KithivaBetter business, built around people.Privacy questions ↗

Kithiva / Legal

Privacy Policy

Last updated August 18, 2026

This policy explains how Kithiva (“Kithiva,” “we,” “us,” or “our”) collects, uses, shares, protects, retains, and deletes information when you use our websites and applications, including Shifty.

Information we collect

Account and contact information. Managers provide a name, email address, password, and optional phone number. Passwords are stored as one-way password hashes, not readable passwords.

Operational and user content. Managers provide establishment details, team rosters and availability, floor plans, scheduling rules, schedules, side-work tasks, and support messages. Team members may submit task-completion photos through their private schedule page.

Purchases. Apple provides subscription and transaction status, product identifiers, expiration information, and an account-linked purchase token. Kithiva does not receive full payment-card information.

Diagnostics and security data. When the service is used, our systems receive account identifiers, application version, request timestamps, network information such as IP address, service errors, and security events. A schedule-problem support ticket includes a manager-reviewed, privacy-reduced diagnostic snapshot. Ordinary on-device logs are not uploaded automatically.

How we collect information

We collect information directly when a manager creates an account, enters or synchronizes workspace data, publishes a schedule, or contacts support; from team members when they use a private schedule link, acknowledge an update, claim a task, or submit task evidence; automatically from the app and backend when necessary to authenticate requests, secure the service, and diagnose failures; and from Apple when a subscription is purchased, restored, renewed, or canceled.

Spoken scheduling rules use Apple's speech-recognition services after the manager grants microphone and speech-recognition permission. A manager may type a rule instead and can withdraw those permissions in iOS Settings.

How we use information

We use information to provide scheduling and task features, synchronize manager workspaces, publish private team schedules, administer subscriptions, respond to support requests, protect accounts, prevent abuse, improve reliability, and comply with applicable legal obligations.

Team schedules and private links

Managers may publish a unique schedule link for each team member. Anyone who receives that private link may be able to view the associated schedule, opportunity score, and assigned side work. Managers are responsible for sharing these links only with the intended recipients. Kithiva may revoke or expire links to protect the service.

Service providers and disclosures

We use service providers, including cloud hosting and storage, email delivery, Apple subscription services, speech recognition, and restricted support-ticket systems. They receive only the information reasonably necessary to provide their service and must provide the same or equivalent protection described in this policy and required by applicable Apple rules. We do not sell personal information, share it with data brokers, or use it to track people across other companies' apps or websites.

Information may be processed in the United States or another country where a provider operates. Where required, we use appropriate contractual or legal safeguards for international transfers. We may disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards and notice where required.

Support tickets

General support tickets exclude roster, schedule, floor-plan, rule, photo, email, phone, credential, and access-key data by default. Schedule-problem reports may include a privacy-reduced diagnostic snapshot using aliases in place of team-member and section names. GitHub receives only limited ticket metadata and automated findings; detailed diagnostics remain in Kithiva's protected backend.

Retention and deletion

Account profiles and synchronized workspace data are retained while the account is active. Authentication sessions expire after 30 days. Published schedule links and their schedule data expire after 90 days unless revoked sooner. Task records and evidence photos remain until the manager deletes the eligible task, the account is deleted, or they are no longer reasonably necessary to provide the service. Subscription records are retained while needed to administer access and satisfy accounting, fraud-prevention, and legal obligations.

Support diagnostic snapshots are removed after 90 days. Closed-ticket conversations are removed after 12 months. A manager may request earlier deletion of a ticket's diagnostics and conversation; Kithiva retains only a minimal audit record containing the ticket number, category, dates, and deletion status.

Managers can initiate permanent account deletion in Shifty under Settings → Account → Delete account. The service immediately removes the manager profile, sessions, synchronized workspace, published schedules and links, side-work records and evidence, and associated support diagnostics. Residual encrypted backup copies, if any, are isolated from normal use and removed through the ordinary backup-rotation cycle. Limited records may be retained only when required by law or reasonably necessary for security, fraud prevention, dispute resolution, or enforcing agreements. Apple retains and controls its App Store transaction records separately.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, access controls, private service credentials, signed webhook verification, and restricted support repositories. No system can guarantee absolute security.

Your choices, consent, and rights

You may review and update profile and operational information in the app, revoke a published schedule link, close or archive support tickets, request deletion of ticket data, or permanently delete your manager account in the app. You can withdraw microphone or speech-recognition permission in iOS Settings and type scheduling rules instead. You may withdraw consent for optional processing or request access, correction, deletion, restriction, objection, or a portable copy of personal information by emailing privacy@kithiva.com. We may verify your identity before fulfilling a request. Withdrawing information required to provide an account may require account deletion or make the affected feature unavailable.

Children

Kithiva's manager products are intended for adults managing a business and are not directed to children under 13. We do not knowingly collect personal information from children under 13.

Changes to this policy

We may update this policy as our products or legal obligations change. We will update the date above and provide additional notice when a change materially affects how personal information is handled.

Contact us

Kithiva is the party responsible for the information described in this policy and is based in Denver, Colorado, United States. For privacy questions, complaints, or requests, email privacy@kithiva.com.

KithivaBetter business, built around people.Home

© 2026 Kithiva