Legal information
Personal data processing and privacy policy
This policy explains what data Shift-Calendar processes, why it is needed, where it is stored and how a user can exercise their rights.
Effective date: August 8, 2026
1. General provisions
This policy applies to the Shift-Calendar.com website, the shift calendar application, user accounts, comments, public schedule links, Pro purchases and related support requests.
The personal data operator is Чабан Сергей Александрович, a self-employed individual under Russian law (taxpayer identification number 781650212029) . Contact details are available on the Contacts page.
The policy is based on Federal Law No. 152-FZ “On Personal Data” and other applicable Russian laws. The policy itself is not a consent form where a separate consent is required by law.
2. Data subjects and processed data
| Purpose | Data | Legal basis |
|---|---|---|
| Website access, security and troubleshooting | IP address in server logs and comments, date and time, requested URL, browser and device information, session and technical identifiers | Operation and protection of the service, legitimate interests of the operator and users, legal obligations |
| Registration, sign-in and account management | Username, email, display name, avatar, internal user ID, Pro status and, when social sign-in is used, the provider ID and authentication data returned by VK, Yandex ID or Mail.ru | Actions requested by the user, performance of the user agreement, consent where required |
| Creating and saving calendars | Schedule cycle and dates, titles, comments, shifts, hours, earnings settings, calendar profiles and events entered by the user | Providing the requested service and performing the user agreement |
| Public schedule links | A read-only schedule snapshot selected by the user, access token, creation/expiry dates and view count | User request and consent to publish the selected snapshot |
| Comments and feedback | Name, email, website if provided, comment text, avatar, account ID, IP address and browser user agent | User consent, publication requested by the user, spam prevention and protection of the service |
| Pro purchase and accounting | Account and order ID, email, product, amount, currency, payment status and receipt-related information. Bank card details are not received or stored by Shift-Calendar | Performance of the purchase agreement and tax/accounting obligations |
| Product analytics | Account ID or a one-way hash of a random guest identifier, session hash, access plan, locale, app version, country code when supplied by trusted infrastructure, and a limited list of feature usage events | Improvement and protection of the service, legitimate interests of the operator and users |
| Support and legally required communication | Name, account email for a signed-in user or an email provided by a guest who requests a reply, account ID, request category and text, correspondence history, and limited technical context such as application version, interface mode, language and screen size. Requests from the corporate calculator may also include anonymised calculation parameters and aggregate results; employee names are not attached | User consent, handling the request, performance of the agreement and legal obligations |
3. Where schedule data is stored
A guest schedule, calendar profiles, interface preferences and guest share management identifiers are stored in the current browser using localStorage. The user can remove them through browser settings. They do not automatically appear on another device.
After sign-in, saved schedules, events, profiles and settings are stored in the service database and linked to the account. JSON backups, spreadsheet exports, print views and PDF preparation are produced in the browser; the selected backup file and print background are not uploaded solely for creating or reading those files.
4. Public links and data about other people
Anyone who has a public link can view its snapshot without signing in. A registered user’s link remains available until revoked. A guest link expires after 30 days and its period is renewed when the guest updates it. Search engines are instructed not to index new public links, but the user must still treat the URL as access information and send it only to intended recipients.
A user may enter names, birthdays or other information concerning relatives, friends or colleagues. The user must have a lawful basis to do so and must not publish another person’s data without permission. Do not enter diagnoses, medical records, passport data, payment credentials or other sensitive data. The “sick leave” event is intended only for a date range and optional payment calculation, not for medical details.
5. Browser storage and analytics
The website, authentication and the calendar use cookies, localStorage and sessionStorage that are necessary for sessions, security, interface preferences, guest data and installation prompts.
Shift-Calendar’s internal analytics does not store schedule titles, comments, wages, shift dates, vacation dates, birthdays or event text. Raw analytics events are deleted after 90 days; anonymous daily totals may be retained without account or browser identifiers. The analytics module does not retain the visitor’s raw IP address, although the web server and WordPress comments may record it for security.
The website uses Yandex Metrica and Google Analytics to measure traffic sources, page views, device characteristics and interactions with the interface. Yandex Metrica’s Session Replay feature may record actions on a page; fields intended for personal or financial information must not be recorded. These analytics services use browser identifiers stored in cookies or localStorage.
On the English version, Yandex Metrica, Google Analytics and anonymous browser product analytics start only after the visitor allows analytics. On the Russian version, the visitor is notified before continuing and may disable analytics. The choice is retained for up to one year and can be changed at any time through “Cookie settings” in the website footer. Necessary storage remains active because it is required for authentication, security, saved guest data and interface preferences.
6. Recipients and processors
- The hosting provider Beget, Россия processes the database, files, backups and technical logs.
- VK, Yandex ID or Mail.ru processes data under its own terms when the user chooses the corresponding social sign-in method.
- Yandex and Google process browser identifiers and visit information when their analytics services are enabled.
- Robokassa processes payment and fiscal data when Pro is purchased. Shift-Calendar does not receive the payer’s bank card details.
- The operator’s email infrastructure processes messages and service notifications.
- Government bodies may receive data where the operator is legally required to provide it.
The operator does not sell personal data. Primary recording, systematization, accumulation and storage of Russian citizens’ personal data must use databases located in Russia. Cross-border transfers, if required by a provider chosen by the user, are performed only where a lawful basis and statutory conditions are met.
7. Retention and deletion
- Account and server-side schedules are kept while the account is used and until deletion or a valid erasure request, unless the law requires continued retention.
- Guest browser data remains until the user clears it or the browser removes it.
- Guest public links expire after 30 days; registered-user links remain until revoked.
- Comments remain while the relevant discussion is published or until deletion/moderation, subject to legal grounds.
- Order, receipt and accounting records are retained for statutory periods.
- Support correspondence is retained until the request and possible claims are resolved.
- Technical log retention is determined by the security and hosting configuration and is limited to the period necessary for those purposes.
8. User rights
A data subject may request information about processing, correction, restriction, blocking or deletion of inaccurate or unlawfully processed data, withdraw consent where processing depends on consent, and request that public disclosure stop. The operator may ask for information necessary to verify the requester and locate the relevant data.
Requests are accepted through the details on the Contacts page. The subject may also complain to Roskomnadzor or seek judicial protection.
9. Security, children and policy changes
The operator uses access controls, authentication, role separation, encrypted HTTPS transport, backups, input validation, rate limits and other reasonable organizational and technical safeguards. No online system can guarantee absolute security.
The service is not intended for independent submission of personal data by children without involvement of a parent or other legal representative.
The policy may be updated when the service, processors or laws change. The current version is published at this URL and states its effective date.