Data privacy

Privacy Policy

This policy explains what information ShiftSync uses to turn ESOSuite roster data into private and shareable calendar feeds, account-connected calendar syncs, shift summaries, subscriber emails, and related support.

1. Overview

ShiftSync is operated by Affolder Creative. The service helps eligible subscribers sync ESOSuite fire department schedule information to calendar feeds and, when enabled, calendars selected by the subscriber, including Google Calendar, Microsoft Outlook or Microsoft 365, and CalDAV calendars.

This policy describes how information is collected, used, stored, and shared when you visit the website, subscribe, use the account portal, receive calendar links, connect a calendar provider, or contact support.

ShiftSync is independently operated by Affolder Creative. ShiftSync is not affiliated with, endorsed by, sponsored by, approved by, or operated by Whitestown Fire Department, the Town of Whitestown, ESO, ESOSuite, or any other fire department, municipality, employer, scheduling platform, or calendar provider unless expressly stated in a separate written agreement.

2. Information we collect

The information handled by ShiftSync depends on which features are enabled for your subscription or deployment.

  • Subscriber information such as email address, name, phone number if provided through Stripe, Stripe customer and subscription identifiers, subscription status, match status, access state, and support messages.
  • Account portal information such as magic-link requests, hashed sign-in tokens, hashed session identifiers, OAuth state values, and selected calendar destinations.
  • Calendar sync information such as Schedule, Department Dates, All Events, shareable, and daily roster feed filenames, randomized feed tokens, calendar URLs, app-managed event IDs, provider account email addresses, OAuth scopes, and provider connection status.
  • Technical and operational information such as request metadata, IP address, browser or device information, sync run statistics, error logs, and delivery status for service emails or notifications.
  • Apple companion app information such as the sign-in email, installation identifier, device name, platform, app version, hashed device-credential record, credential status, notification authorization state, encrypted APNs device token, notification environment, and expiration, invalidation, or revocation timestamps.
  • Shift-change notification information such as the old and new assignment and shift timing, alert urgency, unread status, and delivery or retry state.
  • In compatible preview builds, if you opt into the Siri and Spotlight feature, a rolling on-device index of your assignment, department dates, and relevant roster-leadership names for yesterday through 90 days ahead.

3. Schedule and roster data

ShiftSync uses the configured ESOSuite Scheduling API credentials for the deployment, reads roster and schedule data, and stores the data needed to generate calendar output. This may include employee names, abbreviations, shift dates and times, station or unit assignments, role and qualification labels, shift type, relieving and relieved-by details, same-shift roster sections, trade details, derived annual schedule summaries or trade-balance statistics, and event revision metadata.

If an employee directory is provided, it may include employee names, ESOSuite employee IDs, shift reference metadata, rank or qualification reference data, and optional phone overrides. ShiftSync may also cache ESOSuite employee contact/profile fields such as cell phone, email address, birth date, hire date, and full-time hire date. Phone numbers are only added to calendar descriptions when that optional feature is enabled.

4. Connected calendar accounts

If you connect a calendar provider, ShiftSync uses the access you authorize to list writable calendars where needed and to create, update, or remove app-managed shift events in the calendar you select.

  • Google Calendar sync requests offline access with calendar event access and read-only calendar-list access so you can choose a destination calendar.
  • Microsoft sync requests delegated offline_access and Calendars.ReadWrite permissions so you can choose an Outlook or Microsoft 365 calendar.
  • CalDAV sync uses the calendar collection URL, username, and app password that you enter in the account portal.

OAuth tokens and CalDAV credentials are encrypted before they are stored in SQLite. Magic-link, session, and OAuth state tokens are stored as hashes. ShiftSync is designed to manage only events it creates or marks as app-managed.

ShiftSync's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for advertising, sold to third parties, or used to train generalized AI models.

5. Payments and subscriptions

Payments, checkout, billing portal access, and payment method handling are provided by Stripe. ShiftSync receives subscription lifecycle information from Stripe, such as customer details, subscription identifiers, invoice events, payment status, grace-period status, and cancellation or revocation events.

ShiftSync does not store full payment card numbers. Stripe may collect and process payment information according to Stripe's own terms and privacy policy.

6. How we use data

ShiftSync uses information only for service operation, subscriber support, security, and billing-related access control.

  • To fetch and parse ESOSuite schedule data, resolve roster identities, and generate per-person shift events.
  • To provision Schedule, Department Dates, All Events, shareable calendar feeds, account-connected provider syncs, and optional JSON API, TRMNL schedule output, or shift summaries.
  • To authenticate the Apple companion app, populate its dashboard and widgets, keep a bounded protected cache on the device, and revoke individual connected devices. When enabled, ShiftSync also detects eligible next-shift changes, maintains an account inbox, and sends native alerts and absolute unread badge updates.
  • To match subscribers to roster names, review uncertain matches, send activation, shareable-feed, payment, access, and support emails, and manage subscription access.
  • To diagnose sync problems, prevent unauthorized access, rotate or revoke feed URLs, maintain service reliability, and comply with applicable obligations.

7. How data is shared

ShiftSync does not sell personal information or share schedule data for advertising. Information may be processed by service providers and third-party systems needed to operate the service.

  • Stripe processes checkout, subscription, billing, invoice, and customer portal information.
  • Calendar providers such as Google, Microsoft, and CalDAV services receive the calendar events and provider requests needed for the syncs you connect.
  • Hosting, email, logging, and notification providers may process information necessary to serve pages, deliver service emails, route notifications, and operate the application.
  • Apple Push Notification service receives the device token and short alert payload needed to deliver enabled companion notifications.
  • Information may be disclosed if required by law, to protect the service or users, or to investigate abuse, security issues, or unauthorized access.

8. Calendar feed links

Private and shareable ICS calendar URLs work like bearer links: anyone with a valid link may be able to subscribe to or view the calendar data available at that URL. Schedule, Department Dates, and All Events feeds are intended for the subscriber's own use and may include private-only schedule, date, or summary details. Shareable feeds are intended for family, friends, or others the subscriber chooses to share them with, and they omit private-only date and year-end summary events.

If randomized feed tokens are enabled, URLs are harder to guess and can be rotated when access changes. You should still treat calendar URLs as sensitive and share them only with people who should see the schedule information.

9. Data retention

ShiftSync keeps information for as long as needed to provide the service, maintain subscription records, troubleshoot issues, protect against abuse, satisfy accounting or legal obligations, and preserve calendar sync continuity.

Schedule history, roster cache data, derived summaries, feed tokens, subscriber records, provider links, and event metadata may be stored in SQLite. Some deployments may configure schedule retention, historical reuse, stale feed pruning, or local Stripe data purge behavior. Shift-change inbox records are retained for 90 days by default, including their read state; deployments may configure this period. When a subscription is revoked, ShiftSync may rotate or revoke feed URLs and attempt to remove stored provider credentials after final app-managed calendar cleanup where supported.

The Apple companion stores its device credential in the system Keychain and keeps recent schedule, roster, department-date, and trade-summary data in its shared app-and-widget container. Signing out removes that local data. In compatible preview builds, if you enable the Siri and Spotlight feature, the companion also maintains a protected on-device schedule index that Apple may use to find or speak relevant schedule information. Turning the feature off, signing out, or losing API access deletes ShiftSync's index. Privacy-safe beta diagnostics remain on the device unless the user chooses to copy and send them to support.

Signing out also unregisters that installation, removes its delivered notifications, and clears its local badge. The durable account inbox may remain until its retention period expires.

10. Security

ShiftSync uses reasonable technical and operational safeguards for the type of service it provides. Examples include encrypted storage for OAuth tokens and CalDAV credentials, hashed account portal tokens and sessions, Stripe webhook signature verification, subscription access checks, and hard-to-guess optional calendar feed tokens.

No internet service or storage system can be guaranteed perfectly secure. If you believe a calendar link, connected calendar account, or account portal session has been accessed without authorization, contact support promptly.

11. Your choices

You can manage your subscription through the billing portal when available. You can disconnect Google, Microsoft, or CalDAV calendar syncs from the account portal or revoke access directly through the calendar provider. You can also ask support to update subscriber matching, rotate calendar feed access where supported, or delete information that is no longer needed for the service.

When available in a compatible preview build, the Apple companion's Siri and Spotlight schedule index is optional and off by default. You can enable, refresh, or delete it from the companion app's Siri & Spotlight settings.

Native shift-change alerts are optional. You can allow or deny alert, sound, and badge permission in Apple system settings. If permission is denied, the authenticated in-app inbox remains available. Inbox items are marked read only when you open them or choose Mark All Read.

Some information may need to be retained for billing, security, legal, backup, or operational reasons. Requests can be sent to [email protected].

12. Children

ShiftSync is intended for adult subscribers and authorized schedule users. It is not directed to children under 13, and the service does not knowingly collect personal information from children under 13.

13. Changes to this policy

This policy may be updated from time to time. The effective date at the top of the page shows when the current version took effect. Continued use of ShiftSync after an update means the updated policy applies to your use of the service.

14. Contact

Questions about this Privacy Policy or ShiftSync privacy practices can be sent to [email protected].