Legal

Privacy Policy

Draft - pending attorney review

01

Who Operates RescueShift

RescueShift is a product operated by WhyUAscii LLC, a limited liability company organized under the laws of the State of Florida, United States ("WhyUAscii," "we," or "us") based in the State of Florida, United States (whyuascii.com). WhyUAscii LLC is the company behind RescueShift and is responsible for the RescueShift service described in this policy. For privacy questions or data requests, contact eddy@whyuascii.com.

This policy covers two situations separately: (1) when you use RescueShift as an individual (your personal account and schedule), where we act as the controller of your personal data, and (2) when your department uses RescueShift to manage its roster, where your department is the controller and we act as its processor. See "Department Roster Data" below.

02

Information We Collect

We collect only what is needed to provide the service. The categories below reflect what the app actually stores.

Account and identity data: your email, name, and first and last name; and, if you set them, a nickname and profile picture.

Profile and personnel data: name, nickname, email, phone number, rank, badge number, hire date, and duty roles (for example Fire, EMT, or Paramedic).

Scheduling data: shift patterns, teams, calendars, and calendar events (which can include PTO and sick time), trades, and daily roster entries.

Training and compliance data: trainings, and certifications including license numbers, issuing authority and state, and issue and expiration dates; and leave balances.

Department and organization data: department name, memberships and roles, stations and locations, apparatus, and staffing requirements.

Billing data: Stripe customer and subscription identifiers, and RevenueCat app-user identifiers. We never receive or store your full payment card number; the payment processors handle card data.

Notifications data: device push tokens and the email address we send notifications to.

Usage and device data: product analytics and diagnostic information (for example which screens are used and error reports), collected through PostHog and gated by your consent where required.

We do not intentionally collect special categories of data. Please do not enter more sensitive information than your role requires.

03

Personal Data vs. Department-Controlled Data

Some data you enter is your personal data (for example, your personal calendar events, personal notes, and personal training records on an individual account). Other data is entered and controlled by your department (for example, the roster, ranks, badge numbers, station assignments, staffing requirements, and PTO, trade, and overtime records managed inside a department).

For your personal data, WhyUAscii LLC is the controller. For department-controlled data, the department is the controller and WhyUAscii LLC is the processor acting on the department's instructions. Requests about department-controlled data should be directed first to your department; we will assist the department as its processor.

04

How We Use Your Information

We use your information to: provide and maintain the scheduling service and sync your data across your devices; power department features such as coverage views, trades, rosters, staffing, and training and certification tracking; send transactional email (verification, password reset, invites) and push notifications you have opted into; understand product usage so we can fix problems and improve the app; process subscriptions and prevent fraud and abuse; and meet legal, tax, and security obligations. We do not sell your personal data, and we do not use your schedule or department data to train advertising profiles.

06

Department Roster Data (Controller vs. Processor)

When a department subscribes, the department is the controller of its roster data: the member list, contact details, ranks, badge numbers, certifications, staffing requirements, and PTO, trade, and overtime records it manages in RescueShift. We process that data on the department's behalf and under its instructions, as its processor, and under our Data Processing Addendum where one applies.

Department administrators can see the schedule, assignments, trade requests, staffing, and compliance status of their members. That access is scoped to the department: administrators cannot see your personal calendar events, private notes, or any data from other departments. Questions about how your department uses roster data, or requests to correct or remove it, should be directed first to your department; we will assist the department as its processor.

07

Billing Information

Individual Premium subscriptions on mobile are processed through the Apple App Store or Google Play, with RevenueCat managing your entitlement; we never see your payment card details. Web Premium and all Department subscriptions are billed via Stripe. We store only what is needed to maintain the subscription, such as billing contact, Stripe and RevenueCat identifiers, invoice history, and subscription status. Full payment card details are handled entirely by the payment processors.

08

Overtime and Compliance Data

For departments that track overtime, we calculate work hours against FLSA 7(k) rules (for example a 212-hour threshold over a 28-day work period, configurable by the department). These figures are provided as a convenience only and are not a substitute for the department's own compliant payroll and timekeeping systems. This is sensitive employment information belonging to the department. It is visible only to department members whose role permits it, and we do not share it with any third party for their own purposes.

09

Health Information and HIPAA

RescueShift is a workforce scheduling tool, not a healthcare or medical-records system. We are NOT a HIPAA covered entity or a business associate, we do not collect or process Protected Health Information (PHI), and RescueShift is not designed or intended to store patient records or patient-identifiable medical information. Because we do not handle PHI, we do not sign Business Associate Agreements (BAAs).

The information we do collect is scheduling and employment-context data, inventoried in the "Information We Collect" section above (for example names, contact details, ranks, shift and roster entries, PTO and sick markers, certifications, and staffing records). That is workforce data, not patient data. Our Terms of Service prohibit entering patient records or PHI into RescueShift, and you and your department are solely responsible for any such data entered in violation of those Terms.

10

Data Security

Connections to RescueShift are encrypted in transit using HTTPS/TLS, and our infrastructure host (Amazon Web Services) encrypts data at rest. Authentication and sessions are managed with Better Auth, with rate limiting and account lockout after repeated failed sign-ins. We enforce tenant isolation so one department's data is not accessible to another, and department features are gated by role-based access controls. As defense in depth, our database uses deny-by-default row-level security. No online service can promise perfect security, but we work to protect your data and to limit access to those who need it.

11

Third-Party Processors

We rely on a small set of trusted providers to run RescueShift. Each receives only the data it needs for its role and processes it under its own privacy terms in addition to our agreements with them:

Amazon Web Services (AWS): hosting, database, and storage for the whole service, located in the United States. Supabase: managed database platform used as part of our data infrastructure. Stripe: web Premium and all Department billing. Stripe receives billing contact and payment details and handles all card data; we never see your full card number. RevenueCat: manages mobile subscriptions purchased through the Apple App Store and Google Play. It receives purchase and entitlement data tied to your account, not your card details. PostHog: product and web analytics, including masked session replay, gated by your consent where required. Resend: transactional and notification email delivery. It receives your email address and the message content we send you. Expo Push: delivery of push notifications you opt into, through the Apple Push Notification service and Google Firebase Cloud Messaging. These receive device push tokens. Cloudflare: bot-protection and CAPTCHA challenges (Turnstile) on our login and signup forms. It receives your IP address and browser challenge signals to tell humans from bots. MXRoute: inbound email hosting for our support mailbox. When you email support, it receives your email address and the content of your message. Google AdMob (mobile) and Google AdSense (web): advertising on the free tier only. See the advertising disclosure below.

We do not sell your personal data. We share it with these providers only to deliver the service. A current subprocessor list for department customers is available in our Data Processing Addendum.

12

Advertising and Device Identifiers

On the free tier only, we show ads through Google AdMob on mobile and Google AdSense on the web. To serve and measure ads, these services may set or read device identifiers, such as a mobile advertising ID or advertising cookies. Premium and Department subscribers see no ads and are not part of ad targeting. You can limit personalized ads at any time: on iOS through Settings, then Privacy and Security, then Tracking; on Android through Settings, then Google, then Ads; and on the web through the Cookie Settings link in our footer or the Do Not Sell or Share page. Turning off personalization does not remove ads on the free tier, but it stops them from being tailored to you.

13

Session Replay

We use PostHog to record masked replays of how people use the RescueShift web application so we can find confusing steps and fix problems. These recordings capture on-screen actions like clicks and navigation. Text you type into inputs is masked, so we do not capture what you enter into fields. We use session replay only to improve the product, never to sell your data. You can opt out of analytics, including session replay, through the Cookie Settings link in our footer or the Do Not Sell or Share page.

14

Your Rights and Choices, and How to Delete Your Account

Depending on where you live, you have rights over your personal data. If you are in the European Economic Area or the United Kingdom (GDPR), you have the right to access your data, correct it, delete it, receive a portable copy, restrict processing, and object to certain processing, and to withdraw consent. If you are in California (CCPA and CPRA) or a similar state, you have the right to know what we collect, delete it, correct it, opt out of the sale or sharing of personal information, and not be discriminated against for exercising these rights. We do not sell your data, and we honor Global Privacy Control signals as an opt-out of sharing.

You can review and update your account information in the app. To delete your account and associated personal data you have two options: (1) in the app, go to Settings, then Account, then Delete Account, and confirm by re-authenticating; or (2) on the web, use the public account-deletion page and verify with a one-time code sent to your email. Deletion is a hard delete that cascades to your personal data, cancels active billing, and revokes connected Sign in with Apple and Google tokens; we keep a minimal, hashed audit record of the deletion event as required for security and compliance.

To exercise any other right, email eddy@whyuascii.com. We respond to requests within the timeframe required by applicable law (generally within 30 days) and may ask you to verify your identity first. You can authorize an agent to act for you. If your data is part of a department roster, some requests must be directed to your department as the controller, and we will support the department in responding.

15

Data Retention

We keep your data while your account is active so your schedule stays available across your devices. When you delete your account, we remove your personal data from active systems promptly (generally within 30 days), and backups expire on their normal cycle, except where we must keep certain records to meet legal, tax, or security obligations (for example, a minimal hashed record of the deletion event, and invoice records required by law). Departments can export their roster and schedule data while their subscription is active; after a department's service ends, we delete or return its data as described in the Data Processing Addendum.

16

Children's Data

RescueShift is a workforce scheduling tool for fire and EMS professionals and is not directed to children. We do not knowingly collect personal data from children under 13 (as defined by COPPA), or under 16 in regions where that is the applicable age. If we learn that we have collected data from a child below the applicable age, we will delete it. If you believe a child has provided us personal data, contact eddy@whyuascii.com.

17

International Data Transfers

RescueShift is operated from the United States, and our infrastructure host (Amazon Web Services) processes and stores data in the United States. If you use RescueShift from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. Where required by applicable law, we and our providers rely on lawful transfer mechanisms, such as the European Commission's Standard Contractual Clauses, to protect your data during these transfers.

18

Changes to This Policy

We may update this Privacy Policy as our service, technology, and legal obligations evolve. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you in the app or by email. Your continued use of RescueShift after an update means you accept the revised policy.

19

Contact Us

For privacy questions or data requests, contact eddy@whyuascii.com. For general product support, contact support@rescueshift.com. If your request concerns department roster data, please also contact your department administrator, who is the controller of that data.