PRIVACY POLICY — MyShift & Payslip / MyShift & Paycheck
Last updated: May 7, 2026
1. GENERAL INFORMATION
MyShift & Payslip / MyShift & Paycheck (hereinafter, "the Application") is a personal payroll and shift management tool developed by Víctor de Mora Regañó, an independent developer based in Spain. The Application is available to users in Spain, Portugal, the United Kingdom, the United States and Brazil, and is designed to operate predominantly locally on the user's device.
Depending on your country of residence, different data protection regulations may apply: the General Data Protection Regulation (GDPR) in Spain and Portugal, the UK GDPR and Data Protection Act 2018 in the United Kingdom, the Lei Geral de Proteção de Dados (LGPD) in Brazil, and state privacy laws such as the CCPA/CPRA in the United States. This policy describes how we comply with all of them.
2. DATA STORED LOCALLY — NO TRANSMISSION TO SERVERS
MyShift & Payslip does NOT collect, does NOT transmit and does NOT store on external servers any personal, financial or employment data from the user. All information you enter is saved exclusively in the local storage (localStorage) of your own device. The only exception is the automatic sending of technical diagnostic data when the application experiences a critical error (see section 6). This includes:
- Salary and financial information: base salary, income tax withholding, salary supplements, extra pay periods, variable items (overtime, night shift premiums, etc.) and sick leave records. This data never leaves your device.
- Shift and calendar data: shift patterns, calendar assignments, colors, custom labels, events and notes. Processed and stored locally only.
- Payroll data: fixed items, supplements (per diem, mileage, on-call), deductions and calculations. All generated and kept on your device.
- App preferences: dark mode, currency, country/region for public holidays, billing period and automatic clock-in configuration.
The Application does not request or store your name, email address, phone number or any other personally identifiable information. All the data mentioned above is completely deleted if you uninstall the application or clear its data from Android settings. Optionally, you can sign in with Google to back up your data to Google Drive (see sections 7 and 9).
3. LOCATION (GEOLOCATION) AND BACKGROUND ACCESS
The Application requests access to your location, including background location, exclusively to detect arrival at and departure from the workplace defined by the user (an optional feature called "Automatic Clock-in by Location"). These coordinates are processed locally on the device and are not shared with third parties.
Feature details:
- Allows automatic registration of workplace arrival and departure through geofencing (virtual perimeter) using Android native APIs (GeofencingClient).
- The workplace coordinates configured by the user are stored ONLY in the device's local storage.
- Geofencing processing is performed entirely locally through Android native services. No coordinates, trajectories or any location data are sent to external servers or third parties.
- Background location (ACCESS_BACKGROUND_LOCATION) is necessary for the perimeter detection to work with the app closed or the screen off. Without this permission, automatic clock-in cannot operate autonomously.
- This feature is completely optional. It is disabled by default and can be enabled or disabled at any time from the "Automatic Clock-in by Location" section in Settings.
- If you do not activate automatic clock-in, the Application does not access your location at any time.
4. ADVERTISING — GOOGLE ADMOB
The Application uses Google AdMob as its advertising provider to display ads. Google AdMob is a service provided by Google LLC that may collect and use certain device information in order to display ads, including personalized ads. This information may include:
- Device identifiers (such as the Android Advertising ID / AAID).
- IP address and connection data.
- Device information (model, operating system, language).
- Ad interaction data (impressions, clicks).
- Cookies and similar technologies for ad personalization.
This data collection is performed directly by Google AdMob and is subject to the Google Privacy Policy. The developer of MyShift & Payslip does not have access to any personal data collected by AdMob.
Advertising consent by region:
- European Union, United Kingdom and Brazil: in compliance with the GDPR, UK GDPR and LGPD, the Application requests your explicit consent before showing personalized ads. If you do not grant consent, generic non-personalized ads will be shown.
- United States: personalized ads are enabled by default. You can opt out of personalization at any time.
You can manage your personalized advertising preferences from your Android device settings at: Settings > Google > Ads, where you can reset your advertising ID or opt out of ad personalization. On some devices, this option may be under Settings > Privacy > Ads.
5. NOTIFICATIONS
The Application may send local notifications to alert you of arrivals at or departures from the configured geofencing perimeter. These notifications are generated locally on the device. No third-party push notification services (such as Firebase Cloud Messaging) are used, and no information is sent to external services to generate these notifications.
6. NETWORK CONNECTIONS
In addition to the Google AdMob connections described in section 4, the Application makes the following Internet connections, none of which transmit personal user data:
- OpenStreetMap (tile.openstreetmap.org): downloading map tiles to display the workplace location in the automatic clock-in configuration. No user data is transmitted to OpenStreetMap.
- Nager.Date API (date.nager.at): querying official public holidays by country and region for the work calendar. Only the selected country/region code is sent. No personal data is transmitted.
- Google OAuth (oauth2.googleapis.com): authentication with a Google account for the optional cloud backup feature. Only an authorization code is exchanged for an access token. See section 7.
- Google Drive API (www.googleapis.com/drive): uploading and downloading backups in the application's private folder (appDataFolder). Only the data the user chooses to back up is transmitted. See section 9.
- Crash reporter: when the Application experiences a critical error, a diagnostic report is automatically sent to a private proxy server operated by the developer. This report contains exclusively technical device data: Android version, Chrome/WebView version, device model, screen resolution, RAM, system language, connection status, country and region selected in the app, active tab, theme mode (light/dark), session uptime, number of stored shifts, and the technical error message. An anonymous device identifier (randomly generated, not linked to any personal data) is also included to group errors from the same device. No salary, financial, calendar, or payroll data is sent. This information is used solely to diagnose and fix application errors.
7. THIRD-PARTY SERVICES
The Application uses the following third-party services:
a) Google AdMob: for advertising display, described in section 4.
b) Google Sign-In (optional): allows signing in with your Google account to enable the cloud backup feature. When signing in, the Application accesses only your email address, profile name and profile picture to display in the interface. It does not access contacts, search history or any other data from your Google account. Authentication is handled through the Google Sign-In SDK and is subject to the Google Privacy Policy.
c) Google Drive API (optional): used exclusively to store and retrieve backups of your data in the application's private folder (appDataFolder) within your Google Drive. This folder is invisible to the user in Google Drive and only accessible by the Application itself. No other files or folders in your Google Drive are accessed. The permission used is drive.appdata (limited access to application data).
The Application does NOT use:
- Proprietary analytics services (Google Analytics, Firebase Analytics, etc.).
- Proprietary tracking or tracing tools.
- Social media SDKs.
8. DEVICE PERMISSIONS
The Application requests the following Android permissions:
- INTERNET: to download map tiles, query public holidays and display advertising (AdMob).
- ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION: to obtain your GPS position (only if you activate automatic clock-in).
- ACCESS_BACKGROUND_LOCATION: for geofencing to work with the app in the background (only if you activate automatic clock-in). The application requests background location access exclusively to detect arrival at and departure from the workplace defined by the user.
- POST_NOTIFICATIONS and SCHEDULE_EXACT_ALARM: for local geofencing notifications.
- WAKE_LOCK and RECEIVE_BOOT_COMPLETED: to keep the geofencing service active after device restart.
- FOREGROUND_SERVICE and FOREGROUND_SERVICE_LOCATION: for the background location monitoring service.
All these permissions are requested explicitly and can be revoked at any time from Android settings.
9. EXPORT, IMPORT AND CLOUD BACKUP
The Application allows you to export and import your configuration and data in JSON format. This file is generated and stored locally on your device. The sharing function uses the operating system's native APIs. Data is never sent to the developer's servers.
Additionally, if you sign in with Google (section 7b), you can back up your data to Google Drive. The backup is stored as a single JSON file in the application's private folder (appDataFolder) in your Google Drive. This folder is not visible or directly accessible by the user in Google Drive, nor by other applications. Only MyShift & Payslip can read and write to it. To delete this data, you can: (1) use the "Factory reset" function within the app, (2) revoke the app's access from your Google account at myaccount.google.com/permissions, or (3) uninstall the application.
10. PDF GENERATION
The Application can generate PDF documents with your payroll details. These documents are created and stored locally on your device using the jsPDF library. They are not sent to any server.
11. DATA SECURITY
The employment and financial data you enter in the Application is stored exclusively on your device. Its security depends on your own device's security measures (screen lock, device encryption, etc.). We recommend keeping your device protected with a secure lock method. The developer has no access to this data at any time.
12. CHILDREN'S DATA
The Application is not directed at minors. The minimum age of use varies by jurisdiction:
- European Union (Spain, Portugal): 16 years, in accordance with the GDPR.
- United Kingdom: 13 years, in accordance with the UK GDPR and Data Protection Act 2018.
- United States: 13 years, in accordance with the Children's Online Privacy Protection Act (COPPA).
- Brazil: 18 years for full consent, in accordance with the LGPD (Article 14). Minors aged 16 to 18 may use the Application with parental or legal guardian consent.
We do not knowingly collect information from children under the applicable minimum age in their jurisdiction. If you are a parent or guardian and believe your child has provided personal information, please contact us so we can take the necessary steps.
13. USER RIGHTS
Since all your data is stored locally on your device and the developer has no access to it, you can exercise full control over your information at all times:
- Access and portability: you can export all your data in JSON format from Settings.
- Deletion: you can delete all your data by uninstalling the app or clearing the application data from Settings > Apps.
- Cloud backup: if you have backed up to Google Drive, you can delete it by revoking the app's access from myaccount.google.com/permissions.
- Sign out: you can sign out of Google at any time from the Data section in Settings.
- Advertising: you can manage AdMob ad personalization preferences from Settings > Google > Ads.
14. ADDITIONAL RIGHTS FOR CALIFORNIA RESIDENTS (CCPA/CPRA)
If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights regarding your personal information:
- Right to know: you have the right to request information about the categories and specific pieces of personal information we collect, use and disclose. As described above, MyShift & Payslip stores all personal data locally on your device and does not collect it on external servers.
- Right to delete: you have the right to request deletion of your personal information. Since all data is stored locally, you can delete it at any time by uninstalling the app or clearing its data (see our Data Deletion page).
- Right to opt-out of sale: