Policies
Privacy policy
Effective 24 September 2026 · Version 1.0
This policy explains what ShiftTick does with personal data — on this website, in the admin console agencies use, and in the app their crews use on site. It is written to be read. If anything in it is unclear, ask us.
In short. We run a job workspace for UK traffic-management agencies. Agencies put their crews on a roster and run jobs; crews take site photos, do vehicle checks, chat and sign work off from the app. We collect only what that takes: names, work contact details, mobile numbers, the photos and records crews capture, and the time and place each one was captured. We keep it in the UK and the EU. We do not run advertising, analytics or tracking on any of it, and we never sell it.
1. Who we are and how to reach us
ShiftTick Ltd (“ShiftTick”, “we”, “us”) is a private limited company registered in England and Wales under company number 16908032. Our registered office is 10 Minster Walk, London, England, N8 7JS.
For anything about personal data — a question, a request to exercise your rights, or a complaint — email hello@shifttick.com or write to our registered office, marked “Data protection”. We have not appointed a data protection officer; the person responsible for data protection at ShiftTick reads that mailbox.
This policy applies to shifttick.com (this website, including the enquiry form and the “get the app” page invitation links land on), the ShiftTick admin console used by agencies’ office staff, and the ShiftTick app for iOS and Android used by their crews.
2. The two roles we play
Data-protection law distinguishes a controller, who decides why and how personal data is used, from a processor, who handles it on the controller’s instructions. We are both, depending on the data:
| Personal data | Our role | Who decides |
|---|---|---|
| Visitors to this website and people who send us an enquiry | Controller | We do. |
| Office users’ accounts (name, work email, sign-in, role) and our communications with the agencies we work with | Controller | We do, because we need it to provide, secure and bill the service. |
| Security processing that protects the service — sign-in codes, device sessions, rate limiting, abuse prevention | Controller | We do. |
| Everything inside an agency’s workspace — its roster of operatives, jobs, clients, site addresses, photos, vehicle checks, chat, signatures and activity history | Processor | The agency does. It is the controller; we act on its instructions under the data-processing schedule in our terms. |
If you are an operative, the agency that put you on its roster is the controller of your workspace data, and its own privacy notice applies alongside this one. You can still contact us about it — we will pass your request to the agency and help it respond — but the agency decides. Section 5 explains what the app does with your data in plain terms, whichever of us is the controller.
3. This website and enquiries
Visiting shifttick.com
The site is hosted by Vercel. Like any web server, it records each request — your IP address, browser and device type, the page requested and the time — in short-lived server logs used to keep the site running and to investigate problems and abuse. We do not use those logs to build a profile of you.
There is no analytics, no advertising and no tracking on this site. We do not use Google Analytics or any equivalent, no advertising pixels, no session recording, and no social-media embeds. The site’s font is served from our own domain, so loading a page makes no request to a font provider.
If you choose light or dark mode, the choice is kept in your browser’s local storage under the key st-theme. It is a setting, not a tracker: it never leaves your browser and we cannot read it.
The enquiry form
When you send an enquiry we collect your name, work email address and, if you give it, your agency’s name, together with the time you sent it and a reference number we assign. We use it to reply to you, to set your agency up and walk you through the product if you want that, and to follow up about that enquiry. We do not add you to a mailing list (we do not have one) and we do not share enquiries with anyone else.
Enquiries are stored in two business tools we use for lead handling, Notion and Google Sheets (see section 9). We keep them for up to 24 months from our last contact with you, or for as long as your agency is a customer.
The form is protected against automated abuse in ways that briefly involve your data:
- Cloudflare Turnstile runs on the home page to tell people from bots. Cloudflare receives your IP address and technical signals from your browser to make that judgement. It may set a cookie strictly necessary for the check. It does not show you puzzles, and we receive nothing from it except pass or fail.
- Rate limiting. Your IP address is counted for ten minutes so that no one can flood the form. The counter is held by Upstash in Frankfurt and expires on its own.
- A hidden field and a timing check that bots trip and people never see. Neither stores anything about you.
If, exceptionally, both of our lead tools are unavailable when you submit, the form writes your enquiry to our server logs so that it is not lost, and we move it into the right place by hand.
Invitation links
Crews receive job invitations by text message containing a link to shifttick.com/i/… followed by a one-off code. On a phone with the app installed the link opens the app. On a phone without it, this website shows a page that says how to get the app. That page reads nothing and stores nothing: the code is consumed only by the app, and the page removes it from the address bar as soon as it loads. The request is logged like any other page view.
4. The admin console
The admin console is where an agency’s office staff — its owners and supervisors — set up the roster, create jobs, invite crew, follow the chat, review photos and download job packs.
Your account
Sign-in is handled by Clerk, our identity provider. When you create an account or accept an invitation, Clerk collects your name, email address and password, and keeps your sessions and your membership and role in your agency’s organisation. Your password is held by Clerk in protected form; we never see it. We keep a copy of your name, email address and role in our own database so that the workspace can show who did what.
When an owner invites a colleague, Clerk sends the invitation email to the address the owner typed, and that address is recorded in the agency’s activity log whether or not the invitation is accepted.
What the console records about your actions
Every material action in a workspace — creating a job, editing the roster, inviting crew, requesting a photo be retaken — is written to the agency’s activity log with your name and the time. The log is the agency’s evidence trail: it is append-only, cannot be edited or deleted from the product, and is visible to the agency’s owners and supervisors. It does not record what you read, only what you changed.
Services the console contacts from your browser
- Address search when you create a job uses OpenStreetMap’s Nominatim service, run by the OpenStreetMap Foundation in the UK. Your browser sends it the address you type and, as with any web request, your IP address.
- Maps are drawn from CARTO’s map tiles. Your browser requests the tiles for the area on screen, which reveals your IP address and the area you are looking at.
The console uses a session cookie from Clerk to keep you signed in, and your browser’s local storage to remember your theme and whether the sidebar is collapsed. Nothing else. There is no analytics or advertising in the console either.
5. The ShiftTick app
The ShiftTick app is used by the crews an agency sends to site. This section is written for you if you are one of them.
How your data gets there
You never sign up. Your agency adds you to its roster with your name, mobile number, role (foreman, operative or trainee) and, if it records it, your LANTRA level. That is the agency’s decision as the controller of its roster; it should have told you it was doing so. We do not collect your email address, date of birth, home address or photograph.
Text messages and notifications
On your agency’s instruction, the service sends you:
- a first-contact text with a link to get the app, when the agency first sends you a job;
- a sign-in code by text, when you verify a phone. The code lasts ten minutes and works once;
- push notifications for new jobs, confirmation requests and chat messages. A chat notification shows the sender’s name and their message, exactly as a messaging app would;
- a fallback text if a job is starting soon and you have not answered an invitation, or if your phone cannot receive push notifications.
Texts are sent through Twilio and carry the agency’s name, the job’s date, time and location and a link. Push notifications are relayed through Expo to Apple or Google, who deliver them to your phone. None of these messages is marketing; they are how your agency runs its jobs. You control push notifications through your phone’s settings; if they are off, job messages arrive by text instead. To stop receiving anything at all, ask your agency to remove you from its roster.
Your device and session
When you verify a phone, the app generates a random installation identifier — not a hardware serial number and not an advertising ID — and we store it with a push token (the address Apple or Google use to deliver notifications), the phone’s platform, and a session token so you stay signed in. The token lives in your phone’s secure keychain and is rotated every time it is used. We also record when your device last connected, which is how the agency sees that its crew can be reached.
The app has no sign-out; a device stays signed in until the agency removes you or revokes it — which is what happens if a phone is lost. Tell your agency straight away if that happens.
What you capture on a job
- Site photos, each stamped with the time and GPS position at the moment you pressed the shutter (section 6).
- Vehicle walkaround checks: the vehicle’s registration, seven labelled photos, any defects you flag and your notes, with a time and position stamp.
- Chat messages you send in a job, and the photos and checks that appear in the chat as they are captured.
- Your sign-off: your drawn signature, the statement you confirm, an optional note, and the time and position.
- Your replies to invitations — accepted, declined and the reason if you gave one, and confirmed — and, when you edit it, your name.
Who sees it
- Your agency’s owners and supervisors see everything in its workspace.
- Crew on the same job see each other’s names and roles, and the photos, checks and their stamps captured on that job. They do not see your mobile number.
- The agency’s client may receive a job pack: a document the agency generates containing the job’s photos with their time and location, the vehicle checks, the crew’s names and roles, and the signature that signed it off.
If your number is on more than one agency’s roster, signing in shows you the names of those agencies so you can choose which to open; none of them can see the others.
6. Location, photos and signatures
The app does not track you. It reads your location only while a capture screen is open — a site photo, a walkaround photo or sign-off — and stamps that reading on the record you create. It has no permission to run in the background, never sends your position on its own, and cannot tell anyone where you are at any other time.
The time and place a photo was taken are the reason ShiftTick exists: they are the evidence that the works were in place, at that site, at that time. They are stamped on the phone at capture from the device’s own clock and GPS, written once and never changed by anyone — not by you, not by your agency, not by us. A photo can be queried and retaken, but the original stays. The same is true of a signature.
- Location precision. The app asks for a precise fix while the capture screen is open and stores the coordinates. It does not store the accuracy radius or any movement between captures.
- The photo check runs on the phone. Before a photo is submitted, the app checks whether it is blurred or blank. That check is arithmetic run on your device — no image leaves the phone for it, no cloud service or artificial intelligence sees the frame, and it works with no signal. If you override a rejection you must give a reason, and that reason is recorded and shown to the office.
- Photos carry no hidden metadata. The stamp is stored alongside the photo, not inside it, and the camera is asked not to embed EXIF data in the file.
- Where photos and signatures are stored. In private storage in London, encrypted at rest, in a folder per agency and per job. They can only be fetched through short-lived links the service issues after checking the requester is allowed to see them.
Site photographs are of traffic-management works on public roads. They may incidentally include passers-by, vehicles and registration plates. We do not analyse photos to identify people, and we do not blur them; the agency, as controller, is responsible for capturing them lawfully and for what it does with its packs.
7. Other people in an agency’s records
An agency’s workspace also contains personal data about people who never use ShiftTick, entered by the agency: the names of its clients, which may be individuals or sole traders; site addresses; the free text of job notes, chat messages and check comments; and the documents the agency uploads to a job — risk assessments, method statements, permits and drawings, which may name their authors and contacts.
For all of this the agency is the controller and we are its processor. If you believe an agency holds data about you in ShiftTick, contact the agency; if you do not know which agency, contact us and we will help.
8. Why we use personal data, and our lawful bases
UK GDPR requires a lawful basis for every use of personal data. These are ours. Where we act as a processor, the lawful basis is the agency’s to establish; the rows below cover the uses we make as a controller.
| What we do | Personal data | Lawful basis |
|---|---|---|
| Reply to an enquiry, set an agency up and follow up about it | Name, work email, agency name | Steps taken at your request before entering a contract; our legitimate interest in responding to business enquiries |
| Provide the admin console and app to a subscribing agency, including sign-in, sessions, notifications and support | Office users’ account data; operatives’ device and session data | Performance of our contract with the agency; our legitimate interest in running the service its staff and crews use |
| Keep the service secure: verify phones by text, limit sign-in attempts, block abuse of the enquiry form, investigate incidents | Mobile numbers, IP addresses, installation identifiers, sign-in codes, server logs | Our legitimate interest in the security and integrity of the service, and in protecting agencies’ evidence from tampering |
| Invoice agencies and keep accounting records | Office users’ names and work contact details; usage counts | Performance of the contract; legal obligation (company and tax records) |
| Tell agencies about material changes to the service or these documents | Owners’ email addresses | Performance of the contract; our legitimate interest in keeping customers informed |
| Establish, exercise or defend legal claims, and comply with legal requests | Whatever the matter requires | Our legitimate interest in protecting our rights; legal obligation |
Where we rely on legitimate interests we have weighed them against your rights and expectations. You can ask us for that assessment, and you can object (section 13). We do not rely on consent for any of the above; the camera, location and notification permissions your phone asks for are controls you hold, not consents we rely on.
10. Where your data lives
Your data is stored in the United Kingdom and the European Union. The database and every file — photos, walkaround photos, signatures, documents and job packs — are held in London. Background tasks and rate-limit counters run in Frankfurt. Text messages are processed in Ireland until they reach a UK mobile network. Our servers run in London and Frankfurt.
UK law treats the EU as providing adequate protection, so data in Frankfurt or Ireland is protected as it is in the UK. Some of the providers above are headquartered in the United States, and a few process limited data there: Clerk (office sign-in), Expo, Apple and Google (push notifications in transit), Notion and Google (enquiries), and Cloudflare, Vercel, Neon and Upstash for support, logging or administration of services whose data is stored here. For those transfers we rely on one of the safeguards UK GDPR recognises:
- the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”), where the provider is certified under it; or
- the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, built into the provider’s data-processing terms, together with a transfer risk assessment.
You can ask us which safeguard applies to a particular provider and for a copy of the relevant terms, redacted for commercial confidentiality.
11. How long we keep personal data
We keep personal data for as long as the purpose in section 8 needs it, and no longer. The specific periods are:
| Data | How long |
|---|---|
| Enquiries | Up to 24 months from our last contact with you, or for as long as your agency is a customer |
| Website and API server logs | A short rolling period measured in days, then overwritten |
| Rate-limit counters | Ten minutes (enquiry form) or one hour (sign-in), then expired automatically |
| Sign-in codes | Stored only as a hash; valid for ten minutes and for one use |
| Office user accounts | For the life of the agency’s subscription. A deactivated user stays on record as the author of what they did |
| An agency’s workspace — roster, jobs, photos, checks, chat, signatures, notification records and the activity log | For the life of the agency’s subscription, without deletion: these records are the agency’s evidence and are append-only by design. An operative removed from the roster is deactivated, and what they captured remains part of the jobs it belongs to. After the subscription ends the agency has 30 days to export its data, and we delete the workspace within 90 days of termination. |
| Backups and copies held by our hosting providers | Overwritten in the providers’ normal cycle, and in any event within 90 days of the data being deleted |
| Accounting records | Six years after the end of the financial year they relate to, as company and tax law require |
12. How we protect it
ShiftTick sells evidence, so protecting the integrity of what it holds is the product, not an add-on. The measures we take include:
- Encryption in transit (HTTPS/TLS everywhere, including between our servers and the database) and at rest for files and the database.
- Tenant isolation. Every record carries the agency it belongs to and every query is confined to one agency; the API enforces which kind of user may call each endpoint.
- Private storage with short-lived links. Files can be uploaded or fetched only through links the service issues after checking the requester’s access, valid for minutes.
- Strong sign-in. Office passwords are held by a specialist identity provider with breach-checking; crew sessions use signed, rotating tokens bound to one device, with sign-in codes stored only as hashes, valid once for ten minutes, and locked after five wrong attempts.
- Rate limiting on sign-in and the enquiry form; signature checks on every incoming webhook.
- Write-once evidence. A photo’s and a signature’s time and position are written once and cannot be updated through any part of the service; the activity log is append-only.
- Secrets handling. Credentials live only on servers; nothing secret is built into the website or the app.
- No staff back door. There is no support-access or impersonation feature. Access to production systems is limited to the people who run them.
If a personal-data breach happens we will assess it without delay, notify the ICO within 72 hours where the law requires it, tell any affected agency without undue delay so that it can meet its own obligations, and tell affected individuals directly where the risk to them is high.
13. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- correct it if it is inaccurate or incomplete;
- erase it in certain circumstances — for example where we no longer need it;
- restrict how we use it while a question about it is resolved;
- port data you gave us, in a machine-readable form, where we process it under a contract with you;
- object to processing we base on legitimate interests, and to any direct marketing (we do none);
- not be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you (we make none — section 15).
To exercise any of them, email hello@shifttick.com. We may need to confirm your identity first. We respond within one month; if a request is complex or you have made several, we may extend that by up to two further months and will tell you why. These rights are free to exercise, though we may charge a reasonable fee or decline a request that is clearly unfounded or excessive.
Where we are the processor — an operative asking about their roster record or the photos they took, or a person named in an agency’s job records — the agency is responsible for answering. We will pass your request to it within a few working days and give it whatever it needs from us to respond in time. Some rights, such as erasure, are limited while a workspace is an agency’s evidence of completed works; the agency will explain which apply.
14. Complaints
If you are unhappy with how we have handled your personal data, please tell us first. Email hello@shifttick.com with “Complaint” in the subject, or write to our registered office. We will:
- acknowledge your complaint within 30 days of receiving it;
- look into it without undue delay, keep you informed of progress, and tell you the outcome and what we have done about it;
- keep a record of the complaint and how it was resolved.
You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office: at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You can go to the ICO at any time, though it will usually ask whether you have raised the matter with us first.
15. Automated decision-making
We make no decisions about you by automated means that have legal or similarly significant effects, and we do no profiling. Two things in the product are automated and are worth explaining:
- The on-device photo check accepts or rejects a frame on measurable blur and blankness. It is fixed arithmetic, not a model that learns from you; it runs on the phone; and an operative can override it by giving a reason, which the office sees. The decision about whether the works were done properly is a person’s.
- Notification routing decides whether to reach a crew member by push or by text, based on whether their phone can receive push notifications and whether they have replied. It affects how a message arrives, not whether it does.
17. Children
ShiftTick is a tool for businesses and the people who work for them. It is not directed at children, and we do not knowingly collect personal data about anyone under 16. If you believe an agency has added someone under 16 to its roster, contact us and we will raise it with the agency.
18. Changes to this policy
When the product changes in a way that affects personal data — a new provider, a new kind of record, a new place data is stored — this policy changes with it and the effective date at the top moves. We will email the owners of each subscribing agency about any material change before it takes effect, and agencies should pass that on to their crews. Earlier versions are available on request.
This policy is governed by the law of England and Wales. It was last updated on the effective date shown at the top.