PowerShift
FeaturesPricingAboutContact
NL·EN
Log inStart free

Draft — have a lawyer review before launch.

Privacy policy

Version 2026-09-26

This is an earlier version of this document. See the current version.

This is an English translation. In case of any discrepancy, the Dutch version (Privacyverklaring) prevails.

Who we are

PowerShift is a web application for staff scheduling in hospitality. PowerShift is offered by [TODO: naam eigenaar/eenmanszaak zoals in het KVK-register] (sole proprietorship (eenmanszaak)), trading as PowerShift, registered with the Dutch Chamber of Commerce (KvK) under number [TODO: KvK-nummer], address: [TODO: zakelijk adres of postadres (straat, postcode, plaats)].

For questions about this privacy policy or about your data, email hello@power-shift.nl. PowerShift has not appointed a data protection officer (DPO); this is not required for an organisation of our size and type. This email address is our privacy contact point.

Two roles: controller and processor

Under the General Data Protection Regulation (GDPR) we have two roles:

  • We are the controller for your account (login and security), this website, security and technical logs, billing of organisations and our own product statistics. For these, we decide the purpose and means, and you can contact us directly.
  • We are a processor for the scheduling and HR data we process on behalf of your employer (the organisation that uses PowerShift): your membership and contract details, teams, qualifications, availability, shifts, trade requests and the like. Your employer is the controller for that data and decides what is recorded and why. The arrangements are set out in our Data processing agreement.

If you want to make a privacy request about data your employer keeps in PowerShift (for example your shifts or availability), please contact your employer first. We help your employer handle such requests. If you send the request to us instead, we will forward it to your employer.

What data we process, why, and on what legal basis

Data we are responsible for

Data Purpose Legal basis
Account: name, email address, encrypted password (argon2 hash; we never store a readable password), preferred language, two-step verification setting and one-time login codes we send by email Creating, signing in to and securing your account Performance of the contract (Art. 6(1)(b) GDPR)
Owner’s date of birth: if you create an organisation, the date of birth you entered Checking that you are 18 or older before you accept the terms of service on behalf of the organisation Performance of the contract (Art. 6(1)(b) GDPR)
Acceptance of terms: when, and for which version, you accepted the user terms and this privacy policy, and — as an owner — the terms of service and the data processing agreement on behalf of your organisation Being able to show which terms apply Legal obligation and legitimate interest (Art. 6(1)(c) and (f))
Notifications: your notification preferences and, if you enable push notifications, a push subscription (your browser’s push service address and your browser type) Sending you messages about your roster and requests Performance of the contract; you switch push notifications on and off yourself
Security and technical: session cookies, the browser type (user agent) per signed-in session, IP addresses for rate limiting, and server and error logs Preventing abuse and intrusion, fixing faults Legitimate interest (Art. 6(1)(f)): a secure, working service
Billing (organisation): company name, KvK number, VAT number, billing address, billing email address, subscription and invoices, and per billing period the number of scheduled members the price is based on; later also payment details via our payment provider Providing and invoicing subscriptions, tax records Performance of the contract and legal obligation (Art. 6(1)(b) and (c))
Usage and product statistics: per membership, the time you last used the app (updated at most once an hour), and our own, unshared statistics derived from it and from organisation sign-up and onboarding (for example how many users an organisation had active in the last 7 or 30 days, or how many organisations complete onboarding). Only PowerShift administrators see this data. Running the service and improving the product Legitimate interest (Art. 6(1)(f))
Contact: whatever you send us when you email us Answering your question Legitimate interest, or (preparing) a contract
Website: when you visit power-shift.nl, the web server processes technical data (IP address, time, requested page) in server logs Security and fault analysis Legitimate interest (Art. 6(1)(f))

We do not use third-party analytics or advertising services and we do not build marketing profiles.

Data we process on behalf of your employer

As a processor, we process on behalf of your employer:

  • Date of birth — we ask for it when you create your account or accept an invitation. Your employer uses it to apply the rules for young workers in the Dutch Horeca CAO (collective labour agreement) and the Working Hours Act: PowerShift shows schedulers your age band and gives signals while planning. Only schedulers and administrators of your organisation see your date of birth; co-workers do not.
  • Membership and contract — your role, contract type, contracted hours, start and end date, location(s), teams and qualifications (for example a first-aid certificate).
  • Scheduling — your availability and preferred shifts, the shifts assigned to you, open shifts you claim, trade and hand-over requests including the explanation you type yourself, and event notes.

Your employer determines the legal basis for this, typically the performance of the employment contract, legal obligations (such as the Working Hours Act) or a legitimate interest in proper staff scheduling.

Minimum age

PowerShift is intended for people aged 13 and over. Additional rules apply to work by young people in the Netherlands; applying them is the employer’s responsibility.

Cookies and local storage

This website (power-shift.nl) sets no cookies and loads no scripts, fonts or other files from third parties.

The application (app.power-shift.nl) only uses strictly necessary, first-party cookies:

Cookie Purpose Lifetime
ps_access Keeps you signed in (httpOnly, not readable by scripts) 15 minutes, renewed automatically
ps_refresh Renews your session without signing in again (httpOnly) At most 30 days; expires after 14 days without use
ps_csrf Protects against cross-site request forgery (CSRF); must be readable by the application For the duration of your session (at most 30 days)
ps_2fa While signing in, remembers that your password was correct and the two-step code is still to follow (httpOnly) 10 minutes, only with two-step verification
psa_* The same functions for the administration console used by PowerShift staff PowerShift administrators only

In addition, the application keeps your theme, a few display preferences (such as the view you last chose) and a copy of your user profile in your browser’s local storage (localStorage) so the app loads faster. That data stays on your device.

Because these cookies and this storage are strictly necessary for the service you use, no consent is required (Article 11.7a of the Dutch Telecommunications Act) and we show no cookie banner. We place no tracking, analytics or advertising cookies.

Who we share data with

We never sell your data and only share it with parties we need to provide the service (sub-processors), each bound by arrangements that meet the GDPR:

  • Hosting, database and backups — Scaleway SAS, in data centres in the EU (region fr-par (Paris, France)).
  • Transactional email (invitations, login codes, roster notifications) — Scaleway SAS (Transactional Email), region fr-par (Paris, France).
  • Browser push services — only if you enable push notifications. A notification is delivered through the push service of your browser’s maker, for example Google (Firebase Cloud Messaging) for Chrome, Microsoft for Edge, Mozilla for Firefox or Apple for Safari. Your browser determines which one.
  • Payments — Mollie B.V. (the Netherlands), once paid plans start. PowerShift is currently free and no payment data is processed.

Within an organisation, co-workers and schedulers see the data the organisation has set up for that purpose (for example the published roster). Beyond that, we only disclose data to others where the law requires us to.

If you set up a calendar subscription (iCal) yourself, your calendar app fetches your shifts via a personal, secret link. The provider of that calendar app then processes that data by your own choice and under your own responsibility.

Where your data is stored

We store all data in the European Union and do not transfer it to countries outside the EU/EEA. The only exception is push notifications, if you enable them: the push services of Google, Microsoft, Mozilla and Apple, among others, may process outside the EEA. These parties use the safeguards the GDPR requires, such as certification under the EU-US Data Privacy Framework or the European Commission’s standard contractual clauses. Following the Web Push standard, the content of a push notification is end-to-end encrypted; the push service cannot read the text, but does see technical data such as the subscription address and the time.

Retention periods

  • Account data: for as long as your account exists. You delete your account yourself via Profile → Delete account (or by email request, see "Your rights"); your account data is then anonymised immediately and backups are overwritten within 30 days.
  • Organisation data (scheduling, memberships and other data we process on behalf of the employer): for as long as the agreement with the organisation runs, plus a 30-day retrieval period after it ends; then deleted within 30 days. During the agreement, the employer can ask us to delete data of (former) employees sooner.
  • Backups: backups rotate and are overwritten within 30 days.
  • Security and technical logs: 90 days (session data: 90 days after the session expired or ended).
  • Audit log of administrator access (which PowerShift administrator viewed or did what in the admin console and when, with IP address and browser type): 1 year.
  • Invitations (the email address an employer sent an invitation to): an open or accepted invitation is part of the organisation’s data; invitations that expired, were revoked or were declined are deleted 30 days after the expiry date of the invitation.
  • Acceptance of the terms and data processing agreement (which version you accepted and when — our proof of the agreement): your own acceptance of the user terms and this privacy policy: for as long as your account exists, plus 2 years; the acceptance an owner gives on behalf of an organisation of the terms of service and the data processing agreement: for as long as that agreement runs, plus 5 years (the statutory limitation period for contractual claims, art. 3:307 Dutch Civil Code).
  • Billing records: 7 years (statutory tax retention duty).
  • Usage activity per membership: overwritten on every active use; cleared 12 months after a membership is deactivated.

Security data in our database (sessions, one-time codes and the audit log of administrator access), invitations that were not accepted, and usage activity of an ended membership are deleted automatically every day once their period has passed. An organisation’s data is deleted automatically when the retrieval period ends; the owner receives a confirmation by email. You can delete your account yourself; see below. Other deletion is currently carried out manually, on request, within these periods.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and the right to object. You can change much of your data yourself (name, language, notifications, two-step verification) on your profile page.

You can download a copy of your data yourself via Profile → Download my data, and delete your account via Profile → Delete account. Your employer then keeps your name with the shifts you worked, as its own records. For other requests email hello@power-shift.nl. We may ask you to confirm your identity, for example by replying from your account’s email address. We respond within one month; for complex requests this may be extended by at most two further months, in which case we will let you know. If the request concerns data we process on behalf of your employer, we involve your employer (see “Two roles” above).

If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. We would appreciate it if you contacted us first.

Security

We take appropriate technical and organisational measures, including: encrypted connections (TLS), passwords stored only as argon2 hashes, session cookies that scripts cannot read, CSRF protection, database security that separates data per organisation (row-level security), optional two-step verification, encrypted storage of sensitive identifiers, and hosting and backups within the EU.

Data breaches

If, despite these measures, a data breach occurs, we assess it immediately. Where the law requires it, we report it to the Autoriteit Persoonsgegevens within 72 hours and inform the people affected. If it concerns data we process on behalf of an employer, we inform the employer as agreed in the Data processing agreement, so the employer can meet its own notification duty.

Changes

We may update this privacy policy. The date at the top of this page shows which version applies. We will inform you in advance of significant changes, for example by email or in the application.

Permanent link to this version: /en/privacy/2026-09-26. You can save or print this page (for example as a PDF) to keep the text.

All versions:

  • Version 2026-09-29 (version in force)
  • Version 2026-09-26

Product

FeaturesPricing

Company

AboutContact

Legal

PrivacyUser termsTermsData processing agreementLegal notice
NL·EN

© 2026 PowerShift