ShiftProof is an Australian mobile application for aged care and NDIS workers, participants, and families. ShiftProof is operated from New South Wales, Australia.
This Privacy Policy explains how ShiftProof ("we", "us", "our") collects, uses, stores, and protects your personal information when you use our mobile application and website at shiftproof.au.
We are committed to complying with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Contact: support@shiftproof.au
We use your data only for the following purposes:
We do not use your data for advertising. We do not build advertising profiles. We do not sell your data.
Location: All data is stored in Google Cloud infrastructure in the australia-southeast1 region (Sydney, Australia). Your data does not leave Australia.
Encryption: All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256 encryption.
Access control: Your data is only accessible to you and people you explicitly invite via the shared access feature. ShiftProof staff do not access your personal session data except where required to resolve a technical issue you have reported.
Authentication: We use Firebase Authentication. Passwords are hashed and salted — we never store or see your plain-text password.
File storage: Photos, signatures, and invoice files are stored in Firebase Storage with user-scoped security rules. Only authenticated users can access their own files.
We do not sell, rent, or share your personal data with third parties for commercial purposes.
We share data only in the following limited circumstances:
We use the following third-party services to operate ShiftProof. Each is bound by their own privacy policies:
If you invite a support coordinator, family member, or provider via the Shared Access feature, they will be able to view your session records. You control who you invite and can revoke access at any time.
We may disclose your information if required by Australian law, court order, or regulatory authority. We will notify you of any such disclosure where legally permitted to do so.
If ShiftProof is sold or merged with another entity, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
We retain your data for as long as your account is active or as needed to provide our services.
If you delete your account, we will permanently delete all your personal data within 30 days, except where we are required by law to retain it for a longer period.
Crash logs and error reports are retained for 90 days and then automatically deleted.
Under the Australian Privacy Act 1988, you have the right to:
To exercise any of these rights, email us at support@shiftproof.au. We will respond within 30 days.
ShiftProof is designed for use by adults aged 18 and over. We do not knowingly collect personal information from children under 18.
If you believe a child under 18 has provided us with personal information, please contact us at support@shiftproof.au and we will delete that information promptly.
ShiftProof uses the following third-party services. We encourage you to review their privacy policies:
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and by displaying a notice in the app.
The date at the top of this page shows when this policy was last updated. Continued use of ShiftProof after changes to this policy constitutes your acceptance of the updated policy.
For any privacy questions, data requests, or complaints:
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner: