Privacy Policy

    Last updated: April 24, 2026

    1. Introduction

    policyshift ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at policyshift.io and any associated services.

    2. Information We Collect

    We collect information that you provide directly to us, including:

    • Account information (name, email address, company name)
    • Company policy documents you upload or create
    • Employee information for policy distribution and acknowledgement tracking
    • Billing information processed securely through Stripe
    • Communications you send to us (support requests, feedback)

    We also automatically collect certain information when you use our platform, including device information, IP address, browser type, usage patterns, and business visitor identification signals through analytics and visitor intelligence tools such as Snitcher and Leadfeeder, where you have consented to those tools. This may include inferring the company name and business address associated with a visit from the visitor's IP address.

    3. How We Use Your Information

    We use the information we collect to:

    • Provide, maintain, and improve our services
    • Process transactions and manage your account
    • Send policy updates, acknowledgement requests, and compliance alerts
    • Respond to your enquiries and provide customer support
    • Monitor and analyse usage trends to improve user experience
    • Detect, prevent, and address technical issues and security threats
    • Comply with legal obligations

    4. Data Sharing and Disclosure

    We do not sell your personal information. We may share information with:

    • Service providers who assist in operating our platform and website operations (e.g., AWS for hosting, Stripe for payments, Cloudflare for security, and Snitcher and Leadfeeder for business visitor identification where consented)
    • Within your organisation as required for policy management functionality
    • Law enforcement or regulatory bodies when required by law
    • In connection with a merger, acquisition, or sale of assets

    5. Data Security

    We implement appropriate technical and organisational measures to protect your data, including encryption at rest and in transit, role-based access controls, and regular security assessments. For full details on our security practices, please visit our Security page.

    6. Data Retention

    We retain your personal information for as long as your account is active or as needed to provide our services. When you close your account, we will delete or anonymise your data within 90 days, except where retention is required by law or for legitimate business purposes such as audit trails.

    7. Your Rights

    Under applicable data protection laws (including UK GDPR), you have the right to:

    • Access the personal data we hold about you
    • Request correction of inaccurate data
    • Request deletion of your data
    • Object to or restrict processing of your data
    • Request data portability
    • Withdraw consent at any time

    To exercise any of these rights, contact us at [email protected].

    8. International Transfers

    Our services are hosted on AWS infrastructure. Where data is processed outside the UK or EEA, we ensure appropriate safeguards are in place in accordance with applicable data protection legislation.

    9. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date.

    10. Contact Us

    If you have any questions about this Privacy Policy, please contact us at [email protected].