Privacy policy
Version 2026-09-29 (version in force)
This is an English translation. In case of any discrepancy, the Dutch version (Privacyverklaring) prevails.
Who we are
PowerShift is a web application for staff scheduling in hospitality. PowerShift is offered by [TODO: naam eigenaar/eenmanszaak zoals in het KVK-register] (sole proprietorship (eenmanszaak)), trading as PowerShift, registered with the Dutch Chamber of Commerce (KvK) under number [TODO: KvK-nummer], address: [TODO: zakelijk adres of postadres (straat, postcode, plaats)].
For questions about this privacy policy or about your data, email hello@power-shift.nl. PowerShift has not appointed a data protection officer (DPO); this is not required for an organisation of our size and type. This email address is our privacy contact point.
Two roles: controller and processor
Under the General Data Protection Regulation (GDPR) we have two roles:
- We are the controller for your account (login and security), this website, security and technical logs, billing of organisations and our own product statistics. For these, we decide the purpose and means, and you can contact us directly.
- We are a processor for the scheduling and HR data we process on behalf of your employer (the organisation that uses PowerShift): your membership and contract details, teams, qualifications, availability, shifts, trade requests and the like. Your employer is the controller for that data and decides what is recorded and why. The arrangements are set out in our Data processing agreement. When you join an organisation, the app shows you which organisation that is and you confirm that you have read it.
If you want to make a privacy request about data your employer keeps in PowerShift (for example your shifts or availability), please contact your employer first. We help your employer handle such requests. If you send the request to us instead, we will forward it to your employer.
What data we process, why, and on what legal basis
Data we are responsible for
| Data | Purpose | Legal basis |
|---|---|---|
| Account: name, email address, encrypted password (argon2 hash; we never store a readable password), preferred language, two-step verification setting and one-time login codes we send by email | Creating, signing in to and securing your account | Legitimate interest (Art. 6(1)(f)): a working, secure account |
| Owner’s date of birth: if you create an organisation, the date of birth you entered | Checking that you are 18 or older before you accept the terms of service on behalf of the organisation | Performance of the contract (Art. 6(1)(b) GDPR) |
| Date of birth: the date of birth you enter when creating your account | Checking that you are at least 13, and showing younger-than-16 users a simpler explanation | Legitimate interest (Art. 6(1)(f)) |
| Acknowledgements and acceptance: when, and for which version, you confirmed that you have read the user terms and this privacy policy; per organisation you become a member of, that you have read that that organisation is responsible for your work data; which text version you saw (the standard one or the one for under-16s); and — as an owner — your acceptance on behalf of your organisation of the terms of service and the data processing agreement | Being able to show what you were shown and which terms apply | Legitimate interest (Art. 6(1)(f)); for the owner’s acceptance also performance of the contract (b) |
| Notifications: your notification preferences and, if you enable push notifications, a push subscription (your browser’s push service address and your browser type) | Sending you messages about your roster and requests | Legitimate interest (Art. 6(1)(f)): sending you the messages that come with your organisation’s roster; you switch push notifications on and off yourself |
| Security and technical: session cookies, the browser type (user agent) per signed-in session, IP addresses for rate limiting, and server and error logs | Preventing abuse and intrusion, fixing faults | Legitimate interest (Art. 6(1)(f)): a secure, working service |
| Billing (organisation): company name, KvK number, VAT number, billing address, billing email address, subscription and invoices, and per billing period the number of scheduled members the price is based on; later also payment details via our payment provider | Providing and invoicing subscriptions, tax records | Performance of the contract and legal obligation (Art. 6(1)(b) and (c)) |
| Usage and product statistics: per membership, the time you last used the app (updated at most once an hour), and our own, unshared statistics derived from it and from organisation sign-up and onboarding (for example how many users an organisation had active in the last 7 or 30 days, or how many organisations complete onboarding). Only PowerShift administrators see this data. | Running the service and improving the product | Legitimate interest (Art. 6(1)(f)) |
| Contact: whatever you send us when you email us | Answering your question | Legitimate interest (Art. 6(1)(f)); if your question is about your organisation’s customer agreement with us, (preparing) that agreement (b) |
| Website: when you visit power-shift.nl, the web server processes technical data (IP address, time, requested page) in server logs | Security and fault analysis | Legitimate interest (Art. 6(1)(f)) |
We use your date of birth, as controller, only to check your age; on behalf of your employer we also use the same date of birth to apply the rules for young workers (see “Data we process on behalf of your employer” below).
We do not use third-party analytics or advertising services and we do not build marketing profiles.
Data we process on behalf of your employer
As a processor, we process on behalf of your employer:
- Date of birth — we ask for it when you create your account or accept an invitation. Your employer uses it to apply the rules for young workers in the Dutch Horeca CAO (collective labour agreement) and the Working Hours Act: PowerShift shows schedulers your age band and gives signals while planning. Only schedulers and administrators of your organisation see your date of birth; co-workers do not.
- Membership and contract — your role, contract type, contracted hours, start and end date, location(s), teams and qualifications (for example a first-aid certificate).
- Scheduling — your availability and preferred shifts, the shifts assigned to you, open shifts you claim, trade and hand-over requests including the explanation you type yourself, and event notes.
Your employer determines the legal basis for this, typically the performance of the employment contract, legal obligations (such as the Working Hours Act) or a legitimate interest in proper staff scheduling.
Minimum age
PowerShift is intended for people aged 13 and over. Additional rules apply to work by young people in the Netherlands; applying them is the employer’s responsibility.
Under 16? Read what PowerShift does with your data, in short and simple words.
Cookies and local storage
This website (power-shift.nl) sets no cookies and loads no scripts, fonts or other files from third parties.
The application (app.power-shift.nl) only uses strictly necessary, first-party cookies:
| Cookie | Purpose | Lifetime |
|---|---|---|
ps_access |
Keeps you signed in (httpOnly, not readable by scripts) | 15 minutes, renewed automatically |
ps_refresh |
Renews your session without signing in again (httpOnly) | At most 30 days; expires after 14 days without use |
ps_csrf |
Protects against cross-site request forgery (CSRF); must be readable by the application | For the duration of your session (at most 30 days) |
ps_2fa |
While signing in, remembers that your password was correct and the two-step code is still to follow (httpOnly) | 10 minutes, only with two-step verification |
psa_* |
The same functions for the administration console used by PowerShift staff | PowerShift administrators only |
In addition, the application keeps your theme, a few display preferences (such as the view you last chose) and a copy of your user profile in your browser’s local storage (localStorage) so the app loads faster. That data stays on your device.
Because these cookies and this storage are strictly necessary for the service you use, no consent is required (Article 11.7a of the Dutch Telecommunications Act) and we show no cookie banner. We place no tracking, analytics or advertising cookies.
Who we share data with
We never sell your data and only share it with parties we need to provide the service (sub-processors), each bound by arrangements that meet the GDPR:
- Hosting, database and backups — Scaleway SAS, in data centres in the EU (region fr-par (Paris, France)).
- Transactional email (invitations, login codes, roster notifications) — Scaleway SAS (Transactional Email), region fr-par (Paris, France).
- Browser push services — only if you enable push notifications. A notification is delivered through the push service of your browser’s maker, for example Google (Firebase Cloud Messaging) for Chrome, Microsoft for Edge, Mozilla for Firefox or Apple for Safari. Your browser determines which one.
- Payments — Mollie B.V. (the Netherlands), once paid plans start. PowerShift is currently free and no payment data is processed.
Within an organisation, co-workers and schedulers see the data the organisation has set up for that purpose (for example the published roster). Beyond that, we only disclose data to others where the law requires us to.
If you set up a calendar subscription (iCal) yourself, your calendar app fetches your shifts via a personal, secret link. The provider of that calendar app then processes that data by your own choice and under your own responsibility.
Where your data is stored
We store all data in the European Union and do not transfer it to countries outside the EU/EEA. The only exception is push notifications, if you enable them: the push services of Google, Microsoft, Mozilla and Apple, among others, may process outside the EEA. These parties use the safeguards the GDPR requires, such as certification under the EU-US Data Privacy Framework or the European Commission’s standard contractual clauses. Following the Web Push standard, the content of a push notification is end-to-end encrypted; the push service cannot read the text, but does see technical data such as the subscription address and the time.
Retention periods
- Account data: for as long as your account exists. You delete your account yourself via Profile → Delete account (or by email request, see "Your rights"); your account data is then anonymised immediately and backups are overwritten within 30 days.
- Organisation data (scheduling, memberships and other data we process on behalf of the employer): for as long as the agreement with the organisation runs, plus a 30-day retrieval period after it ends; then deleted within 30 days. During the agreement, the employer can ask us to delete data of (former) employees sooner.
- Backups: backups rotate and are overwritten within 30 days.
- Security and technical logs: 90 days (session data: 90 days after the session expired or ended).
- Audit log of administrator access (which PowerShift administrator viewed or did what in the admin console and when, with IP address and browser type): 1 year.
- Invitations (the email address an employer sent an invitation to): an open or accepted invitation is part of the organisation’s data; invitations that expired, were revoked or were declined are deleted 30 days after the expiry date of the invitation.
- Acknowledgements and acceptance (which versions of the user terms, the privacy policy and, per organisation you are a member of, the employer notice you read, and, if you are an owner, which version of the terms of service and the data processing agreement you accepted; this is our proof of the arrangements): your own acceptance of the user terms and this privacy policy: for as long as your account exists, plus 2 years; the acceptance an owner gives on behalf of an organisation of the terms of service and the data processing agreement: for as long as that agreement runs, plus 5 years (the statutory limitation period for contractual claims, art. 3:307 Dutch Civil Code).
- Billing records: 7 years (statutory tax retention duty).
- Usage activity per membership: overwritten on every active use; cleared 12 months after a membership is deactivated.
Security data in our database (sessions, one-time codes and the audit log of administrator access), invitations that were not accepted, and usage activity of an ended membership are deleted automatically every day once their period has passed. An organisation’s data is deleted automatically when the retrieval period ends; the owner receives a confirmation by email. You can delete your account yourself; see below. Other deletion is currently carried out manually, on request, within these periods.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and the right to object. You can change much of your data yourself (name, language, notifications, two-step verification) on your profile page.
You can download a copy of your data yourself via Profile → Download my data, and delete your account via Profile → Delete account. Your employer then keeps your name with the shifts you worked, as its own records. For other requests email hello@power-shift.nl. We may ask you to confirm your identity, for example by replying from your account’s email address. We respond within one month; for complex requests this may be extended by at most two further months, in which case we will let you know. If the request concerns data we process on behalf of your employer, we involve your employer (see “Two roles” above).
If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. We would appreciate it if you contacted us first.
Security
We take appropriate technical and organisational measures, including: encrypted connections (TLS), passwords stored only as argon2 hashes, session cookies that scripts cannot read, CSRF protection, database security that separates data per organisation (row-level security), optional two-step verification, encrypted storage of sensitive identifiers, and hosting and backups within the EU.
Data breaches
If, despite these measures, a data breach occurs, we assess it immediately. Where the law requires it, we report it to the Autoriteit Persoonsgegevens within 72 hours and inform the people affected. If it concerns data we process on behalf of an employer, we inform the employer as agreed in the Data processing agreement, so the employer can meet its own notification duty.
Changes
We may update this privacy policy. The date at the top of this page shows which version applies. We will inform you in advance of significant changes, for example by email or in the application.
Permanent link to this version: /en/privacy/2026-09-29. You can save or print this page (for example as a PDF) to keep the text.
All versions:
- Version 2026-09-29 (version in force)
- Version 2026-09-26