Privacy Policy
Effective Date: January 9, 2026
Last Updated: January 9, 2026
StaffTraq ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our employee scheduling platform.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Name (first and last)
- Email address
- Profile photo (optional)
- Phone number (optional)
- Password (encrypted)
1.2 Employment Information
When your employer adds you to their organization or you input employment details, we may collect:
- Employee ID
- Job title and department
- Work location assignments
- Hire date
- Hourly rate (if provided by employer)
- Work schedules and shift assignments
- Time entries (clock in/out records)
- Time-off requests and balances
- Availability preferences
1.3 Payroll Information
If your employer uses our payslip feature, we may store:
- Payslip documents (PDFs uploaded by your employer)
- Pay period dates
Note: We do not store Social Insurance Numbers (SIN), Social Security Numbers (SSN), or bank account information. Payment processing is handled by Stripe.
1.4 Communications
If you use our chat feature, we collect:
- Messages sent within the platform
- Files and attachments shared in conversations
- Message read receipts and delivery status
1.5 Device and Usage Information
We automatically collect:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and features used
- Date and time of access
- Referring website
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our services
- Process your employment data for scheduling purposes
- Facilitate communication between team members
- Send notifications about schedule changes, shift swaps, and requests
- Process time tracking and attendance records
- Generate reports for your employer
- Respond to your inquiries and support requests
- Detect, prevent, and address technical issues or security threats
- Comply with legal obligations
3. Legal Basis for Processing (Canada & California)
For Canadian Users (Alberta PIPA)
Under Alberta's Personal Information Protection Act (PIPA), we process your personal employee information without consent when it is reasonably required for establishing, managing, or terminating the employment relationship. We provide this notice to inform you of our collection practices.
For California Users (CCPA/CPRA)
Under the California Consumer Privacy Act and California Privacy Rights Act, you have specific rights regarding your personal information. See Section 6 for details.
4. Who We Share Information With
4.1 Your Employer
Your employer (the organization administrator) has access to your employment data within StaffTraq, including schedules, time entries, requests, and availability.
4.2 Service Providers (Subprocessors)
We share data with third-party service providers who help us operate our platform. See our Subprocessor List for details.
4.3 Legal Requirements
We may disclose information if required by law, including:
- Court orders or legal process
- Requests from law enforcement
- To protect our rights, privacy, safety, or property
- In connection with a merger, acquisition, or sale of assets
4.4 With Your Consent
We may share your information with other parties when you explicitly consent.
5. Data Retention
We retain your information as follows:
| Data Type | Retention Period | Reason |
|---|---|---|
| Payroll records (payslips, time entries) | 6 years after archival | CRA/IRS tax compliance |
| Employment records | 3 years after employment ends | Alberta Employment Standards |
| Account data | Until account deletion requested | Service provision |
| Chat messages | Per organization retention policy | Configurable by employer |
When you leave an organization or request deletion, we archive legally-required records and delete other personal data. Archived data is automatically purged after the retention period expires.
6. Your Privacy Rights
All Users
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Data Portability: Export your data in a machine-readable format
Canadian Residents (Alberta PIPA)
You may file a complaint with the Office of the Information and Privacy Commissioner of Alberta (OIPC) if you believe your privacy rights have been violated.
California Residents (CCPA/CPRA)
In addition to the above, you have the right to:
- Know what personal information we collect and how we use it
- Opt out of the sale or sharing of your personal information (we do not sell data)
- Non-discrimination for exercising your privacy rights
- Limit use of sensitive personal information
How to Exercise Your Rights
You can exercise your data rights directly in the StaffTraq app under Settings > Privacy, or by contacting us at privacy@stafftraq.com.
7. Security
We implement industry-standard security measures to protect your information, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Secure authentication via Clerk
- Role-based access controls
- Regular security assessments
- Employee access limited to those who need it
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
8. Data Breach Notification
In the event of a data breach that poses a real risk of significant harm, we will notify:
- The Office of the Information and Privacy Commissioner of Alberta (OIPC)
- Affected individuals (as required by law)
- The California Attorney General (if 500+ California residents affected)
9. Children's Privacy
StaffTraq is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
10. International Data Transfers
Your data may be processed in the United States, where our service providers are located. We ensure appropriate safeguards are in place for cross-border data transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page
- Updating the "Last Updated" date
- Sending an email notification for significant changes
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
StaffTraq Privacy TeamEmail: privacy@stafftraq.com
Address: [Your Business Address]
Alberta, Canada
For privacy complaints in Alberta, you may also contact the Office of the Information and Privacy Commissioner of Alberta.