Your data. Your rules. Our responsibility.
Last updated: June 23, 2026 — Schedaddle LLC
We built Schedaddle to save retail managers time, not to harvest their data. This policy explains what we collect, how we use it, and why. No legalese marathons. If you have questions, email us at privacy@schedaddle.co.
This policy is operated by Schedaddle Limited Liability Company, a Texas limited liability company doing business as "Schedaddle" ("Schedaddle," "we," "us," "our").
The Manifest — What We Collect
We only collect what we need to run the scheduling service. Here is the full manifest:
Account & Store Data
- Email address and password (hashed — we never see it in plaintext)
- Store name, country, timezone, and GPS coordinates (if you enable geofencing)
- Subscription tier and billing status (payment details handled by Stripe — we do not store card numbers)
Employee & Schedule Data
- Employee names, roles, and email addresses
- Weekly availability windows set by the employee
- Shift assignments, role blocks, and published schedules
- Clock-in/out timestamps and GPS coordinates at the moment of clock-in/out
- Break records and attendance history
Device & Usage Data
- Push notification tokens (stored to deliver schedule alerts)
- Device platform (iOS/Android) for notification routing
- Standard server logs (IP address, request timestamps) for security purposes
Our Role & Legal Basis — Who Controls What
Schedaddle serves two kinds of data, and our legal role is different for each. This matters because it determines who decides how the data is used.
- Account holder / store data (we are the controller). For the data of the store owner or manager who signs up — your account email, billing contact, and the choices you make about your store — Schedaddle decides the purposes and means of processing.
- Employee data (we are a processor). For the data of employees a store adds to the platform — names, availability, schedules, attendance, and clock-in location (where geofencing is enabled) — the store is the controller and Schedaddle acts as a processor on the store's documented instructions. We process this data to provide the Service and do not use it for our own purposes.
For employees: because your employer controls your data in Schedaddle, requests to access, correct, or delete your information are generally directed to your employer first. We will assist the store in responding, and we will honor requests we are legally required to action directly. Our Data Processing Addendum sets out these processor obligations in full.
Legal Basis for Processing
Where data protection law (such as the GDPR or UK GDPR) applies, we rely on the following bases:
- Performance of a contract — to provide the scheduling service you or your employer signed up for.
- Legitimate interests — to secure, maintain, and improve the Service, balanced against your rights.
- Legal obligation — to retain certain attendance and payroll-adjacent records where law requires.
- Consent — for optional features such as geofencing, where consent is collected by the store before the feature is used.
The Hangar — How We Protect It
The Hangar is our internal name for the security layer around your data. We take this seriously.
- Supabase Row-Level Security (RLS): Every database query is constrained by your store ID at the database level — not just the application layer. A query from Store A physically cannot return data from Store B, even if misconfigured.
- Encryption in transit: All data is transmitted over TLS 1.2+. No plaintext connections.
- Encryption at rest: Supabase encrypts all data at rest on managed infrastructure.
- Service role keys: Admin-level database operations use a service role key stored only in server-side environment variables — never exposed to the client.
- 2FA support: TOTP-based two-factor authentication is available for all accounts.
Biometric App Unlock & Geofencing — The Sensitive Stuff
We know biometrics and location data are sensitive. Here is exactly what happens and what does not happen:
Biometric App Unlock (Face ID / Fingerprint)
- What it is. Schedaddle's only use of biometrics is an optional convenience at sign-in: you can use your device's built-in Face ID or fingerprint unlock to open the Schedaddle app instead of typing your password. This is the same operating-system unlock you use for other apps.
- We never receive a biometric identifier. The face or fingerprint match happens entirely inside your device's Secure Enclave (iOS) or TrustZone (Android). Schedaddle does not collect, store, or transmit any biometric identifier or biometric information (no facial geometry, no fingerprint template). The app only learns whether the device unlock succeeded.
- It is optional. You can always sign in with email and password instead.
- We do not offer face-match clock-in. Clocking in and out is verified by a personal PIN and, optionally, a geofence check — not by matching your face or fingerprint. We do not run facial recognition on anyone.
Plain English: Because Schedaddle never collects or stores a biometric identifier or biometric information, biometric-privacy laws that govern the collection of such identifiers (such as the Illinois Biometric Information Privacy Act and the Texas Capture or Use of Biometric Identifier Act) do not apply to our processing. If we ever introduce a feature that captures a biometric identifier, we will first obtain the consent those laws require and publish the applicable retention and destruction schedule here.
Geofencing & GPS Location
- GPS is sampled only at the moment of clock-in or clock-out. We do not track employee location continuously. There is no background location streaming.
- The geofence boundary (typically 100m radius around the store) is computed on-device. The device checks "am I inside this circle?" and sends us only the timestamp and a yes/no result.
- Store GPS coordinates are set by the store manager and stored in our database. Employees can see that geofencing is enabled but cannot see the exact coordinates.
- Geofencing is optional and configurable per store in Settings. Stores can disable it entirely or use manual clock-in only.
Plain English: We do not know where your employees are except at the exact moment they tap Clock In or Clock Out. That timestamp and location is stored for attendance records only.
The Tower — How We Use Your Data
We use your data only to run Schedaddle. Specifically:
- To build and display your schedule
- To send shift notifications and emails to your team
- To calculate labor budgets, overtime flags, and training progress
- To generate clock-in/out reports for your payroll process
- To understand how the product is used and improve it. This product-analytics data is pseudonymized — tied to an account user ID rather than directly to your name — and, on the web app, includes in-app session analytics and session replay (recordings of in-app interactions) provided by PostHog, with all text inputs masked. We use it to debug issues and improve the apps, not to build advertising profiles, and it only loads where analytics are permitted (see Cookies & Tracking).
What we never do:Sell your personal information for money. Share your employees' or scheduling data with advertisers. Use your schedule data to train AI models without explicit consent. Mine your data for any purpose not described here.
Third Parties & Sub-processors
We use a small set of trusted vendors ("sub-processors") to run the Service. Each is bound by a data-processing agreement and may only use data to provide its service to us. We never share employee data with third parties for advertising.
- Vercel — Web hosting and edge delivery. All requests to the web app and scheduled jobs run on Vercel's infrastructure.
- Supabase — Database and authentication. Data is hosted in their managed cloud (AWS infrastructure).
- Resend — Transactional email for schedule notifications. Your employees' email addresses are shared with Resend solely to deliver schedule emails.
- Expo / EAS — Mobile app build and push notification delivery. Push tokens are shared to route notifications to the correct device.
- Stripe — Payment processing. We share billing contact information. Stripe handles all card data; we never see it.
- Google — Optional sign-in (Google OAuth) and, if you connect it, an optional Google Calendar sync that pushes shift data to a store-specific calendar. You can disconnect at any time in Settings.
Separately, our public marketing site uses analytics and advertising technologies (Google, Microsoft, Meta, and Reddit) to measure visits and our own advertising. These are described in detail under Cookies & Tracking, including how to opt out. They process marketing-site visitor activity and the hashed identifiers of people creating an account — never employee or scheduling data.
The current, authoritative list of all vendors — including each one's role, the data it touches, and its region — is published at schedaddle.co/subprocessors. We will give customers advance notice through that page before a new sub-processor that handles personal data is engaged, so you have the opportunity to object.
International Data Transfers & Residency
Schedaddle is operated from the United States, and our sub-processors may store or process data in the United States. If you or your employees are located outside the U.S. (for example, in the UK or EEA), your data will be transferred to and processed in the U.S.
Where such transfers are subject to the GDPR or UK GDPR, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) — together with the technical measures described in The Hangar above. To request a copy of the transfer mechanism that applies to you, email privacy@schedaddle.co.
EEA / UK representative. Where we are required to designate a representative under Article 27 of the GDPR or UK GDPR, we will appoint one and publish their contact details here. In the meantime, individuals in the EEA or UK can raise any data-protection matter with us directly at privacy@schedaddle.co.
Data Breach Notification
We maintain procedures to detect, investigate, and respond to security incidents. If we become aware of a personal-data breach affecting your data, we will notify the affected store (as controller) without undue delay after becoming aware of it, and provide the information needed to meet your own notification obligations. Where Schedaddle is the controller, we will notify affected individuals and regulators as required by applicable law.
Your Rights
Depending on your jurisdiction, you have rights regarding your data:
- Access: Request a copy of all data we hold about you or your store.
- Correction: Ask us to correct inaccurate data.
- Deletion: Request deletion of your account and all associated data. We will action this within 30 days.
- Portability: Request your data in machine-readable format (CSV or JSON).
- Objection: Object to specific processing activities.
To exercise any right, email privacy@schedaddle.co. We will respond within 30 days (within 45 days for California requests), and may extend that period where the law allows, in which case we will tell you. If you are an employee, see "Our Role & Legal Basis" above — we may direct your request to your employer, who controls your data. There is no charge to exercise these rights, and we will not discriminate against you for doing so.
Appeals
If we decline to act on your request, you may appeal that decision within a reasonable time by emailing privacy@schedaddle.co with "Privacy Appeal" in the subject line. We will review the appeal and respond in writing — with our reasoning — within 60 days. If we deny your appeal, you may submit a complaint to your state attorney general: for example, the Texas Attorney General (Texas residents) at texasattorneygeneral.gov, or the equivalent authority in your state.
California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the rights described above plus the right to know, delete, correct, and to limit the use of sensitive personal information. The categories below describe what we collect and how we handle it.
- Categories collected: identifiers (name, email), commercial information (subscription/billing status), internet/network activity (server logs), geolocation (clock-in GPS), and sensitive personal information (precise geolocation, where geofencing is enabled). We do not collect biometric identifiers — biometric app unlock happens on your device and no template or identifier is ever sent to us.
- Sources: directly from you and your employer, and from your use of the apps.
- Purposes: to provide, secure, and improve the scheduling service, as described in The Tower above.
- Disclosed to: the sub-processors listed above to provide the Service, and — for marketing-site visitors only — the advertising and analytics platforms described under Cookies & Tracking.
- "Shared" for advertising: identifiers and internet activity of marketing-site visitors are disclosed to advertising platforms for cross-context behavioral advertising. We do not "share" the data of employees or the categories collected inside the app.
We do not sell your personal information for money. However, our marketing site uses advertising technologies (such as the Meta, Google, and Reddit pixels) that disclose limited, hashed identifiers to those platforms for cross-context behavioral advertising — which the CPRA defines as "sharing." California residents have the right to opt out: use the "Do Not Sell or Share My Personal Information" link in our footer, and we automatically honor the Global Privacy Control (GPC) signal. We never share employee or scheduling data with advertisers, and we do not use or disclose sensitive personal information beyond the purposes permitted by law. You may also limit the use of sensitive personal information by disabling geofencing, or by emailing privacy@schedaddle.co.
Other U.S. State Privacy Rights
Schedaddle is a Texas company and is subject to the Texas Data Privacy and Security Act (TDPSA). If you are a resident of Texas, Virginia, Colorado, Connecticut, Utah, Oregon, Montana, or another state with a comprehensive consumer-privacy law, you have rights similar to those described above, which generally include:
- To confirm whether we process your personal data and to access it.
- To correct inaccuracies in your personal data.
- To delete personal data you provided or that we obtained about you.
- To obtain a portable copy of your data.
- To opt out of targeted advertising, the "sale" of personal data, and certain profiling.
To exercise these rights, email privacy@schedaddle.co; to appeal a decision, see Appeals above. The only activity that qualifies as "targeted advertising" or a "sale/share" is the marketing-site advertising described under Cookies & Tracking— which you can opt out of using the "Do Not Sell or Share My Personal Information" footer link and the Global Privacy Control. We never sell, share, or use for targeted advertising any employee or scheduling data.
Children & Minors
Schedaddle is a workforce-scheduling tool intended for business use by adults. The Service is not directed to children, and we do not knowingly collect personal information directly from anyone under 16. Where a store schedules workers who are minors under local law, the store (as controller) is responsible for obtaining any consent the law requires — including, for minors, from a parent or guardian — before adding that worker's data to the platform, and for complying with applicable youth-employment rules. If you believe a minor has provided us personal information directly, email privacy@schedaddle.co and we will delete it.
Delete Your Account
You can request deletion of your Schedaddle account and all associated data at any time. This includes your profile, store data, employees, schedules, attendance records (subject to legal retention requirements below), and any other personal information we hold.
To request account deletion: Email privacy@schedaddle.co with the subject line "Account Deletion Request" and include the email address associated with your account.
- We will confirm receipt within 2 business days.
- Your account and personal data will be permanently deleted within 30 days of your request.
- Attendance and clock-in records that law requires us to keep may be retained only for the period and purpose the applicable law requires (up to 7 years in some jurisdictions), then deleted.
- Deletion is irreversible. All store data, schedules, and employee records will be permanently removed.
Cookies & Tracking
Strictly necessary cookies
The Schedaddle web app uses essential cookies to keep you logged in and secure. These are always on and cannot be turned off, because the Service will not work without them.
Analytics & advertising on our marketing site
On our public marketing site we also use the following technologies. They run subject to your choices below.
- Analytics — Google Analytics 4, Microsoft Clarity (input-masked session analytics), and PostHog help us understand how visitors find us and improve the site and product. PostHog also provides in-app product analytics and session replay for signed-in web-app sessions — recordings of in-app interactions, tied to an account user ID, with all text inputs masked. It loads only where analytics are permitted under your choices below.
- Advertising — the Meta, Google Ads, Microsoft (UET), and Reddit pixels let us measure which ads lead to signups and reach people who visited but did not sign up. The only personal data shared with these platforms is limited, hashed identifiers (such as a hashed email address or a cookie/device ID) of someone creating an account — used solely to measure and optimize our own advertising.
We never sell your personal information for money, and we never share employee or scheduling data with advertising platforms. The current list of these vendors — with each one's role and region — is on our sub-processors page.
Your choices
- EEA, UK & Switzerland: we ask for your consent before any non-essential analytics or advertising technology loads. You can accept or decline on the banner shown on your first visit; declining keeps everything except the strictly necessary cookies switched off.
- California (and anyone sending a Global Privacy Control signal): California treats the advertising activity above as "sharing." We automatically honor the Global Privacy Control browser signal, and you can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our footer. We do not sell your information for money in any case.
- Everywhere else: these technologies are on by default; you can still use the "Do Not Sell or Share" link or your browser's privacy controls to opt out.
Data Retention
- Active account data is retained for as long as your account is active.
- On account deletion, all personal data is purged within 30 days. De-identified aggregates that can no longer reasonably be linked to an individual (e.g., total shifts processed) may be retained for product analytics; we do not attempt to re-identify them.
- Where labor or tax law requires it, attendance and clock-in records may be retained for the period the applicable law requires (up to 7 years in some jurisdictions) and only for that compliance purpose, then deleted. This is the one carve-out to the deletion timeline above.
Retention by category: account and store identifiers and commercial (billing) information are kept for the life of the account and purged within 30 days of deletion; server-log network activity is kept only for as long as needed for security monitoring and then deleted; clock-in geolocation and attendance records follow the labor-law schedule above. We retain each category only as long as needed for the purpose it was collected for, or as the law requires.
Changes to This Policy
We may update this policy from time to time. When we make a material change, we will update the "Last updated" date above and, where the change significantly affects how we handle your data, give notice by email or an in-app notice before it takes effect. Your continued use of the Service after a change takes effect means you accept the updated policy.
Contact
Schedaddle Limited Liability Company (d/b/a Schedaddle)
privacy@schedaddle.co
schedaddle.co
If you have a complaint about how we handle your data and we have not resolved it to your satisfaction, you have the right to lodge a complaint with your local data protection authority.