Skip to main content

Data Protection & Privacy

At ShiftNest, we take data protection seriously. We follow strict standards under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 to ensure your information is handled securely and transparently.

Leo avatar
Written by Leo
Updated over a month ago

This page explains how your data is used, stored, and protected when you use ShiftNest.

1. Our Commitment to Privacy

We only collect information necessary to operate the ShiftNest platform effectively. This includes contact details, shift records, timesheet data, and billing information for agencies.
Your information is never sold or shared with unauthorised third parties. Any data processing we do is solely to support your use of the platform.

2. How We Protect Your Data

All information on ShiftNest is stored and transmitted securely.

  • Data is encrypted both in transit and at rest using advanced encryption standards (TLS 1.2+).

  • Access is restricted through role-based permissions to ensure only authorised users can view specific information.

  • Our servers are hosted in UK- or EU-based data centres

  • Regular system monitoring and encrypted backups protect your data from loss or unauthorised access.

  • ShiftNest is a product of &Element, a Cyber Security Certified firm, following best practices in system monitoring, access control, and data encryption.

3. Third-Party Providers

To deliver our services, we work with trusted third-party partners who meet industry and legal data protection standards:

  • Stripe – for secure payment processing (PCI DSS Level 1 compliant).

  • AWS – for hosting and encrypted data storage.
    All third-party providers are bound by confidentiality and compliance obligations to protect your information.

4. Your Rights

Under UK GDPR, you have the right to:

  • Access a copy of your personal data.

  • Request correction of inaccurate information.

  • Request deletion of personal data when it’s no longer required.

  • Withdraw consent for specific data uses (where applicable).

To make a data request, contact [email protected] with your name, organisation (if applicable), and registered email address. We aim to respond as soon as possible.

5. How Long We Keep Data

We retain data only for as long as necessary to fulfil legal and operational purposes - such as invoicing, shift records, or compliance checks. Once this period ends, data is securely deleted or anonymised.

6. Learn More

For more detailed information about how we handle personal and organisational data, please see our full Privacy Policy.
https://shiftnest.co.uk/legal/privacy

Did this answer your question?