Privacy Policy
What Shifti collects about you, who can see it, and how long it stays — in plain language.
Last updated: 2026-09-13
Who we are and who owns your data
Shifti is operated by **Mohammed bin Muaidh bin Mohammed Al-Shatwi** as a self-employed professional under Saudi freelance licence No. FL-585051391. For anything concerning your data: support@shifti.cc.
Your data belongs to your employer: they decide what is collected and why, and we **process it on their behalf** to run the service for them — never for a purpose of our own. So a request starts with your employer; if that does not resolve it, write to us and we will coordinate with them.
What we actually collect
- Employment identity — Name, national ID or iqama number, employee number, hire date, email, branch and shift. Entered by your employer, not by you.
- Attendance record — Check-in and check-out times, the branch, the punch method (QR scan, location, or manual), and any note you add with a punch.
- Location — only at the moment of a punch — If you punch by location, your coordinates and their accuracy are recorded at that moment only, to compare against your branch. No tracking before or after, and none in the background.
- Device — A hashed fingerprint of your device identifier (not the identifier itself), plus platform, model, app version, binding time and last seen — so nobody can punch as you from another phone.
- Your requests and documents — Leave requests with their reasons and attachments, punch corrections, disciplinary inquiries and your replies, and documents uploaded by you or your employer.
- Financial data — Salary, allowances, IBAN, advances and payslips — entered by your employer.
- Operational data — Sign-in attempts, an audit trail of actions inside your company account, and app sessions. App crash reports reach our server only, carry six technical fields, and their text is automatically stripped of any email, long number or access token before it is stored.
Health data
Health data may pass through us: whether a leave request is a sick leave, the reason you write for it, medical reports you attach, and health certificates among your documents.
It is stored like your other documents outside the public folder and downloaded only through an authenticated link. Only your employer and those they authorise can see it. It is never used for any other purpose and never shared.
What we never collect
- We do not track your location outside the moment of a punch, and we do not read it while the app is closed.
- We do not access your contacts, photos or microphone, and the camera only while you scan a branch code.
- No advertising identifier and no ads. We do not sell or share data for marketing — now or later.
- No third-party tracking or analytics SDK inside the app.
Who sees what
- Your employer sees their own company only — the isolation is enforced in the database, not by a setting that can be changed.
- A branch supervisor sees the employees of their own branches only.
- You see your own data. Internal management notes are never shown to you — deliberately — and they are not shown to your colleagues either.
- We — the platform operators — do not look at your company data in day-to-day work. We do hold a "sign in as" capability for technical support: it is **read-only** and every use is written to a log that cannot be edited.
Where your data is stored
On servers of our hosting provider Namecheap in the United States. We state this plainly because you deserve to know: your data is processed outside Saudi Arabia today, and moving hosting into the Kingdom is on our published roadmap.
Connections are always encrypted (HTTPS), passwords are stored hashed and cannot be read by us, documents live outside the public folder with no direct link, and backups run daily.
Who receives any of your data
Three parties only, each for a single purpose:
- Resend — Email delivery service. It receives your email address and the content of the message we send you (a leave notice, sign-in details).
- Cloudflare Turnstile — A check that tells humans from bots on the sign-in page. It receives your IP address and browser information — not your name and not your password.
- Zoho — The mailbox provider that receives what you send to our support address.
And nothing else: no fonts or libraries from external servers — every file on the page comes from our own server, so no third party learns that you opened the app.
How long your data is kept
Each type has a stated period, enforced by actual deletion rather than promised in text: **attendance records for five years** from the punch date (the limitation period for labour claims) · **documents, leave requests and their attachments — including health-related ones — are deleted twelve months after your company's subscription ends** · **the audit trail for three years** · app sessions are deleted as soon as they expire. Deletion runs automatically, daily.
The attendance record specifically is your employer's statutory register and may be requested by the authorities. An employee with an attendance record therefore has their **account deactivated, not their record deleted** — which blocks sign-in while keeping the record attributed to their employee number.
Your rights
- To know what we hold about you and request a copy.
- To correct your data if it is wrong.
- To request deletion of your account within what the law allows (see the section above).
- To object to processing or withdraw consent where processing rests on consent.
Start with your employer — they hold the decision over your data. If that does not resolve it, write to support@shifti.cc and we will answer **within thirty days** at most. We may ask you to prove your identity before releasing any data — to protect you, not to delay you.
support@shifti.cc
Other matters
Shifti is an employment product intended for people **aged 18 and over**. We do not address children or knowingly collect their data; if we learn otherwise we delete the data and inform the employer.
If a breach affects your data we notify **your company's administrators within seventy-two hours** of becoming aware, with what we know of its scope and what we have done. Notifying employees rests with the employer as the party responsible for their data — we are a processor acting on their behalf.
If we change this policy we update the date above, and we notify company administrators of material changes before they take effect.