SHIFT Privacy Policy
Last updated: 23 September 2026
SHIFT is two things, and this policy covers both. Part 1 covers the website at useshift.app, where athletes set a race goal and the people around them pledge money behind it. Part 2 covers the SHIFT iOS app. Part 3 applies to both.
Part 1: the website and pledge platform
The platform is opening in stages. This part says plainly what is collected today and what will be collected once pledging opens, so nothing arrives as a surprise. We will update the date above whenever a stage goes live.
What we collect today
- Founding athlete applications. If you fill in the form at useshift.app/start we store your name, email address, the race you are training for, your goal, whether you are applying for yourself, a club or a company, and the club or company name if you give one.
- Hosting and security logs. Our hosting provider (Vercel) and database provider (Supabase) record technical request data such as IP address, user agent, requested page, timestamp and response status. We use this to keep the site running, to rate-limit the form and to stop abuse.
That is the full list, plus one thing: cookieless usage analytics. We use PostHog (EU servers) to count page views and how many people start a page, apply or open a pledge. It sets no cookies and stores nothing in your browser, does not record your session, does not build a profile of you, and never receives your name, email or pledge details. Web addresses are stripped of everything except the path and campaign tags before they are sent. Requests go to our own domain (useshift.app/ingest) and are forwarded to PostHog. There are no advertising trackers, and fonts load from our own domain rather than from a third party.
The athlete pages currently shown on the site are examples written by SHIFT to show the format. The people and backers named on them are fictional and no real person's data appears on them.
What we will collect when pledging opens
- Athletes. Account email, name, town, the race, goal and story you choose to publish, your chosen charity, your funding target, and, if you switch on personal funding, the list of costs you publish. To receive payouts you will verify your identity and bank details directly with Stripe. SHIFT does not see or store your identity documents or full bank details.
- Backers. Name, email address, optional message, pledge amount, how you split it between the athlete and the charity, and whether the athlete's share depends on the goal being met. Your card is saved with Stripe at the time of pledging and charged after race day. SHIFT never receives or stores your card number. We keep only the Stripe reference needed to take the payment you authorised.
- Race results. The athlete's official finish time and a link to the public results page, used to settle pledges that depend on the goal.
What is public
An athlete page is public by design: the athlete's name, town, race, goal, story, charity, target and total raised. For each backer the page shows the name you enter, your message, your pledge amount and whether it depends on the goal. It never shows your email address or any payment detail. If you would rather not appear under your own name, enter a name you are comfortable with.
Why we use it, and the legal basis
| Purpose | Data | Legal basis (UK GDPR) |
|---|---|---|
| Replying to a founding athlete application and setting up the page with you | Application details | Steps taken at your request before entering into a contract |
| Running athlete pages, taking pledges, paying out | Athlete, backer and result data | Performance of a contract |
| Receipts and messages about a pledge or a page | Name, email | Performance of a contract |
| Preventing fraud and abuse, keeping the service reliable | Logs, pledge records | Legitimate interests |
| Tax and accounting records | Payment records | Legal obligation |
We do not sell personal data. We do not add founding athlete applicants or backers to a marketing list. We will only send marketing email if you separately ask for it.
Who processes it for us
- Vercel: website hosting and request logs.
- Supabase: database and authentication, hosted in London (eu-west-2).
- Stripe (when pledging opens): card storage, payment processing, identity verification and payouts. Stripe is an independent controller for parts of this; see Stripe's own privacy policy.
- Email provider: receipts and service messages.
- Your chosen charity (when pledging opens): receives the money. We pass on a backer's name and contact details only if that backer asks us to, for example to allow a Gift Aid claim.
Some of these providers process data outside the United Kingdom, including in the United States. Where they do, the transfer is covered by the provider's UK-approved safeguards such as the UK International Data Transfer Addendum or the UK Extension to the EU-US Data Privacy Framework.
How long we keep it
- Founding athlete applications: until your page is set up, or for 12 months if it never is, then deleted. Ask sooner and we will delete it sooner.
- Athlete pages: while the page is live and for 12 months after the race so backers can see the outcome, then removed from public view on request or archived.
- Pledge and payment records: 6 years after the end of the financial year they fall in, which is what UK tax and accounting law requires.
- Hosting and database logs: normally up to 7 days on Supabase and for the short period set by our Vercel plan, longer only for a specific security investigation.
Part 2: the SHIFT iOS app
This part describes the current SHIFT iOS app. SHIFT for iOS is a race-weekend activity, hydration and preparation app. The current App Store candidate uses email authentication and does not offer a connected-fitness-provider flow.
Information the app collects
- Account and profile information: email address, display name, role and account identifiers used for sign-up, sign-in, verification, account management and private crew features.
- Fitness information: activity type, duration, distance, pace or speed, calories when entered, workout notes and saved session history.
- Health and wellness information: hydration logs and user-entered recovery, readiness, nutrition or goal information where those controls are used.
- User content: goals, private crew or challenge setup content, workout notes, support reports and questions submitted to Ask Coach.
- Subscription information: Apple subscription product, purchase, restore and entitlement history linked to the signed-in SHIFT user identifier through RevenueCat. SHIFT never receives the user's payment-card details.
- Security and reliability information: Supabase-hosted authentication and API logs may record the user identifier, authentication action, timestamp, IP address, user agent, requested API route, response status and country-level network metadata. SHIFT uses this information for authentication, abuse prevention, troubleshooting and service reliability, not advertising.
Location and Device-Only Information
If you start a tracked Run, Ride or Walk and allow foreground location, SHIFT uses raw coordinates on the device to calculate distance, pace or speed and draw a private route preview. Raw coordinates are not uploaded, synced or shared in the current candidate; background location and live location sharing are not enabled. Only the resulting fitness values, such as distance and duration, may be saved to your SHIFT account.
Network requests can expose an IP address and country-level network metadata to SHIFT's hosting provider as described above. This is security and diagnostic logging, not the app's precise-location feature.
If you choose a profile photo, SHIFT resizes it and keeps it only inside the app on that device. The current candidate does not upload or share the photo. It is removed from that device when account-bound local data is cleared, the account is deleted, app storage is cleared or the app is uninstalled.
How the app uses information
SHIFT uses information to authenticate users, save private progress, show history and passport state, operate private crew features, prevent abuse, provide support, manage subscriptions and keep the service reliable. Health, fitness and user-entered goal information may also personalize the preparation suggestions that a user asks SHIFT to provide. RevenueCat uses the signed-in user identifier and purchase history for entitlement functionality, fraud prevention, customer history and subscription analytics. SHIFT does not sell personal data or use health, fitness, location or user content for advertising.
AI Features
Before the first Ask Coach request, SHIFT presents a point-of-use notice describing the data that will leave the device and asks for consent to the current notice. When a signed-in user then submits a question, SHIFT sends that question and a compact context containing recent SHIFT activity, hydration, goals and Cups state to OpenAI through a SHIFT server function. The request excludes the device-only profile photo, exact route coordinates and connected-provider data.
SHIFT requests that OpenAI not persist Responses API application state. OpenAI may still retain API content in abuse-monitoring logs for up to 30 days under its API data controls, or longer where legally required. If you do not submit Ask Coach, SHIFT does not send coaching context to OpenAI. Withdrawing Ask Coach consent in Settings blocks future AI requests; it cannot reverse provider retention that has already begun for an earlier request.
Service Providers and International Processing
- Supabase: authentication, database, private storage, security logs and server functions.
- RevenueCat and Apple: subscription product lookup, purchase, restore, entitlement, fraud prevention and subscription history.
- OpenAI: generation of a response only after a user submits Ask Coach under the current consent notice.
- Web hosting and email providers: delivery of public policy/support pages and support correspondence.
These providers may process data in the United Kingdom, European Economic Area, United States or other locations where they operate. SHIFT requires service providers acting for SHIFT to protect user data to standards at least equivalent to those described in this policy, subject to their contracts and applicable law, and does not authorize advertising or unrelated use of the data.
Retention and Deletion
- Account, profile, activity, hydration, private crew and user-entered content is kept while the account is active and is removed from live SHIFT account systems when in-app deletion completes, unless a specific legal obligation requires limited retention.
- Supabase-hosted authentication and API logs for the current production plan are normally available for up to 7 days. A security incident record extracted for investigation may be kept only as long as needed to resolve and document that incident or meet a legal obligation.
- Daily database backups may retain a deleted record for up to 7 days before rotation. A restoration process must reapply completed deletion requests before restored data is returned to service.
- OpenAI abuse-monitoring retention for an Ask Coach request may last up to 30 days as described above.
- Support correspondence is kept for up to 12 months after the request is resolved, unless a longer period is required for a dispute, fraud prevention or legal obligation.
- A completed deletion request may leave a minimal, de-identified status and timestamp record for up to 24 months so SHIFT can demonstrate completion; the completed record does not retain the account email or user identifier.
- Apple and payment-service records are controlled by those providers and may be retained for their legal, tax, fraud-prevention and platform obligations. Deleting SHIFT does not cancel an Apple subscription.
Your choices in the app
- Decline or revoke foreground location in iOS Settings and use the timer/manual passport path instead.
- Decline Ask Coach or withdraw Ask Coach consent in SHIFT Settings to stop future AI requests.
- Correct editable account information in the app, or contact support for access or correction help.
- Delete the account in SHIFT Settings. If you cannot sign in, use the instructions at useshift.app/delete-account.
- Clear phone-only data from Settings or remove the app to clear device-only information.
Part 3: your rights, children and contact
Your rights
Under UK data protection law you can ask us for a copy of your data, ask us to correct or delete it, ask us to restrict or stop using it, object to processing based on legitimate interests, and ask for your data in a portable format. Email sam@useshift.app and we will reply within one month. Payment records we are legally required to keep cannot be deleted early, but we will tell you exactly what is being kept and why.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. We would appreciate the chance to put it right first.
Children
SHIFT is not directed to children under 13. You must be 18 or over to pledge money or to receive payouts. A parent or guardian should review use of the SHIFT app by a minor, and a minor must not use Ask Coach without the consent required in their country and by the applicable AI-service terms.
Changes
When this policy changes we update the date at the top. If a change affects how we use data you have already given us, we will tell you before it takes effect.
Contact
SHIFT is the controller of the personal data described here. For privacy or support questions, contact sam@useshift.app.