Privacy Policy
Last Updated: August 6, 2026
1. Overview
ShiftSeal ("we," "our," or "us") provides a secure electronic timesheet and approval platform designed for workforce management and payroll workflow verification. This Privacy Policy explains how we collect, use, store, and protect personal information and organizational data when you access or use ShiftSeal.
2. Information We Collect
We collect information necessary to operate our timesheet tracking and administrative approval workflow:
- Account & Identity Data: Names, usernames, email addresses, job roles (e.g., Substitute, Teacher, Secretary, Admin), and company affiliations.
- Timesheet Records: Dates worked, coverage periods, teacher covered entries, rates, and custom form field data configured by your organization.
- Electronic Signatures: Digital vector signature tokens captured during submission and managerial approval.
- Security & Authentication Data: Password hashes, multi-factor authentication tokens (TOTP/email OTP state), login timestamps, and security audit logs.
3. How We Use Your Information
We process collected data exclusively to support product functionality and maintain security:
- Authenticating users and maintaining multi-tenant organization boundaries.
- Calculating hours, periods, and payroll totals for export and review.
- Validating timesheet approvals and verifying audit trail compliance.
- Sending automated transactional notifications (e.g., approval status updates, password changes, security verification codes).
4. Data Protection & Security
ShiftSeal implements strict administrative and technical security measures. Electronic signatures are encrypted at rest using strong cryptographic ciphers (Fernet / AES). Access control rules restrict tenant data strictly to authorized organizational users. Account passwords and authentication codes are stored only using modern salted hashing algorithms.
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information. Data is disclosed only to authorized administrative personnel within your organization or as strictly required by law.
6. Cookies & Session Management
ShiftSeal uses essential HTTP session cookies solely for user authentication, security verification, and CSRF protection. We do not use third-party tracking or advertising cookies.
7. Data Retention & User Rights
Timesheet records and audit logs are retained in accordance with your organization's administrative retention configuration. Users may request access, updates, or account changes through their designated Company Administrator.
8. Contact Us
If you have questions regarding this Privacy Policy or our security practices, please contact your organization's ShiftSeal Administrator or reach out to ShiftSeal Support.