Privacy Policy
Effective: May 25, 2026 · GDPR · CCPA · CPRA
Your privacy matters. This policy explains what data Shift collects, why we collect it, and the rights you have over it.
1. Introduction & Scope
Who we are
Shift, LLC ("Shift," "we," "us," or "our") operates the Shift mobile application and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use Shift.
This policy applies to all users of the Shift platform, including passengers, driver-partners, and visitors to our services, regardless of location. Where required by law, additional region-specific rights are described in the relevant sections below.
Applicability — GDPR (EEA/UK residents)
If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data. We process your data under the lawful bases described in Section 3 and you have the rights described in Section 6.
Applicability — CCPA (California residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you specific rights regarding your personal information. See Section 6 for a full description of your CCPA rights, including the right to opt out of the sale or sharing of your personal information.
Shift does not sell your personal information to third parties for monetary consideration.
2. Information We Collect
Information you provide directly
- Account registration: name, email address, phone number, date of birth, gender, profile photo
- Driver onboarding: Social Security Number (last 4 digits displayed only), driver's license, vehicle registration, proof of insurance, vehicle inspection report, background check consent
- Payment: credit/debit card details, bank account numbers and routing numbers (processed and stored securely via Stripe)
- Communications: messages sent through the app, support inquiries, ratings, and reviews
Location information
We collect precise GPS location data when the app is in use. For drivers, we collect location in the background while you are online (status: active) to enable ride matching and navigation. For passengers, we collect location to identify your pickup point and show nearby drivers.
You may disable location access through your device settings, but doing so will prevent core features of Shift from functioning.
Ride and transaction data
- Pickup and drop-off addresses
- Route taken (actual GPS path during the trip)
- Ride type, distance, duration, and fare
- Payment method used and transaction amounts
- Promo codes applied
- Tips given or received
- Ratings and feedback submitted after rides
Device and usage information
- Device type, operating system, and version
- Expo push notification token
- App version and session timestamps
- Crash reports and error logs
- IP address at time of login
- Interactions with in-app features (buttons tapped, screens visited)
Information from third parties
- Background check results from our screening partners (provided to us in summary form: pass/fail/flag)
- Payment verification signals from Stripe (e.g., card validity, fraud risk score)
- Location data enriched via mapping services (JAWG for map tiles, Google Maps for geocoding + routing)
- Event data from Ticketmaster used to display local event zones on the driver map
3. How We Use Your Information
To provide the service (Contract performance — GDPR Art. 6(1)(b))
- Match passengers with available driver-partners
- Calculate and display fares, surge pricing, and promotions
- Process payments and issue refunds
- Enable in-app navigation and live ride tracking
- Manage your account profile and ride history
- Send transactional push notifications (driver status, arrival alerts, ride completion)
For safety and security (Legitimate interest — GDPR Art. 6(1)(f))
- Conduct driver background checks and identity verification
- Detect and prevent fraud, account misuse, and prohibited conduct
- Monitor platform integrity (e.g., duplicate account detection, fare manipulation)
- Respond to safety incidents and law enforcement requests
- Maintain audit logs for dispute resolution
To improve our services (Legitimate interest — GDPR Art. 6(1)(f))
- Analyze aggregate usage patterns to improve matching algorithms and app performance
- Diagnose crashes and technical errors
- Test new features on subsets of users
- Conduct internal analytics on ride demand, pricing efficiency, and driver utilization
For marketing and communications (Consent — GDPR Art. 6(1)(a))
- Send promotional push notifications about deals, credits, and new features (only if you opt in via Settings)
- Send referral program updates
- Email newsletters and product announcements (you can unsubscribe at any time)
You can manage notification preferences in Menu → Settings at any time.
Legal compliance (Legal obligation — GDPR Art. 6(1)(c))
- Comply with tax reporting obligations (1099-NEC for driver earnings ≥ $600/year)
- Respond to valid legal process (subpoenas, court orders, regulatory requests)
- Enforce our Terms of Service
- Fulfill insurance and transportation network company (TNC) regulatory requirements in North Carolina
4. Sharing Your Information
Between passengers and drivers
When a ride is matched, we share limited profile information between the passenger and driver: first name, profile photo, rating, and vehicle details (make, model, color, plate). Phone numbers are never shared directly — all communication is routed through the app.
Service providers (sub-processors)
We share data with vendors who help us operate Shift. All sub-processors are bound by data processing agreements:
- Firebase / Google LLC — authentication, database, file storage, and analytics (USA)
- Google Maps Platform — geocoding, directions, and place autocomplete (USA)
- Stripe, Inc. — payment processing and driver payouts (USA)
- Expo — push notification delivery (USA)
- JAWG Maps — map tile rendering (France/EU)
- Ticketmaster — local event data for driver alerts (USA)
- Checkr / Persona — driver background checks (USA)
Legal and safety disclosures
We may disclose your information to law enforcement, government agencies, or courts when:
- Required by a valid legal process (subpoena, warrant, court order)
- Necessary to protect the safety of any person
- Required to prevent fraud or illegal activity
- Necessary to protect the rights and property of Shift
We will notify you of government data requests to the extent permitted by law.
Business transfers
In the event of a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred to the acquiring entity. We will provide notice via email or in-app notification before your information becomes subject to a different privacy policy.
We do not sell your personal information
Shift does not sell, rent, or trade your personal information to third parties for monetary consideration. We do not share personal information for cross-context behavioral advertising. This applies to all users, including California residents under the CCPA.
5. Data Retention
Retention periods by category
- Account profile data: retained while your account is active, plus 30 days after deletion request
- Ride history and transaction records: 7 years (required for tax and financial compliance)
- Driver documents (license, insurance, background check results): 5 years after driver deactivation (regulatory requirement)
- Location data from completed trips: 2 years
- Push notification tokens: until account deletion or token refresh
- Crash logs and error reports: 90 days
- Support communications: 3 years
Account deletion
When you request account deletion, we begin the deletion process within 30 days. Some data may be retained longer where required by law (e.g., tax records, fraud investigation records). Anonymized and aggregated data derived from your account may be retained indefinitely as it can no longer identify you.
To delete your account, use the in-app path: Menu → Settings → Delete Account. Alternatively, submit a request via our Delete Account request page.
Driver data after deactivation
Driver-specific data (SSN reference, background check results, vehicle records) is retained for 5 years after deactivation to comply with TNC regulatory requirements in North Carolina and to defend against legal claims arising from rides completed during the active period.
6. Your Privacy Rights
Rights for all users
Regardless of where you live, you may:
- Access the personal information we hold about you
- Correct inaccurate information via Menu → Personal Info
- Delete your account and personal data by contacting privacy@shift.app
- Opt out of marketing communications via Menu → Settings → Notifications
- Withdraw consent for optional data processing (marketing) at any time
GDPR rights (EEA and UK residents)
If you are in the EEA or UK, you have the following rights under GDPR:
- Right of Access (Art. 15) — request a copy of your personal data
- Right to Rectification (Art. 16) — correct inaccurate data
- Right to Erasure (Art. 17) — "right to be forgotten" (subject to legal retention obligations)
- Right to Restriction (Art. 18) — limit how we process your data
- Right to Data Portability (Art. 20) — receive your data in a machine-readable format
- Right to Object (Art. 21) — object to processing based on legitimate interests
- Rights related to automated decision-making (Art. 22)
To exercise any right, contact dpo@shift.app. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
CCPA rights (California residents)
If you are a California resident, you have the right to:
- Know — request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months
- Delete — request deletion of your personal information, subject to certain exceptions
- Correct — request correction of inaccurate personal information
- Opt Out — opt out of the sale or sharing of personal information (note: Shift does not sell your data)
- Non-Discrimination — we will not discriminate against you for exercising any CCPA right
- Limit Use of Sensitive Personal Information — limit our use of your SSN and precise geolocation to what is necessary to provide the service
To submit a CCPA request, contact privacy@shift.app or use the in-app request form. We will verify your identity before responding. Authorized agents may submit requests on your behalf with written proof of authorization.
How to submit a data request
Email privacy@shift.app with subject line "Privacy Request" and include:
- Your full name and email address on file
- The type of request (access / delete / correct / portability / opt-out)
- A description of the specific data or action requested
We will acknowledge your request within 10 business days and fulfill it within 45 days (extendable by an additional 45 days with notice for complex requests). We do not charge a fee for reasonable requests.
Shine the Light (California Civil Code § 1798.83)
California residents may request a list of third parties to whom we disclosed personal information for direct marketing purposes in the past year. Shift does not share personal information with third parties for their own direct marketing purposes, so no such list currently applies. To confirm or submit a request, contact privacy@shift.app.
7. Security
How we protect your data
- All data in transit is encrypted using TLS 1.2 or higher
- Firestore data is encrypted at rest by Google Cloud
- Payment card data is never stored on Shift servers — all card processing is handled by Stripe (PCI DSS Level 1 certified)
- SSNs are stored only as a reference (last 4 digits visible to driver); the full number is processed only during background check submission and not retained
- Access to production systems is restricted to authorized personnel and requires multi-factor authentication
Data breach response
In the event of a data breach affecting your personal information, we will:
- Notify affected users within 72 hours of discovery (as required by GDPR)
- Notify relevant supervisory authorities as required by applicable law
- Describe the nature of the breach, categories of data affected, and steps taken to mitigate harm
- Provide guidance on protective steps you can take
To report a security vulnerability, email security@shift.app.
Your responsibility
You are responsible for maintaining the confidentiality of your account credentials. Do not share your password or grant account access to others. Shift will never ask for your password via email, phone, or in-app message. If you suspect your account has been compromised, contact us immediately at privacy@shift.app.
8. Children's Privacy
Shift is not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account or provided personal information through Shift, please contact privacy@shift.app and we will delete the account and associated data within 30 days.
9. International Transfers
Cross-border data transfers
Shift is based in North Carolina, USA. If you use Shift from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country.
Safeguards for EEA/UK transfers
For transfers of personal data from the EEA or UK to the United States, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to our US-based sub-processors
- Adequacy decisions where applicable
- Binding Corporate Rules maintained by our cloud providers (Google, Stripe)
You may request a copy of the applicable transfer mechanisms by contacting dpo@shift.app.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Display a prominent in-app notice at least 30 days before the change takes effect
- Send an email notification to the address on your account
- Update the "Effective Date" at the top of this policy
For non-material changes (formatting, clarifications, typos), we will update the policy without prior notice. Continued use of Shift after the effective date of any change constitutes your acceptance of the revised policy.
Current version: May 25, 2026. Prior versions of this Privacy Policy are available upon request by emailing privacy@shift.app.
CCPA — Categories of Personal Information Collected
- Identifiers — Name, email, phone, IP address, device ID, push token
- Personal records — Date of birth, gender, profile photo
- Financial information — Payment card data (via Stripe), bank account info, transaction history
- Geolocation data — Precise real-time GPS location during trips, saved home/work addresses
- Commercial information — Ride history, purchase history, promo code usage
- Biometric identifiers — None collected directly (background check providers may process; we receive summary result only)
- Internet / network activity — App interactions, crash reports, session logs
- Professional / employment info — Driver's license, vehicle registration, insurance, SSN (drivers only)
- Sensitive personal info — Precise geolocation, SSN (drivers), financial account numbers
Contact
Privacy questions or data requests
General inquiries, CCPA requests, or GDPR rights: privacy@shift.app
EU/UK Data Protection Officer: dpo@shift.app
Security vulnerabilities: security@shift.app