Security
Your rosters, pay rates and employee records are sensitive. This is how ShiftSync protects them. We process personal information in line with the Protection of Personal Information Act (POPIA).
Hardened web pages
Strict security headers stop the site being framed by other sites, block content from unknown sources, and force secure connections (HSTS).
Encrypted in transit and at rest
Every connection to ShiftSync uses HTTPS (TLS). The database and file storage are encrypted at rest by our database provider.
Each business kept separate by the database
Row-level security rules in the database itself decide which rows each person can read or change, so one business can never see another's information, even if there were a mistake in the app.
People only see what their role needs
Staff see the published roster, their own shifts, leave and requests. They never see wages, other people's leave or contact details, or draft rosters. Managers only see the locations they run, and admins can keep pay rates and leave balances to HR.
Sign-in that resists guessing
Owners and managers sign in with a one-time email link. Staff use a username and a 6-digit PIN that HR gives them and they then change. PINs are stored as one-way hashes, easy PINs are refused, and 5 wrong tries lock the login for 15 minutes. HR or ShiftSync can reset a PIN, which signs the person out on every device.
Sick notes stay private
Medical certificates can only be opened by the employee they belong to and their managers, through the app. They are never public links.
Card details never touch our servers
Payments are handled by Paystack, a PCI DSS certified payment provider. We only store your plan and payment status.
Hosted in Frankfurt, Germany
The app and database run on Vercel and Supabase in the EU (Frankfurt), under data protection agreements. See our Privacy Policy for how this meets POPIA.
Our own access is locked down and logged
ShiftSync staff sign in to a separate admin console with a password and an authenticator code. We only open your workspace to help with a problem you've raised: read-only by default, for at most an hour, and every session is recorded with its reason. Plan changes and any other change we make to your account are kept in an audit log that can't be edited.
Defence in depth
Nobody can write to the database directly. Every change goes through a checked function that confirms who you are, your business and your role, and tables that hold passwords, billing references or logs can't be read from the app at all.
What you can do
- Only invite people who need access, and remove members when they leave.
- Give managers only the locations they run, and use “Only admins (HR) can set pay rates and leave balances” in Settings.
- Keep the email accounts you sign in with secure, with a strong password and two-step verification.
Reporting a security problem
If you think you have found a vulnerability or suspect unauthorised access, email support@shiftsync.co.za with “Security” in the subject. We investigate every report and will keep you informed. Please don't access other people's data while testing. Read our Privacy Policy for how we handle personal information.