Legal

Privacy Policy

Last updated: August 4, 2026

ShiftSteward is a volunteer shift-scheduling service operated by Gnomon, LLC (“we”, “us”). It is used by organizations — schools, churches, and similar groups — to post volunteer shifts, and by their volunteers to sign up for them. This policy covers the website at shiftsteward.com and the ShiftSteward iOS app.

What we collect

  • Account detailsyour name, email address, and (optionally) a phone number. If you sign in with Apple or Google we receive your name and email address from them; we never receive your password. If you use Apple’s “Hide My Email”, we only ever see the relay address.
  • Organization membership — which organizations you belong to, your role (volunteer, coordinator, administrator), and any category or group a coordinator assigns you to.
  • Scheduling activity — the shifts you sign up for, cancellations, attendance marks recorded by your coordinator, and the volunteer hours computed from them.
  • Messages — the content of messages you post in an organization, group, or shift channel, and who they were visible to.
  • Notification settings and delivery data — your email and text reminder preferences, and the push notification token of each device where you enable notifications.
  • Technical records — sign-in sessions with their IP address and browser or device type, plus ordinary server logs. These exist for security and troubleshooting.

We do not collect location data, contacts, photos, or health data. We do not use advertising or analytics SDKs that track you across other apps and websites.

Why we use it

To run the service you asked for: showing you the right shifts, holding your spot, sending shift reminders and coordinator announcements, computing volunteer hours, answering support requests, and billing organizations for their subscription. We do not sell personal information, and we do not share it for advertising.

Who can see your information

Within an organization, coordinators and administrators can see your name, email address, phone number (if you provided one), your signups, and your attendance record — they need it to run the schedule. Other volunteers see a shortened form of your name wherever a shift shows who is on it — the schedule, the calendar and the shift itself (for example “Rachel K.”) — and never your contact details. Messages are visible to the members of the channel you post in. Organizations are isolated from each other: nobody outside your organization sees your activity in it.

Service providers

We use a small number of processors, each limited to what its job requires: Railway (hosting and database, United States), Resend (email delivery), Plivo (text messages), Stripe (subscription payments — card details go directly to Stripe and never reach our servers), Apple Push Notification service (push delivery), Apple and Google for optional sign-in, and Sentry (United States), which receives technical error reports from our website and background services. Aside from these, we do not disclose personal information except when the law requires it.

An error report is the error message, the page or job it happened in, and a stack trace. We strip email addresses, phone numbers and web addresses that identify a person before sending, and we do not send names, contact details, sign-in cookies, or your IP address. The iOS app contains no diagnostics or analytics SDK and sends nothing to Sentry.

Keeping and deleting your data

We keep your information for as long as your account exists. You can review and correct your details at any time in Profile, on the web or in the app.

You can delete your account yourself: in the iOS app open Profile and choose Delete account, or on the web open Profile and do the same. We email you a confirmation link, and once you confirm it we delete your account and personal information — including your contact details, sessions, device tokens, message authorship, and signups.

One thing survives deletion by design: shifts that a coordinator created stay in their organization’s schedule, with the creator no longer identified. This keeps an organization’s calendar intact when a coordinator leaves. Backups are rotated on a short cycle and expire on their own.

Technical error reports are kept separately, for 30 days, and then deleted automatically. They are not linked to an account and are not searchable by name or email, so deleting your account does not need to reach them.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. Most of this is self-service in Profile; for anything else write to support@shiftsteward.com and we will respond within 30 days. If your organization holds the data (for example an attendance record), we will work with them on your request.

Children

ShiftSteward is designed for adult volunteers and staff, and is not directed to children under 13. Accounts require an email address and are created either by the person themselves or through an invitation from an organization. If an organization invites minors as volunteers, that organization is responsible for obtaining any parental consent its jurisdiction requires. If you believe a child under 13 has created an account, write to us and we will remove it.

Security

All traffic runs over HTTPS. Passwords are stored hashed, never in plain text. Access to production data is limited to the people who operate the service. No system is perfectly secure, but we treat volunteer contact details as data worth protecting.

Changes and contact

If we change this policy materially we will update the date above and, for significant changes, notify account holders by email. Questions, requests, or concerns: support@shiftsteward.com, Gnomon, LLC.