Policies
Terms & conditions
Effective 24 September 2026 · Version 1.0
These are the terms on which ShiftTick Ltd provides ShiftTick. Part A is for the agencies and contractors who subscribe. Part B is for the crews who use the app. Part C covers this website. Part D is the data-processing schedule that sits under all of them.
In short. ShiftTick costs £19.99 per user per month, invoiced monthly in arrears. You commit to three months, then it rolls monthly and either of us can end it on thirty days’ notice. Your data stays yours; we hold it as your processor, in the UK and EU, and when you leave you get thirty days to export it before we delete it. We keep the evidence your crews capture exactly as they captured it. We do not promise that a client will accept it — that depends on the works.
1. About these terms
1.1 Who these terms bind
Part A (sections 1 to 15) is a contract between ShiftTick Ltd, a company registered in England and Wales under number 16908032 with its registered office at 10 Minster Walk, London, England, N8 7JS (“ShiftTick”, “we”, “us”), and the business that subscribes to the Service (“you”, the “Customer”). Part A is business-to-business: by subscribing you confirm you are acting in the course of a business and not as a consumer.
Part B applies to each individual who uses the ShiftTick app because a Customer put them on its roster. Part C applies to anyone who visits shifttick.com. Part D forms part of Part A and governs the personal data we process for the Customer.
1.2 How the contract is formed
You accept Part A when you confirm in writing (email is enough) that you want a subscription, when you create a workspace or accept an invitation to one, or when you otherwise use the Service — whichever comes first. The person doing so confirms they have authority to bind the Customer. If we have agreed anything in writing that differs from these terms — a pilot, a different start date, a different number of users — that written agreement (the “Order”) prevails over the section it varies.
1.3 Definitions
- Service
- The ShiftTick admin console, API and the ShiftTick app for iOS and Android, with the support described in section 9, as we make them available from time to time.
- Workspace
- The Customer’s own area of the Service — its roster, vehicles, clients, jobs and everything captured in them.
- Office User
- A person the Customer gives an account in its workspace, as an owner or a supervisor.
- Operative
- A person the Customer puts on its roster to use the app — a foreman, an operative or a trainee.
- Billable User
- Each individual who, at any point in a calendar month, holds an active Office User account or an active (not deactivated) place on the Customer’s roster. The same person in both roles counts once.
- Customer Data
- Everything in the Customer’s workspace, including the personal data of its Office Users, Operatives, clients and anyone else its records describe, and every photo, check, message, signature and document captured or uploaded there.
- Job Pack
- The document the Service generates from a job’s records for the Customer’s client.
- Start Date
- The date in the Order or, if none, the date the Customer’s workspace is created.
- Initial Term
- The three months from the Start Date.
- Business Day
- A day other than a Saturday, Sunday or public holiday in England.
2. The service
2.1 The Service is a job workspace for traffic-management work. It lets a Customer keep a roster and vehicle register; create jobs and invite crew to them by push notification and text message; run one chat per job; capture site photos and vehicle walkaround checks that are checked on the phone for blur and blankness and stamped with the time and place of capture; collect an operative’s sign-off with a drawn signature; keep an append-only activity log; and generate Job Packs.
2.2 We provide the Service to the Customer for use by its Office Users and Operatives, on the terms in Part A. We grant the Customer a non-exclusive, non-transferable right to use the Service during the subscription for its own traffic-management business.
2.3 The Service is a record-keeping tool. It does not provide traffic-management services, does not design or check traffic-management schemes, and does not advise on whether works comply with any standard, permit or contract. What is captured, whether it is captured, and whether it satisfies a client are matters for the Customer and its crews.
3. Your workspace and your users
3.1 The Customer decides who its Office Users are and what role each holds. Owners can manage the team and the agency profile; supervisors can do everything else. The Customer is responsible for everything done in its workspace by anyone using an Office User account or an Operative’s signed-in device, and must keep accounts and devices secure. Tell us at once if you believe an account has been compromised.
3.2 Office User sign-in is provided by our identity provider (Clerk). Each Office User must keep their password confidential and not share an account.
3.3 The Customer must give us accurate contact and billing details and keep them current. Notices under Part A go to the email addresses of the workspace’s owners.
4. Your crew
4.1 The Customer adds Operatives to its roster by name and mobile number. In doing so the Customer confirms that it is entitled to give us those details, that it has a lawful basis under data-protection law for us to process them on its behalf, and that it has told each Operative — for example in its own privacy notice — that it uses ShiftTick and what the app records (see Part B and section 5 of the privacy policy).
4.2 On the Customer’s instruction, the Service sends Operatives text messages and push notifications about jobs and chat, and sends a sign-in code by text when a phone is verified. The Customer authorises every such message. Messages are operational, never marketing; the Customer must not use the Service to send anything else to an Operative.
4.3 The Customer is responsible for the relationship with its Operatives: their engagement, pay, hours, training and welfare are the Customer’s affair, and nothing in the Service makes us their employer, agent or intermediary.
4.4 An Operative’s name can be edited by the Operative; their mobile number can be changed only by the Customer. Deactivating an Operative ends their access but keeps what they captured, because it belongs to the jobs it evidences.
5. Fees and payment
5.1 Price. The Service costs £19.99 per Billable User per month, exclusive of VAT, which is added at the prevailing rate. There is no minimum number of users and no setup fee.
5.2 Invoicing. We invoice monthly in arrears, at the end of each calendar month, for that month’s Billable Users. A part month at the start or end of a subscription is charged in full for each Billable User active in it. Invoices are sent by email to the owners of the workspace.
5.3 Payment. Invoices are payable by bank transfer within 30 days of the invoice date, in pounds sterling, without set-off or deduction. Queries about an invoice must be raised within 14 days of receipt; the undisputed part remains payable on time.
5.4 Late payment. If an invoice is not paid when due we may charge interest and compensation under the Late Payment of Commercial Debts (Interest) Act 1998, and, after giving 14 days’ written notice, suspend the Customer’s workspace until the account is settled. Suspension does not stop Fees accruing, and does not delete anything.
5.5 Price changes. We may change the price on at least 60 days’ written notice, taking effect no earlier than the end of the Initial Term. If you do not accept a price change you may end the subscription under section 6.2 before it takes effect.
5.6 Pilots. Where we have agreed a pilot in writing, no Fees are payable for the pilot period and either party may end the pilot on seven days’ written notice. Part A otherwise applies in full to a pilot, including Part D.
6. Term, cancellation and what happens after
6.1 Term. The subscription starts on the Start Date, runs for the Initial Term of three months, and then continues month to month until ended under this section.
6.2 Ending it by notice. Either party may end the subscription by giving the other at least 30 days’ written notice, taking effect no earlier than the end of the Initial Term. Fees remain payable for the whole of the Initial Term and the notice period.
6.3 Ending it for cause. Either party may end the subscription at once by written notice if the other materially breaches Part A and, where the breach can be put right, fails to do so within 30 days of being asked; or becomes insolvent, enters administration or liquidation, or stops trading.
6.4 Suspension. We may suspend access without notice where we reasonably believe it is necessary to prevent harm to the Service, to other customers, to an Operative or to the integrity of Customer Data — for example a compromised account or a breach of section 8 — and will restore it as soon as the cause is resolved.
6.5 After the end. When the subscription ends, for whatever reason:
- access to the workspace stops, and Operatives’ devices are signed out;
- for 30 days the Customer may ask us for an export of its Customer Data — the records in a machine-readable form and every photo, check, signature, document and Job Pack as files — which we will provide within 10 Business Days of the request;
- we delete the workspace and all Customer Data within 90 days of the end date, including from our sub-processors, save for what the law requires us to keep (such as accounting records) and copies in backups that are overwritten in the normal cycle;
- Fees accrued to the end date remain payable, and sections 7.1, 11, 12, 13, 14 and 15 survive.
7. Your data
7.1 Ownership. Customer Data is and remains the Customer’s. The Customer grants us a licence to host, copy, transmit, display and process it only as needed to provide the Service, to comply with the law and as Part A allows. We claim no other right in it.
7.2 Roles. For the personal data in Customer Data the Customer is the controller and we are its processor, on the terms in Part D. For Office Users’ account data, our security processing and our own dealings with the Customer we are a controller, as the privacy policy explains.
7.3 The Customer’s responsibilities. The Customer is responsible for Customer Data: for having the right to put it in the Service, for its accuracy, for what its crews capture and upload, and for what it does with Job Packs. It must not upload anything unlawful, infringing, or that it has no right to share, and must not put special-category personal data (such as health information) in the Service unless a job genuinely requires it and the Customer has a lawful basis.
7.4 Evidence integrity. We do not alter what crews capture. A photo’s and a signature’s time and position are written once at capture and cannot be changed through any part of the Service; a queried photo is retaken, never replaced; the activity log is append-only; and nothing in a workspace can be deleted from the product during the subscription. These properties are the point of the Service and the Customer may not ask us to depart from them, including under a data-subject request, except where the law requires it.
7.5 Limits of the stamp. The time and position stamped on a capture come from the phone’s own clock and satellite fix. We record what the device reports. We do not warrant the accuracy of a device’s clock or GPS, which depend on the phone, its settings and the sky above it.
7.6 Where it lives. We store Customer Data in the United Kingdom and the European Union, as section 10 of the privacy policy describes, and will give at least 30 days’ notice before moving it elsewhere.
8. Acceptable use
The Customer must not, and must ensure its users do not:
- use the Service for anything unlawful, or to store or send anything defamatory, obscene, threatening or discriminatory;
- falsify a capture — stage a photo of works that were not done, spoof a location or clock, or sign off in another person’s name — or ask an Operative to;
- use the Service to monitor or surveil individuals beyond what it is designed to record. It stamps captures; it does not track people, and must not be repurposed to;
- share accounts, sell or resell access, or give access to anyone who is not an Office User or an Operative of the Customer;
- probe, scan or test the security of the Service, interfere with its operation, or try to access another customer’s workspace or data;
- copy, modify, reverse-engineer or create derivative works of the Service, or use automated means to extract data from it other than through the exports we provide;
- send messages through the Service to anyone who has not been put on the roster, or for any purpose other than running the Customer’s jobs.
9. Availability, support and changes
9.1 Availability. We will use reasonable skill and care to keep the Service available. It depends on third-party infrastructure, mobile networks and app stores, and we do not offer a guaranteed level of availability. We will schedule planned maintenance outside UK working hours where we can and tell owners in advance where it will interrupt use.
9.2 Offline capture. The app is built so that photos and checks can be captured with no signal and upload when the phone reconnects. Until an upload completes, a capture exists only on the phone; the Customer should make sure its crews let the app finish uploading before leaving site.
9.3 Support. Support is by email to hello@shifttick.com on Business Days. We aim to reply within one Business Day and to fix faults that stop the Service being used as soon as reasonably possible.
9.4 Changes to the Service. We improve the Service continuously and may add, change or remove features. We will give at least 30 days’ notice of a change that materially reduces what the Customer subscribed to, and the Customer may end the subscription under section 6.2 if it does not accept it. Updates to the app are delivered through the app stores and may be required to keep using it.
10. Third-party services
10.1 Text messages travel over mobile networks, push notifications through Apple and Google, and the app is distributed through the App Store and Google Play, each under its own terms. We are not responsible for a network failing to deliver a message, a store being unavailable, or a phone that cannot receive notifications, though the Service is designed to fall back from push to text when it can detect the problem.
10.2 The admin console shows maps from OpenStreetMap data and CARTO tiles and looks addresses up through OpenStreetMap’s Nominatim service. We do not control their content or availability, and an address or pin is a starting point for a crew, not a survey.
11. Intellectual property
11.1 We own, or are licensed to use, all intellectual-property rights in the Service, its software, design, documentation and the ShiftTick name and mark. Nothing in Part A transfers any of them to the Customer, who receives only the right in section 2.2.
11.2 If the Customer gives us feedback or suggestions we may use them without obligation, but we will not identify the Customer as their source without permission.
11.3 We will not use the Customer’s name or logo in our marketing without its written agreement.
12. Confidentiality
Each party will keep the other’s confidential information — the Customer’s business and Customer Data on one side, our pricing arrangements, roadmap and non-public product information on the other — confidential, use it only for Part A, and disclose it only to its staff and advisers who need it and are bound to keep it confidential, or where the law requires. This does not apply to information that is public through no fault of the receiving party or that it already lawfully had. This section survives the end of the subscription for five years, and for Customer Data for as long as we hold any.
13. What we promise, and what we do not
13.1 What we promise. We will provide the Service with reasonable skill and care, materially as described in section 2, and in compliance with the laws that apply to us as a provider, including data-protection law.
13.2 What we do not. The Service is a tool. We do not warrant that:
- any client, adjudicator, court or authority will accept a photo, check, signature or Job Pack as sufficient evidence of anything;
- the Service will prevent a payment dispute, or that records captured in it will win one;
- the on-device photo check will catch every poor photo, or that a photo it accepts is adequate for the Customer’s client;
- the Service will meet any regulatory, contractual or industry standard applying to the Customer’s works, or be uninterrupted or error-free.
13.3 Except as set out in Part A, all warranties, conditions and terms implied by law are excluded to the fullest extent the law allows.
14. Liability
14.1 Nothing excluded that cannot be. Nothing in Part A limits either party’s liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot be limited by law.
14.2 What we are not liable for. Subject to 14.1, we are not liable, in contract, tort (including negligence), breach of statutory duty or otherwise, for: loss of profit, revenue, business, contracts or goodwill; loss of or damage to data caused by the Customer or its users; sums a client withholds or disputes; fines or penalties imposed on the Customer; or any indirect or consequential loss.
14.3 The cap. Subject to 14.1, our total liability to the Customer arising in any 12-month period, however it arises, is limited to the greater of £1,000 and the Fees paid or payable by the Customer for the 12 months before the event giving rise to the claim.
14.4 The Customer’s indemnity. The Customer will compensate us for losses, claims and costs we suffer because of Customer Data it had no right to put in the Service, its breach of section 4.1, 7.3 or 8, or its failure to have a lawful basis for the personal data it asks us to process.
15. General
- Changes to these terms. We may update Part A by giving owners at least 30 days’ notice by email. A change that materially reduces the Customer’s rights takes effect no earlier than the end of the Initial Term, and the Customer may end the subscription under section 6.2 before it does. Continued use after a change takes effect is acceptance of it. The version at shifttick.com/policies/terms is the current one, and its effective date is at the top.
- Entire agreement. Part A, Part D, the privacy policy and any Order are the whole agreement between us about the Service, and replace anything said or written before. Neither party has relied on any statement not set out in them.
- Assignment. Neither party may transfer Part A without the other’s written consent, except that we may transfer it to a successor to our business on notice, and the successor takes on all our obligations.
- Events beyond our control. Neither party is liable for failing to perform because of something beyond its reasonable control, provided it tells the other and does what it reasonably can to resume.
- Notices are given by email — to the Customer at its owners’ addresses, to us at hello@shifttick.com — and are treated as received on the next Business Day.
- Waiver and severance. A delay in enforcing a right is not a waiver of it. If any provision is found unenforceable, the rest of Part A stands.
- No third-party rights. Part A confers no rights on anyone other than the parties, and the Contracts (Rights of Third Parties) Act 1999 does not apply to it. Part B gives Operatives their own terms with us.
- Law and courts. Part A is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.
16. Part B — Terms for crews using the app
This part is for you if you use the ShiftTick app. It is written for you, not for lawyers. It applies from the first time you verify a phone with the app, and it sits alongside whatever arrangement you have with the agency that sent you a job.
16.1 Where you stand
- Your agency put you here. You are on the app because an agency added your name and number to its roster and sent you a job. We act on that agency’s instructions. What jobs you get, what you are paid and what is expected of you on site are between you and the agency, not us.
- Your agency sees what the app records. Every photo, walkaround check, chat message and sign-off you make in a job is visible to the agency’s office and to the rest of the crew on that job, and may go to the agency’s client in a job pack. The time and place of each capture are recorded with it. Section 5 of the privacy policy sets it all out.
- The app does not track you. It reads your location only while you are taking a photo, a walkaround photo or signing off, and never in the background.
16.2 What we ask of you
- Capture honestly. Take photos of the actual works, where they are, when you are there. Do not stage, edit, or fake a capture, do not try to spoof your location or the time, and never sign off in someone else’s name or let anyone sign in yours. The records are evidence and other people rely on them.
- Give a real reason if you override the photo check. The reason is recorded and the office reads it.
- Keep your phone secure. The app stays signed in on a verified phone. Lock your phone, and tell your agency straight away if it is lost or stolen so they can sign that device out.
- Use it for the job. The chat is for the crew and the office about that job. Do not use it to abuse, harass or threaten anyone, and do not post anything unlawful.
16.3 Your account
- You can edit your name in the app. Only the agency can change your number.
- Push notifications are how jobs and messages reach you. You control them in your phone’s settings; if they are off, the agency’s messages arrive by text instead.
- To stop using ShiftTick, ask your agency to remove you from its roster. What you captured stays with the jobs it belongs to, because it is the agency’s record of those works.
- If more than one agency has you on its roster, the app shows you which, and you choose which to open. No agency can see another’s workspace.
16.4 The app itself
- We give you a personal, non-transferable licence to use the app on phones you control, for the agency’s jobs. You must not copy, modify or reverse-engineer it, or interfere with how it works.
- The app is distributed through the App Store and Google Play under their terms as well as these. It may need updating to keep working.
- We do our best to keep the app working, but we do not promise it will always be available, and a capture made with no signal exists only on your phone until it uploads. Let the app finish uploading before you leave site.
- We are not liable to you for loss you suffer using the app in the course of your work except where the law does not let us exclude it — including death or personal injury caused by our negligence, or fraud. Nothing in this part affects any right you have against your agency.
16.5 Questions
Ask your agency first about anything to do with a job. For anything about the app or your personal data you can also email us at hello@shifttick.com. This part is governed by the law of England and Wales.
17. Part C — Terms of use for this website
- Use of the site. shifttick.com is operated by ShiftTick Ltd. You may browse it and use the enquiry form for their intended purposes. You must not use the site or the form for anything unlawful, submit false or automated enquiries, or try to interfere with the site or its anti-abuse measures.
- Information, not advice. The site describes what ShiftTick does and costs. It is general information about the product, not legal, regulatory or commercial advice, and it does not form part of any contract except as Part A says. We try to keep it accurate and may change it at any time.
- Enquiries. Sending an enquiry does not create a subscription. What we do with your details is in section 3 of the privacy policy.
- Invitation links. The pages under
/i/exist so that a job invitation sent by text lands somewhere useful on a phone without the app. They read nothing about you. A code in such a link belongs to the person it was sent to; do not share or forward one. - Intellectual property. The site, its text, design, images and the ShiftTick name and mark are ours. You may not reproduce them except to link to the site or quote it fairly with attribution.
- Links. The site links to third-party sites — the app stores, the ICO and others. We are not responsible for their content.
- Liability. We provide the site as it is. To the extent the law allows, we exclude liability for loss arising from using or relying on it. We do not exclude liability for death or personal injury caused by our negligence, for fraud, or for anything else the law does not let us exclude.
- Law. This part is governed by the law of England and Wales.
18. Part D — Data-processing schedule
This schedule forms part of Part A. It sets out the terms required by Article 28 of the UK GDPR for the personal data in Customer Data that we process on the Customer’s behalf. Terms used here have the meaning given in the UK GDPR. “Data Protection Law” means the UK GDPR and the Data Protection Act 2018, each as amended, and where it applies to the Customer, the EU GDPR.
18.1 Roles and instructions
- The Customer is the controller and ShiftTick the processor of the personal data described in 18.9.
- We process that personal data only on the Customer’s documented instructions. Part A, this schedule and the Customer’s use of the Service’s features are those instructions; anything further must be agreed in writing. We will tell the Customer if, in our opinion, an instruction breaches Data Protection Law.
- We may process the personal data where UK law requires it, in which case we will tell the Customer before doing so unless the law prevents us.
18.2 Confidentiality
Everyone we authorise to process the personal data is bound by a duty of confidentiality, and has access only to what their role requires.
18.3 Security
We implement appropriate technical and organisational measures to protect the personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs, and the risks. They include those in section 12 of the privacy policy: encryption in transit and at rest, tenant isolation enforced on every query, private file storage reached only through short-lived authorised links, hashed sign-in codes and rotating device-bound tokens, rate limiting, webhook signature verification, write-once capture stamps and an append-only activity log, server-only secrets, and the absence of any staff impersonation or back-door access. We may update these measures provided the overall level of protection does not fall.
18.4 Sub-processors
- The Customer gives general authorisation for us to use sub-processors. The current list, with what each does and where it processes data, is section 9 of the privacy policy.
- We will give the Customer at least 30 days’ notice by email to its owners before adding or replacing a sub-processor that will process Customer Data. The Customer may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, the Customer may end the subscription without penalty, and section 6.5 applies.
- We impose data-protection obligations on each sub-processor equivalent to those in this schedule, and we remain fully liable to the Customer for its performance.
18.5 International transfers
We store Customer Data in the United Kingdom and the European Union, and transfer it outside the UK only to the sub-processors and under the safeguards described in section 10 of the privacy policy — the UK Extension to the EU–US Data Privacy Framework where a provider is certified, and otherwise the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. We will not make any other transfer without the Customer’s prior written instruction.
18.6 Assistance
- Data-subject requests. We will tell the Customer within three Business Days of receiving a request from a data subject about Customer Data, will not respond ourselves except to direct the person to the Customer, and will give the Customer the assistance it reasonably needs to respond in time, using the Service’s own features wherever possible.
- Security, breaches and impact assessments. Taking into account the nature of the processing and the information available to us, we will assist the Customer in meeting its obligations under Articles 32 to 36 of the UK GDPR.
- Personal-data breaches. We will notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal-data breach affecting Customer Data, giving what we know of its nature, the data and people affected, the likely consequences and the measures taken, and updating the Customer as we learn more.
18.7 Return and deletion
At the end of the subscription we will, at the Customer’s request made within 30 days, provide an export of the personal data as section 6.5 describes, and will delete all Customer Data, including copies at sub-processors, within 90 days of the end date, unless UK law requires us to keep some of it. Backup copies are overwritten in the normal cycle and are not accessed for any purpose other than restoration.
18.8 Records, information and audit
- We will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28, including this schedule, the sub-processor list, the security measures in 18.3 and, on request, summaries of any third-party assessments we hold.
- Where that information is not enough to satisfy a genuine requirement of Data Protection Law, the Customer or an independent auditor it appoints (bound by confidentiality and not a competitor of ours) may audit our compliance once in any 12-month period, on at least 30 days’ written notice, during Business Days, in a way that does not disrupt the Service or breach our duties to other customers, at the Customer’s cost. A supervisory authority’s audit is not subject to these limits.
- Our liability under this schedule is subject to section 14 of Part A.
18.9 Details of the processing
| Item | Description |
|---|---|
| Subject matter | The operation of the Customer’s ShiftTick workspace: its roster, jobs, crew invitations, chat, site photos, vehicle checks, sign-off, activity log and Job Packs. |
| Duration | The subscription, plus the 30-day export window and the deletion period of up to 90 days after it ends. |
| Nature and purpose | Storage, transmission, display, structuring and retrieval of the data to provide the Service; sending job invitations, reminders, sign-in codes and chat notifications to Operatives by push and text on the Customer’s instruction; generating Job Packs; keeping the activity log; exporting and deleting the data at the end. |
| Categories of data subject | The Customer’s Office Users; its Operatives; its clients and their staff where named; the authors and contacts named in documents the Customer uploads; and people incidentally present in site photographs. |
| Types of personal data | Names, roles and LANTRA levels; work email addresses; mobile numbers; device installation identifiers, push tokens and session records; job assignments and the replies to them, including any decline reason; site addresses and coordinates; photographs with capture time and GPS position; vehicle registrations, walkaround photos, defect notes and comments; chat messages; drawn signatures with time and position, and any sign-off note; the names of clients; uploaded documents; and the activity log recording who did what and when. No special-category data is required by the Service; any the Customer includes is at its own discretion under section 7.3. |
| Sub-processors | As listed in section 9 of the privacy policy. |