Privacy Policy
Last updated: August 24, 2026
This policy applies to SHIFT_, operated by SHIFT Syndicate Inc. (registered in Québec as Le Syndicat SHIFT Inc.), at shiftsyndicate.ca.
Our Commitment to Your Privacy
SHIFT Syndicate (“we”, “our”, or “us”) is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, store, and protect your data when you use our platform at shiftsyndicate.ca.
Google User Data
SHIFT Syndicate integrates with Google services (such as Google Calendar) via OAuth 2.0. When you authorize this integration, we access the following Google user data:
- •Google Calendar events — read and write access to the events on your primary Google calendar (the
calendar.eventsscope). We read your existing events so the booking system knows when you are already busy, and we create and update events on your calendar when one of your SHIFT bookings is confirmed or rescheduled, so your appointments appear alongside the rest of your schedule. Write access is required for that synchronisation; a read-only scope cannot place a booking on your calendar. SHIFT never deletes calendar events — no deletion capability exists in the integration — and never accesses any calendar other than your primary one. - •Google account profile — your name and email address, used to identify your account during the OAuth authorization flow.
How we use Google data
- •Google Calendar data is used exclusively to keep your own calendar and your SHIFT bookings in step — showing your existing events inside the platform so you are not double-booked, and writing your confirmed SHIFT bookings back to your calendar. It is used for nothing else.
- •We do not share, sell, transfer, or disclose your Google user data to any third parties.
- •We do not use Google user data for advertising, profiling, AI model training, or any purpose other than providing the calendar integration feature.
- •OAuth tokens are stored securely server-side and are never exposed to other users.
Google API Limited Use Disclosure
SHIFT Syndicate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google user data only with your explicit consent, use it only for the features you authorized, and do not transfer it to others except as necessary to provide those features.
Revoking Google access
You can disconnect your Google account at any time from the Integrations section of your professional dashboard, or by visiting your Google Account permissions and revoking access for SHIFT Syndicate.
Core Privacy Principles
Your Data is Never Sold or Shared Without Permission
We will never sell, rent, or share your personal information — including Google user data — with third parties without your explicit consent, except as described in this policy.
You Have Rights to Your Data
You have the right to access, correct, download, or delete your personal information at any time.
Full Account Deletion Available
You can delete your account yourself at any time, from inside the app or the website. It takes effect immediately — you do not have to ask us.
Information We Collect
Account Information
When you create an account, we collect your name, email address, phone number, and other information necessary to provide our services.
Profile Information
For professionals, we collect additional information such as services offered, certifications, portfolio images, and business details to create your professional profile.
Booking and Transaction Data
We collect information about bookings, appointments, payments, and communications between clients and professionals to facilitate our services.
Location Information
With your permission, we collect location data to match you with nearby professionals and facilitate on-demand services.
Usage Data
We collect information about how you use our platform, including pages visited, features used, and interactions, to improve our services.
Google User Data
If you connect your Google account, we collect Google Calendar event data as described in the “Google User Data” section above.
How We Use Your Information
- •To provide and maintain our platform and services
- •To facilitate connections between clients and professionals
- •To process bookings, payments, and transactions
- •To send service notifications, updates, and communications
- •To improve and personalize your experience on our platform
- •To ensure safety and security on our platform
- •To comply with legal obligations
We do not use your data for targeted advertising, to sell to data brokers, to train AI models, or for any purpose unrelated to providing or improving the SHIFT Syndicate platform.
How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only in these limited circumstances:
- •Between clients and professionals — when you make or accept a booking, relevant contact and appointment details are shared between the parties to fulfill the service.
- •Service providers — we share data with trusted vendors (Firebase/Google Cloud, payment processors, communication services) solely to operate our platform. These providers are contractually prohibited from using your data for other purposes.
- •Legal requirements — we may disclose information if required by law, court order, or to protect the safety of our users or the public.
Google user data is never shared with, transferred to, or disclosed to any third party for any purpose other than providing the calendar integration feature you authorized.
Data Security
We implement industry-standard security measures to protect your personal information, including:
- •Encryption of data in transit (TLS/HTTPS) and at rest
- •Secure authentication systems via Firebase Authentication — we never store raw passwords
- •Multi-layer Firestore Security Rules enforced at Google's database servers, independent of our application code
- •Role-based access controls (RBAC) verified server-side on every request — cannot be elevated from the client
- •All production secrets stored in GCP Secret Manager — never in source code or configuration files
- •Secure Google Cloud Run infrastructure certified SOC 2 Type II, ISO 27001, and FedRAMP
- •OAuth tokens stored server-side only and never exposed to other users
For a full technical description of our security architecture — including AI-layer controls, prompt injection defences, and breach scenario analysis — see our Security Overview.
Your Privacy Rights
You have the following rights regarding your personal data:
- Access:Request a copy of the personal data we hold about you
- Correction:Request correction of inaccurate or incomplete data
- Deletion:Delete your account yourself, in the app or on the website — no request needed
- Portability:Request export of your data in a machine-readable format
- Objection:Object to processing of your data for specific purposes
- Withdrawal:Withdraw consent at any time, including disconnecting your Google account
To exercise any of these rights, please contact us at privacy@shiftsyndicate.ca
Data Retention and Deletion
We retain your personal information only as long as necessary to provide our services and comply with legal obligations. You can delete your account yourself, from inside the app or the website — Account → Danger Zone → Delete Account. It is not a request, and you do not need to contact us. Deletion begins the moment you confirm it and cannot be undone.
Your sign-in is disabled immediately. We then permanently remove:
- •Your login, profile, photo and banner image, and your @handle
- •Everything our AI assistant had remembered about you — including any address, contact details or preferences it had noted from your conversations
- •Your notifications, saved availability, services, expenses, QR codes and gallery photos
Records that belong to two people — a booking, an invoice, a review, a message thread — are not deleted, because the other person is entitled to their own history and their own books. Instead your name and contact details are removed from them. The amount, date and service remain; you do not.
The one exception: an unpaid balance
If you still owe money for a service you received, or a professional still owes platform fees, we keep your name and one contact channel — and nothing else — so that the person you owe can pursue it. We do not keep your address, your photo, or your history. That record appears nowhere in the app, is removed when the balance is settled, and is deleted in any case after three years. Under Quebec's Law 25 and PIPEDA, the right to erasure gives way where information is needed to comply with a legal obligation or to establish and defend a legal claim; this is the minimum that does so.
Financial records are kept where tax law requires it (transaction history for up to 7 years), with your identifying details removed.
Because SHIFT is invitation‑only, deleting your account means you would need a new invitation from a professional to return. Nothing is recoverable afterwards.
Google user data (OAuth tokens and imported calendar data) is deleted immediately upon disconnecting your Google account integration.
Third-Party Services
We use trusted third-party services to operate our platform:
- •Firebase / Google Cloud Platform: Authentication, database, cloud infrastructure, and hosting
- •Google Calendar API: Optional calendar integration (requires your explicit authorization)
- •Payment Processors: Secure payment processing (we do not store credit card information)
- •Google Gemini and Google Cloud Speech-to-Text: Power Agent Shift AI chat and voice sessions, and AI sentiment analysis of platform interactions. Conversation text and voice audio are transmitted to Google for processing per Google Cloud's AI usage policies.
- •Communication Services (Twilio, Resend): SMS and email delivery for booking notifications
These services have access to your information only to perform tasks on our behalf and are contractually obligated not to disclose or use it for other purposes.
Children's Privacy
Our services are not intended for users under 16 years of age. We do not knowingly collect personal information from anyone under that age. If you believe we have collected information from someone under 16, please contact us immediately at privacy@shiftsyndicate.ca.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last updated” date. For significant changes involving Google user data, we will notify you by email and require re-authorization if necessary. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your data (including Google user data), please contact us:
Privacy inquiries: privacy@shiftsyndicate.ca
General inquiries: Contact Form
Website: shiftsyndicate.ca