Security

How Shift Terminal protects your data

Schedules, hours and wages are sensitive data. This page describes how Shift Terminal protects them.

Account security

Sign-in is protected by a CAPTCHA, account lockout after repeated failures, and password rules. Anyone can turn on two-factor authentication with an authenticator app from My Profile; it is mandatory for platform administrators, and sensitive operations such as a full data export require a recent second factor.

  • Two-factor authentication (TOTP)
  • Turnstile CAPTCHA on sign-in and sign-up
  • Lockout after repeated failed attempts
  • Signed, expiring sessions

Every organization is isolated

Each organization’s data is separated by row-level security in the database itself, so a query from one organization can never return another’s rows, even if the app has a bug. Inside an organization, four roles and 34 permission switches decide who sees wages, approves timesheets or changes settings.

  • Row-level security per organization
  • Admin, manager, supervisor and employee roles
  • Per-role and per-user permission overrides
  • Supervisor wage visibility off by default

Encryption and hosting

Data is encrypted in transit with TLS 1.2 or later and at rest with AES-256. Passwords are hashed with bcrypt. Your database and uploaded files are hosted in Canada, in AWS Canada Central (Montréal), on infrastructure providers that hold SOC 2 Type II and ISO 27001 certifications.

  • TLS 1.2+ in transit
  • AES-256 at rest
  • Database and files in AWS ca-central-1 (Canada)
  • SOC 2 Type II / ISO 27001 infrastructure providers

Application hardening

The web app ships a strict Content Security Policy, HSTS, and headers that stop it being framed by other sites. Sensitive endpoints are rate-limited, administrative actions are written to an audit trail, uploaded documents are virus-scanned before they are stored, and errors are monitored so problems are caught early.

  • Strict Content-Security-Policy and HSTS
  • Rate limiting on sensitive endpoints
  • Audit trail for administrative actions
  • Virus scanning of uploaded documents

Privacy and compliance

Shift Terminal is a Canadian company and processes personal information under PIPEDA. Electronic messages follow CASL. Every organization is covered by our Data Processing Agreement, which lists sub-processors and their locations, security measures and breach-notification commitments.

  • PIPEDA
  • CASL-compliant notifications
  • Data Processing Agreement with sub-processor list
  • Breach notification commitments in the DPA

Exporting and deleting your data

Administrators can request a complete export of the organization’s data from Settings. Any user can delete their own account from My Profile, the website or by e-mail; records an employer is required to keep for payroll are anonymized rather than removed. Logs are pruned on a published retention schedule.

  • Complete organization export
  • Self-serve account deletion
  • Anonymization of retained payroll records
  • Log retention and pruning

Reporting a vulnerability

We publish a security.txt with our disclosure contact. Privacy questions go to privacy@shiftterminal.com. The full legal detail lives in the Privacy Policy and the Data Processing Agreement.

Questions

Security questions

Is my data secure?

Yes. Data is encrypted in transit and at rest, and each organization is isolated with role-based access controls.

Where is my data stored?

Your database and uploaded files are hosted in Canada (AWS Canada Central, Montréal). Some service providers (payments, e-mail delivery and error monitoring) process limited data in the United States, as listed in our Data Processing Agreement.

Do you support two-factor authentication?

Yes. Anyone can turn on two-factor authentication with an authenticator app from My Profile, and it is mandatory for platform administrators.

Can I export or delete my data?

Admins can request a complete export of the organization’s data from Settings, and any user can delete their own account from My Profile or the website. Records an employer must keep for payroll are anonymized rather than removed.

Ready to simplify your workforce management?

Join teams that schedule smarter, track time accurately, and keep everyone connected.

Start free trial

No credit card required. 14-day free trial included.