Back to app

Last updated: July 6, 2026

Privacy and cookie notice

This notice explains what personal data we process when you use EasyTurni to create accounts, manage organizations, plan shifts, and receive operational communications.

1. Controller and contacts

EasyTurni and the entity operating the service act as controller for data collected through the platform. Privacy contact: privacy@easyturni.app. Before production, replace this contact with the controller's official legal and privacy details if different.

2. Data we process

  • Account data: email, display name, role, organization, invite status, and consent metadata.
  • Scheduling data: locations, roles, availability, shifts, assignments, swap requests, rules, and calendar preferences.
  • Administrative data: organization settings, invite codes, and any compensation or payroll data entered by owners.
  • Technical and security data: session identifiers, IP address, application logs, device/browser, language, and local preferences.
  • Communication data: transactional emails, shift notifications, support requests, and service messages.
  • Analytics data: pseudonymous usage events through PostHog only after analytics cookie consent.

3. Purposes and lawful bases

  • Account creation, authentication, organizations, and invites: performance of a contract or pre-contractual steps.
  • Shift planning, availability, operational notifications, and dashboards: performance of the requested service.
  • Security, abuse prevention, continuity, and debugging: legitimate interest in protecting the platform and users.
  • Tax, accounting, or authority requests: legal obligation where applicable.
  • Analytics, product improvement, and non-operational communications: consent, which can be withdrawn at any time.

4. Cookies and similar technologies

  • Necessary technical cookies and storage support login, Supabase sessions, language, active organization, active calendar, and security. They are required for the service and do not require prior consent.
  • PostHog analytics cookies or storage are disabled until you choose Accept in the banner. If you choose Reject, you can still use the service.
  • The cookie choice is stored as a technical preference for up to 6 months or until this notice version changes. Cookie version: 2026-07-06.
  • You can change your choice by clearing site data in your browser; the banner will be shown again on the next visit.

5. Retention

  • Account and organization data: for the account lifetime and up to 24 months after closure, deletion, or inactivity, unless disputes or legal obligations require longer retention.
  • Shifts, availability, assignments, and operational requests: for the organization lifetime and up to 24 months after organization deletion, unless specific settings or obligations apply.
  • Payroll, compensation, or administrative records: up to 10 years when needed for accounting, tax, or legal defense purposes.
  • Technical and security logs: normally up to 12 months, unless abuse, incident investigation, or legal obligations require longer retention.
  • Operational email and support data: up to 24 months after ticket or account closure, unless further obligations apply.
  • Backups: up to 90 days before ordinary overwrite.
  • Analytics: up to 14 months in pseudonymous form; aggregate non-identifying metrics may be retained longer.

6. Recipients and providers

  • Owners and authorized members of your organization can access data needed for scheduling.
  • Supabase provides authentication and database services.
  • PostHog provides analytics and feedback according to your choices.
  • Resend or equivalent providers send transactional emails.
  • Hosting, logging, email, and infrastructure providers may process data as processors.

7. Transfers outside the EEA

Where a provider processes data outside the European Economic Area, we use GDPR safeguards such as adequacy decisions, standard contractual clauses, or proportionate supplementary measures.

8. Your rights

You can request access, rectification, erasure, restriction, portability, objection, and withdrawal of consent for processing based on consent. You may also lodge a complaint with your competent data protection authority.

9. Security

We use authentication, organization-based access control, encryption in transit, passwords handled by the auth provider, application logs, and data minimization. No measure is absolute, but we work to reduce unauthorized access, loss, and misuse.

10. Children

The service is intended for work and organizational use. It is not intended for children under 16 without appropriate authorization.

11. Updates

We may update this notice for legal, technical, or organizational changes. Privacy version: 2026-07-06. For material changes, we will show a new notice or request renewed acknowledgement.

Cookies and privacy

We use necessary technical cookies and, only with your consent, analytics to improve EasyTurni. Read the notice