Disco Shift ← Back to Disco Shift
Disco Shift · Your information

Privacy notice

Working draft · Version 2026-10-02-v2 · Prepared 2 October 2026

Draft — complete before collecting live user data. The controller’s identity, contact, supplier arrangements, retention periods and international-transfer details are not yet confirmed. This notice describes the current application and proposed purposes. It is not a completed assurance of compliance.

1. Who is responsible

The intended controller for Disco Shift account and marketplace data is [operator’s legal name, postal address and privacy email]. Contact [privacy contact; data protection officer only if appointed] about this notice or your rights. Businesses also use applicant and worker data for their own recruitment and engagement purposes and may be separate controllers; ask the Business for its own privacy information.

Acknowledging this notice records that it was presented to you. It does not waive your rights or provide blanket consent. Where a particular use requires consent, we must ask separately and explain how to withdraw it.

2. Information in the current app

You provide most data directly. Other users supply applications, decisions, hours, payment reports and reviews relating to you. Disco Shift calculates distances, eligibility results, fees and activity totals from those records. Please do not put health details, identity documents, bank credentials or other unnecessary sensitive information in profiles, reviews or free-text payment references. The current app does not provide a verified identity-document collection process.

3. Purposes and proposed lawful bases

The operator must confirm the following bases against its actual role before launch. Necessary account, application, booking and fee administration is proposed on the basis of performing our contract with the individual account holder or taking requested steps before that contract. Where an individual is a representative of a corporate Business, the proposed basis is legitimate interests in administering that business relationship, subject to a balancing assessment.

Proposed legitimate interests also include securing the service, preventing misuse, maintaining reliable records, handling complaints and enabling relevant profile and review information. These interests must be balanced against your rights, especially for children, public photos, cancellation metrics and reputation data. Information required for a specific legal record-keeping, tax or regulatory duty would be processed to comply with that identified legal obligation. We must not label every record as legally required without identifying a duty.

Birth dates are used to compare a Professional’s age on the shift date with configured eligibility rules. Exact postcode data is used to validate location and calculate distance. The operator must document the necessity and lawful basis for these checks and consider less intrusive alternatives. Marketing consent, advertising tracking and sensitive-data processing are not authorised by agreement to the Terms.

You can omit optional profile text, a photo and optional phone details. Account credentials and role are necessary for account use; missing location or date-of-birth information can prevent relevant location or application functions. Required fields are indicated in the forms.

4. Who can see what

Business accounts can view Professional profiles; Professionals can view Business profiles. Reviews are accessible to signed-in members under the current database rules. Profile information and aggregate metrics should therefore be treated as marketplace-visible, not private notes. Uploaded profile photos are stored in a public bucket: anyone with a file URL can access the image. Do not upload an image you need to keep private.

Public open adverts can be viewed without signing in. Trusted Pros adverts have restricted access based on that Business’s team membership and the participants’ access rights. A Professional’s application and completion/payment records are available to that Professional and the relevant Business through the applicable database permissions.

A Professional’s stored birth date and personal postcode are kept in owner-access tables and are not shown on the marketplace profile. Server functions use them for eligibility or distance checks. The Business can request a Professional’s email and optional phone through Disco Shift once that Business has approved the application. Sharing these details enables direct coordination; a recipient may retain a lawful copy outside Disco Shift. This does not make the Business’s separate processing subject to Disco Shift’s exclusive control.

Disco Shift’s authorised administrators and service providers may access information when needed to operate, support or secure the service. Owner-only database rules describe access by other marketplace accounts, not a promise that service administrators cannot access data. Necessary disclosures may also be made to professional advisers, regulators or courts where legally justified.

5. Suppliers, browser storage and transfers

The current app uses Supabase for authentication, database and photo storage. Disco Shift’s current payment design is direct payment: the Business pays the Professional outside Disco Shift, and Disco Shift separately invoices the Business for its service fee. The app can record the parties’ payment reports and references; it does not process, hold, transfer or verify wage payments. Disco Shift does not currently send payment receipts through an integrated payment processor. It sends entered postcodes directly from your browser to Postcodes.io for validation and coordinates; that service consequently receives the postcode and ordinary network request information, such as your IP address. The app also loads code from esm.sh and fonts from Google Fonts, which receive network requests. The website hosting provider also handles requests. [Confirm contracting entities, hosting region, processor terms, provider privacy links, subprocessors and any additional operational tools.]

The browser stores configured Supabase connection settings and authentication/session information so the app can connect and maintain sign-in. Browser storage is not confined to cookies. The reviewed application code has no added advertising or analytics tracker, but deployed hosting, provider behavior and any later integrations require an actual storage and network audit. Clearing browser storage may remove settings or sign you out. Sign out on shared devices.

Printable Professional invoices include information you edit in the browser, such as payment instructions. The invoice is printed or saved as a PDF for the Professional to send to the Business; Disco Shift does not send it or process its payment. The current invoice editor does not submit those extra editable fields to the Disco Shift database. A printed or saved PDF and anything you send to the Business become separate copies under your control and the recipient’s handling.

International transfers: [Identify where each supplier stores and accesses personal data, any transfers outside the UK, the applicable adequacy decision or safeguards, and how users can obtain a copy of relevant safeguards.] We do not claim that all data stays in the UK. Supplier contracts and transfer assessments must be completed before live use.

6. Automated checks and profile measures

Disco Shift automatically checks whether the supplied date of birth meets the shift’s configured age rule at the shift start date. It can block an application if the age rule is not met, a required date of birth is missing, an approved booking overlaps, capacity is filled, or Trusted Pros access is absent. A Business makes the approval decision for an eligible application. These checks are not identity verification and do not establish that the work arrangement is lawful.

Profiles display calculations from recorded completions, reviews and late cancellations. An attendance-related percentage is based on confirmed completions and recorded late cancellations, not a separate verified no-show register. These records can influence a Business’s decision. To correct data or challenge a check, contact [monitored support/privacy channel]. [Before launch, establish and publish a human review process and assess the automated-decision rules applicable to these employment-related checks.]

7. How long information is kept

Records should be kept only as long as needed for the stated purpose, applicable legal duties and proportionate handling of claims, then deleted or anonymised. Account closure may require retention of selected invoices or engagement records, but does not justify retaining every profile field indefinitely.

[Complete a retention schedule for accounts, unsuccessful applications, booked shifts, reviews, cancellations, private birth dates/locations, consent records, invoices, security logs and backups. State periods or specific criteria and implement deletion jobs.] The current code does not implement a full timed deletion or self-service account-erasure workflow; no automatic deletion period is promised by this draft.

8. Your rights and complaints

Depending on the processing and applicable law, you can request access to your data, correction, erasure, restriction or portability, and object to processing based on legitimate interests. If a use relies on consent, you can withdraw it without affecting the lawfulness of earlier processing. You may have rights concerning significant automated decisions, including challenging a decision and requesting human involvement. Rights have legal exceptions; we must explain any refusal or necessary retention.

Contact [privacy email/address]. We may need proportionate information to verify a request. You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. You do not need Disco Shift’s permission to contact the ICO.

9. Young users and changes

The current app includes age-based shift checks, but Disco Shift’s minimum account age and arrangements for under-18s remain [to be decided before launch]. Those checks are not a complete safeguarding or child-employment system. Children’s privacy, age assurance and the appropriateness of public photos, reviews and location processing require a specific assessment before young users are admitted.

We will date and version changes to this notice and bring material changes to users’ attention through an available account or contact channel. Acknowledgment of an update is not a substitute for obtaining consent where the law requires it. This draft must be updated to reflect the completed operational arrangements before launch.