Privacy

Privacy Policy for Zchedule

What Zchedule collects, why, who receives it, how long it is kept, and the choices you have. Written to match what the product actually does.

Data stored in Google Firebase (US)No background location trackingGlobal Privacy Control honoured
Effective Date:
20 Jul 2026
Last Updated:
17 Sep 2026
Company:
Lazy Leaf LLC, a California Limited Liability Company

1. Overview

This Privacy Policy describes how Lazy Leaf LLC (“Zchedule,” “we,” “us”) collects, uses, shares and retains information when you use Zchedule: the website and web dashboard at zchedule.app, the Zchedule iPhone app, the shared-device time kiosk, and the account, scheduling, time-clock and billing features available through them (together, the “Service”).

Zchedule is used by businesses to schedule and track the hours of their staff. That means two kinds of people read this policy: team owners and managers, who create a team and enter information about the people who work there, and team members, who join a team and use the app to see their schedule and, on some teams, to clock in and out. Where a practice applies to only one of those groups, or to only one surface (for example advertising cookies on the website), we say so.

This policy is a description of our practices, not a contract you sign by browsing. Where the law or a platform requires your permission for something specific — for example, your device asking whether Zchedule may use your location — we ask for it separately, at the moment it is needed.

2. Information We Collect

Account information. When you create an account we collect your name, email address and a password (the password is handled by Google Firebase Authentication; we never see or store it in plain text). If you sign in with Google, Google provides your name, email address and profile photo. Each account has an internal identifier (a Firebase user ID) and a record of which teams it belongs to and with what role (owner, manager or worker).

Team and workforce information (entered by your employer). The owner or a manager of a team can record information about each member: name, email address, phone number, job title or position, employment type, start date, maximum weekly hours, tags, and scheduling permissions (for example whether the member may request swaps or work overtime). A team can also keep a private payroll profile that only its owner and managers can see: hourly rate, overtime rate, pay type, payroll ID, certifications, uniform size, emergency contact name and phone, and internal notes. You, as a member, cannot view that private profile in the app; ask your employer.

Scheduling data. Shifts, published schedules, shift templates, your availability and blocked-out dates, time-off entries, swap and coverage requests, announcements, notes attached to shifts, and (if a manager enters it) the team's daily revenue and business hours, used for labour-cost reporting.

Attendance and timekeeping. If your team uses the time clock, we record each attendance record: scheduled start and end, clock-in and clock-out times, break start and end, worked minutes, paid minutes, overtime and late minutes, a status (present, late, absent, no-show, unscheduled and so on), how the record was created (kiosk punch, phone GPS punch, derived from the schedule, or entered by a manager), the kiosk or device that recorded it, manager edits and their reasons, approvals, review decisions, and a “voided” flag when a manager rejects a punch. Rejected or voided punches are kept in the record but stop counting toward worked hours. Every attendance change is also written to a team audit log (who did what, when, from which device) that only the team's owner and managers can read.

Precise location (GPS clock-in only). If your employer turns on location-verified clock-in and has assigned a work zone to you, then when you tap Clock in or Clock out on your own phone or web browser, the app reads your device's location once and sends it to our servers. We store, on that attendance record: the latitude and longitude, the reported accuracy in metres, the time the device captured the fix, whether the device reported a mocked (fake) location, the work zone the punch was checked against (a snapshot of its name, coordinates and radius), the distance from that zone, whether the punch was inside it, and any review flag or manager decision that resulted. If you ask a manager to approve a clock-in that was blocked, the location you attempted from is stored on that request. Section 4 explains exactly when location is read. When location verification is off for your team, or no zone applies to you, no coordinate is stored.

Work zones (entered by your employer). A manager defines each clock-in zone: a name, an address, a centre latitude and longitude, a radius, which members it applies to, and an enforcement mode.

Kiosk data. On a team that uses the shared-device time kiosk, each member has a numeric clock PIN. We store only a bcrypt hash of it, never the PIN. Kiosk devices have a label, a device identifier, an admin PIN hash, and a heartbeat timestamp. Failed PIN attempts and lockouts are recorded in the audit log.

Device and technical data. Our servers and hosting providers (Vercel for the website, Google Cloud for our Firebase functions) receive your IP address, browser or device type and operating system with each request, in ordinary server logs. The iPhone app sends crash and error reports to Sentry, which include the device model, OS version, app version, technical details of the error and recent diagnostic log lines (which may contain your account ID), but not your name, email, location or schedule. We do not use your device's advertising identifier and the app does not request App Tracking Transparency permission, because it does not track you across other companies' apps or websites.

Notifications. If you allow notifications in the app, we store an Expo push token for your device in your member record so we can deliver shift, swap, coverage, announcement and time-clock notices. We also keep the notification messages addressed to you, your notification preferences, and — if you enable email digests — send those emails through Resend.

Payments and subscriptions. Paid plans are bought by the team owner on our website and processed by Stripe. Stripe collects the card details and billing address; we store the Stripe customer and subscription identifiers, the plan, billing interval and status, and the trial dates for the team. We never see or store full card numbers. A small number of teams that subscribed through the App Store before in-app purchases were retired are marked as legacy App Store subscribers; those subscriptions are managed by Apple.

Website analytics and advertising (website only). On zchedule.app we use Google Analytics 4, the Google Ads tag, the Meta Pixel and Meta's Conversions API, described in Section 5. The iPhone app contains none of these.

Marketing attribution (first party). When you first arrive at zchedule.app we record, in your browser, the campaign parameters on the link you used (utm_source, utm_medium, utm_campaign, utm_content, utm_term), any advertising click identifier on it (fbclid, gclid, gbraid, wbraid), the domain of the site that referred you, the path of the page you landed on, and the time. If you go on to create an account and a team, that record is saved with the team so we know which campaign produced it. We do not record full URLs, page contents or anything you type.

Support and contact. If you email us, or use the contact or request-access forms, we keep the message and your contact details to reply.

3. How We Use Information

We use information to:

  • provide the Service: build and publish schedules, show you your shifts, run the time clock, kiosk and location-verified clock-in, and calculate hours and labour cost for your team;
  • verify a clock-in or clock-out against the work zone your employer configured, flag punches for manager review, and support the manager approval workflows described in Section 4;
  • authenticate you, keep your session signed in, and protect accounts and teams from misuse (for example rate-limiting password resets and locking a kiosk after repeated wrong PINs);
  • deliver the notifications and emails you or your team have enabled;
  • process subscriptions through Stripe and determine which plan features a team can use;
  • answer support requests;
  • understand how visitors find zchedule.app and whether our advertising works, as described in Sections 5 and 7;
  • tell our own team, in a private internal channel, when a new account or team is created, so we can follow up (Section 6, Discord);
  • detect, investigate and fix bugs and outages; and
  • comply with law and enforce our Terms.

We do not use attendance, location, pay or any other workforce information for advertising, and we do not send any of it to Google Analytics, Google Ads or Meta.

4. Location & Attendance

When location is read. Zchedule reads your device's location only in direct connection with a location-verified attendance action that you start: when you tap Clock in or Clock out on the location clock-in screen (in the iPhone app or the web dashboard), and if you then ask a manager to approve a clock-in that a strict zone refused. Each of those reads a single position fix at that moment. A manager creating a zone can also tap “use my location” to centre the map on where they are standing; that fix is used for the map and is not stored as a punch.

Zchedule does not continuously track your location in the background. The app asks only for “While Using the App” location permission. It never requests “Always” permission, has no background location mode, does not sample your location between a clock-in and a clock-out, and reads nothing when you are off shift, on your days off, or simply have the app open on another screen. The shared-device kiosk does not use location at all.

Before your phone asks. The first time you open the location clock-in screen, the app explains this in its own words and asks you to continue before the operating system shows its permission prompt. You can decline, and you can change the permission later in your device settings. If location is unavailable, the punch is still recorded; depending on your employer's settings it may be flagged for review or, on a strict zone, refused until a manager approves it.

How work zones work. Your employer defines one or more zones — a centre point and a radius — and chooses, per zone, whether an out-of-range punch is simply recorded, flagged for a manager to look at, held for review, or refused. Our servers do the comparison; the app only collects the fix and shows you the result. The zone as it existed at the moment of the punch is snapshotted onto the record, so later edits to the zone do not change how an old punch is judged.

Who can see it. The owner and managers of your team can see each punch's time, zone, distance, accuracy, in-or-out result, review status and a point on a map, in the attendance screens of the dashboard and the app. Other team members cannot. Zchedule staff can access it only for support and operations. It is never shared with advertising partners.

Retention. Location evidence is stored on the attendance record it belongs to and is currently kept for as long as that record is kept — which is for as long as the team exists, because attendance records are part of your employer's timekeeping history. It is deleted when the team is deleted. We are designing a shorter, separate retention period for the raw coordinates (keeping the in-or-out result and distance but removing the exact position after a set time); when that is in place this section will say what the period is. Section 8 has the details.

5. Cookies & Tracking Technologies

This section is about the website, zchedule.app. The iPhone app does not use cookies, an analytics SDK or an advertising SDK.

Essential (always on). A session cookie (zs_fb_session, 5 days, or 14 days if you choose “remember me”) that keeps you signed in; a role hint cookie used for routing; browser storage that remembers which team you last opened, your theme, an unfinished signup draft, and a kiosk device's pairing; a cookie recording your region-based consent mode; and the cookie that records your advertising opt-out (Section 11). None of these are used for advertising and they are not affected by the opt-out.

Google Analytics 4 (site measurement). Records page views on zchedule.app, including the page path and the campaign parameters on the URL, and a small set of site events (a call-to-action click, the pricing section being viewed, the signup page being reached, a signup being started, a team being created, an account being registered). Each event may carry the landing page, the referring domain and, if you arrived from an AI assistant such as ChatGPT, that assistant's name as a category. Google sets its own cookies (_ga, _ga_*) whose lifetimes are controlled by Google. We run it with Google signals and ad-personalisation signals turned off, and it is not affected by the advertising opt-out because it is our own site measurement rather than sharing for cross-context advertising. It does not run on non-production copies of the site.

Google Ads. The Google Ads tag (account AW-18423682904) is loaded alongside Google Analytics. It reads Google click identifiers from an ad link into Google's _gcl_* cookies and, when an account is created, reports one “Sign Up” conversion with a random transaction identifier so the same registration is never counted twice. No name, email or other personal detail is sent with it. Google Consent Mode v2 is set before the tag loads; under the advertising opt-out or Global Privacy Control the Ads tag is not configured at all.

Meta Pixel (browser). Pixel ID 914329748387383. When loaded it sets Meta's _fbp and _fbc cookies and sends Meta a page view on the marketing pages, plus events for steps in becoming a customer: clicking a call-to-action, viewing pricing, reaching and starting signup, choosing a signup method, completing registration, creating or joining a team, completing or skipping onboarding, creating a first shift, publishing a first schedule, creating a first clock-in zone, beginning checkout, and a failed Google sign-in. Events carry the campaign parameters and landing page from Section 2 (“Marketing attribution”) and, for some, a literal such as which button was pressed, the selected plan and billing interval, or the business type chosen during onboarding. Page views are not sent from the operator, kiosk or internal screens. The pixel is not loaded on non-production copies of the site, and not loaded at all under the advertising opt-out or Global Privacy Control.

Meta Conversions API (server). Our servers send Meta a copy of a few of those events so they are still counted when a browser blocks the pixel: SignupStarted, a failed Google sign-in, CompleteRegistration, InitiateCheckout, StartTrial (when a team's trial actually begins) and Purchase (when Stripe confirms a paid subscription). Where the browser also sent the event, both carry the same event identifier so Meta counts one. Depending on the event, the server copy may include: your email address and first name, each hashed with SHA-256 before sending; your Zchedule user ID, also SHA-256 hashed; your IP address and browser user-agent; the _fbp/_fbc values; the campaign parameters; and the plan, billing interval, price and currency for checkout and purchase events. We do not send phone numbers, dates of birth, gender, postal addresses, or any attendance, location, pay, schedule or workforce data. Under the advertising opt-out or Global Privacy Control no Conversions API event is sent for you, and the _fbp/_fbc values are not stored.

First-party attribution. The campaign record described in Section 2 is stored in your browser's local storage (zs_attribution_v1) and, once you create a team, on that team's record in our database. It is our own record and is never sent to an advertising platform; it is also included in the internal new-account notice described in Section 6.

Maps. The zone editor in the web dashboard loads Google Maps to show the map; Google receives the manager's IP address and map requests under Google's terms. The iPhone app uses Apple Maps and Apple's geocoder.

6. Sharing & Service Providers

Your team. Information you enter or generate inside a team is visible to that team's owner and managers and, for schedules, announcements and requests, to other members of the team, as needed to run the schedule. Attendance records, location evidence, the audit log, the private payroll profile and clock-in zones are visible to the owner and managers only.

Service providers. We use these companies to run Zchedule. Each receives only what is needed for its job:

  • Google Firebase / Google Cloud — authentication, the database (Firestore, US multi-region) that holds everything in Section 2, and the server functions that process punches, notifications and billing events.
  • Google Sign-In — if you choose it, Google authenticates you and shares your name, email and profile photo with us.
  • Google Analytics and Google Ads — website measurement and advertising, Section 5.
  • Google Maps Platform — the map in the web zone editor.
  • Meta Platforms — the Meta Pixel and Conversions API, Section 5.
  • Stripe — subscription billing on the website; receives the team owner's email, card and billing address.
  • Apple — distributes the iPhone app through the App Store, delivers push notifications to iPhones, and manages any legacy App Store subscription.
  • Expo (EAS) — routes push notifications to your device using the push token in Section 2, and delivers app updates.
  • Sentry — crash and error reporting for the iPhone app, Section 2.
  • Resend — sends verification, password-reset and digest emails; your email address and the message pass through it.
  • Vercel — hosts the website and its server routes and keeps ordinary request logs.
  • Discord — hosts a private channel for Zchedule staff. When a new account or team is created, a message is posted there with the name, email, sign-in method, campaign source, landing page, platform and account ID of the new account, and the owner's name and email and plan for a new team, so we can follow up. Discord holds those messages under its own terms.

Legal and safety. We may disclose information when required by law, legal process or a government request, or to protect the rights, safety and security of Zchedule, our users or others.

Business transfers. If Lazy Leaf LLC is involved in a merger, acquisition or sale of assets, information may be transferred as part of that transaction; this policy would continue to apply until changed with notice.

We do not share personal information with third-party advertisers other than the Meta and Google advertising measurement described in Section 5, and we do not sell it.

7. Advertising, “Sale” and “Sharing”

We do not sell personal information for money, to anyone, and never have.

We do send limited website activity to Meta and Google for advertising measurement (Section 5). California law can treat that kind of disclosure as “sharing” for cross-context behavioural advertising even though no money changes hands, and some other states use the term “targeted advertising.” You can turn it off for your browser at any time — see Section 11 — and we honour the Global Privacy Control signal as the same request. We do not knowingly “share” the personal information of anyone under 16.

Nothing that happens inside the product — schedules, attendance, location, pay, kiosk activity — is ever shared for advertising. The advertising measurement concerns only how someone came to the website and whether they became a customer.

8. Retention

This is what happens to each kind of information today.

  • Account and membership — kept until you delete your account or are removed from a team (Section 10 explains what deletion removes).
  • Team data: schedules, shifts, requests, announcements, zones, kiosk settings, attendance records, location evidence, the audit log — kept for as long as the team exists, as the employer's operating and timekeeping records, and deleted when the owner deletes the team. We do not currently apply a separate expiry to any of these. If you leave a team or are removed, your past shifts and attendance records stay with the team; your future shifts are unassigned.
  • Raw location coordinates — kept with the attendance record today. We are designing a separate, shorter retention for the exact coordinates while keeping the verification result (see Section 4); until it ships, the coordinates follow the record.
  • Notifications — the app shows the last 14 days; the underlying messages are kept with the team.
  • Push tokens — kept in your member record until you delete your account, are removed from the team, or the token is reported invalid, at which point we remove it.
  • Marketing attribution — kept on the team record for the life of the team; the copy parked at signup is deleted with your account.
  • Password-reset and verification rate-limit counters — one hour, keyed by a hash rather than your address.
  • Billing — subscription identifiers stay on the team while it exists; when an owner deletes their account we cancel the Stripe subscription and delete the Stripe customer. Stripe keeps its own transaction records as the law requires.
  • Server, hosting and crash logs — kept by Google Cloud, Vercel and Sentry for their standard retention periods, which we do not control individually.
  • Data held by Google Analytics, Google Ads and Meta — retained under those companies' policies.

We may keep limited information longer where the law requires it or to resolve a dispute, prevent fraud or enforce our agreements.

9. Security

We use reasonable administrative and technical safeguards appropriate to a service of our size. In practice: all traffic between the apps and our servers is encrypted in transit (HTTPS); data is stored in Google Firebase, which encrypts it at rest; access to team data is enforced by database security rules and server-side role checks so that members cannot read other teams, workers cannot read payroll or location review data, and clients cannot write attendance or location evidence directly; kiosk and clock PINs are stored only as bcrypt hashes; email and name are hashed before being sent to Meta; and secrets are kept out of the apps. No system is perfectly secure, and we do not claim any particular certification.

10. Your Privacy Rights

Depending on where you live, you may have legal rights to access, correct, delete or receive a copy of your personal information, and to opt out of certain uses. Whether a specific law applies to Zchedule depends on thresholds we may not meet; we offer the following to everyone regardless.

  • Delete your account. In the app: Settings → Delete account (or email us). This deletes your sign-in, your profile and push tokens in every team, your signup attribution, and — if you own teams — those teams entirely, including everyone's schedules and attendance, after cancelling the team's Stripe subscription. Records you generated in a team someone else owns (past shifts, attendance and location evidence, audit-log entries) stay with that team as the employer's records, showing the name the team had for you at the time; we are working on a way to de-identify those on request while preserving the employer's timekeeping totals.
  • Correct your information. Your name and notification settings can be changed in the app. Team-controlled information — the details a manager entered about you, your schedule and your attendance records — is corrected by your employer; kiosk users can request a punch correction from the kiosk's Review Timestamps screen, which a manager approves or denies.
  • Access or export. Email support@zchedule.app from the address on your account. There is no self-service export yet; we compile the information we hold about you by hand and send it to you, normally within 30 days.
  • Opt out of advertising sharing. Section 11.

To protect your account we may ask you to confirm a request from the email address on file. We will not treat you differently for exercising any of these rights. If you are a team member and your employer is the one who entered information about you, we may refer some requests to your employer, who controls that information.

11. Your Privacy Choices

Do Not Sell or Share My Personal Information. Visit zchedule.app/privacy-choices and turn the switch on. From then on, in that browser: the Meta Pixel is not loaded and sets no cookies, no Conversions API event is sent for you (including the trial and purchase events our servers would otherwise send later), and the Google Ads tag is not configured. Google Analytics continues, with advertising signals off. The choice is stored in that browser (local storage plus a one-year zs_ads_opt_outcookie) and is not linked to your account, so set it in each browser you use.

Global Privacy Control. If your browser sends the GPC signal, we treat it as that opt-out automatically, both on the page and on our servers, and it cannot be overridden by the switch.

Your browser and platforms. You can also block or clear cookies for zchedule.app, use Google's Ads Settings and Analytics opt-out browser add-on, and manage ad preferences in your Facebook and Instagram settings.

Location. The iPhone app asks for location only from the location clock-in screen. You can decline, and change it later in Settings → Privacy → Location Services → Zchedule. The web dashboard uses your browser's location prompt.

Notifications. Turn push notifications off in the app's settings or your device settings. Email notifications have their own master switch on your profile page at zchedule.app/profile, and each digest email carries an unsubscribe link to it.

12. Children

The Service is not intended for individuals under 18, and our Terms require account holders to be at least 18. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact us and we will delete it.

13. International Users

Zchedule is operated from California and built for teams in the United States. Our servers and service providers are in the United States. If you use the Service from elsewhere, your information will be transferred to, stored and processed in the United States, where privacy laws may differ from those of your country. Visitors we identify as being in the European Economic Area, the United Kingdom or Switzerland are shown a consent choice before any analytics or advertising tag loads.

14. Changes

We will update this policy when our practices change. The “Last Updated” date at the top shows the current version. For a material change — for example a new category of data, a new advertising partner, or a change to how location is used — we will give notice in the app or by email before it takes effect, and where the law requires it we will ask for your consent.

15. Contact

Lazy Leaf LLC
Support and privacy requests: support@zchedule.app
Advertising opt-out: zchedule.app/privacy-choices
Account deletion: zchedule.app/delete-account

In one screen
  • Location is read only when you clock in or out (or ask for an override). Never in the background.
  • Your employer sees your punches and attendance; other team members do not.
  • The website uses Google Analytics, Google Ads and the Meta Pixel; the app uses none of them.
  • We never sell personal information. Advertising sharing can be switched off at /privacy-choices, and GPC is honoured.
  • Deleting your account removes your sign-in and profiles; teams you own are deleted entirely.