CMP Shift privacy notice

Version 1, in force from 30 September 2026

Shift is the app that a venue's staff use to clock in, check their shifts and make requests, and that managers use to organise the week. Here you find what data it processes, why, who sees it and how long it is kept.

Who controls your data

The controller is the venue you work for, that is your employer: it decides why and how data about shifts and attendance is used, and gives you its own privacy notice for staff. For any request about your data, contact your employer.

Who built the app and keeps it running

The app and its server are built and run by Coffee Marketing Pro di Matteo Borea (Calle Italia 25, 35006 Las Palmas de Gran Canaria, Spain), which processes the data on behalf of the venue and on its instructions, as processor (Article 28 of Regulation (EU) 2016/679, the GDPR). Coffee Marketing Pro uses the data only to make the app work: it does not use it for itself, does not sell it and does not write to you in its own name.

What data we process

For your account: name, email address, password and PIN. Password and PIN exist only as an encrypted hash that nobody can read back, not even us.

For each venue you work at: your role (staff or manager) and your work profile (contract type and scheduled hours); your shifts; your clock-ins, with the time, the phone or iPad they came from and your note, if you write one; your absences (holidays, leave, rest days and sick leave, meaning only the type and the days, never the medical reason); your requests and the manager's answer; the notices you receive; the corrections made by managers, with the reason and who made them. If you turn on notifications, the identifier needed to deliver them to your phone. When the app talks to the server, the server records the IP address and the type of app, to protect itself from abuse.

Shift does not ask for or collect your location, fingerprint or face, contacts, photos, payment data or advertising identifiers, and it contains no analytics or tracking tools.

Why we use it and on what legal basis

To manage the hours, attendance, absences and requests of your work and to keep the records the law requires from your employer (Article 6(1)(b) and (c) GDPR; for sick leave, Article 9(2)(b)). To send you service reminders and notices. Your consent is not needed, and no data is used for advertising.

Who sees your data

You see your own. The venue's managers see the data of the venue's staff. Each venue sees only its own data, even if you work at more than one.

Coffee Marketing Pro and the providers it relies on, bound by contracts that oblige them to protect the data: Hostinger, which hosts the server in a data centre in Frankfurt, Germany, and sends the service emails; Backblaze, which keeps the backups in Amsterdam, encrypted before they leave the server with a key Backblaze does not hold; Expo (650 Industries, Inc., United States), which hands notifications over to Apple and Google, keeping the phone's identifier and the text of the notice only for the time needed to deliver it. Apple and Google deliver the notifications to phones.

The venue may send the attendance sheet to its payroll consultant. Lawyers and authorities see the data only when the law requires it or to defend a right.

Where it is kept

The server, emails and backups are in the European Union. Expo, Apple and Google may process the phone's identifier in the United States too, on the basis of the Data Privacy Framework or of the European Commission's standard contractual clauses.

How long we keep it

As long as you work at the venue and, afterwards, for the time the law requires your employer to keep records of hours and attendance; then it is deleted on the employer's instructions. Technical logs with the IP address are deleted after 14 days. Backups overwrite themselves within six months, and nobody uses them in the meantime.

Your rights

You can ask to see your data, correct it, delete it within the limits of legal obligations, restrict its use, object and receive it in a file (Articles 15 to 22 GDPR). Requests go to your employer; if you write to info@coffeemarketingpro.com, we pass them on. You can also contact the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it).

How we protect it

Password and PIN only as an encrypted hash, the session in the phone's protected keychain, encrypted connections, each venue's data kept apart in the database, encrypted backups, and only the people who run the server can access it.

If this notice changes

Each version has a number and a date, and if something important changes we say so in the app before it applies.