TipShifts Privacy Policy
Version 1.0 — Effective date: July 30, 2026
Provider: TipShifts, a Florida-based sole proprietorship doing business as "TipShifts" ("TipShifts," "we," "us")
At a Glance
| What we collect | Account data (name, email, hashed password); your restaurant's imported Toast POS payroll data (employee names, IDs, hours, sales, tips); optional encrypted Toast API credentials; billing status from Stripe; support email; server logs |
| Why | Only to run the service: compute tip-outs from your rules, operate accounts, send transactional email, bill subscriptions, and keep the service secure |
| Who sees it | Only our subprocessors (Render, Stripe, Resend, Backblaze) as needed to run the service — never advertisers, brokers, or analytics companies |
| How long | While the account is active; after cancellation, a 60-day export window, then deletion from production (backups rotate out on our retention schedule) |
| Your choices | Restaurant employees: contact your employer, who controls payroll data. Account holders: manage your account in-app or contact us at hello@tipshifts.com |
1. Who We Are and What This Policy Covers
TipShifts operates tipshifts.com, a business-to-business software service that helps restaurants calculate tip-outs. The service imports a restaurant's own Toast POS data (by CSV upload, or by API pull using the restaurant's own Toast credentials), applies tip-out rules that the restaurant itself configures (percentages, calculation bases, roles, shift cutoffs), and produces payroll-ready tip-out reports.
Every computed amount is traceable to the rule and the input data that produced it, and each payroll period is finalized only when the restaurant's administrator explicitly reviews and validates it — a deliberate action that creates a versioned, immutable audit snapshot. TipShifts computes numbers; it does not move money, and the restaurant pays its employees through its own payroll.
This policy addresses two audiences:
- Our Customers and their authorized users — the restaurant businesses that subscribe to TipShifts, and the administrators and staff members who hold TipShifts accounts.
- Our Customers' employees — the restaurant workers whose names, hours, sales, and tip data appear in the information a Customer imports into TipShifts.
The service-provider relationship, stated plainly. For employee payroll data, the Customer restaurant is the data controller (in California terms, the "business"): the restaurant decides what data to import, what rules apply to it, and how the resulting reports are used. TipShifts processes that data solely on the restaurant's behalf and at its direction. TipShifts does not own that data, and we will never sell it, share it for advertising, rent it, or otherwise monetize it.
For the limited data TipShifts collects for its own operations — account credentials, billing and support contacts, and server logs — TipShifts itself is the responsible party ("business"), and requests about that data come to us directly (Section 12).
Nothing in this policy overrides the terms of our written agreement with a Customer; where that agreement imposes stricter data-handling obligations on us, the agreement controls.
2. Data We Collect
We collect a deliberately narrow set of data, described in full below.
a. Account data (administrators and staff)
- Name
- Email address (used for login, invitations, and password resets)
- Username
- Password — stored only as a salted PBKDF2 hash (600,000 iterations); we never store plaintext passwords
- Role and location assignments within the Customer's account
b. Employee payroll data (imported from the Customer's Toast POS)
This data belongs to the Customer and describes the Customer's employees:
- Employee names and Toast employee IDs
- Work email addresses (where the Customer enables staff self-service accounts)
- Clock punches and worked hours
- Sales figures
- Tips, gratuities, and computed tip-out earnings
What we do NOT collect: no Social Security numbers, no bank account numbers, no payment card data, and no funds — TipShifts performs calculations only and never moves money.
c. Toast POS credentials (optional, Customer-supplied)
If a Customer connects the Toast API, the Customer's own Toast credentials are stored encrypted (Fernet symmetric encryption) and write-only — once saved, they are used to pull the Customer's data at the Customer's direction and are never displayed back in the interface.
d. Billing data
Subscriptions ($89/month or $899/year per location, with a 30-day free trial that requires a card) are handled entirely through Stripe-hosted Checkout and Customer Portal pages. Payment card details never touch, and are never stored or processed on, TipShifts systems. Payment information you enter on those pages is collected and processed by Stripe under Stripe's own privacy policy (https://stripe.com/privacy). We receive from Stripe only what we need to administer the subscription (e.g., subscription status and billing contact information).
e. Support communications
If you email us, we keep the correspondence so we can respond and maintain a record of the issue.
f. Server logs
Our hosting infrastructure keeps standard server logs (such as IP address, request path, timestamp) for security and troubleshooting, retained for a limited period per our hosting provider's log-retention schedule.
g. Cookies — strictly necessary only
We use no advertising trackers, no third-party analytics, and no behavioral tracking of any kind. The only cookies TipShifts itself sets are strictly necessary for the service to function:
| Cookie | Purpose |
|---|---|
| Session token | Keeps you signed in |
| Location preference | Remembers which restaurant location you were viewing |
| Date-range preference (a start/end cookie pair per restaurant location you view) | Remembers the reporting period you last selected for that location |
| Language preference | Remembers your language choice (English/Spanish/French) |
These are the only cookies TipShifts itself sets, and none of them is used to track you across other websites. When you check out or manage billing, you do so on pages hosted by Stripe; Stripe sets its own cookies on those pages under Stripe's privacy policy (Section 4).
3. How We Use Data
We use the data described above only to:
- Provide the service — import the Customer's POS data, apply the Customer's configured tip-out rules, and generate tip-out reports and audit trails
- Operate accounts — authenticate users, enforce role and location permissions, and maintain per-restaurant data isolation
- Send transactional email — account invitations and password resets (we do not send marketing email to Customers' employees)
- Bill Customers — administer subscriptions through Stripe
- Secure and maintain the service — detect abuse, troubleshoot problems, and keep backups so data can be restored
We do not use any Customer or employee data for advertising, profiling, model training, or any purpose beyond delivering the service.
4. When We Share Data
a. Subprocessors
We use a small number of service providers to run TipShifts. Each receives only what its function requires:
| Provider | Purpose |
|---|---|
| Render | Cloud hosting of the application and database (United States) |
| Stripe | Subscription billing — Stripe-hosted checkout and customer portal; card data goes directly to Stripe and never touches TipShifts; Stripe processes payment data under its own privacy policy (https://stripe.com/privacy) |
| Resend | Transactional email delivery (account invitations, password resets) |
| Backblaze B2 | Off-site storage of daily database backups (transmitted over encrypted connections) |
| Toast | Data source, not recipient — we access the Customer's Toast data using the Customer's own credentials, at the Customer's direction |
We will update this list before or promptly after any change. (Customers who want contractual notice of subprocessor changes can request our service-provider addendum — Section 11.)
b. Legal process
We may disclose data if required by law, subpoena, or court order, or where reasonably necessary to protect the rights, safety, or property of TipShifts, our Customers, or others. Where lawful and practicable, we will notify the affected Customer before disclosing its data.
c. Business transfers
If TipShifts is involved in a merger, acquisition, or sale of assets, data may transfer as part of that transaction. In that event, we will require the successor to assume the commitments of this policy with respect to previously collected data, or we will provide affected Customers notice and an opportunity to export and request deletion of their data before the transfer.
d. Never for advertising
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. There are no advertising partners, data brokers, or analytics resellers in our data flows — none.
5. Security
We take security measures that are real and verifiable in our system. Specifically:
- Encryption in transit: all connections to TipShifts use TLS.
- Password protection: passwords are stored only as salted PBKDF2 hashes (600,000 iterations).
- Tenant isolation: hard per-restaurant data isolation, enforced in the application and covered by automated tests, designed to prevent one restaurant's users from accessing another restaurant's data.
- POS credential protection: Toast API credentials are stored encrypted (Fernet) and are write-only — they are never displayed back after entry.
- Payroll integrity: validated payroll periods are frozen as versioned, immutable snapshots, and every payroll requires explicit administrator approval before it is treated as final.
- No trackers: no advertising trackers or third-party analytics run on our pages.
- Backups: automated daily database backups, including off-site copies transmitted over encrypted connections.
We are candid about scope: TipShifts is an early-stage service and does not currently claim certifications or controls it does not have (for example, we do not currently offer multi-factor authentication and have not undergone a SOC 2 audit). No system is perfectly secure, and we do not promise absolute security — but we maintain the measures above and treat Florida's reasonable-security requirement (Fla. Stat. § 501.171) as a binding baseline.
6. Data Retention
- Active accounts: we retain Customer and employee data for as long as the Customer's account is active, because historical payroll periods, audit trails, and validation snapshots are the core of the service.
- After cancellation: following termination of a subscription, we retain the Customer's data for a wind-down period of 60 days so the Customer can request an export (contact hello@tipshifts.com), after which the data is scheduled for deletion from our production systems, completed within 30 days after the window closes.
- Backups: deleted data may persist in off-site backup copies until those copies rotate out of our backup retention (approximately 30 daily copies — roughly 30 days in normal operation). Backups are retained for disaster recovery only and are not used to restore data a Customer has asked us to delete, except as needed to recover from a system failure — in which case deletions are re-applied.
- Support correspondence and billing records are retained as needed for legal, tax, and accounting purposes.
7. Rights of Our Customers' Employees
If you are an employee of a restaurant that uses TipShifts, your employer — not TipShifts — decides what data about you is imported and how it is used. Please direct requests to access, correct, or delete your data to your employer, who is the data controller. When a Customer asks us to help fulfill such a request, we will assist promptly.
One exception where you can contact us directly: if you hold a TipShifts staff self-service account, we will handle requests concerning your own account credentials (email, username, password reset, and deactivation or deletion requests, which we fulfill manually) directly at hello@tipshifts.com. Note that deleting your login account does not delete the payroll records your employer maintains about your work — those remain under your employer's control.
8. California Disclosures (CalOPPA)
This section is provided under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code § 22575 et seq.):
- Categories collected and shared: as described in Sections 2 and 4 above — in brief: account data, employee payroll data imported by Customers, billing-administration data, support correspondence, and server logs, shared only with the subprocessors listed in Section 4.
- Do Not Track: TipShifts does not track its users across third-party websites and does not collect personally identifiable information about your online activities over time and across different websites. Because we do no such tracking at all, we do not respond differently to browser "Do Not Track" signals — there is no tracking to turn off.
- Third-party collection: we do not knowingly permit any third party to collect personally identifiable information about your online activities over time and across different websites through our service. We run no third-party advertising or analytics code.
- Reviewing and changing your information: account holders can review and update their account information in the application, or by contacting hello@tipshifts.com. Employees of Customers should see Section 7.
- Policy changes: if we make material changes to this policy, we will post the updated policy at this URL with a new effective date, and we will notify Customer administrators by email (or other direct notice) before the changes take effect. The effective date at the top of this policy tells you when it was last revised.
9. Breach Notification (Florida Information Protection Act)
TipShifts is subject to, and maintains its practices to meet, the Florida Information Protection Act of 2014 (Fla. Stat. § 501.171), which requires reasonable measures to protect personal information and prompt notice of a breach of security:
- Notice to affected individuals: where TipShifts is the covered entity for the data involved, we will notify affected individuals of a breach of security as expeditiously as practicable and within 30 days of determination of the breach, subject to the statute's provisions (including any authorized law-enforcement delay).
- Notice to Customer restaurants: where TipShifts holds data on behalf of a Customer (our normal posture as a third-party agent for employee payroll data), we will notify the affected Customer as expeditiously as practicable and within 10 days of determination of a breach or reason to believe one occurred, so the Customer can meet its own notification obligations. We will cooperate with the Customer's response, including providing the information the Customer needs to notify its employees and regulators.
- Notice to regulators: where required, we will also notify the Florida Department of Legal Affairs within the statutory timeframe.
10. Children
TipShifts is a workforce tool for restaurant businesses and is not directed to children. We do not offer accounts to, or knowingly collect information directly from, anyone under 16. Employee payroll data imported by a Customer may lawfully include minors employed by that Customer; such data is processed solely on the Customer's behalf as described in Sections 1 and 7, and the Customer is responsible for its lawful collection. If you believe we have collected information directly from a child in error, contact hello@tipshifts.com and we will delete it.
11. State Privacy Laws (California CCPA/CPRA and Others)
TipShifts is currently below the applicability thresholds of the comprehensive state privacy laws we have evaluated (including the California Consumer Privacy Act as amended, the Florida Digital Bill of Rights, and the Texas Data Privacy and Security Act), and several of these laws also exclude employment-context data of the kind we process.
Even so:
- We operate as a service provider. With respect to employee payroll data, TipShifts operates in the posture of a CCPA "service provider" — processing personal information only on behalf of and per the instructions of the Customer, and never selling or sharing it. A service-provider addendum is available to Customers on request at hello@tipshifts.com.
- Voluntary courtesy handling. Although these laws may not currently bind us, if we receive a privacy request from a California resident (or a resident of another state with a comprehensive privacy law), we will handle it in good faith: routing employee-data requests to the controlling employer per Section 7, and honoring account-credential requests directly per Section 7.
- We do not sell personal information and have not done so; no opt-out of sale is needed because there is nothing to opt out of.
12. Contact Us
Questions, requests, or concerns about this policy or our data practices:
TipShifts Email: hello@tipshifts.com
Use of the service, and any dispute, is governed by our Terms of Service, including its Florida governing-law and venue provisions.
End of Privacy Policy (Version 1.0).