required.
How to exercise: /contact?topic=privacy. We will verify your identity as required. Authorized agents may submit requests where law allows, with proof of authorization. If we process your data only as a processor for a restaurant, we may direct you to the restaurant or fulfill in coordination with them.
11. International transfers
The Service is offered for United States restaurants. Primary infrastructure is in the United States. We do not currently operate an EU/EEA/UK/Swiss program (no prior-consent cookie banner, no Standard Contractual Clauses package, and no Art. 27 representative). Do not onboard EU/EEA/UK/Swiss worker populations without a written transfer plan with us.
12. Restaurant responsibilities
As the employer, your organization is responsible for giving workers any legally required notices and obtaining consents for timekeeping, location-based clock-in, and tip/payout features. A template notice is available on request for pilots.
13. Changes
We will post updates here with a new "Last updated" date. Material changes will be notified by email or in-product notice where appropriate.