1. Scope and operator
ShiftSend is a Canada-based web service currently available to eligible job seekers residing in Canada and the United States. ShiftSend helps users find public business leads, prepare job application emails, review outreach, and send approved applications. This policy applies to the ShiftSend website, workspace, accounts, and related support.
ShiftSend is operated by Luca Aubry DeFilippo, a sole proprietor operating under the business name ShiftSend. Luca Aubry DeFilippo is responsible for the personal information described in this policy and serves as ShiftSend's Privacy Officer. The Privacy Officer can be contacted at [email protected]. ShiftSend's current business location is Montréal, Quebec, Canada.
2. Information we collect
- Account and eligibility data, including name, email address, Firebase identifier, authentication status, birth day, month and year, calculated age band, country-of-residence confirmation, account status, and last activity time.
- Job preferences, including starting location, workplace categories, roles, schedule, availability, language, and relevant experience.
- Documents and profile content, including CVs, motivation letters, file metadata, extracted document text, and notes or facts supplied by the user.
- Lead data, including public business names, addresses, websites, public email addresses, Google Maps links, selected roles, and outreach status.
- Application data, including generated drafts, revision comments, approval status, recipient addresses, attachment names, Gmail message identifiers, and sending history.
- Billing data, including Stripe customer identifiers, plan, subscription and payment status, invoice references, and credit usage. ShiftSend does not receive or store full payment-card numbers.
- Google connection data, as explained in section 6.
- Support communications and information users choose to include in them.
- Technical data needed to operate and secure the service, such as request timestamps, error and security logs, browser storage values, and limited device, browser, or network information made available through normal web requests.
- Consent evidence, including policy versions, the accepted wording, plan and renewal terms, timestamp, IP address, browser user agent, and Stripe Checkout Session reference.
Users decide what documents, profile details, notes, and instructions they provide to ShiftSend. Users are responsible for making sure those materials are appropriate, lawful, accurate, and that they have permission to use them.
3. Where information comes from
We collect information directly from users, from authentication and payment providers when users use those services, and from public business sources such as Google Places and business websites. We do not treat public business contact information as private Gmail content.
4. How and why we use information
- Provide accounts, onboarding, job-lead search, application drafting, review, approval, and sending.
- Tailor leads and drafts to the user's saved location, preferences, entered experience, motivation letter, notes, availability, and language. CVs are stored and attached to approved emails; their contents are not analyzed for drafting.
- Prevent duplicates, enforce plan limits, maintain sending history, and let users manage their workflow.
- Process subscriptions, credits, invoices, cancellations, and payment status.
- Authenticate users, protect accounts, investigate abuse, troubleshoot errors, and maintain reliability.
- Respond to support, privacy, deletion, and legal requests.
- Comply with legal obligations and enforce ShiftSend's Terms of Service.
- Verify age and supported-country eligibility, preserve evidence of consent, and apply the retention schedule.
ShiftSend may use user-provided documents, notes, and instructions to draft application emails for user review and to send emails that the user approves.
Where laws such as the GDPR or UK GDPR apply, we process information as necessary to perform our contract with the user, based on consent for optional connections such as Gmail, to comply with law, and for legitimate interests such as securing and improving the service when those interests are not overridden by the user's rights. Users may disconnect Gmail and may withdraw consent for optional processing at any time, although doing so may disable the related feature.
5. AI-assisted email drafting
ShiftSend uses Google Cloud Vertex AI and Gemini to generate or revise application drafts. A drafting request may contain the selected workplace and role, public lead details, saved job preferences, availability, entered experience, motivation letter text and notes, target language, prior revision comments, and an existing draft when the user requests a revision.
ShiftSend removes email-address patterns from the drafting payload before it is sent to Vertex AI. ShiftSend does not send Gmail OAuth tokens, Gmail inbox content, or data retrieved from Gmail to the AI model. AI drafts may be inaccurate. Users must review and approve drafts before sending, and ShiftSend does not make employment or hiring decisions for users or employers.
6. Google and Gmail user data
Google sign-in may provide an email address, profile identifier, and authentication status. When a user
separately connects Gmail, ShiftSend requests only the
https://www.googleapis.com/auth/gmail.send scope, along with basic identity scopes needed to
identify the connected account. ShiftSend stores the connected Gmail address, granted scope, token expiry,
and encrypted OAuth access and refresh tokens.
Gmail access is used only to send an application email and selected CV attachment after the user approves that application. ShiftSend does not request access to read inbox messages, delete mail, manage labels, change Gmail settings, scan private messages, or retrieve Gmail content for advertising or AI training.
ShiftSend does not sell Google user data, use it for advertising, credit or lending decisions, or transfer it to data brokers. ShiftSend personnel do not read Google user data except when the user gives specific permission for support, when access is necessary to investigate a security or abuse issue, when required by law, or when data has been aggregated and anonymized for permitted internal operations.
ShiftSend's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Users can disconnect Gmail in ShiftSend settings. ShiftSend then attempts to revoke the Google token and deletes the stored Gmail connection and tokens from the active database. Users can also revoke access in their Google Account security settings.
7. Service providers and disclosures
ShiftSend uses providers only for the operating purposes described below:
- Google Firebase: authentication, account verification, password recovery, and identity tokens.
- Google Cloud: application hosting, database operations, document storage, security logs, and Vertex AI/Gemini drafting.
- Google Places and Maps: processing a search area, workplace categories, and search queries to return public business information.
- Google Gmail API: connecting Gmail and sending user-approved messages and attachments.
- Stripe: checkout, subscriptions, payment status, invoices, refunds, fraud prevention, and the billing portal.
- Public business websites: locating publicly displayed workplace contact information without sending the user's CV, profile, or Gmail data to those websites.
We may also disclose information when required by law, to protect users or the service, or in connection with a proposed merger, financing, acquisition, or sale. Where legally required, users will receive notice and consent choices before their information is transferred for a materially different purpose.
8. No sale or behavioral advertising
ShiftSend does not sell personal information. ShiftSend does not share personal information for cross-context behavioral advertising, does not serve targeted advertising, and does not use Google user data for advertising. If these practices change, this policy and the required consent or opt-out controls will be updated before the change takes effect.
9. International processing
ShiftSend is operated from Canada and uses providers that may process information in Canada, the United States, and other countries where they operate. Those countries may have privacy laws different from the user's home country, and information may be accessible to courts or authorities under local law. Where required, ShiftSend uses provider contracts and other legally recognized safeguards for international transfers. Users may contact the Privacy Officer for information about safeguards relevant to them.
10. Browser storage and cookies
ShiftSend uses browser local storage and authentication technologies to keep users signed in, remember setup progress and interface preferences, connect requests to the correct account, and protect the service. ShiftSend does not currently use advertising cookies or third-party behavioral analytics. Blocking required browser storage may prevent account and workspace features from working.
11. Retention
- Account, profile, lead, draft, document, Gmail connection, and workflow records are kept while the account is used and are scheduled for deletion after 24 consecutive months without account activity, unless the account has an active, trialing, incomplete, or recoverable past-due subscription.
- When a verified user requests account deletion in Settings, active service data is deleted as soon as the request can be securely completed and the subscription is cancelled. The account is blocked while an incomplete deletion is retried.
- Gmail connection data and encrypted tokens are kept until Gmail is disconnected, access is revoked, the account is deleted, or the connection is otherwise no longer required.
- Browser storage remains on the device until it is removed by ShiftSend during logout where applicable, cleared by the user, or removed by the browser.
- Consent, payment, tax, fraud-prevention, dispute, transaction, and legal records may be retained for the period required or permitted by applicable law, even after active account data is deleted.
- Security, support, and error records are kept only as long as reasonably necessary to resolve issues, protect the service, and meet legal obligations.
When information is no longer required, ShiftSend deletes it, anonymizes it, or isolates it until secure deletion is possible, subject to legal obligations and limited backup retention.
12. User choices and privacy rights
Depending on where a user lives, they may have rights to access, receive a portable copy of, correct, or delete personal information; withdraw consent; object to or restrict processing; and complain to a privacy regulator. Users will not be discriminated against for exercising applicable privacy rights.
Requests may be sent to [email protected] from the account email address. ShiftSend may request information reasonably necessary to verify identity. We will respond within the period required by applicable law and explain any lawful exception that prevents us from completing all or part of a request. Users can correct many preferences in Settings, disconnect Gmail, manage or cancel subscriptions through the billing portal, permanently delete their ShiftSend account, and revoke Google access through their Google Account.
13. Teen users
ShiftSend asks for birth day, month and year before account creation and calculates whether the person is under 14, aged 14–17, or 18 or older. It is not directed to children under 14, and users under 14 may not create or use an account. If ShiftSend learns that it collected personal information from a child under 14, it will disable the account and delete the information unless retention is legally required. A parent or guardian may contact the Privacy Officer about a suspected underage account.
ShiftSend uses high-privacy defaults, does not sell teen data, does not serve behavioral advertising, and requires users to review applications before sending. Privacy explanations are written to be understandable to teenage users as well as adults.
14. Security
ShiftSend uses safeguards appropriate to the information it handles. These include HTTPS, Firebase authentication, encrypted Gmail token storage, access controls, restricted document storage, database controls, input and upload validation, and security logging. Access by personnel is limited to what is needed to operate, support, secure, or legally administer the service. No system can guarantee absolute security.
Users should use a unique password, protect their email account, and contact ShiftSend promptly if they believe their account or personal information has been compromised.
15. Regional information
Canada: Users may request access and correction and may challenge ShiftSend's compliance. Canadian users may contact the Office of the Privacy Commissioner of Canada or their provincial privacy regulator where applicable. Quebec users may contact the Commission d'accès à l'information du Québec and can access a French version of this policy.
European Economic Area and United Kingdom: Users may have rights of access, correction, deletion, portability, restriction, objection, and withdrawal of consent, and may complain to their local supervisory authority. ShiftSend does not use personal information to make solely automated decisions that produce legal or similarly significant effects.
United States: Residents of states with applicable privacy laws may have rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of certain sales, sharing, targeted advertising, or profiling. ShiftSend does not currently sell personal information or use it for cross-context behavioral advertising. Applicable requests can be submitted using the contact method in section 12.
16. Changes to this policy
ShiftSend may update this policy when the service, providers, or legal requirements change. The updated date will appear at the top. Material changes will be communicated through the website, workspace, email, or another appropriate method before they take effect when required. ShiftSend will request new consent before using information for a materially different purpose when applicable law or Google policy requires it.
17. Contact the Privacy Officer
Luca Aubry DeFilippo, Privacy Officer
ShiftSend
Montréal, Quebec, Canada
[email protected]
