Back to shiftcaddie.comEffective date: 2026-08-05
This Privacy Policy explains how ShiftCaddie (“ShiftCaddie,” “we,” “us”) collects, uses, and shares information through shiftcaddie.com, our admin/manager web application, and the no-login staff QR experience (together, the “Service”).
ShiftCaddie is sold to golf courses, clubs, and similar facilities (each a “Customer”). Most of the operational data in the Service — task lists, schedules, tee sheet data, issue reports — is entered or imported by a Customer and describes that Customer's own business. Where that data also identifies or relates to one of the Customer's employees or hourly staff (a “Staff User”), we process it primarily on the Customer's behalf, as described in Staff and Hourly Workers below.
Account information. When an admin or manager creates an account, we collect their name, job title, email address, and password (stored by our authentication provider in hashed form — we never see it in plain text).
Organization and facility information. Business name, address, facility type, and timezone provided during setup. We use the address to look up approximate geographic coordinates and timezone (via OpenStreetMap's geocoding service) so schedules and forecasts use local time correctly.
Operational data. Everything a Customer creates or uploads to run its operations through the Service: areas, shifts, tasks and their completion history, issues and announcements, events, and tee sheet data (currently via CSV upload; in the future, potentially via a direct connection to a Customer's point-of-sale or tee sheet provider).
Usage and device data. Standard technical data such as IP address, browser and device type, pages visited, and timestamps of actions taken in the Service, collected automatically through server logs and a session cookie used to keep you signed in.
Weather data. We fetch current weather conditions for a facility's location from a third-party weather provider to display on the dashboard. We don't store a history of this data beyond what's needed to render the current view.
Support communications. If you email us or otherwise contact us for support, we keep a record of that correspondence.
We do not collect payment card data directly. If and when billing is enabled, card details will be collected and processed by a PCI-compliant third-party payment processor, not stored on our own servers.
We use the information above to:
Certain operational patterns in the Service — for example, how busy a golf course tends to be at a given hour relative to its tee sheet, or how long a task of a given type typically takes to complete — are useful signal for improving the accuracy of ShiftCaddie's forecasting and other features, beyond just the one Customer that generated them.
Where we use data this way, we aggregate it across a broad set of Customers and strip it of information that identifies a specific Customer, facility, or individual (names, exact addresses, account identifiers, and free-text content are removed or generalized before aggregation). We do not use a Customer's raw, identifiable operational data to train models for other Customers, and we do not sell any of this data.
If we ever build a feature that would use identifiable Customer data (rather than aggregated, de-identified patterns) to train a model in a way that goes beyond providing the Service to that Customer, we'll update this policy and provide notice before doing so.
ShiftCaddie's staff view is deliberately built with no account creation: a Staff User reaches it by scanning a QR code posted at their facility, which grants access scoped to that facility's area. We do not ask a Staff User for their name, email, or any other direct identifier through this flow. What we do collect is limited operational data: which tasks were marked complete and when, and the content of any issue a Staff User chooses to report (which may incidentally include personal details if the Staff User types them in).
For this data, ShiftCaddie generally acts as a service provider processing information on behalf of the Customer (the Staff User's employer), not as the party that decides why or how a Staff User's workplace activity is monitored. The Customer is responsible for providing any notice to its own staff that applicable employment or labor law requires, and for having the authority to grant its staff access to the Service. A Staff User with questions about how their activity data is used should start with their employer, who can in turn contact us.
We retain Customer operational data for as long as the Customer's account is active, plus a limited period afterward to allow for account recovery, comply with legal obligations, resolve disputes, and maintain backups. Note that the Service is generally designed to archive records (tasks, areas, shifts, and similar) rather than delete them outright, so that historical completion records stay intact even after the thing they relate to is retired — archived records remain subject to this policy and to a Customer's deletion requests.
Aggregated, de-identified data as described above may be retained and used indefinitely, since it's no longer tied to an identifiable Customer, facility, or individual.
We use industry-standard safeguards, including encryption of data in transit, and database-level access controls that logically separate each Customer's data from every other Customer's. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
Depending on where you're located, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing (for example, under the California Consumer Privacy Act or the EU/UK General Data Protection Regulation, where applicable). Admins and managers can access, correct, or archive most of their organization's data directly in the Service. For anything else, or to make a request on behalf of a Staff User, email privacy@shiftcaddie.com. We do not sell personal information and do not use it for cross-context behavioral advertising, so there's no opt-out needed for either.
The Service is intended for business use by golf courses, clubs, and their staff, and isn't directed to children. We don't knowingly collect personal information from anyone under the minimum age of employment applicable where they work.
We are based in and operate the Service primarily from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home jurisdiction.
We may update this policy from time to time. We'll post the revised version here with a new effective date, and for material changes, we'll provide additional notice (such as an email to admins) before the change takes effect. New Customers agree to the then-current version of this policy when they sign up; the version an admin agreed to is recorded on their account.
Questions about this policy or your data can be sent to privacy@shiftcaddie.com.
See also our Terms of Service.