Last updated: August 12, 2026
Sciometa ("we", "our", or "us") operates the Shift Management application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service, in compliance with applicable data protection laws including the EU General Data Protection Regulation (GDPR) and the Japanese Act on the Protection of Personal Information (APPI).
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service.
The data controller responsible for your personal data is:
Sciometa
Email: hello@sciometa.com
Website: https://sciometa.com
We collect the following personal information when you register and use our Service:
If you sign in using a third-party provider (Google or Apple), we receive the following information from the provider:
We do not receive or store your third-party account password. Authentication is handled securely by the respective provider (Google LLC or Apple Inc.).
When using Sign in with Apple, you may choose to hide your real email address. In this case, Apple provides a unique private relay email address that forwards messages to your real email. We will use this relay address to communicate with you. Please note that some features requiring email verification or organization invitations may require your real email address.
We collect work-related data including:
When you clock in or out, we may collect location data to verify your presence at designated work locations (geofencing). This includes:
Note: Location tracking is only active during clock-in/clock-out events and is not continuous. You may be allowed to clock in outside geofenced areas depending on your organization's settings.
Presence Verification (QR Codes and NFC Tags): At locations that require it, you scan a QR code or NFC tag posted at the workplace to clock in or out. The scan sends a location-specific code to our servers together with your clock-in/clock-out event to verify your presence, and a record of the scan (which code or tag was used, and when) is stored with the time entry. The camera is used only to read the QR code on your device; no photos or video are captured, stored, or transmitted. NFC scanning reads only the workplace tag posted by your organization, not other tags or payment cards.
We automatically collect certain technical information:
When you use our mobile application, we collect a device push notification token (Firebase Cloud Messaging token) to send you relevant notifications. The types of notifications we may send include:
Your push notification token is stored on our servers and linked to your user account. The token is automatically removed when you sign out of the application. You can control which types of notifications you receive through the notification settings within the app. You can also disable push notifications entirely through your device's system settings.
Push notifications are delivered through Firebase Cloud Messaging (FCM), a service provided by Google LLC, and Apple Push Notification service (APNs) for iOS devices. These services may process your device token and notification data according to their respective privacy policies.
If you use our chat features, we collect:
For security and compliance purposes, we maintain audit logs that record actions taken within the Service, including who performed them and when.
Under the GDPR, we process your personal data based on the following legal grounds:
We use the collected information for the following purposes:
We do not sell, rent, or trade your personal data. We may share your information in the following limited circumstances:
Your information may be transferred to and processed in countries other than your country of residence, including countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure adequate safeguards are in place, such as:
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:
When data is no longer needed, it is securely deleted or anonymized.
We implement appropriate technical and organizational measures to protect your personal information, including:
While we implement reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
Under the GDPR and other applicable data protection laws, you have the following rights regarding your personal data:
To exercise these rights, please contact your organization administrator or reach out to us directly at hello@sciometa.com. We will respond to your request within 30 days.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by GDPR Article 34.
Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact us at hello@sciometa.com.
The Service may contain links to third-party websites or services that are not operated by us (e.g., Google, Apple, Firebase). We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party services you access.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by updating the "Last updated" date at the top of this page and, when practicable, by providing notice through the Service. Your continued use of the Service after the updated Privacy Policy becomes effective constitutes your acknowledgment of the changes.
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a complaint about how we handle your personal data, please contact us at:
You also have the right to lodge a complaint with your local data protection supervisory authority.