Opening JumpShift…
Opening JumpShift…

What we collect, why, how long we keep it, and the control you have — in plain language. Read it with the JumpShift terms.
JumpShift is operated by Vereus Ltd (“JumpShift”, “we”, “us”), registered in Scotland, company number SC839263. Registered office: Office 19, Rosyth Business Centre, 16 Cromarty Campus, Rosyth, Fife, Scotland, KY11 2YB. Vereus Ltd is the data controller for the personal data described in this notice — you can reach the data controller at support@jumpshift.co.uk.
JumpShift is a notice board for same-day hospitality shift cover in Edinburgh. The employer engages and pays the Shifter directly — JumpShift never handles wages.
Account data: your email address and sign-in records. Sign-in is by a short-lived one-time code sent to your email — we do not store passwords.
Shifter profile and CV: display name, home postcode and approximate location, travel radius, phone number if supplied, the roles you can cover, availability, languages and equipment, and the employment history you add to your CV.
References: when a Shifter asks for a reference, we store the referee's name, role or relationship, email address or phone number, request status, and the answers and comment they submit through our form. The Shifter can read the reference and decide whether to show it on their CV. Referee contact details are never placed on a CV or shared with a venue.
Credentials and documents: the certificates you upload (for example food hygiene or PVG), right-to-work evidence, and identity documents used for the ID verified badge. Files are stored in private object storage and shown only to you, to venues you apply to or are engaged by, and to our review team.
Right-to-work share code: if you choose the share-code route, your 9-character Home Office share code and (optionally) your date of birth. These are stored privately and revealed only to venues you apply to or are engaged by, so they can complete the official check at gov.uk/view-right-to-work — every reveal is recorded in the audit log.
Shift activity: applications and their messages, invites, offers, engagements, check-ins, and the attendance ledger (completions, missed confirmations, no-shows).
Ratings: two-sided ratings and written reviews left after completed shifts.
Notifications: the in-app notifications we show you and a record of the emails we send you.
Billing (venues only): your plan, and the Stripe customer and subscription identifiers for your venue. Card details are handled entirely by Stripe — we never see or store them.
Waitlist: if you join the waitlist, your email, postcode and the role you are interested in.
Referrals: your referral code, and when someone joins with your link, a record connecting the two accounts so we can count sign-ups and grant rewards. Referrers only ever see counts — never who signed up.
Technical and audit records: an audit log of who viewed which document (pii_access_log), anonymised-pattern board search instrumentation, and short-lived rate-limit counters used to protect the service.
Running the notice board — matching Shifters to shifts, handling applications, offers and check-ins — is necessary to perform our contract with you (UK GDPR Article 6(1)(b)).
Attendance tracking, reliability scores, ratings and references are processed under our legitimate interests (Article 6(1)(f)) in running a trustworthy board where venues and Shifters can choose quickly on attributed evidence. You can object; see “Your rights” below.
Identity and right-to-work evidence is processed under our legitimate interests in platform trust and safety, and to support the engaging employer's legal obligation to complete right-to-work checks. The statutory check always belongs to the employer.
Transactional email and text messages are used for offers, confirmations, reminders and reference requests. Reference messages are sent only to the address or number the Shifter supplies for that request; they do not subscribe a referee to marketing.
Billing records are processed to perform our contract with venues and to meet our legal obligations (Article 6(1)(c)) on tax and accounting.
Search instrumentation and security counters are processed under our legitimate interests in improving and protecting the service.
Venues you interact with: your profile summary, platform record, visible references, attributed employment history and badge-level credentials are visible to venues whose shifts you apply to. Referee email addresses and phone numbers are never shared with venues, including after an offer. Document files are visible only to you, to venues you have applied to or are engaged by, and to our review team — every view by someone else is recorded in our audit log.
Service providers (processors): Stripe (payments, venues only), Resend (transactional email), Twilio (reference text messages, when selected), Trigger.dev (background jobs), postcodes.io (postcode lookup, UK), Cloudflare R2 (document storage, when enabled), and Didit (online identity verification — when you verify online, Didit processes the photos of your ID and your selfie to run the check). They process data on our instructions only.
Stripe, Resend, Twilio, Trigger.dev and Cloudflare are US-based providers, so using them involves transferring personal data to the United States. These transfers are made under the UK International Data Transfer Agreement or the UK addendum to EU standard contractual clauses, and Stripe additionally participates in the EU-US and UK-US Data Privacy Frameworks. Where Didit processes identity verification data outside the UK, that transfer is covered by the same safeguards.
postcodes.io processes postcode lookups in the UK. Document storage is local to our own infrastructure in development and moves to Cloudflare R2 in production.
Account and profile data: kept while your account is open, and erased or anonymised when you delete it (see “Your rights”).
Rejected identity documents: the file is deleted 30 days after the rejection decision; we keep the decision record itself.
Document-view audit log (pii_access_log): 12 months, then deleted.
Board search instrumentation: 90 days, then deleted.
Rate-limit counters: 24 hours.
Notifications and email records: kept while your account is open and erased with it.
References: marked as over a year old after 12 months and deleted after 24 months. A referee can withdraw a submitted reference from their original link for 12 months; withdrawal removes it from every CV immediately. Declined and unanswered requests never appear to venues. Pseudonymous reference-contact reuse signals used for human trust-and-safety review are also deleted after 24 months.
Attendance ledger and ratings: after you delete your account these are kept in anonymised form — attached to a “Deleted Shifter” profile with your name, contact details and documents removed — so the completion and attendance figures both sides rely on stay honest. Written review comments are not automatically rewritten; ask us if a comment identifies you and we will remove it through the moderation process.
Billing records (venues): kept for the period required by UK tax law, normally six years.
You have the right to access, correct, delete, restrict or object to our use of your personal data, and the right to data portability.
Access and portability: Shifters can download everything we hold about them as a JSON file from Account settings → Download my data (/worker/settings).
Erasure: Shifters can delete their account from Account settings → Delete my account. This anonymises your profile, deletes your uploaded documents, and erases your applications, messages, CV history, reference requests, reference evidence and notifications. It cannot be undone. Venue owners can request organisation deletion from Venue settings — because venue data involves Shifters and financial records, our team processes it manually.
Correction: most profile details can be edited in the app; anything else, email support@jumpshift.co.uk.
For anything else — restriction, objection, or a question — email support@jumpshift.co.uk and we will respond within one month.
If you are unhappy with how we handle your data, please contact us first at support@jumpshift.co.uk.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator: ico.org.uk/make-a-complaint, or 0303 123 1113.
JumpShift uses only strictly necessary cookies: the NextAuth session cookie that keeps you signed in, and its security companions (CSRF and callback cookies). If you follow a referral link, we also set a single referral cookie (js_ref) that remembers the link for 30 days so the sign-up can be counted — it is not used for advertising or tracking beyond that. We do not use analytics, advertising or tracking cookies, and no cookie banner is needed for strictly necessary cookies.
If we change what we collect or how we use it, we will update this page and, for significant changes, tell you by email or in the app.
Questions about this notice: support@jumpshift.co.uk.