Effective date: September 12, 2026 Last updated: September 12, 2026
This policy explains what Weeksolved collects, where it goes, who can reach it, and what you can do about it. It covers weeksolved.com and the Weeksolved application.
We have tried to write this so you can actually read it. Where something is unflattering, we have said it anyway.
Weeksolved handles two different kinds of information, and the legal roles are different for each. This distinction matters, so it comes first.
| Your account information | Your employees' information | |
|---|---|---|
| Whose data | The manager or admin who signs up | The staff you schedule |
| Who decides what is collected | We do | You do |
| Our role under the CCPA | Business | Service provider |
| Your role under the CCPA | Consumer | Business |
| Who gives the privacy notice | We do (this document) | You do, to your employees |
| Who answers rights requests | We do | You do; we assist you |
What that means in practice. We process your employees' information only on your documented instructions, to provide the service. We do not decide what to collect about them, we do not use it for our own purposes, and we do not sell or share it. If one of your employees contacts us directly, we will refer them to you, tell you they contacted us, and take no action on their data without your instruction.
Since January 1, 2023, when the CCPA's exemption for employee data expired, California employers have had to give their own employees a notice at collection and honor their privacy rights. That obligation is yours. We will give you what you need to meet it.
| Category (CCPA terms) | What it is | Where it comes from | Why we have it | Kept for |
|---|---|---|---|---|
| Identifiers | Your email address; your account ID | You, at sign-up | To create and secure your account; to contact you about the service | While your account is active, then 30 days |
| Account credentials | Your password | You, at sign-up | Authentication. Held in hashed form by the authentication service — Firebase Authentication today, Supabase Auth after the move. We never see it and cannot retrieve it. | While your account is active |
| Identifiers, if you sign in with Google | The name, email address and profile-picture link on your Google account | Google, when you choose "Sign in with Google" | Authentication. We use the email address only; the name and picture sit unused in the sign-in record. | While your account is active, then 30 days |
| Commercial information | Your invitation code; your plan; subscription status; renewal date | You, and Stripe once paid plans begin | To grant access, run billing | While active + 7 years for tax records |
| Commercial / financial information | Billing contact name and email; billing address; invoices, charges, refunds and disputes; the last four digits, brand and expiry of your card. Never the full card number — that stays with Stripe. | You, at checkout, through Stripe | To take payment, issue receipts and refunds, and answer a disputed charge | 7 years, for tax and accounting law |
| Internet or network activity | Basic technical error information in problem reports | Your browser, when you file a report | To fix bugs | Up to 24 months |
What Stripe holds, and what we hold. When paid plans begin, Stripe, Inc. runs checkout and the billing portal for us. Stripe holds the name and email address you give at checkout, your billing address, your card details, and your billing history — invoices, charges, refunds and disputes. Your full card number never reaches us. It goes from your browser to Stripe. What comes back to us is the last four digits, the brand and expiry, whether a charge succeeded, and the invoice record, which is what we need to run your account and answer a dispute.
Weeksolved is the seller of record — you buy from us, not from a reseller — and Stripe is the payment processor. Stripe also uses the payment information it collects for its own purposes as a payments business, including fraud prevention and its own legal obligations, under its own privacy policy. That part is between you and Stripe, and we cannot vary it.
Nothing about your employees goes to Stripe. No names, no hours, no pay rates, no schedules. Stripe knows a business subscribed and paid; it knows nothing about who works there.
You decide what goes in here. The fields the product offers are:
| Category (CCPA terms) | Fields | Optional? | Why the product has it |
|---|---|---|---|
| Identifiers | Name, email address, phone number | Email/phone optional | To identify staff and let you contact them |
| Professional or employment information | Employment type, availability, hours worked and scheduled, license expiry dates | Some optional | To build schedules; to warn on expiring licenses |
| Commercial / financial information | Hourly pay rate | Optional | To calculate labor cost on a schedule |
| Protected classification characteristic | Date of birth | Optional | Only to warn about work-hour limits for employees under 18 |
| Professional or employment information | Time-off records, sick-leave records, callout and no-show records | — | Availability and attendance tracking |
| Any category, depending on what you type | Free-text notes | — | Whatever you use them for |
| Professional or employment information | If you turn on the optional advanced features: overtime offers and refusals; mandatory-overtime rotation position; an audit log of changes made to schedules after posting | Off by default | Fair-rotation tracking and change history, if you want them |
Three honest notes on this table.
Free-text notes accept anything. We have no way to stop you typing something sensitive into a notes field. Our Terms of Service ask you not to. Whatever you type is stored the same way as everything else.
Sick-leave records are health-adjacent. The product records that leave was taken, not why. It is not a medical record system, we are not a HIPAA business associate, and no diagnosis, condition, or medical document should be entered. If you work anywhere that handles patient or client health records: none of it belongs in Weeksolved.
The optional advanced features record employee conduct. Overtime refusals, callouts, no-shows, and the post-posting audit log create a record of individual behavior that could be used in a discipline or grievance process. They are off by default and it is your decision whether to turn them on. If you have a collective bargaining agreement, check it before you do.
We want to be exact about this, because "no trackers" is true and still not the whole picture.
When the page loads, your browser fetches one thing from outside our control:
| What | From | What they can see |
|---|---|---|
| The sign-in and sync library | Google (www.gstatic.com) today; Supabase's United States endpoint after the move |
Your IP address, browser and operating system, and that a Weeksolved page was opened |
It used to be three. The typefaces came from Google Fonts and the library that builds PDF exports came from Cloudflare's public CDN; both are now carried inside the page itself, so neither company is contacted at all. The sign-in library is the one that cannot go, because it is the service that holds your account and your board. When the move to Supabase is complete, that request goes to Supabase's United States endpoint instead of to Google, and we will update this table then. It stays one request either way.
The page itself is served by GitHub Pages, so GitHub sees the same thing any web host sees: your IP address and the fact that a page was requested. It never receives your board, your staff, or anything you typed — the application runs inside your browser.
It does not receive your schedule, your staff, or anything you typed. It serves a file; that is all. But a request carries an IP address, and an IP address is personal information, so we are not going to describe this product as "nothing leaves your browser" when one request does.
It is not required for the product to work. Blocked — by a corporate firewall, an ad blocker, or no internet at all — Weeksolved still opens, still drafts a schedule, still places breaks, still prints and still exports a PDF, in the designed typefaces. The only thing you lose is signing in to an account, and with it the copy of your board that syncs between devices. Everything else is unaffected. We test this.
If your organization cannot accept even that one request, tell us. A build with no account service at all — the board stored on the device and nothing sent anywhere — is a change to how we package it, not to how it works.
The CCPA defines a specific list of "sensitive personal information" — Social Security and government ID numbers, financial account details, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of private communications, genetic and biometric data, health information, and sexual orientation or sex life.
The product has no fields for any of it, and we do not ask you for any of it. Date of birth is not on that list. We do not use or disclose sensitive personal information for any purpose that would require us to offer a "Limit the Use of My Sensitive Personal Information" link.
The one gap is the free-text notes field, where you could enter such information yourself. Please do not. Our Terms of Service section 4(f) lists what to keep out.
In your browser. Weeksolved is a single-page application: the whole program runs in your browser. Your data is stored there, in browser localStorage, which is why the app keeps working when you are offline. That copy is on your device and under your control. Clearing your browser data clears it.
In our database, if you sign in. If you sign in, your data also syncs to our database. That database is in the United States, and only in the United States. We are in the middle of moving it:
us-west-1 region, in the United States. Supabase becomes the live system when the move is complete.Both are listed as subprocessors in section 4 while the transition runs. When it is finished, Firebase comes off that list and this section says so. We are not running two live copies of your data indefinitely: one system is authoritative at a time, and we will tell you when that changes. Nothing about the move sends your data outside the United States, and nothing about it changes who can reach your data or what we may do with it.
In both systems your data is protected in transit and at rest by the platform's encryption, and by per-account rules enforced at the database itself — Firestore security rules today, Postgres row-level security on Supabase — under which an account can read only its own data.
Your password is held hashed by the authentication service — Firebase Authentication today, Supabase Auth after the move. We never see it and cannot recover it; if you lose it, you reset it. If you choose Sign in with Google instead, Google confirms who you are and passes us the name, email address and profile-picture link on your Google account; we use the email address only, and no password is created unless you add one yourself.
Your billing details live with Stripe, in the United States, as set out in section 2.1. They are not in the scheduling database.
Your data is protected from other customers by per-account security rules. Those rules are how accounts are kept apart, and they are enforced by the database provider's infrastructure, not by our application code alone.
They do not, and cannot, keep us out.
We operate the database. Like the operator of any hosted service, we can technically reach it through the provider's console — the Google Firebase console today, the Supabase dashboard after the move. We are telling you this plainly because the alternative — implying that we have made it technically impossible for us to see your data — would not be true. We do not offer customer-managed encryption keys, and we do not hold your data under a key we cannot access. Changing database providers does not change this, and we are not going to present the move as if it did.
What we commit to instead is a rule about when we will look:
Access to the production database — either one, during the transition — is limited to one person, the owner of the business. As the company grows, access will be granted on a need-to-do-the-job basis and removed when the need ends.
If you are a business or agency buyer and you want these commitments as contract terms rather than policy statements, our Data Processing Addendum puts them in writing and is signable.
To be clear about what the encryption above does and does not do: your data is encrypted in transit between your browser and the database, and encrypted at rest on the provider's disks. It is not end-to-end encrypted in the sense of being unreadable to us. That is true of Firebase today and it will be true of Supabase. See 3.2.
We do not sell your data and we do not share it for advertising. We do use a small number of vendors to run the service. Here is the complete list.
| Subprocessor | What they do | What they get | Where | Status |
|---|---|---|---|---|
| Supabase, Inc. | Database and authentication — the system your account and your board live in | Account information and all customer data you sync; your email address and hashed password | United States (region us-west-1) |
Becoming live. The system we are moving to. |
| Stripe, Inc. | Payments — checkout, the billing portal, invoices and refunds | Your billing contact name and email, billing address, card details and billing history. Stripe holds the card number; we never see or store it. No employee information of any kind. | United States | Not live. Begins when paid plans start. |
| Google LLC — Firebase / Cloud Firestore and Firebase Authentication | Database and sign-in during the transition, while we move to Supabase | Account information and all customer data you sync; your email address and hashed password; with Google sign-in, the name, email address and profile-picture link Google provides | United States | Live during the transition. Comes off this list when the move is complete. |
| GitHub, Inc. — GitHub Pages | Hosting — serving the website and the application file to your browser | Your IP address and standard web request information when a page loads. No account data and no employee data: the application runs in your browser and does not send your board to the host. | United States | Live |
That is the whole list. Paddle is no longer on it — we chose Stripe instead, and Weeksolved, not the payment company, is the seller of record for your purchase.
We will update this table before adding a subprocessor, and customers under a Data Processing Addendum get advance notice and a right to object, as set out there.
Right now, Weeksolved sends no email at all.
When you use a feature that emails a staff member, the app opens a pre-filled draft in your own mail client using a mailto: link. The message is composed and sent by you, from your own email account, through your own email provider. It never touches our servers, and we have no copy of it and no record that you sent it.
That means your own email provider's privacy practices apply to those messages, not ours.
This is changing. We plan to add a server-side email sender in January 2027, so that we can send the things a paid service has to send — receipts, renewal reminders, and security notices — from our own systems rather than by hand. When that happens, messages you send through the product will pass through our systems and a third-party sending provider. We will name that provider in the table above at least 30 days before it starts handling anything, and we will tell you before the change takes effect. Billing emails from Stripe (receipts and card-expiry notices) come from Stripe as part of the payment service.
We may disclose information:
Any successor takes the data subject to the same commitments. A change of ownership is not permission to start selling data.
| What | How long |
|---|---|
| Account information | While your account is active, then 30 days after termination |
| Customer data (employee information) | While your account is active. On termination, available for export for 30 days, then deleted |
| Data in your browser | Until you clear it. It is on your device; we cannot delete it for you |
| Billing and transaction records (held by us and by Stripe) | 7 years, for tax and accounting law |
| Card details | Held by Stripe for as long as the subscription needs them, then under Stripe's own retention rules. We never hold them at all |
| The list of devices that have opened your account | While the device is signed in. It is removed when you sign that device out, when you use "sign out everywhere else", or when you close the account |
| Problem reports | Up to 24 months |
| Security and access logs | Up to 12 months |
| Backups | Deleted data may persist in routine backups for up to 14 days and is then overwritten. Deleted data is not restored to live systems |
Tester accounts. If your tester access expires, your data is retained so you can come back. Ask us and we will delete it. We will contact expired tester accounts before the paid launch to ask whether to keep or delete the data, and we will delete data belonging to any tester who does not respond within 90 days of that notice.
Deletion is real. When we delete, we delete — subject only to the backup window above and to records we are legally required to keep.
You have the right to:
How to exercise them. Email privacy@weeksolved.com with what you want. You can also export your data yourself from inside the app at any time, and delete your account yourself.
How we verify you. We will ask you to send the request from the email address on the account, and we may ask you to confirm details only the account holder would know. We do this to avoid handing your data to someone pretending to be you. We do not ask for government ID.
How long we take. We confirm receipt within 10 business days and respond within 45 calendar days. If we need more time we will tell you why, and take no more than 90 days total. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you before doing anything.
Authorized agents. You may use an authorized agent. We will ask for written permission signed by you, and we may ask you to confirm directly.
Appeals. If we deny a request, we will tell you why. You may appeal by replying to our decision, and a human being will review it. You may also complain to the California Privacy Protection Agency at cppa.ca.gov or the California Attorney General at oag.ca.gov.
Your employer decided to put your information into Weeksolved. They chose the tool, they chose what to enter, and they control it.
So your request goes to your employer, not to us. Ask your manager, your HR department, or whoever handles privacy at your workplace. Under California law, your employer must give you a notice about the information it collects on you and must honor your privacy rights.
If you contact us instead, we will tell you this, let your employer know you got in touch, and not act on your data ourselves. That is not us brushing you off — we are legally the service provider here, and acting on your data without your employer's instruction would be the wrong thing for us to do.
If your employer will not respond, you can complain to the California Privacy Protection Agency (cppa.ca.gov), the California Attorney General (oag.ca.gov), or the California Civil Rights Department.
We extend the access, correction, deletion, and portability rights above to everyone who asks, wherever you are, rather than checking your address first.
Weeksolved builds draft schedules from rules that the manager sets, and shows warnings. A human manager reviews and publishes every schedule. The software does not assign anyone to a shift on its own, and it does not make hiring, pay, promotion, discipline, or termination decisions.
California's regulations on automated decisionmaking technology take effect January 1, 2027. They apply to businesses that use such technology to make significant employment decisions, including work assignment and compensation. If those rules apply to a use of Weeksolved, the obligations fall on the employer using the tool, not on us as the vendor.
If you are a customer and you need to document how the product works for a risk assessment or a pre-use notice, ask us at privacy@weeksolved.com and we will help.
Weeksolved is not directed to children and is not intended for anyone under 18. Only managers have accounts, and account holders must be 18 or older. Employees, including employees under 18, have no logins and never use the product.
The product lets an employer optionally record an employee's date of birth for one reason: to warn the employer about work-hour limits that apply to workers under 18. That value is entered by the adult employer, about their employee.
The Children's Online Privacy Protection Act does not apply to us. COPPA covers operators of sites and services directed to children under 13 that collect personal information from children. We do not collect information online from children. Information an adult employer enters about a young worker is not information collected from a child, and the FTC's own guidance states that COPPA does not apply to information about children collected from adults. In any event, employees under 13 are not lawfully employable in the settings Weeksolved serves.
Employers remain responsible for handling a minor employee's information under the laws that apply to them.
What we actually do:
What we are not claiming: we hold no SOC 2 report, no ISO 27001 certificate, and no third-party penetration test as of this policy's date. If we get them, we will say so here. We would rather tell you that now than have you find out during a security review.
No system is perfectly secure. Anyone who tells you otherwise is selling something. Keep your password strong and unique, do not share accounts, and remove access for people who leave.
Settings shows every device that has opened your account — a rough label such as "Windows · Chrome", the nearest city from the time zone the browser reports, and when it was last seen. Two things you can do with that, described honestly, because the difference matters:
Signing devices out does not change your password, and no sign-out keeps out somebody who still knows it. We would rather say that here than have you press the reassuring button and think you are finished.
If you believe you have found a vulnerability, email security@weeksolved.com. We will acknowledge within 3 business days. We will not pursue legal action against anyone who reports a vulnerability in good faith, does not access or alter other people's data, and gives us a reasonable chance to fix it before going public.
If personal information is exposed by a security incident, we will:
What changed on September 12, 2026. The subprocessor list in section 4 changed, and this is the notice of it:
This paragraph is the 30 days' notice that section 5.3 of the Data Processing Addendum requires, and it starts running today. If you are under a Data Processing Addendum and you object on reasonable data-protection grounds, section 5.4 there tells you what happens next, including your right to leave and get your unused fees back.
If we change this policy materially, we will post the new version with a new effective date and notify account holders by email or in the app at least 30 days before it takes effect. Non-material changes take effect when posted.
We keep prior versions available at https://weeksolved.com/privacy.html so you can see what changed.
We will not apply a materially less protective policy to data we already collected without asking you first.
Privacy questions, rights requests, and complaints: privacy@weeksolved.com
Security reports: security@weeksolved.com
Postal: Weeksolved, a California sole proprietorship 2108 N Street, Suite 17551, Sacramento, CA 95816
We are a small company. A person reads these, and it is usually the person who wrote the software.