DutyShiftsBack

Privacy policy

Last updated: 10 September 2026

This document is available in English and Polish.

Who is responsible

The data controller is Maksymilian Furtak, the author of DutyShifts (maksymilian.org). For anything concerning your data, write to [email protected].

What we collect

When you create an account: first name, last name, username, email address and password. We never store the password itself, only a cryptographic hash that cannot be turned back into the original.

While you use the service: your interface language, the projects you belong to and your role in them, the duties and assignments you create or take part in, and project invitations.

Technically: a sign-in session identifier and its expiry. If you link a Google account, we store that account's identifier. We never see your Google password.

Why we use it

Only to run the service: so you can sign in, see your roster, assign someone to a duty, and receive an email confirming your address or resetting your password. The legal basis is performance of a contract (Article 6(1)(b) GDPR) and, for security measures, our legitimate interest (Article 6(1)(f) GDPR).

We do not sell data, profile users, or send newsletters.

Who processes it with us

Oracle Cloud hosts the application and the database on a server in the European Union. Cloudflare provides connection encryption, abuse protection and inbound mail routing. Resend delivers our outgoing email. Google provides Google sign-in, if you choose to use it, and visit statistics, if you consent to them.

Each of them processes the data on our instructions and only as far as their part of the service requires.

Cookies

Necessary: the session cookie, without which you cannot stay signed in. Preferences: your chosen language and theme, and your remembered decision about statistics.

Statistics: Google Analytics loads only after you agree, and we remember that choice for a year. Declining changes nothing about how the service works. You can revise the decision by clearing cookies in your browser.

How long we keep it

Account data stays until you delete the account. Database backups are taken nightly and we keep the last fourteen, so deleted data disappears from backups within fourteen days at the latest.

Deleting your account removes your account data, your project memberships and your duty assignments. Projects and duties run by other people remain, because they belong to those projects rather than to your account.

Your rights

You have the right to access your data, correct it, delete it, restrict or object to its processing, and receive a copy of it. Most of this you can do yourself: edit your details in your profile and delete your account with one button.

For anything else, write to [email protected]. You may also lodge a complaint with your data protection supervisory authority.

Changes

If we change this policy we will update the date at the top of the page, and we will announce significant changes in the application before they take effect.