Legal

Privacy Policy

Last updated June 24, 2026

This Privacy Policy applies to the SHIFT mobile app, our website at www.joinshift.com, and the related tasks, recordings, and features we provide (together, the “Services”), operated by microagi GmbH (“Shift,” “we,” “us”).

Last updated: June 24, 2026 Version: EU version · Version 1.0

1. Introduction

This Privacy Policy explains how microagi GmbH collects, uses, shares, and protects information when you use the SHIFT app, visit our website, create an account, book a task, work as an operator, or otherwise interact with our Services. It explains what personal data we process, on what legal basis, and the rights you have under the EU General Data Protection Regulation (GDPR).

Who is responsible for your data (controller): microagi GmbH, Jülicher Straße 209 q/s, 52070 Aachen, Germany (Amtsgericht Aachen, HRB 110642), is the controller within the meaning of Art. 4(7) GDPR for the personal data processed through the Services and determines the purposes and means of processing. We create reduced-identifiability datasets from recordings and make them available to other microagi group entities and to customers, who act as separate, independent controllers for their own purposes. For certain partnership collections where we and a partner jointly determine the purposes and means of processing, we act as joint controllers under Art. 26 GDPR on the basis of a separate arrangement, the essence of which is made available to the data subjects concerned.

2. Who this policy covers

  • App and website users — anyone who uses the SHIFT app or browses our website.
  • Clients and households — people who book a task and anyone present where a task is recorded.
  • Operators — individuals who perform recorded tasks whether directly for Shift or as personnel of a Provider on the platform.

3. Information we collect

3.1 Information you provide

  • Account data: name, email, phone, password, and (for operators) information needed for payment, identity, residency, and tax compliance.
  • Booking data: service address, task details, and scheduling information. Payment data (clients): where a booking carries a cancellation or no-show fee, we collect your payment-card details, processed by our payment provider, to authorise and, where applicable, charge that fee.
  • Communications: messages you send through contact forms, support requests, or email.
  • SMS opt-in: your mobile number if you choose to receive text messages (see Section 9).

3.2 Recordings (service data)

When a task is performed, our operator records a session consisting of first-person (egocentric) video, motion and sensor data (IMU), and a metadata file that includes GPS location, the operator’s approximate height, phone model, and camera parameters. These recordings necessarily capture the space where the task takes place — its interior, contents, and layout — and may capture other people who are present. See Section 7 for how recordings are processed, stored, and how you can ask us to remove a session.

3.3 Information collected automatically

When you use the app or website, we and our service providers automatically collect:

  • Log and device data: IP address, browser type and version, operating system, mobile device type and identifiers, app version, referring/exit pages, and dates/times of access.
  • Usage and app interaction data: pages and screens viewed, features used, links and buttons tapped, time spent, and similar activity, collected through server logs and, in the app, mobile SDKs (see Section 5).
  • Approximate location: derived from your IP address or, with your permission, more precise location from your device (see Section 3.4).

3.4 Permissions you grant in the app

To perform recorded tasks, the SHIFT app asks your permission to access certain features of your device. You can grant or withdraw these at any time in your device settings; withdrawing a permission may stop parts of the Services from working.

  • Camera and microphone — to record task sessions.
  • Motion and other sensors — to capture device motion and movement data during a task.
  • Precise location (GPS) — to associate a session with where it was performed.
  • Photos/files and notifications — to upload session files and to send you service and (with opt-in) marketing messages.

4. How we use information

  • Operate, maintain, secure, and improve the Website and our services.
  • Create, schedule, and perform tasks, and pay operators.
  • Create training datasets for AI and robotics and license them to customers (see Section 6).
  • Respond to your inquiries and provide support.
  • Send service messages and, with your opt-in, marketing messages.
  • Detect, prevent, and address fraud, security, and safety issues, and comply with law.

We do not sell your personal information for third-party advertising, and we do not share it for cross-context behavioral advertising.

Legal bases (GDPR). We process your personal data on the following bases: performance of a contract with you and pre-contractual steps (Art. 6(1)(b)) to create and perform tasks and pay operators; our legitimate interests (Art. 6(1)(f)) in building and improving AI and robotics datasets, securing the Services, and preventing fraud, balanced against your rights; compliance with legal obligations (Art. 6(1)(c)) such as tax and accounting duties; and your consent (Art. 6(1)(a)) for non-essential cookies, precise location, marketing messages and — together with Art. 9(2)(a) — for any special categories of data a recording may reveal. You may withdraw consent at any time without affecting prior processing.

5. Cookies, SDKs, and analytics

On our website we use a consent management platform to control non-essential cookies and similar browser storage. Essential cookies and storage are used to deliver and secure the site. Where required, analytics and marketing technologies load only after you consent to the relevant category. In our app we may use software development kits (SDKs) and mobile identifiers to operate the Services, remember your preferences, and understand how the Services are used. You can manage mobile identifiers and tracking through your device settings; blocking some of these may affect how the Services work.

CategoryPurposeControl
Strictly necessaryDeliver and secure the site and Services.Always on
Performance / analyticsMicrosoft Clarity may be used to understand site usage, conversion performance, heatmaps and session replay after analytics consent where required.Opt-in / opt-out where required
MarketingMeta Pixel may be used to measure campaign performance and form conversions after marketing consent where required.Opt-in / opt-out where required
FunctionalRemember app preferences such as language or region.Device settings / opt-in where required

We honor recognized opt-out preference signals (such as Global Privacy Control) where required by law. You can change your website cookie choices through the cookie banner or revisit control.

6. How we share information

  • microagi group and customers: recordings are processed into datasets that are transferred to microagi group entities and licensed to customers for AI/robotics development.
  • Service providers: payment and identity-verification providers (for example dots and Remofirst), cloud hosting (Google Cloud, EU/Belgium), analytics, and communications vendors, acting on our documented instructions as processors under a data processing agreement pursuant to Art. 28 GDPR.
  • Legal and safety: where required by law or to protect rights, safety, and property.
  • Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets.
  • Providers (the business performing your booking): to carry out a booking you make, we share the booking details and your contact details, including your name and phone number, with the Provider (for example the cleaning company) and its assigned personnel so they can perform the Service and contact you about the appointment.

International transfer. Recordings and related data are stored and processed on our cloud provider’s servers in the European Union (Belgium) from the time of upload, and reduced-identifiability datasets are made available to microagi group entities and customers. Data is collected worldwide, it is transferred to and processed in the EU. Personal data is processed within the EU/EEA. Where data is transferred to a recipient outside the EU/EEA (for example a group entity or customer in a third country), we rely on an adequacy decision or appropriate safeguards under Art. 44 et seq. GDPR, in particular the European Commission’s Standard Contractual Clauses, and make a copy of the safeguards available on request.

7. How we handle recordings and your choices

Where recordings are processed and stored

Recordings, together with the related motion and metadata, are transmitted from the operator’s device to our cloud service provider using encryption and are stored and processed on servers located in the European Union (Belgium). When a recording is first created and uploaded, it still contains personal information, including images of people and surroundings.

How we reduce identifiability

We use automated tools to reduce the likelihood that an individual can be identified from a recording. These tools blur or mask faces and heads, license plates, screens, identity documents, and payment cards, and we reduce the precision of the location data associated with a session. We apply these measures before a dataset is finalized, and customers receive only this reduced-identifiability version.

We do not represent that recordings are fully or permanently anonymous. The interior of a home and its contents remain part of a recording by design, and such details can sometimes be associated with a person or household. We therefore continue to treat recordings, and the datasets created from them, as personal information that carries a risk of re-identification, and we protect them accordingly.

Who can access recordings

Access to recordings is limited to personnel and service providers who need it to operate, secure, and improve our services. In limited cases — such as reviewing a recording flagged for possible fraud or a policy violation — trained reviewers may access a recording before identifying details have been reduced.

Your choice to remove a session

You may ask us to delete a specific recorded session. We can delete a session at any time before it has been incorporated, in reduced-identifiability form, into a dataset that has been made available to others. After that point, our ability to remove it from datasets already provided to others is limited; we will explain what we can and cannot do and will delete it to the extent technically possible. To make a request, see Section 12.

8. Consent to recording

Where a Service is booked through the platform, recording proceeds only where the Client has consented to it at booking, as a condition of the preferential (free or discounted) price. The Client is responsible for informing, and where required obtaining the agreement of, other adults present, and for ensuring the area does not include spaces or activities that should not be recorded. Where an individual performs and records tasks directly for Shift (an Operator), that individual is informed of the recording and consents to it. In all cases, recordings are limited to the work and its immediate surroundings; minors, intimate or medical situations, and sensitive identifiers must not be recorded; and recording may be paused or stopped at any time. See the Shift Platform Terms, the Service Terms, and the Operator Terms for details.

9. SMS messages

If you opt in, you may receive SMS such as appointment reminders and confirmations, onboarding and account updates, support responses, and (with separate opt-in) promotional messages. Message frequency varies and message/data rates may apply. Reply STOP to cancel or HELP for help. Consent is not a condition of any service. We do not share mobile information with third parties or affiliates for their marketing or promotional purposes.

10. Your privacy rights

Your rights depend on where you live, and we honour the rights available to you under the law that applies to you.

EEA, United Kingdom and Switzerland. Under the EU GDPR, the UK GDPR and the Swiss FADP you have the right to access your personal data and obtain a copy; to rectification; to erasure; to restriction of processing; to data portability; to object to processing based on our legitimate interests; and, where processing is based on consent, to withdraw consent at any time without affecting processing before withdrawal. You may lodge a complaint with your supervisory authority — for microagi GmbH the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (Germany), in the UK the Information Commissioner’s Office (ICO), in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or the authority of your country of residence or workplace.

United States (including California and other states with privacy laws). You may have the right to know what personal information we collect and how it is used and shared; to access, correct and delete it; to opt out of any “sale” or “share” of personal information and of targeted advertising; to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights. You may use an authorized agent where the law allows. We do not sell personal information or share it for cross-context behavioral advertising.

Türkiye. Under the Turkish Personal Data Protection Law (KVKK) you may learn whether your data is processed, request information, correction or deletion, object to outcomes of automated analysis, and seek compensation for unlawful processing; you may apply to us and then to the Turkish Data Protection Authority (Kişisel Verileri Koruma Kurumu).

Other countries. Depending on your country of residence you may have additional or different rights; we honour them as required by applicable law.

To exercise a right, contact us using Section 12. We will verify and respond within the timeframes required by applicable law. To remove a recorded session, see Section 7.

11. Data retention, security, and children

  • Retention: we keep personal information only as long as needed for the purposes in this Policy or as required by law. Unless a longer period is required by law, we apply the following schedule:
Data categoryRetention periodReason
Account dataUp to 7 years after account closure where required for tax/accounting obligations; otherwise deleted soonerLegal and tax compliance
Operator payment & tax records7 yearsTax and accounting law
Support requests & communications3 yearsResponding to and documenting inquiries and disputes
Raw recordings (still containing personal information)Until the de-identified dataset is created, plus up to 90 daysValidation, quality control, and fraud review; deleted after this window
De-identified dataset copiesFor the life of the relevant dataset/product, reviewed at least every 3 yearsAI and robotics development
Website/app log & usage data18 monthsSecurity, troubleshooting, and analytics
Cookies / SDK dataBrowser storage only as technically required for the website; app SDK/mobile identifier data as controlled in your device settings, typically up to 13 monthsSecurity, preferences and app analytics
Marketing / SMS opt-in dataUntil you opt out, after which we keep a minimal suppression recordHonoring your communication choices
  • Security: recordings and related data are stored and processed on our cloud provider’s servers in the European Union (Belgium), with encryption in transit and at rest and access controls aligned to the provider’s security standards. We also use monitoring and staff training. No method of transmission or storage is completely secure.
  • Children: the Services are not directed to children; operators are instructed not to record minors; we do not knowingly collect personal information from children under 16 (the age of digital consent in Germany under Art. 8 GDPR and § 25 TTDSG).

12. Changes and how to contact us

We will post material changes here and update the “Last updated” date. For privacy questions or to exercise your rights, contact:

microagi GmbH — Data Protection

Jülicher Straße 209 q/s, 52070 Aachen, Germany

info@joinshift.ai

© 2026 microagi GmbH. All rights reserved.