What Zchedule collects, why, who receives it, how long it is kept, and the choices you have. Written to match what the product actually does.
This Privacy Policy describes how Lazy Leaf LLC (“Zchedule,” “we,” “us”) collects, uses, shares and retains information when you use Zchedule: the website and web dashboard at zchedule.app, the Zchedule iPhone app, the shared-device time kiosk, and the account, scheduling, time-clock and billing features available through them (together, the “Service”).
Zchedule is used by businesses to schedule and track the hours of their staff. That means two kinds of people read this policy: team owners and managers, who create a team and enter information about the people who work there, and team members, who join a team and use the app to see their schedule and, on some teams, to clock in and out. Where a practice applies to only one of those groups, or to only one surface (for example advertising cookies on the website), we say so.
This policy is a description of our practices, not a contract you sign by browsing. Where the law or a platform requires your permission for something specific — for example, your device asking whether Zchedule may use your location — we ask for it separately, at the moment it is needed.
Account information. When you create an account we collect your name, email address and a password (the password is handled by Google Firebase Authentication; we never see or store it in plain text). If you sign in with Google, Google provides your name, email address and profile photo. Each account has an internal identifier (a Firebase user ID) and a record of which teams it belongs to and with what role (owner, manager or worker).
Team and workforce information (entered by your employer). The owner or a manager of a team can record information about each member: name, email address, phone number, job title or position, employment type, start date, maximum weekly hours, tags, and scheduling permissions (for example whether the member may request swaps or work overtime). A team can also keep a private payroll profile that only its owner and managers can see: hourly rate, overtime rate, pay type, payroll ID, certifications, uniform size, emergency contact name and phone, and internal notes. You, as a member, cannot view that private profile in the app; ask your employer.
Scheduling data. Shifts, published schedules, shift templates, your availability and blocked-out dates, time-off entries, swap and coverage requests, announcements, notes attached to shifts, and (if a manager enters it) the team's daily revenue and business hours, used for labour-cost reporting.
Attendance and timekeeping. If your team uses the time clock, we record each attendance record: scheduled start and end, clock-in and clock-out times, break start and end, worked minutes, paid minutes, overtime and late minutes, a status (present, late, absent, no-show, unscheduled and so on), how the record was created (kiosk punch, phone GPS punch, derived from the schedule, or entered by a manager), the kiosk or device that recorded it, manager edits and their reasons, approvals, review decisions, and a “voided” flag when a manager rejects a punch. Rejected or voided punches are kept in the record but stop counting toward worked hours. Every attendance change is also written to a team audit log (who did what, when, from which device) that only the team's owner and managers can read.
Precise location (GPS clock-in only). If your employer turns on location-verified clock-in and has assigned a work zone to you, then when you tap Clock in or Clock out on your own phone or web browser, the app reads your device's location once and sends it to our servers. We store, on that attendance record: the latitude and longitude, the reported accuracy in metres, the time the device captured the fix, whether the device reported a mocked (fake) location, the work zone the punch was checked against (a snapshot of its name, coordinates and radius), the distance from that zone, whether the punch was inside it, and any review flag or manager decision that resulted. If you ask a manager to approve a clock-in that was blocked, the location you attempted from is stored on that request. Section 4 explains exactly when location is read. When location verification is off for your team, or no zone applies to you, no coordinate is stored.
Work zones (entered by your employer). A manager defines each clock-in zone: a name, an address, a centre latitude and longitude, a radius, which members it applies to, and an enforcement mode.
Kiosk data. On a team that uses the shared-device time kiosk, each member has a numeric clock PIN. We store only a bcrypt hash of it, never the PIN. Kiosk devices have a label, a device identifier, an admin PIN hash, and a heartbeat timestamp. Failed PIN attempts and lockouts are recorded in the audit log.
Device and technical data. Our servers and hosting providers (Vercel for the website, Google Cloud for our Firebase functions) receive your IP address, browser or device type and operating system with each request, in ordinary server logs. The iPhone app sends crash and error reports to Sentry, which include the device model, OS version, app version, technical details of the error and recent diagnostic log lines (which may contain your account ID), but not your name, email, location or schedule. We do not use your device's advertising identifier and the app does not request App Tracking Transparency permission, because it does not track you across other companies' apps or websites.
Notifications. If you allow notifications in the app, we store an Expo push token for your device in your member record so we can deliver shift, swap, coverage, announcement and time-clock notices. We also keep the notification messages addressed to you, your notification preferences, and — if you enable email digests — send those emails through Resend.
Payments and subscriptions. Paid plans are bought by the team owner on our website and processed by Stripe. Stripe collects the card details and billing address; we store the Stripe customer and subscription identifiers, the plan, billing interval and status, and the trial dates for the team. We never see or store full card numbers. A small number of teams that subscribed through the App Store before in-app purchases were retired are marked as legacy App Store subscribers; those subscriptions are managed by Apple.
Website analytics and advertising (website only). On zchedule.app we use Google Analytics 4, the Google Ads tag, the Meta Pixel and Meta's Conversions API, described in Section 5. The iPhone app contains none of these.
Marketing attribution (first party). When you first arrive at zchedule.app we record, in your browser, the campaign parameters on the link you used (utm_source, utm_medium, utm_campaign, utm_content, utm_term), any advertising click identifier on it (fbclid, gclid, gbraid, wbraid), the domain of the site that referred you, the path of the page you landed on, and the time. If you go on to create an account and a team, that record is saved with the team so we know which campaign produced it. We do not record full URLs, page contents or anything you type.
Support and contact. If you email us, or use the contact or request-access forms, we keep the message and your contact details to reply.
We use information to:
We do not use attendance, location, pay or any other workforce information for advertising, and we do not send any of it to Google Analytics, Google Ads or Meta.
When location is read. Zchedule reads your device's location only in direct connection with a location-verified attendance action that you start: when you tap Clock in or Clock out on the location clock-in screen (in the iPhone app or the web dashboard), and if you then ask a manager to approve a clock-in that a strict zone refused. Each of those reads a single position fix at that moment. A manager creating a zone can also tap “use my location” to centre the map on where they are standing; that fix is used for the map and is not stored as a punch.
Zchedule does not continuously track your location in the background. The app asks only for “While Using the App” location permission. It never requests “Always” permission, has no background location mode, does not sample your location between a clock-in and a clock-out, and reads nothing when you are off shift, on your days off, or simply have the app open on another screen. The shared-device kiosk does not use location at all.
Before your phone asks. The first time you open the location clock-in screen, the app explains this in its own words and asks you to continue before the operating system shows its permission prompt. You can decline, and you can change the permission later in your device settings. If location is unavailable, the punch is still recorded; depending on your employer's settings it may be flagged for review or, on a strict zone, refused until a manager approves it.
How work zones work. Your employer defines one or more zones — a centre point and a radius — and chooses, per zone, whether an out-of-range punch is simply recorded, flagged for a manager to look at, held for review, or refused. Our servers do the comparison; the app only collects the fix and shows you the result. The zone as it existed at the moment of the punch is snapshotted onto the record, so later edits to the zone do not change how an old punch is judged.
Who can see it. The owner and managers of your team can see each punch's time, zone, distance, accuracy, in-or-out result, review status and a point on a map, in the attendance screens of the dashboard and the app. Other team members cannot. Zchedule staff can access it only for support and operations. It is never shared with advertising partners.
Retention. Location evidence is stored on the attendance record it belongs to and is currently kept for as long as that record is kept — which is for as long as the team exists, because attendance records are part of your employer's timekeeping history. It is deleted when the team is deleted. We are designing a shorter, separate retention period for the raw coordinates (keeping the in-or-out result and distance but removing the exact position after a set time); when that is in place this section will say what the period is. Section 8 has the details.
We do not sell personal information for money, to anyone, and never have.
We do send limited website activity to Meta and Google for advertising measurement (Section 5). California law can treat that kind of disclosure as “sharing” for cross-context behavioural advertising even though no money changes hands, and some other states use the term “targeted advertising.” You can turn it off for your browser at any time — see Section 11 — and we honour the Global Privacy Control signal as the same request. We do not knowingly “share” the personal information of anyone under 16.
Nothing that happens inside the product — schedules, attendance, location, pay, kiosk activity — is ever shared for advertising. The advertising measurement concerns only how someone came to the website and whether they became a customer.
This is what happens to each kind of information today.
We may keep limited information longer where the law requires it or to resolve a dispute, prevent fraud or enforce our agreements.
We use reasonable administrative and technical safeguards appropriate to a service of our size. In practice: all traffic between the apps and our servers is encrypted in transit (HTTPS); data is stored in Google Firebase, which encrypts it at rest; access to team data is enforced by database security rules and server-side role checks so that members cannot read other teams, workers cannot read payroll or location review data, and clients cannot write attendance or location evidence directly; kiosk and clock PINs are stored only as bcrypt hashes; email and name are hashed before being sent to Meta; and secrets are kept out of the apps. No system is perfectly secure, and we do not claim any particular certification.
Depending on where you live, you may have legal rights to access, correct, delete or receive a copy of your personal information, and to opt out of certain uses. Whether a specific law applies to Zchedule depends on thresholds we may not meet; we offer the following to everyone regardless.
To protect your account we may ask you to confirm a request from the email address on file. We will not treat you differently for exercising any of these rights. If you are a team member and your employer is the one who entered information about you, we may refer some requests to your employer, who controls that information.
Do Not Sell or Share My Personal Information. Visit zchedule.app/privacy-choices and turn the switch on. From then on, in that browser: the Meta Pixel is not loaded and sets no cookies, no Conversions API event is sent for you (including the trial and purchase events our servers would otherwise send later), and the Google Ads tag is not configured. Google Analytics continues, with advertising signals off. The choice is stored in that browser (local storage plus a one-year zs_ads_opt_outcookie) and is not linked to your account, so set it in each browser you use.
Global Privacy Control. If your browser sends the GPC signal, we treat it as that opt-out automatically, both on the page and on our servers, and it cannot be overridden by the switch.
Your browser and platforms. You can also block or clear cookies for zchedule.app, use Google's Ads Settings and Analytics opt-out browser add-on, and manage ad preferences in your Facebook and Instagram settings.
Location. The iPhone app asks for location only from the location clock-in screen. You can decline, and change it later in Settings → Privacy → Location Services → Zchedule. The web dashboard uses your browser's location prompt.
Notifications. Turn push notifications off in the app's settings or your device settings. Email notifications have their own master switch on your profile page at zchedule.app/profile, and each digest email carries an unsubscribe link to it.
The Service is not intended for individuals under 18, and our Terms require account holders to be at least 18. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact us and we will delete it.
Zchedule is operated from California and built for teams in the United States. Our servers and service providers are in the United States. If you use the Service from elsewhere, your information will be transferred to, stored and processed in the United States, where privacy laws may differ from those of your country. Visitors we identify as being in the European Economic Area, the United Kingdom or Switzerland are shown a consent choice before any analytics or advertising tag loads.
We will update this policy when our practices change. The “Last Updated” date at the top shows the current version. For a material change — for example a new category of data, a new advertising partner, or a change to how location is used — we will give notice in the app or by email before it takes effect, and where the law requires it we will ask for your consent.
Lazy Leaf LLC
Support and privacy requests: support@zchedule.app
Advertising opt-out: zchedule.app/privacy-choices
Account deletion: zchedule.app/delete-account