DistroShift
Legal

Privacy Policy

Last updated: 20 July 2026 · Governed by Irish and EU law

1. Who we are

DistroShift is a software-as-a-service platform that helps Irish businesses manage staff operations — including rosters, leave, attendance, records, and where applicable, tip distribution in compliance with the Payment of Wages (Amendment) (Tips and Gratuities) Act 2022. The platform serves a range of business types including restaurants, hotels, pharmacies, golf clubs, spas, and other venues. It is operated by DistroShift (“DistroShift”, “we”, “us”). Contact: info@distroshift.com.

DistroShift acts as a data processor on behalf of the businesses (our customers) who use the platform. Those businesses are the data controllers for the personal data of their staff members. DistroShift acts as a data controller for the personal data of the business owners and administrators who hold DistroShift accounts.

2. What data we collect

CategoryDataPurpose
Account holdersName, email addressPasswordless authentication (OTP via email), account management, support
Business detailsBusiness name, address, sector, VAT number, company sizeCompliance documents, WRC notices, platform configuration
Staff recordsFirst name, surname, role, contracted hours, employment type, email (optional), IBAN (encrypted — see below)Roster management, leave tracking, staff statements, tip distribution (where applicable)
Operational dataShift records, roster assignments, leave requests and approvals, clock-in/out times, unavailabilityWorkforce management, payroll support, compliance records
Tip distribution data (tipping venues only)Weekly tip pools, hours worked, payout amounts, distribution calculationsWRC-compliant tip distribution, staff statements, audit trail
Reservation guest data (Bookings add-on only)Guest or party name, optional phone number, party size, visit date and time, service, status, source, and optional operational noteManage a venue reservation diary and produce totals-only demand forecasts. Guest identity and contact fields never enter AI context.
Audit logTimestamped record of all actions (user, event, timestamp)Compliance, dispute resolution, security
Usage dataLogin events (rate-throttled), IP addressSecurity monitoring, fraud prevention

IBANs are never stored in plaintext. All IBAN values are encrypted using AES-256-GCM before being written to the database. Only the last 4 digits are ever returned to the client interface.

3. Legal basis for processing (GDPR)

4. How we share your data

We do not sell personal data. We share data only with the following sub-processors who provide infrastructure services:

Sub-processorPurposeLocation
Neon (Neon, Inc.)PostgreSQL database hosting — all business and staff dataEU (AWS eu-central-1, Frankfurt)
Vercel (Vercel, Inc.)Application hosting and edge deliveryEU edge nodes (US entity — SCCs in place)
Resend (Resend, Inc.)Transactional email — OTP login codes and system notifications (email address only)USA (SCCs in place)
Stripe (Stripe, Inc.)Subscription billing — account holder billing details only; no staff personal data is shared with StripeUSA / EU (SCCs in place)

We may disclose data to the Workplace Relations Commission (WRC), the Data Protection Commission, or other regulatory or law enforcement bodies where required by Irish or EU law.

5. Data retention and deletion

Employment and payroll records, staff statements, and audit logs are retained for the duration of your subscription. Under Irish law (including the Payment of Wages Act and the Organisation of Working Time Act), employers are required to retain payroll and working-time records for a minimum of 3–6 years. This obligation rests with the business operator (Data Controller), not with DistroShift.

Where a venue enables the Bookings add-on, guest name, phone number, and reservation note are automatically removed 30 days after the visit date. The non-identifying operating record, including visit date, time, party size, service, source, and status, may be retained to measure demand and service patterns. Forecasting and AI features read only daily aggregate counts and never receive guest names, phone numbers, or notes.

When a venue operator deletes their account via the platform, DistroShift performs a soft delete — the business and all associated data is immediately made inaccessible but retained for 30 days to allow accidental-deletion recovery. Restoration within this window can be requested at info@distroshift.com. After 30 days, data is permanently purged from our systems.

Data portability: Before deleting an account, venue operators are strongly encouraged to export their compliance records (staff statements, payroll history, audit logs). DistroShift provides data export tools for this purpose.

6. Your rights

Under GDPR (as applicable in Ireland), you have the right to:

To exercise any of these rights, email info@distroshift.com. We will respond within 30 days. You also have the right to lodge a complaint with the Data Protection Commission (Ireland).

7. Security

We implement appropriate technical and organisational measures to protect personal data, including AES-256-GCM encryption for financial identifiers, role-based access controls, TLS in transit, rate-limited authentication via one-time codes, and a full audit log of all data access and modification events.

8. Authentication and cookies

DistroShift uses passwordless authentication — account holders sign in by requesting a one-time code sent to their email address. No passwords are stored. Session state is managed via a secure, HTTP-only cookie set by DistroShift’s own authentication system. We do not use advertising or tracking cookies. The only cookies set are those strictly necessary for session management.

9. Data Processing Agreement

Where DistroShift processes personal data on behalf of a venue operator, a full Data Processing Agreement (DPA) governs the relationship under GDPR Article 28. The DPA is accepted digitally at account creation and covers sub-processors, security obligations, breach notification, data subject rights assistance, and deletion procedures.

10. GDPR responsibility when you leave DistroShift

When a venue operator deletes their account or exports their data to another platform, responsibility for that data transfers to the operator as Data Controller. DistroShift is not responsible for the handling of exported data after it leaves our systems, or for any gaps in the operator’s own retention obligations following departure. Operators remain responsible for ensuring their data is handled lawfully at its new destination.

11. Changes to this policy

We will notify account holders of material changes by email at least 14 days before they take effect. Continued use of the platform after that date constitutes acceptance.

12. Contact

For any privacy-related queries, contact us at info@distroshift.com.