Privacy Policy
Last updated: July 27, 2026
1. Introduction
This Privacy Policy describes how SPIPUS ("we", "us", or "our") collects, uses, stores, and protects your personal information when you use our scheduling, payroll, invoicing, and staff management platform (the "Service"). This policy applies to all users of the Service, including staff members, administrators, and company owners. By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
Account Information
When you create an account or are added as a staff member, we collect your full name and display name, email address, phone number (optional), and password (stored in hashed form). Company administrators may add your details and assign you a role within their organization.
Employment Information
For workforce management we collect:
- Employment status (active/inactive)
- Role and permissions within your organization
- Hourly rate and pay rate history
- Manager notes and employment records
- External payroll/accounting identifiers (e.g., QuickBooks vendor IDs)
Schedule & Availability Data
Weekly recurring availability, time-off requests and reasons, shift assignments and confirmation status, shift preferences, and coverage request and volunteer history.
Time Clock & Hours
If your company uses the time clock, we record clock-in and clock-out timestamps, the work category (e.g. meeting, admin, training, travel), any notes you add, and the resulting hours worked.
Payroll & Financial Data
If your company uses payroll, invoicing, or accounting features, we process pay rates, hours worked, pay calculations (base, travel, admin), deductions and adjustments, pay period status and payment records, and invoices. When a company connects QuickBooks, payroll bills and related vendor/staff and amount details are shared with Intuit to record them in the company's accounting system.
Contact & Device Information
If you enable push notifications, we collect a push subscription endpoint / device token (via standard Web Push and Firebase Cloud Messaging), device encryption keys, and basic device/browser information. If your company enables SMS notifications, we use your phone number to send text messages through Twilio.
Google Calendar Data (Optional)
If your organization enables Google Calendar integration, we process calendar event information (dates, times, event details) and store OAuth tokens securely for synchronization.
3. How We Use Your Information
- Provide the Service โ manage scheduling, track availability, record time, process payroll, and facilitate shift coverage.
- Communications โ send shift notifications, coverage requests, reminders, broadcasts, and system notifications via email, push, and (when enabled) SMS.
- Authentication โ verify your identity and secure your account.
- Administration โ enable administrators to manage staff, schedules, and payroll.
- Calendar Sync โ synchronize shifts with Google Calendar when enabled.
- Accounting Export โ share payroll bills with Intuit QuickBooks when your organization connects it.
- Improve the Service โ analyze usage patterns to enhance functionality and user experience.
4. Legal Basis for Processing
- Contractual Necessity โ processing necessary to provide the workforce management services.
- Legitimate Business Interests โ managing employment relationships, payroll processing, and operational efficiency.
- Consent โ for optional features like push/SMS notifications and the Google Calendar and QuickBooks integrations.
- Legal Obligations โ maintaining employment and payroll records as required by law.
5. Information Sharing & Third-Party Services
We use the following third-party services to operate the platform. We do not sell your personal data to any third party.
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, and backend infrastructure | All user data (stored with encryption and row-level security) |
| Gmail SMTP | Email delivery (invitations, notifications, broadcasts) | Email addresses, names, message content |
| Web Push & Firebase Cloud Messaging | Browser and mobile-app push notifications | Push endpoints / device tokens, notification content |
| Twilio | SMS text notifications (optional, per company) | Recipient phone numbers, message content |
| Google Calendar | Calendar synchronization (optional) | Shift details, event information, OAuth tokens |
| Intuit QuickBooks | Accounting / payroll-bill export (optional, per company) | Payroll bills, vendor/staff names, amounts, OAuth tokens |
Within Your Organization
Company administrators have access to your profile and contact details, schedule and availability data, payroll information and work hours, and coverage request history, based on their role and permissions.
Legal Requirements
We may disclose your information if required by law, legal process, or government request, or to protect the rights, property, or safety of our users or others.
6. Data Security
- Encryption โ all data is transmitted over HTTPS with TLS encryption.
- Access Controls โ row-level security ensures users only access their own organization's data.
- Secure Authentication โ passwords are hashed; sessions use secure, HTTP-only cookies.
- Token Security โ OAuth tokens and API keys are stored securely with appropriate access restrictions.
- Multi-Tenant Isolation โ each organization's data is logically separated and protected.
7. Data Retention
We retain your personal information for as long as your account remains active, as necessary to provide the Service, as required by applicable laws (e.g., payroll record retention), and as needed for legitimate business purposes such as resolving disputes. When data is no longer needed, it is securely deleted or anonymized. Staff records may be marked inactive rather than permanently deleted to maintain historical payroll and scheduling records.
8. Cookies & Local Storage
We use the following for core functionality:
| Item | Purpose | Duration |
|---|---|---|
| Authentication cookies | Maintain your login session | Session |
| Company selection | Remember your selected organization (multi-company users) | Persistent |
| Local storage (preferences & drafts) | Remember UI preferences and unsent drafts (e.g. broadcasts) | Persistent (on your device) |
| Google Calendar tokens | Secure calendar integration (HTTP-only) | Up to 30 days |
We do not use third-party analytics, advertising cookies, or tracking technologies.
9. Your Rights
Depending on your location, you may have the following rights:
- Access & Portability โ request a copy of your personal data via your administrator or our support.
- Correction โ update your profile in the app or request corrections through your administrator.
- Deletion โ request deletion of your account and data. Company owners can delete their entire company and associated data from Settings. Certain records may be retained for legal or business purposes (e.g., payroll history).
- Opt-Out โ disable push notifications, opt out of SMS (e.g. reply STOP), and adjust email preferences through your administrator.
- Revoke Consent / Disconnect โ disconnect the Google Calendar or QuickBooks integration at any time; withdrawing consent does not affect the lawfulness of prior processing.
10. Push & SMS Notifications
If you enable push notifications, we store your device's push subscription endpoint and encryption keys and send notifications for coverage requests, approvals, broadcasts, and other time-sensitive updates. Subscription data is deleted when you disable notifications. If your organization enables SMS, messages are sent to your phone number via Twilio; you can opt out at any time.
11. Google Calendar & QuickBooks Integrations
If your organization enables Google Calendar, we request access to read and write calendar events to synchronize shifts; OAuth tokens are stored securely and can be revoked at any time. If your organization connects Intuit QuickBooks, we share payroll bills and related details to record them in your accounting system; administrators can disconnect the integration at any time from Settings. Use of these integrations is also subject to the respective provider's terms and privacy policies.
12. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
13. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with applicable laws.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by posting the updated policy on this page, updating the "Last updated" date, and (for material changes) sending notification through the Service. Continued use of the service after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please reach out to your company administrator for questions about how your organization uses the Service, or contact our support team at calvku@gmail.com for support and data-protection inquiries.
16. Additional Information for Specific Jurisdictions
California Residents (CCPA)
California residents have additional rights under the CCPA, including the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information.
European Economic Area Residents (GDPR)
If you are in the EEA, you have rights under the GDPR, including access, rectification, erasure, restriction, portability, and objection. You also have the right to lodge a complaint with a supervisory authority.