← Back to site

ShiftCraft — Terms of Service & Privacy Policy

Provider: R.D. Hitson, d/b/a ShiftCraft (sole proprietor) · rdhitson@shift-craft.com · 907 206-9295 · Shift-Craft.com Effective date: June 23, 2026 · Version 1.0

This is the published Terms of Service & Privacy Policy for ShiftCraft. It is the canonical source for the public page at Shift-Craft.com/legal and is incorporated by reference into each License Agreement. (Plain-English; have counsel review when you formalize the business or change the governing-law state.)

ShiftCraft ("the Service") is a voluntary teamwork app for shift-based teams. It is built around one rule: track the work, protect the people. The Service is designed to record what helps a team improve — never to measure an individual.


Part A — Terms of Service

1. Agreement

By creating an account or using the Service, you ("you" or "Customer") agree to these Terms. If you use the Service on behalf of an organization, you confirm you are authorized to bind that organization.

2. Accounts, organizations & roles

3. Acceptable use

You agree not to:

Provider may suspend access for material breach of this section, with notice where practicable.

4. The no-PHI / no-individual-measurement rule

The Service is intentionally built to hold no PHI and no individual performance data. Content is stored without an author, and dashboards are de-identified. You must keep your use consistent with this design. This is what allows the Service to clear infosec review quickly and typically without a HIPAA BAA.

5. Availability & changes

Provider aims for high availability but does not guarantee uninterrupted service. Provider may improve or modify features but will not materially reduce core functionality during a paid term.

6. Fees

Fees, term, and renewal are set in your License Agreement / Order Form. These Terms govern use; the Order Form governs commercials. If they conflict on commercial points, the signed Order Form controls.

7. Intellectual property

Provider owns the Service and all related IP. You own your organization's data (see Part B). You receive only the limited right to use the Service stated in your License Agreement.

8. Disclaimer & liability

The Service is provided "as is" except as expressly warranted in your License Agreement. To the extent permitted by law, Provider disclaims implied warranties, is not liable for indirect or consequential damages, and total liability is capped at the fees paid in the prior 12 months.

9. Termination

Either party may terminate per the License Agreement. On termination your access ends; you may request a data export before deletion (see Part B, Section 5).

10. Governing law & changes to terms

These Terms are governed by the laws of the State of Tennessee. Provider may update these Terms; material changes will be posted at Shift-Craft.com with a new effective date and, for active customers, notified by email.


Part B — Privacy Policy

The Service is built to collect as little personal data as possible and to make individual activity technically unrecoverable from its records.

1. What we collect

Category Examples Why
Account / contact data Name, work email, role, org/unit assignment To create and secure accounts
De-identified unit activity Frictions, improvements, rollups — stored with no author To show unit-level progress
Operational logs Sign-in events, error logs Security and reliability

We do not collect or store: patient data, PHI, clinical records, or any individual performance or productivity score.

2. How activity is de-identified

3. Tenant isolation

Each organization's data is fully separated and enforced at the database level (Row-Level Security scoped membership → unit → site → org). No customer can see another customer's data.

4. Sub-processors & hosting

The Service runs on Supabase (PostgreSQL) for hosting and authentication. Data is stored in the United States. We use no custom server and no service keys in the client. A current sub-processor list is available on request.

5. Your data: ownership, export & deletion

6. Security

Row-Level Security, k-anonymity on all dashboards, server-enforced protected-data blocking, encryption in transit, and zero service keys in the app. The Service has been reviewed internally (architecture review plus an automated security pass); a security/architecture packet is available to your infosec team on request.

7. Cookies & local storage

The Service uses essential cookies / local storage for sign-in and app state only. No advertising or third-party tracking cookies.

8. Children

The Service is for workplace use by adults and is not directed to children.

9. Changes & contact

We will post material changes to this Policy at Shift-Craft.com with a new effective date. Questions or requests:

R.D. Hitson, d/b/a ShiftCraft · rdhitson@shift-craft.com · 907 206-9295 · Shift-Craft.com