Privacy Policy
Last updated
This service is in alpha
Who is responsible for your data
The data controller for Consoris is CONTROLLER LEGAL NAME, at REGISTERED ADDRESSCOMPANY REGISTRATION NUMBER (if a company). You can reach us about anything on this page at support@consoris.app.
What we hold
Everything below is data you enter yourself, or that is required to run your account. We do not buy data about you, and we do not track you across other websites.
- Account — your email address. Your password is handled and stored, hashed, by our authentication provider; it is never visible to us.
- Profile — first name, last name and phone number. All three are optional and can be left blank.
- Settings — display currency, how dates, times, durations and amounts are shown and which day your week starts on (preferences, not personal data), the country you work in (optional — it only unlocks country-specific features such as the Belgian student-hours counter), your maximum daily and weekly hour limits, and your notification preferences: whether you want the weekly recap email, the unlogged-shift reminder email and the shift-starting-soon push notification (each off unless you turn it on), the time zone your browser reported when you did, so the recap covers the right week and the reminders arrive at the right local hour, which panels you switched off on the Analytics page, and answers you asked the app to remember (“Don’t ask again” — for example, what clearing a shift’s hourly rate should mean).
- Push devices — only if you turn the shift-starting-soon notification on: for each browser you allow it in, the delivery address its push service issued (a long URL that identifies only that browser), the two keys that encrypt messages to it, and its browser name. Turning the notification off deletes them all; you can also remove a single browser from the browser’s own site settings.
- Calendar connections — only if you turn one on. For the calendar feed: a fingerprint of its private link (never the link itself), the time zone your browser reported and when your calendar app last fetched it. For Google Calendar sync: the credential Google issues (encrypted), the permissions you granted, the email address of the Google account you connected (so Settings can show which account it is), the calendar you chose (its Google id, and its name when Consoris created it), the time zone your browser reported when you connected, and the ids of the events Consoris wrote there, so it can update or remove them later. Turning the feed off or disconnecting deletes them.
- Workplaces — name, optional address, hourly pay, break rules, meal voucher flag, shift templates, your pay-rate history, and your contract history (contract type and start/end dates).
- Shifts — date, start and end time, break length, overtime, tips, any pay premiums you enter (amount, whether flat or percentage, and the label you give them), your free-text comments, whether the shift was worked, and if not, the reason you selected plus any comment you added. Also the tags you assign, the hourly rate recorded at the time, and the calculated duration and estimated pay.
- Goals and tags — the targets and labels you create.
- Technical — a login token stored in your browser, and your interface preferences (see Cookies and local storage below).
Health-related information
Why we hold it, and on what legal basis
- To provide the service (performance of a contract) — your shifts, workplaces and settings exist so the app can show your schedule and calculate your earnings. Without them there is no product.
- To keep the service secure and working (legitimate interests) — authentication, and diagnosing crashes and errors.
- To understand whether the product works (legitimate interests) — we occasionally compute anonymous, aggregate usage statistics from our own database: counts like “how many accounts logged a shift this week”, never individual profiles, never a list of what you did. The queries produce totals only, are run by hand, and both they and their results are recorded in our repository — and we’ll share them with anyone who asks, so the “aggregate only” claim is checkable, not just asserted.
Who else can see it
Consoris is a single-user tool: no other user can see your data. We use a small number of service providers to run it, each of which processes data only on our instructions:
- Supabase — database, authentication, the application’s own API and account deletion. Your data is stored in the EU (Ireland) and processed in the EU too. Access is restricted at the database level so that a signed-in account can only ever read or write its own rows.
- Brevo — delivers the emails your account needs: confirming your address when you sign up, resetting your password and, only if your account goes unused for 22 months, the two reminders before it is deleted (see How long we keep it). If you turn on the weekly recap or the unlogged-shift reminder (both off by default, in Profile → Notifications), Brevo also delivers those emails — the recap every Monday, the reminder at 09:00 the morning after a shift you haven't logged. To deliver them, Brevo (an EU-based email provider) processes your email address and the content of those messages: for account emails, only the confirmation or reset link; for the recap, last week's hours and earnings per workplace, your student-hours position if the counter is on, and how many past shifts still need a decision; for the reminder, the date, times and workplace name of yesterday's unlogged shifts — never what they paid; for the deletion reminders, when your account was last used and the date it would be deleted. Nothing else you enter in the app is sent to Brevo. The recap and the reminder each have a one-click unsubscribe; the deletion reminders don’t, because they are about your account itself.
- Vercel — hosts and serves the application to your browser. Vercel also gives us anonymous usage and performance statistics: which pages are visited and how fast they load, collected without cookies by a script served from our own domain. Visits are counted with a salted hash that cannot identify you and is discarded within a day, so you cannot be followed across sites, or even across two days on this one. What we see is aggregated counts — never your IP address, and never anything you entered into the app. If your browser sends the Do Not Track or Global Privacy Control signal, we don’t measure your visit at all.
- GitHub — stores our nightly backup. So that your records can be recovered if something goes wrong, a complete copy of the database is taken once a night, kept for 14 days, and then deleted. The copy is encrypted before it leaves our systems, with a key GitHub does not hold, so GitHub cannot read what is in it. GitHub keeps that encrypted copy in the United States, under its EU-US Data Privacy Framework certification and the European Commission’s standard contractual clauses. Nothing you do in the app sends anything to GitHub.
- Sentry — when error monitoring is enabled, technical details of crashes (error message, stack trace, browser, which environment) are sent so we can fix them. It is configured not to attach personal information, and we do not send your shifts, earnings or profile. If you use Send feedback, whatever you choose to write — and a screenshot only if you attach one — goes to Sentry too; nothing is captured beyond what you submit.
- Photon (Komoot) — address suggestions while you type a workplace’s street, from OpenStreetMap data. What it receives is the characters you type into that one field — nothing else: no name, no account identifier, no other part of the app. It sees your IP address the way any website you visit does. The address fields work without it, so nothing is sent unless you type there.
That is the complete list. In particular, the app loads no fonts, scripts or assets from third-party servers — everything it needs is served from our own domain, so no one else learns your IP address from your using Consoris — except Photon, above, and only while you type in the address field. We do not sell your data, share it with advertisers, or use it to train machine-learning models.
Your browser’s push service — only if you turn the notification on. The shift-starting-soon notification is delivered through the push service your browser belongs to (Google’s for Chrome and Android, Mozilla’s for Firefox, Apple’s for Safari, Microsoft’s for Edge). What we hand that service is an encrypted message only your browser can open — the service sees that a message arrived for your browser, and when, but not what it says. What the message says, once your browser decrypts it: the workplace name and the start and end time of the shift — never your pay or tips. The push service operates under its privacy policy, which may include processing outside the EU. Nothing is sent unless the notification is on.
Your calendar app — only if you turn the feed on. The optional calendar feed gives you a private link your calendar app (Google Calendar, Apple Calendar, Outlook, …) fetches on its own schedule. Whoever runs that calendar then receives your shift times, workplace names and addresses — never your pay or tips — and handles them under their privacy policy, which may include processing outside the EU. When you create the link we also keep the time zone your browser reported, so the times land right in your calendar; it is stored with the link and goes when the link goes. You choose the calendar, you can regenerate the link at any time (the old one stops working immediately), and turning the feed off removes the link entirely. Anyone who has the link can read the feed, so treat it like a password.
Google Calendar — only if you connect it. Calendar sync (Settings → Calendar sync) asks Google, in a separate step, for permission. You choose where your shifts go: a calendar Consoris creates just for them (the default — we can then only touch that one calendar), or a calendar you already have, which requires the wider permission to write events on your calendars. Either way the request also asks to read the names of your calendars, meant for a calendar picker that hasn’t shipped; nothing is read with it today. It also asks for your Google account’s email address, and nothing else about you, so Settings can show which Google account is connected; that can differ from the address you sign in to Consoris with. From then on Consoris sends Google your shift times, workplace names and addresses — never your pay or tips — as events it creates, updates and deletes. It only ever works with the events it created itself. To tidy up leftovers — an event whose shift was deleted while Google couldn’t be reached, for example — it asks Google for its own events in a date range, and in a calendar you already had, Google sends back only the events Consoris created; your own never reach us. In the calendar Consoris created for you, it reads that one calendar’s events, so anything you add there yourself would pass through too; whatever isn’t one of its own events is dropped on the spot, never stored, shown or used. Google holds those events under its privacy policy, which may include processing outside the EU. We keep the credential Google gives us encrypted, in the EU, and use it for nothing else; Disconnect revokes it at Google and deletes it here (events already in your calendar stay until you remove them). If you sign in with Google, Google tells us your email address and name so we can open your account — nothing more is requested or stored from Google at sign-in.
Consoris’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: it serves the calendar sync you turned on and nothing else, and it is never sold or used for advertising.
How long we keep it
For as long as your account exists. You can delete individual shifts and workplaces at any time. Deleting your account, from the Profile page, removes your login and all associated records — shifts, workplaces, goals, tags, push devices and profile — from the live database immediately. Deletion is permanent and we cannot undo it, so export anything you want to keep first.
If you stop using Consoris, we don’t keep your data forever: an account with no sign-in and no change to its data for 24 months is deleted, exactly as if you had deleted it yourself. We email you twice before that, at 22 and 23 months, with a one-click link to keep your account and a link to export your shifts. Those two emails are sent even if you turned our other emails off, and an account is never deleted unless both were sent. An account whose email address was never confirmed is deleted after 30 days, without an email — there is no confirmed address to write to.
One exception, so it doesn’t surprise you: the nightly backup described above still contains a copy of your data for up to 14 days after you delete. We never read those backups except to recover from a disaster, and if we ever do restore one, we re-apply any deletions made since it was taken. After 14 days the last copy is gone.
Your rights
If you are in the UK or EU you have the right to access your data, correct it, delete it, receive a portable copy, restrict or object to how we use it, and withdraw consent where we rely on it. Most of these you can exercise yourself, without asking us:
- Access and portability — the Shifts page exports your records as a CSV file.
- Correction — edit any shift, workplace or profile field in the app.
- Erasure — delete individual records, or your whole account from the Profile page.
For anything else, contact support@consoris.app. You also have the right to complain to your local data protection authority (SUPERVISORY AUTHORITY FOR YOUR JURISDICTION).
Cookies and local storage
Consoris sets no advertising or analytics cookies — usage statistics are measured without cookies (see Who else can see it). We store only what is needed to keep you signed in and remember how you like the interface:
- Your login session — kept in your browser. If you tick “Remember me” it persists until you sign out; if you do not, it is cleared when you close the tab.
- Interface preferences — dark mode, whether the sidebar is collapsed, your calendar view, whether shifts are grouped, and whether you dismissed the onboarding checklist. These never leave your browser.
Children
Consoris is intended for people in work and is not directed at children under 16. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If we change how we handle your data we will update this page and its date. For changes that materially affect you, we will tell you in the app or by email.
Contact
Questions, requests or complaints: support@consoris.app.