Security
Last updated: June 28, 2026
Shops trust ShiftDesk with their operations and their customers’ records. Here’s how we protect that data. Security is built into the architecture, not bolted on.
Per-tenant isolation
ShiftDesk is multi-tenant by design. Every record is scoped to a tenant and shop, enforced in the database with row-level security (RLS) so one shop can never see another’s data.
Authentication & access
Sign-in uses scoped JWT authentication over secure cookies. Access is role-based (admin, manager, advisor, tech, accountant), so staff only see what their role allows.
Encryption
All traffic is encrypted in transit over TLS (HTTPS). Data is encrypted at rest by our infrastructure providers.
Hosting & data location
The Service runs on managed cloud infrastructure in the United States. We don’t run our own servers.
Backups
The production database is backed up regularly, with restore procedures tested so data can be recovered.
Payments
Card payments are handled by Stripe (PCI DSS compliant). ShiftDesk never stores full card numbers — only limited billing metadata.
Monitoring
We run error monitoring and uptime monitoring so issues are caught and addressed quickly.
Your data is yours
You own your data. It’s available to export from the app, and we never sell it. See our Privacy Policy.
Subprocessors
We rely on a small set of vetted providers — for cloud hosting, database and authentication, email delivery, payment processing (Stripe), AI features, and error monitoring. Each is bound by contract to protect your data and use it only to perform its function. A current subprocessor list is available to customers on request; see our Privacy Policy.
Responsible disclosure
If you believe you’ve found a security vulnerability, please report it to support@shiftdesk.ai. We appreciate responsible disclosure and will work with you to verify and address valid reports.