Privacy Policy

Thyft  ·  Last updated: 28 August 2026

The short version. Thyft holds the information a workplace needs to build a schedule: names, work emails, which shifts people can work, time off they asked for, shifts they swapped, and messages they send each other in the app. We do not sell it, we do not advertise, and we do not use it to train anything. The workplace that invited you owns their data; we hold it for them.

Who we are

Thyft is a shift scheduling service operated by Thiago Litzkow, based in Florida, United States. Throughout this policy, "we" means Thyft and "you" means the person using it.

Thyft is sold to businesses, not to individuals. If you are using Thyft, an employer set up a workplace and invited you to it. They decide what goes in and who can see it; we hold it on their behalf.

What we collect

WhatWhy
Your nameSo the schedule can say who works when.
Your email addressTo invite you, to let you sign in, and to reset your password.
Your passwordStored only as an irreversible fingerprint. We cannot read it, and neither can your manager.
Your availabilityWhich shifts you can work, so the schedule fits.
Time off you requestIncluding the reason you type, if you type one. Your manager sees it.
Shifts and swapsWhat you are scheduled for, what you gave away, what you took on.
Signatures on swapsThe mark you draw with your finger when you confirm a swap, kept as proof for about three months.
Messages you sendIn the workplace chat. Your manager can read them.
Your language choiceSo the app and our emails reach you in it.
A notification tokenA meaningless string your phone gives us so a notice can reach it. It is not your phone number.

We do not collect your location, your contacts, your photos, your calendar, or anything else on your phone. We do not track you across other apps or websites.

What we never do

Who can see what

Your manager can see everything about your work: your schedule, your availability, your time off and the reason you gave, your swaps, and the chat. That is the job the app exists to do.

Your co-workers can see who is working when, and the chat rooms they belong to. They cannot see the reason you gave for a day off, nor your email or password.

Other workplaces cannot see anything of yours. Each workplace is kept separate.

We can see your information only when we need to keep the service working — fixing a fault, restoring something that was lost, or answering a question your workplace asked us.

Where it is kept

Thyft runs on Google Firebase, on servers in the United States. Notifications are delivered through OneSignal. Email is delivered through Resend. Each of these companies handles only what it needs to do its part, and none of them may use your information for their own purposes.

How long we keep it

Your choices

Wherever you are

Thyft is used around the world, and local law may give you rights beyond what is described above — to a copy of your data, to have it corrected or erased, to object to how it is used, to withdraw consent, and to complain to a regulator. We honour those rights wherever they apply, not only where we are obliged to.

Write to privacy@thyft.com and we will answer within 30 days, free of charge.

Who is responsible for what. Your employer decides what goes into the workplace and why; under most privacy laws they are the controller. Thyft holds it for them and acts on their instructions; we are the processor. Requests we cannot answer alone, we pass to them and tell you.

Crossing borders. Thyft runs on servers in the United States, so information travels there whatever country you are in. For people in the European Economic Area, the United Kingdom and Switzerland, that transfer is covered by the European Commission's Standard Contractual Clauses. For Brazil, it is made under the LGPD's provisions for international transfer.

If you are in California: we do not sell or share personal information as those words are defined in the CCPA, and we never have.

Children

Thyft is a workplace tool and is not meant for children under 13. We do not knowingly collect anything from them. Where a workplace employs people aged 13 to 17, the employer is responsible for whatever consent local law requires.

Security

Passwords are stored only as an irreversible fingerprint. Traffic is encrypted. Access to production data is limited to what is needed to run the service.

No service can promise it will never be breached. If information is exposed in a way that puts you at risk, we will tell the affected workplaces without undue delay.

Changes

If this policy changes in a way that matters, we will say so in the app before it takes effect. The date at the top always shows the current version.

Contact

Questions, requests, or complaints: privacy@thyft.com