Privacy Policy

Effective Date: July 10, 2026

This Privacy Policy describes how Neel Software Solutions Inc. handles information in connection with the SHIFT application and the related cloud services we operate. Please read it carefully to understand our practices.

Introduction and Scope

This Privacy Policy (the “Policy”) applies to the SHIFT mobile application for iOS and watchOS (the “App”) provided by Neel Software Solutions Inc. (“we,” “us,” or “our”), together with the cloud services we operate to enable account sign-in, synchronization, sharing, and the vendor marketplace (the “Services”). It explains what information we process, how it is used, and the rights available to you. It does not apply to third-party services that maintain their own privacy policies, as described in the “Third-Party Services” section below.

In this Policy, “Personal Information” means information that identifies, relates to, or could reasonably be linked to an identifiable individual. By using the App, you acknowledge that you have read and understood this Policy.

Information You Provide

You may provide the following information when you use the App:

Account and Authentication

An account is required to use the App. To sign in, the App uses Supabase Auth. You authenticate with a one-time passcode (OTP): if you sign in with an email address, the code is delivered by email through Resend; if you sign in with a phone number, the code is delivered by SMS through Twilio. We process your email address and/or phone number to verify your identity, and we create a profile that stores your account identifier, the email and/or phone you signed in with, your name, and your account type. Because we use your account as the single, complete record of who you are, a name is required for every account and, for accounts created with a phone number, an email address is also required so that we can reliably identify and contact you. We do not use passwords and do not store any.

App Passcode and Biometric Unlock

After your first sign-in, you create a numeric passcode used to unlock the App. We never store your passcode itself. Instead, the App stores only a salted, one-way cryptographic representation (a hash) of it, both in your device’s Keychain and, so that your passcode is available when you sign in again, as an opaque record on our backend associated with your account. This representation cannot be used to recover your passcode.

You may also enable biometric unlock using Face ID or Touch ID. Biometric authentication is performed entirely by your device’s operating system; we do not receive, access, or store your biometric data, and your biometric information never leaves your device.

Synchronization, Sharing, and Our Backend

When you are signed in, the content described above — your events, timelines, vendor details, sharing and acknowledgment state, and your profile — is synchronized to and stored on our backend, which is provided by Supabase, Inc. and hosted on cloud infrastructure operated by Amazon Web Services. This allows your data to be available across your devices and to be shared with collaborators you invite. Unlike earlier versions of the App, your event content is processed and stored on servers we operate through Supabase, and is no longer confined to your device.

When you invite a vendor or other collaborator to a timeline, we store the phone number or email address you addressed the invitation to, so that the invited person can claim the invitation when they sign in. A collaborator you invite receives read-only access to the timeline you shared, together with the contact and acknowledgment information necessary for that collaboration.

The Vendor Marketplace

The App includes a marketplace that connects event planners with vendors. Whether you use it as a planner, a vendor, or both is determined by the account type you choose, which you can change in Settings.

If you create a vendor profile, the information in that profile — such as your business name, service category, region or service area, biography, skills, availability, your profile photo, portfolio photographs and videos, and aggregate statistics derived from events you have run through the App (for example, the number of completed events and your average rating) — is publicly visible to other signed-in users who browse or search the marketplace. You control whether your profile is listed, and you can unlist or delete it at any time. Please do not include information in your public profile that you do not wish to be seen by others.

When you create a vendor profile, we record that you accepted our Terms of Service, together with the date and the version of the Terms you accepted. We keep this record to demonstrate that every user who publishes content to the marketplace has agreed to our policies, including our no-tolerance policy for objectionable content.

Vendor business contact details. To be listed in the marketplace, a vendor must provide a business email address and a business telephone number. These are not part of your public profile. They are never shown in search results, on your public profile page, or to anyone who merely browses the directory. They are disclosed to a single planner, at one moment: when you accept that planner’s service request. At that point they are added to that planner’s event so the planner can contact you about the work you have agreed to perform. If you decline a request, or never respond to it, your business contact details are not disclosed to that planner. These details are stored separately from the email address and telephone number you use to sign in, and may be different ones. You can change them at any time in Settings, and a vendor profile cannot remain listed without them.

When a planner sends a service request to a vendor, we process the details of that request and enable the two of you to exchange messages within the App to coordinate. These messages are visible to the planner and the vendor involved in the request, and are stored on our backend so the conversation is available to both of you. We may also process service requests and messages as necessary to operate, secure, and support the marketplace.

If you save a vendor, we store that association so your saved list is available to you. The marketplace operates online and is not available offline.

Community Templates

The App lets you publish an event template — a reusable run-sheet consisting of a name, a description, a category, and a set of block titles, durations, and ordering — to a shared community library. Templates are shared using times measured relative to the first block, so a template never contains the real dates of any event.

A template you publish is publicly visible to other signed-in users, together with your name or business name, the number of times other users have applied it, and, where applicable, a badge indicating that it originated from an event you completed in the App. Please do not include client names, personal details, or any other information you do not wish to be seen by others in a template you publish. You may unpublish or delete your published templates at any time, and deleting your account removes them.

Published templates are user-generated content. They may be reported by other users and removed by us in accordance with our Terms of Service, as described below.

Reviews, User Content, and Safety

The marketplace lets planners leave reviews and star ratings for vendors they have worked with through the App. A review you submit, along with your name, is publicly visible on the relevant vendor’s profile. Reviews are tied to events actually run through the App, which is central to our “Verified by Shift” approach.

Vendor profiles, profile photos, portfolio photographs and videos, reviews, service requests, messages, and community templates are forms of user-generated content. To keep the marketplace safe, the App lets you report any of this content where you believe it is objectionable, and lets you block another user; when you block someone, we store that preference so we can hide their content and prevent further contact between you. We review reports of objectionable content and may remove content or restrict or remove accounts that violate our Terms of Service. We process reports, blocks, and related content for the purposes of moderation, safety, and abuse prevention.

Push Notifications

If you enable notifications, the App registers a device push token with the Apple Push Notification service and stores that token on our backend. We use it, through server functions, to deliver alerts that are relevant to you — including timeline-change (“shift”) alerts to affected collaborators, block-assignment and event-go-live alerts, and, for the marketplace, notifications about new service requests, responses, messages, and reviews. You can disable notifications at any time in your device settings.

Information Collected Automatically

To understand how the App is used and to improve its functionality, the App collects limited, anonymous usage information through TelemetryDeck, a privacy-focused analytics provider. This information is aggregated and is not used to identify you.

Such information may include the frequency of feature usage (for example, creating an event, applying a timeline shift, exporting a document, viewing the marketplace, or joining the waitlist), non-identifying parameters (such as the magnitude of a shift, or whether a waitlist signup is for a vendor or planner and the general category), and general diagnostic information used to detect and resolve errors. These signals are aggregated and do not include your name, email, phone number, or the contents of your events, messages, or reviews.

Information We Do Not Collect

The App does not:

How We Use Information

We use the information processed by the App and Services to:

Data Storage

Your data is stored locally on your device using Apple SwiftData, so the App remains fully functional offline once you are signed in. Your data is also synchronized to and stored on our backend (Supabase, hosted on Amazon Web Services) to enable synchronization and sharing. Voice recordings you attach to a block are uploaded to and stored in our backend so they sync across your devices and are available to collaborators with whom you share the timeline.

Location and Venue Information

The App does not access your device’s GPS location and does not perform background location tracking. When you search for a venue, Apple MapKit returns location results from which you select the coordinates associated with your event.

The selected coordinates, together with the relevant event date, are transmitted to Apple WeatherKit to obtain a weather forecast and to sunrise-sunset.org to calculate sunset and golden-hour times. Only coordinates and a date are transmitted; no Personal Information is included in these requests.

Voice Recordings

If you choose to attach a voice memo to a timeline block, the App will request access to your device’s microphone. Recordings are stored on your device and uploaded to our backend (Supabase storage) so that they synchronize across your devices and are available to collaborators with whom you share the relevant timeline. Access is restricted to you and the collaborators you have granted access to that event. You may delete a recording at any time, and deleting it or the associated event or account removes it from our backend; you may revoke microphone access through your device settings.

Third-Party Services

The App relies on the following third-party services, each of which processes information solely for the purpose indicated and in accordance with its own terms and privacy policy:

We are not responsible for the privacy practices of these third parties and encourage you to review their respective policies.

Disclosure of Information

We do not sell, rent, or trade Personal Information. We may disclose information only: (a) with your consent or at your direction, such as when you invite a collaborator to a timeline, or when, as a vendor, you accept a planner’s service request and your business contact details are shared with that planner; (b) to service providers, such as Supabase, that process information on our behalf and under our instructions to provide the Services; (c) to comply with applicable law, legal process, or a governmental request; or (d) to protect the rights, property, or safety of Neel Software Solutions Inc., our users, or the public, as permitted by law.

Data Retention

Content you store on our backend is retained until you delete it — for example, by deleting an event, removing a vendor, unlisting or deleting your vendor profile, or deleting your account. You can permanently delete your account and its associated server-side data — including events, timelines, vendor details, voice recordings, your vendor marketplace profile, your business contact details, your profile photo and portfolio photos and videos, your service requests and messages, the reviews you have written, the community templates you have published, and your profile — directly within the App, under Settings → Account → Delete Account. Business contact details already disclosed to a planner whose request you accepted remain in that planner’s event, in the same way as contact details for any vendor a planner has added to an event themselves; the planner controls that event and can remove them. Deleting the App removes its locally stored data from that device. Aggregate, anonymous analytics cannot be associated with you and are retained only in de-identified form.

Your Privacy Rights

Depending on your jurisdiction, you may have rights under data-protection laws such as the EU and UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”), including the rights to access, correct, delete, and port your Personal Information, and to object to or restrict certain processing.

Because your Personal Information is stored on our backend, you may exercise these rights by contacting us using the details in the “Contact Us” section below, and we will respond as required by applicable law. You may also delete your account and its associated server-side data yourself at any time, directly within the App, under Settings → Account → Delete Account. We do not sell Personal Information, and therefore no opt-out of sale is required.

International Transfers and Security

Our backend provider (Supabase) and the other third-party services described above may process information in the United States and other countries, which may have data-protection laws different from those of your own country. Those providers maintain their own safeguards for international data transfers.

We take reasonable measures to support the security of information processed by the App and Services; data is encrypted in transit using TLS and at rest by our backend provider. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children’s Privacy

The App is intended for use by event professionals and is not directed to children under the age of 13, or the equivalent minimum age in your jurisdiction. We do not knowingly collect Personal Information from children. If you believe that a child has provided Personal Information, please contact us so that we may take appropriate action.

Changes to This Privacy Policy

We may update this Policy from time to time. When we do, we will revise the Effective Date shown above and, where the changes are material, provide notice within the App. Your continued use of the App after an update takes effect constitutes your acceptance of the revised Policy.

Contact Us

If you have questions or requests regarding this Policy, you may contact Neel Software Solutions Inc. at privacy@shifttimeline.app.