Privacy Policy
Last updated: June 28, 2026 · Effective: June 28, 2026
This Privacy Policy explains how ShiftDesk (“we”, “us”) handles personal information. ShiftDesk is a B2B platform used by auto service shops (“Shops”), owned and operated by Phineworks Inc.
- For a Shop’s own account data (the Shop’s staff who sign in), we act as a controller.
- For data a Shop enters about its own customers (vehicle owners), we act as a processor on the Shop’s behalf — the Shop is the controller and is responsible for the notices/consents to those individuals. We process that data only to provide the Service per our agreement with the Shop.
1. Information we collect
- Account & staff data: name, email, phone, role, and login credentials (auth is handled by our provider; we don’t store raw passwords).
- Shop’s customer data (as processor): the Shop’s customers’ names, emails, phones, vehicle details (VIN, make/model, mileage), service history, inspection results, estimates, and invoices.
- Payment data: subscription billing is processed by Stripe; we receive limited billing metadata (e.g., status, last4), not full card numbers. Shops’ own customer card payments, where used, are likewise processed by the payment processor.
- Usage & technical data: log data, device/browser info, and error diagnostics used to operate and secure the Service.
2. How we use information
To provide, maintain, secure, and improve the Service; to authenticate users; to process subscriptions; to send transactional and service messages; to provide support; and to comply with law. We do not sell personal information. AI-assisted features (e.g., inspection summaries, VIN/image extraction) process the relevant input to produce that feature’s output. We may use aggregated/de-identified data to improve the Service.
3. How information is shared
We share personal information only as needed to run the Service, with providers bound by contract to protect it and use it solely to perform their function:
- Service providers / vendors — companies that provide cloud hosting, database and authentication, file storage, email delivery, and error monitoring on our behalf.
- Payment processor — Stripe processes subscription billing and card payments; we do not store full card numbers.
- AI provider — AI-assisted features (inspection summaries, VIN/image extraction) process the relevant input through a third-party AI provider to produce that feature’s output.
- Legal & business transfers — we may disclose information to comply with law, enforce our terms, or in a merger or acquisition (with notice).
We do not sell personal information or share it for cross-context behavioral advertising. A current list of our subprocessors is available to customers on request.
4. Data retention
We retain personal information for as long as needed to provide the Service and as required by law. On account termination, Customer Data may be exported beforehand and is deleted after a retention window per our retention policy.
5. Security
We use technical and organizational measures including per-tenant data isolation (row-level security), encryption in transit, scoped authentication tokens, access controls, and monitoring. No method is 100% secure, but we work to protect your data.
6. Your rights (California / CCPA-CPRA)
California residents may request to know, access, correct, or delete personal information, and to opt out of “sale”/“sharing” (we do not sell or share for cross-context behavioral advertising). For data a Shop holds about its customers, direct requests to the Shop (the controller); we assist Shops in responding. To exercise rights for data we control, contact us below. We will not discriminate for exercising rights.
7. Cookies, tracking & text messages
We use strictly necessary cookies/local storage for authentication and app function. We do not currently respond to browser “Do Not Track” signals.
If you or a Shop provide a mobile number for text (SMS) messages, the mobile opt-in and consent data is used only to send the messages requested and is not sold or shared with third parties or affiliates for their own marketing.
8. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect their data.
9. International
The Service is operated in the United States. If you access it from elsewhere, you consent to processing in the US.
10. Changes
We may update this Policy; material changes will be notified and the “Last updated” date revised.
11. Contact
ShiftDesk · support@shiftdesk.ai