Privacy Policy

This Privacy Policy explains which personal data ShiftAlarm processes in the mobile app and on these information pages.

1. Controller

Marcel Nitsch
ShiftAlarm
Eschmarer Str. 23
53859 Niederkassel
Germany
Email: support.shiftalarm@gmail.com

2. Overview

ShiftAlarm is primarily a local shift and calendar app. Its core features can be used free of charge without a registered account. A registered account is required for account-related functions and to purchase or restore ShiftAlarm Pro.

Guest use is local. ShiftAlarm does not create an anonymous Firebase account merely because the app is used without registration.

ShiftAlarm does not use advertising networks, advertising identifiers, Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring or tracking cookies on this website. Shifts and calendar content are not automatically synchronised to the cloud.

3. App data stored locally

Shifts, shift templates, rotations, personal and work calendar entries, vacation, sickness and other absences, overtime, profiles, settings, colours, alarms, reminders, widgets and manually created backups are generally stored locally on the device. Selected display information for iOS widgets may also be stored in the app's protected App Group.

This content is not automatically sent to a ShiftAlarm server. It remains stored until you delete it in the app, clear the app's data or uninstall the app. A storage or sharing service selected by you may process an export or backup file under its own terms.

The legal basis for processing required to provide these app functions is Article 6(1)(b) GDPR.

4. Registered accounts and Firebase

ShiftAlarm uses Google Firebase Authentication and Cloud Firestore for registered accounts and account-related functions.

When you register or sign in, ShiftAlarm may process your email address, display name, Firebase user ID, authentication provider identifiers, platform information, account creation and sign-in timestamps and account-related Pro metadata.

Depending on platform and availability, email and password, Google or Apple may be offered as sign-in methods. Local shift, calendar, vacation, sickness, overtime, alarm, profile and backup data is not automatically uploaded because you create an account.

Firebase services and their software development kits may also process technical information required to provide, secure and operate their services. This can include IP addresses, app and SDK information, device information, technical identifiers and diagnostic information. Depending on the platform, Firebase identifiers or messaging-related tokens may also be processed.

ShiftAlarm does not use the Firebase Analytics product. Technical data that Firebase components classify for analytical or diagnostic purposes does not mean that Firebase Analytics is enabled in ShiftAlarm.

The legal basis for account-related processing is Article 6(1)(b) GDPR.

5. Google and Apple sign-in

If you voluntarily choose Google or Apple sign-in, the selected provider processes information required for authentication under its own privacy terms. ShiftAlarm receives the authentication information made available to the app, such as an authentication identifier, sign-in token and account information released by the provider.

Depending on the provider and your settings, this may include your name, email address or a provider-specific user identifier. Apple may provide a private relay email address if you choose to hide your email address.

Authentication SDKs may also process technical device, network, usage and security-related information required to provide and protect the sign-in service. Such processing is subject to the privacy terms of the respective provider.

6. ShiftAlarm Pro, RevenueCat and app stores

Subscriptions and digital purchases are offered and billed through the respective app store. ShiftAlarm does not receive complete payment-card details.

ShiftAlarm uses RevenueCat for purchase processing, subscription-status checks, entitlement management and purchase restoration. The registered account's Firebase user ID is used as the RevenueCat App User ID.

RevenueCat may process the Firebase user ID, optional email address or display name, product identifiers, purchase and subscription status, entitlements, expiry information, store information and technical transaction data.

RevenueCat diagnostics are disabled in ShiftAlarm. RevenueCat is used only for registered accounts.

Contract-related processing is based on Article 6(1)(b) GDPR. Records required by law may be processed under Article 6(1)(c) GDPR. Apple or Google independently processes payments and retains store records under its own responsibility.

7. Voluntary feedback and support through Supabase

If you voluntarily use the in-app feedback function, ShiftAlarm may send the selected category, your message, app version, platform, language, selected theme and screen size to the feedback backend operated with Supabase.

Contact information and profile name are included only if you voluntarily provide them or choose to include them. Feedback information is used to answer requests, troubleshoot problems and improve ShiftAlarm.

To protect the feedback service against abuse and excessive requests, ShiftAlarm also uses a locally generated installation identifier and a network-related signal for rate limiting. The installation identifier and network/IP-related signal are immediately processed using salted hashing for this purpose. Raw network/IP information is not stored in the feedback record for rate limiting.

Rate-limit hash buckets are removed after seven days as part of the cleanup process.

Please do not submit passwords, payment details, complete backups or confidential calendar or employer information through the feedback function.

The legal basis is Article 6(1)(b) GDPR for support requests, Article 6(1)(a) GDPR for voluntarily supplied additional information and Article 6(1)(f) GDPR for technical protection, abuse prevention and handling of technical error reports.

Feedback is stored separately from the Firebase account and is not automatically deleted when a ShiftAlarm account is deleted. You may contact support.shiftalarm@gmail.com regarding deletion of separately stored feedback associated with you.

8. Public holiday data

To retrieve public holidays, the app sends the selected country and year to the Nager.Date API. The service necessarily receives the IP address and standard connection data required for the request.

Personal shift or calendar content is not transmitted to Nager.Date. Results are cached locally.

The legal basis is Article 6(1)(b) GDPR.

9. Notifications, alarms and widgets

Notifications, alarms and widgets are provided through operating-system functions. Required content and settings are processed locally or, where applicable, in the protected iOS App Group.

ShiftAlarm does not create advertising or tracking profiles from this information.

10. Backup, import and export

Backups and exports are created, opened, imported or shared through a system dialog only at your request. ShiftAlarm does not automatically upload backups to a cloud service.

External storage and sharing services selected by you operate under their own privacy terms.

11. This website

These static information pages are provided through Firebase Hosting. Google processes technically required access information, including IP address, time, requested URL, browser information and server-log information, to deliver and protect these pages.

This website uses no forms, analytics tools, advertising services or tracking cookies. No cookie-consent banner is therefore currently required for these static pages.

12. Recipients and possible international transfers

Depending on the function used, Google/Firebase, Apple, Google Play, RevenueCat, Supabase and Nager.Date may process data.

Processing outside the European Economic Area may occur. Where required, transfers rely on an adequacy decision, standard contractual clauses or other safeguards permitted by applicable data-protection law.

The providers' own privacy information also applies:

13. Retention and deletion

14. Account and data deletion

A registered ShiftAlarm account can be deleted directly in the app under Profile icon → Account → Delete account.

Account deletion removes the Firebase Authentication account, the associated Firestore user data and the associated RevenueCat customer data handled by ShiftAlarm. Referenced administrative audit fields may be anonymised where required for integrity or security purposes.

For accounts using Sign in with Apple, ShiftAlarm performs the required re-authentication and revokes the Apple sign-in authorisation as part of the deletion process where applicable.

Local app data and separately stored feedback are not automatically deleted together with the online account. Local data can be removed separately from the device. For separately stored feedback, contact support if deletion is required.

Further information and an external deletion option are available under Delete account and data.

Important: Deleting the ShiftAlarm account does not automatically cancel an active subscription. Active subscriptions must be cancelled separately through the respective app store.

15. Your rights

Subject to the GDPR, you may have rights of access, rectification, erasure, restriction of processing, data portability and objection.

Where processing is based on consent, you may withdraw that consent for the future. You also have the right to lodge a complaint with a competent data-protection supervisory authority.

Requests can be sent to support.shiftalarm@gmail.com . Only information necessary to process the request and prevent unauthorised access will be requested.

16. Children

ShiftAlarm is not specifically directed at children. Users who cannot enter contracts independently under the law applicable to them require any consent or involvement of their legal representative required by law.

17. Changes

This Privacy Policy will be updated when functions, service providers, data processing or legal requirements change. The current version will be published at this address.

Last updated: September 2, 2026