ShiftCaddieBack to shiftcaddie.com

Privacy Policy

Effective date: 2026-08-05

Overview

This Privacy Policy explains how ShiftCaddie (“ShiftCaddie,” “we,” “us”) collects, uses, and shares information through shiftcaddie.com, our admin/manager web application, and the no-login staff QR experience (together, the “Service”).

ShiftCaddie is sold to golf courses, clubs, and similar facilities (each a “Customer”). Most of the operational data in the Service — task lists, schedules, tee sheet data, issue reports — is entered or imported by a Customer and describes that Customer's own business. Where that data also identifies or relates to one of the Customer's employees or hourly staff (a “Staff User”), we process it primarily on the Customer's behalf, as described in Staff and Hourly Workers below.

Information we collect

Account information. When an admin or manager creates an account, we collect their name, job title, email address, and password (stored by our authentication provider in hashed form — we never see it in plain text).

Organization and facility information. Business name, address, facility type, and timezone provided during setup. We use the address to look up approximate geographic coordinates and timezone (via OpenStreetMap's geocoding service) so schedules and forecasts use local time correctly.

Operational data. Everything a Customer creates or uploads to run its operations through the Service: areas, shifts, tasks and their completion history, issues and announcements, events, and tee sheet data (currently via CSV upload; in the future, potentially via a direct connection to a Customer's point-of-sale or tee sheet provider).

Usage and device data. Standard technical data such as IP address, browser and device type, pages visited, and timestamps of actions taken in the Service, collected automatically through server logs and a session cookie used to keep you signed in.

Weather data. We fetch current weather conditions for a facility's location from a third-party weather provider to display on the dashboard. We don't store a history of this data beyond what's needed to render the current view.

Support communications. If you email us or otherwise contact us for support, we keep a record of that correspondence.

We do not collect payment card data directly. If and when billing is enabled, card details will be collected and processed by a PCI-compliant third-party payment processor, not stored on our own servers.

How we use information

We use the information above to:

  • Operate, maintain, and secure the Service, including authenticating users and enforcing that each Customer only sees its own data.
  • Generate the Service's core features: busy-period forecasts, task scheduling, shift briefings, and activity reporting.
  • Respond to support requests and send Service-related communications (account, security, and billing notices).
  • Monitor, debug, and improve the reliability and performance of the Service.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our Terms of Service.
  • Improve and develop new features, including through the aggregated and de-identified use described in the next section.

Aggregated data, and AI/ML model improvement

This section covers a specific, limited practice: using de-identified, aggregated operational patterns — not a Customer's raw, identifiable business data — to improve how the Service's models work for everyone.

Certain operational patterns in the Service — for example, how busy a golf course tends to be at a given hour relative to its tee sheet, or how long a task of a given type typically takes to complete — are useful signal for improving the accuracy of ShiftCaddie's forecasting and other features, beyond just the one Customer that generated them.

Where we use data this way, we aggregate it across a broad set of Customers and strip it of information that identifies a specific Customer, facility, or individual (names, exact addresses, account identifiers, and free-text content are removed or generalized before aggregation). We do not use a Customer's raw, identifiable operational data to train models for other Customers, and we do not sell any of this data.

If we ever build a feature that would use identifiable Customer data (rather than aggregated, de-identified patterns) to train a model in a way that goes beyond providing the Service to that Customer, we'll update this policy and provide notice before doing so.

How we share information

We do not sell personal information. We share information only in the following ways:

  • Service providers. Vendors who host and run parts of the Service on our behalf, under contractual confidentiality and security obligations — currently our database/backend provider, our application hosting provider, and our weather and geocoding data providers.
  • Within your organization. Data you enter is visible to other admins and managers at your organization according to their assigned role and area access.
  • Integrations you connect. If a Customer connects a third-party tee sheet or point-of-sale system, data flows to and from that provider as directed by the Customer, subject to that provider's own terms.
  • Legal and safety. When required by law, legal process, or to protect the rights, property, or safety of ShiftCaddie, our users, or the public.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy (or a successor policy of which you're given notice).
  • With your consent. Any other sharing we ask your permission for first.

Staff and hourly workers

ShiftCaddie's staff view is deliberately built with no account creation: a Staff User reaches it by scanning a QR code posted at their facility, which grants access scoped to that facility's area. We do not ask a Staff User for their name, email, or any other direct identifier through this flow. What we do collect is limited operational data: which tasks were marked complete and when, and the content of any issue a Staff User chooses to report (which may incidentally include personal details if the Staff User types them in).

For this data, ShiftCaddie generally acts as a service provider processing information on behalf of the Customer (the Staff User's employer), not as the party that decides why or how a Staff User's workplace activity is monitored. The Customer is responsible for providing any notice to its own staff that applicable employment or labor law requires, and for having the authority to grant its staff access to the Service. A Staff User with questions about how their activity data is used should start with their employer, who can in turn contact us.

Data retention

We retain Customer operational data for as long as the Customer's account is active, plus a limited period afterward to allow for account recovery, comply with legal obligations, resolve disputes, and maintain backups. Note that the Service is generally designed to archive records (tasks, areas, shifts, and similar) rather than delete them outright, so that historical completion records stay intact even after the thing they relate to is retired — archived records remain subject to this policy and to a Customer's deletion requests.

Aggregated, de-identified data as described above may be retained and used indefinitely, since it's no longer tied to an identifiable Customer, facility, or individual.

Data security

We use industry-standard safeguards, including encryption of data in transit, and database-level access controls that logically separate each Customer's data from every other Customer's. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

Your rights and choices

Depending on where you're located, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing (for example, under the California Consumer Privacy Act or the EU/UK General Data Protection Regulation, where applicable). Admins and managers can access, correct, or archive most of their organization's data directly in the Service. For anything else, or to make a request on behalf of a Staff User, email privacy@shiftcaddie.com. We do not sell personal information and do not use it for cross-context behavioral advertising, so there's no opt-out needed for either.

Children's privacy

The Service is intended for business use by golf courses, clubs, and their staff, and isn't directed to children. We don't knowingly collect personal information from anyone under the minimum age of employment applicable where they work.

International data transfers

We are based in and operate the Service primarily from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home jurisdiction.

Changes to this policy

We may update this policy from time to time. We'll post the revised version here with a new effective date, and for material changes, we'll provide additional notice (such as an email to admins) before the change takes effect. New Customers agree to the then-current version of this policy when they sign up; the version an admin agreed to is recorded on their account.

Contact us

Questions about this policy or your data can be sent to privacy@shiftcaddie.com.

See also our Terms of Service.

Also see our Terms of Service. Questions about either document? Email legal@shiftcaddie.com.