Privacy Policy

Last updated: July 26, 2026

1. About Schedulizer and contact

Schedulizer is a workforce scheduling service operated from Slovenia, European Union. This Privacy Policy explains how personal data is processed when you use Schedulizer.

For privacy-related questions or requests, contact privacy@schedulizer.eu.

2. Scope

This policy applies to your use of Schedulizer, including account access, organization and team management, scheduling, availability, shift swaps, notifications, settings, and related functionality provided through the Schedulizer web application.

3. Roles and responsibilities

Organizations using Schedulizer determine much of the workforce information they enter and manage in the service, such as team member names, contact details, schedules, and related workforce records.

For organization-controlled workforce data, the organization is generally responsible for determining why and how that data is used, while Schedulizer provides the platform that processes the data on behalf of the organization.

Schedulizer may separately determine processing that is necessary to operate accounts, security, infrastructure, service communications, and its own service administration.

If you have questions about workforce records controlled by your employer or organization, you should normally contact that organization first. You may also contact privacy@schedulizer.eu regarding Schedulizer privacy matters.

4. Data we collect

The data processed through Schedulizer depends on how you use the service. It may include:

Account and profile information

  • Name, email address, and authentication identifiers
  • Phone number (where provided or required for team coordination)
  • Avatar image (optional; stored as image data associated with your profile or employee record)
  • Optional birthday day and month (no birth year), if you choose to share it with coworkers in your organization
  • Role, organization membership, and account preferences (such as language, accessibility, and display settings)

Organization and workforce information

  • Organization and location configuration managed by administrators
  • Employee or team member records, including display name, position, employment type, and assignment permissions
  • Hourly rate and administrator notes where your organization chooses to use those fields
  • Invitation information, including pending or accepted invites

Scheduling and activity information

  • Shifts, schedules, availability submissions, and published schedule data
  • Shift swap requests, reasons, and outcomes
  • In-app notifications related to scheduling activity

Authentication and session information

  • Sign-in method (email and password and/or Google sign-in)
  • Session and authentication tokens managed through Supabase Auth

Technical and security information

  • Server and application logs used for security, abuse prevention, diagnostics, and reliability
  • Rate-limiting counters and related metadata (via Upstash)
  • Error and diagnostic information (via Sentry)

Optional analytics (consent-based)

  • Product usage events (for example, schedule published or shift created) via PostHog, when enabled and consented
  • Aggregated page and performance metrics via Vercel Analytics and Vercel Speed Insights, when consented
  • Session recording via PostHog, only when analytics consent is enabled

5. Internal visibility within organizations

Authorized users within the same organization may see information needed for scheduling and team coordination, such as names, shifts, availability, positions, and related workforce details.

Employee phone numbers may be visible to authorized coworkers within the same organization through the scheduling interface. This information is intended for internal workforce coordination and is not made publicly accessible through Schedulizer.

If you optionally add your birthday (day and month only) and enable visibility, authorized coworkers in the same organization may see a birthday indicator in the schedule on that calendar day. Birth year is not collected for this feature. You can hide or remove your birthday at any time in profile settings.

6. Purposes and legal bases

Schedulizer processes personal data for purposes that may include:

  • Providing and operating the service, including accounts, organizations, scheduling, swaps, and notifications
  • Authenticating users and maintaining sessions
  • Enabling organizations to manage workforce scheduling and related team coordination
  • Operating, securing, maintaining, and improving the reliability of the platform
  • Detecting abuse, enforcing rate limits, and protecting users and the service
  • Sending transactional communications necessary to operate accounts and scheduling
  • Collecting diagnostics and error information to investigate and resolve issues
  • Understanding product usage through optional analytics, where you have given consent

Where the GDPR applies, processing may rely on one or more legal bases depending on the context, such as performance of a contract or steps prior to entering a contract, compliance with legal obligations, legitimate interests in operating and securing the service, and consent for optional analytics. The appropriate basis depends on the specific processing activity and your relationship to Schedulizer or your organization.

7. Google sign-in

You may sign in to Schedulizer using Google. If you choose this option, Google authenticates your identity and Schedulizer receives the authentication information needed to create or access your account through Supabase Auth, such as your email address and basic profile information made available by Google for sign-in purposes.

Google's processing is subject to Google's own terms and privacy policies. Schedulizer uses Google sign-in only for authentication and account access, not for marketing communications.

8. Transactional email

Schedulizer may send transactional emails necessary to operate the service, such as:

  • Employee or team invitations
  • Password reset messages
  • Magic-link login messages, where used
  • Welcome messages after account creation
  • Shift-related invitations or notifications, where used

These messages are service communications. They are not marketing newsletters. Schedulizer does not currently send promotional marketing email through the application.

9. Service providers

Schedulizer uses service providers to host, operate, secure, and support the application. Relevant providers may include:

  • Supabase — authentication and database services
  • Vercel — application hosting and infrastructure
  • Google — optional OAuth sign-in authentication
  • Resend — transactional email delivery
  • Sentry — error monitoring and diagnostics
  • Upstash — rate limiting and security-related infrastructure
  • PostHog — optional, consent-gated product analytics and session recording when enabled
  • Vercel Analytics / Speed Insights — optional, consent-gated analytics and performance telemetry when enabled
  • Better Stack — operational uptime monitoring of service health endpoints; this monitoring is not intended to collect workforce scheduling datasets

These providers process data as needed to deliver their services to Schedulizer. Service providers may process data in locations determined by their infrastructure and contractual arrangements, subject to applicable law and the safeguards available for international processing.

10. Retention

Information is retained for as long as needed to provide an active account, organization, or related service functionality, unless a longer retention period is required or permitted by applicable law.

You may request account deletion through the implemented account erasure flow described below. Deletion or anonymization may occur through that process, but some information may remain where necessary for security, legal obligations, dispute handling, fraud prevention, or system integrity.

Service providers may retain logs and diagnostic information according to their own applicable retention practices. Backup copies may remain temporarily until normal backup rotation removes them; Schedulizer does not represent that all backup copies are deleted immediately upon account erasure.

11. Your data rights

Depending on applicable data-protection law, you may have rights such as access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent where processing is based on consent.

Schedulizer provides privacy controls in Settings, including:

  • Download my data — export relevant personal data associated with your account in JSON format
  • Delete my account — permanently remove sign-in access and anonymize personal information through the implemented erasure process
  • Analytics preferences — enable or disable optional analytics at any time

Account deletion may be subject to eligibility restrictions needed to preserve organization and scheduling integrity, including restrictions that apply when you are the sole active administrator of an organization or assigned to future shifts. Where appropriate, deletion may anonymize records rather than physically remove every historical relational record needed for organizational scheduling history.

You may also contact privacy@schedulizer.eu to exercise applicable rights or ask questions about your data.

If you believe your data-protection rights have been infringed, you may have the right to lodge a complaint with a competent supervisory authority. In Slovenia, this is generally the Informacijski pooblaščenec (Information Commissioner).

12. Cookies and local storage

Necessary mechanisms

  • Supabase session cookies — authentication and session refresh
  • mvp_locale, mvp_dyslexia, mvp_dark — language and accessibility preferences (also mirrored in localStorage)
  • schedulizer_consent — stores your privacy choice (policy version and analytics flag only; no personal content)
  • schedulizer-consent (localStorage) — same consent record for the client

Optional analytics (consent required)

PostHog identifiers, analytics persistence, Vercel Analytics, and Speed Insights are used only after you opt in through the in-app consent banner or Privacy settings. Session recording through PostHog is active only when analytics consent is enabled.

Functional storage

  • UI dismiss flags (for example, add-to-home banner preferences)
  • Admin assignment method preference (localStorage)

13. Security

Schedulizer uses technical and organizational measures intended to protect personal data, including encrypted transport (HTTPS), access controls, row-level security in the database, and rate limiting. No method of transmission or storage is completely secure, and Schedulizer cannot guarantee absolute security.

14. Younger workers and workforce context

Schedulizer is a workforce scheduling service used by organizations to coordinate teams. Organizations may include students, secondary-school students, younger workers, temporary workers, and other team members.

Schedulizer is not directed at children as a consumer audience. Organizations are responsible for ensuring that their use of personal data, including information concerning younger workers, has an appropriate lawful basis and complies with applicable employment and data-protection law.

15. Automated decision-making

Schedulizer currently does not use solely automated decision-making that produces legal or similarly significant effects concerning individuals.

16. Changes to this policy

This policy may be updated as the service changes. Material changes will be communicated through an appropriate service channel where required by applicable law. If the analytics consent policy version changes, you may be asked to make your privacy choice again.

17. Contact

Privacy inquiries and data-protection requests: privacy@schedulizer.eu

Privacy Policy — Schedulizer