Privacy Policy

Effective date: September 9, 2026

This Privacy Policy explains how CRC Group Ltd ("CRC Group," "we," "us," or "our") collects, uses, and protects information in connection with Shifti (the "Service"). It applies to the account holders who use the Service directly, and to the employee information that Company administrators enter into the Service.

1. Information We Collect

We collect the following categories of information through the Service:

2. How We Use Information

We use this information to: operate and provide the scheduling, time clock, and time-off features of the Service; send account-related email such as sign-up verification, password reset, and activity notifications; send optional push notifications you opt into (for example, shift reminders); maintain the security and integrity of the Service, including audit logging; and communicate with you about the Service, including support requests you send to us. We do not use your information for advertising, and we do not run analytics or ad-tracking software on the Service.

3. Cookies & Sessions

The Service uses cookies that are necessary for it to function: a session cookie that keeps you signed in, and, for platform administrators, a separate signed cookie used to authenticate administrative access. We do not use advertising or third-party tracking cookies.

4. Third-Party Services

We rely on a small number of service providers to operate the Service:

These providers process information solely on our behalf and only to the extent necessary to deliver the functionality described above. If we introduce a payment processor to handle subscription billing in the future, we will update this policy to describe how payment information is handled.

5. How We Share Information

We do not sell your personal information. Within the Service, information is visible to your own Company's administrators and managers according to the roles and permissions your Company configures. We share information outside your Company only with the service providers described above, when required by law, or with your consent.

6. Data Retention

We retain account and Company data for as long as the related account or Company subscription is active. If an account or Company is terminated, we will delete or anonymize the associated personal information within a reasonable period, except where we are required to retain it for legal, security, or accounting purposes.

7. Data Security

We use technical and organizational measures designed to protect your information, including password hashing, role-based access controls, and data isolation between Companies at the database level. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children's Privacy

The Service is intended for use by working adults and is not directed to individuals under 18. We do not knowingly collect personal information from children.

9. Your Choices & Access Requests

If you are an employee whose information was entered by your employer, requests to access, correct, or delete that information should generally be directed to your employer's administrator, as they control that data within the Service. You may also contact us directly at [email protected] with any privacy request, and we will work with you and, where applicable, your employer to respond.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by posting the updated policy on this page and updating the effective date above.

11. Contact

Questions about this Privacy Policy can be sent to [email protected].

CRC Group Ltd
Alberta, Canada