WS
Weeksolved
Open the app →

Privacy Policy

Effective date: September 12, 2026 Last updated: September 12, 2026

This policy explains what Weeksolved collects, where it goes, who can reach it, and what you can do about it. It covers weeksolved.com and the Weeksolved application.

We have tried to write this so you can actually read it. Where something is unflattering, we have said it anyway.


The short version


1. Who is responsible for what

Weeksolved handles two different kinds of information, and the legal roles are different for each. This distinction matters, so it comes first.

Your account information Your employees' information
Whose data The manager or admin who signs up The staff you schedule
Who decides what is collected We do You do
Our role under the CCPA Business Service provider
Your role under the CCPA Consumer Business
Who gives the privacy notice We do (this document) You do, to your employees
Who answers rights requests We do You do; we assist you

What that means in practice. We process your employees' information only on your documented instructions, to provide the service. We do not decide what to collect about them, we do not use it for our own purposes, and we do not sell or share it. If one of your employees contacts us directly, we will refer them to you, tell you they contacted us, and take no action on their data without your instruction.

Since January 1, 2023, when the CCPA's exemption for employee data expired, California employers have had to give their own employees a notice at collection and honor their privacy rights. That obligation is yours. We will give you what you need to meet it.


2. What we collect

2.1 Information you give us about yourself (account information)

Category (CCPA terms) What it is Where it comes from Why we have it Kept for
Identifiers Your email address; your account ID You, at sign-up To create and secure your account; to contact you about the service While your account is active, then 30 days
Account credentials Your password You, at sign-up Authentication. Held in hashed form by the authentication service — Firebase Authentication today, Supabase Auth after the move. We never see it and cannot retrieve it. While your account is active
Identifiers, if you sign in with Google The name, email address and profile-picture link on your Google account Google, when you choose "Sign in with Google" Authentication. We use the email address only; the name and picture sit unused in the sign-in record. While your account is active, then 30 days
Commercial information Your invitation code; your plan; subscription status; renewal date You, and Stripe once paid plans begin To grant access, run billing While active + 7 years for tax records
Commercial / financial information Billing contact name and email; billing address; invoices, charges, refunds and disputes; the last four digits, brand and expiry of your card. Never the full card number — that stays with Stripe. You, at checkout, through Stripe To take payment, issue receipts and refunds, and answer a disputed charge 7 years, for tax and accounting law
Internet or network activity Basic technical error information in problem reports Your browser, when you file a report To fix bugs Up to 24 months

What Stripe holds, and what we hold. When paid plans begin, Stripe, Inc. runs checkout and the billing portal for us. Stripe holds the name and email address you give at checkout, your billing address, your card details, and your billing history — invoices, charges, refunds and disputes. Your full card number never reaches us. It goes from your browser to Stripe. What comes back to us is the last four digits, the brand and expiry, whether a charge succeeded, and the invoice record, which is what we need to run your account and answer a dispute.

Weeksolved is the seller of record — you buy from us, not from a reseller — and Stripe is the payment processor. Stripe also uses the payment information it collects for its own purposes as a payments business, including fraud prevention and its own legal obligations, under its own privacy policy. That part is between you and Stripe, and we cannot vary it.

Nothing about your employees goes to Stripe. No names, no hours, no pay rates, no schedules. Stripe knows a business subscribed and paid; it knows nothing about who works there.

2.2 Information you enter about your employees (customer data)

You decide what goes in here. The fields the product offers are:

Category (CCPA terms) Fields Optional? Why the product has it
Identifiers Name, email address, phone number Email/phone optional To identify staff and let you contact them
Professional or employment information Employment type, availability, hours worked and scheduled, license expiry dates Some optional To build schedules; to warn on expiring licenses
Commercial / financial information Hourly pay rate Optional To calculate labor cost on a schedule
Protected classification characteristic Date of birth Optional Only to warn about work-hour limits for employees under 18
Professional or employment information Time-off records, sick-leave records, callout and no-show records — Availability and attendance tracking
Any category, depending on what you type Free-text notes — Whatever you use them for
Professional or employment information If you turn on the optional advanced features: overtime offers and refusals; mandatory-overtime rotation position; an audit log of changes made to schedules after posting Off by default Fair-rotation tracking and change history, if you want them

Three honest notes on this table.

Free-text notes accept anything. We have no way to stop you typing something sensitive into a notes field. Our Terms of Service ask you not to. Whatever you type is stored the same way as everything else.

Sick-leave records are health-adjacent. The product records that leave was taken, not why. It is not a medical record system, we are not a HIPAA business associate, and no diagnosis, condition, or medical document should be entered. If you work anywhere that handles patient or client health records: none of it belongs in Weeksolved.

The optional advanced features record employee conduct. Overtime refusals, callouts, no-shows, and the post-posting audit log create a record of individual behavior that could be used in a discipline or grievance process. They are off by default and it is your decision whether to turn them on. If you have a collective bargaining agreement, check it before you do.

2.3 What we do not collect

2.3a One other company sees your browser connect

We want to be exact about this, because "no trackers" is true and still not the whole picture.

When the page loads, your browser fetches one thing from outside our control:

What From What they can see
The sign-in and sync library Google (www.gstatic.com) today; Supabase's United States endpoint after the move Your IP address, browser and operating system, and that a Weeksolved page was opened

It used to be three. The typefaces came from Google Fonts and the library that builds PDF exports came from Cloudflare's public CDN; both are now carried inside the page itself, so neither company is contacted at all. The sign-in library is the one that cannot go, because it is the service that holds your account and your board. When the move to Supabase is complete, that request goes to Supabase's United States endpoint instead of to Google, and we will update this table then. It stays one request either way.

The page itself is served by GitHub Pages, so GitHub sees the same thing any web host sees: your IP address and the fact that a page was requested. It never receives your board, your staff, or anything you typed — the application runs inside your browser.

It does not receive your schedule, your staff, or anything you typed. It serves a file; that is all. But a request carries an IP address, and an IP address is personal information, so we are not going to describe this product as "nothing leaves your browser" when one request does.

It is not required for the product to work. Blocked — by a corporate firewall, an ad blocker, or no internet at all — Weeksolved still opens, still drafts a schedule, still places breaks, still prints and still exports a PDF, in the designed typefaces. The only thing you lose is signing in to an account, and with it the copy of your board that syncs between devices. Everything else is unaffected. We test this.

If your organization cannot accept even that one request, tell us. A build with no account service at all — the board stored on the device and nothing sent anywhere — is a change to how we package it, not to how it works.

2.4 Sensitive personal information

The CCPA defines a specific list of "sensitive personal information" — Social Security and government ID numbers, financial account details, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of private communications, genetic and biometric data, health information, and sexual orientation or sex life.

The product has no fields for any of it, and we do not ask you for any of it. Date of birth is not on that list. We do not use or disclose sensitive personal information for any purpose that would require us to offer a "Limit the Use of My Sensitive Personal Information" link.

The one gap is the free-text notes field, where you could enter such information yourself. Please do not. Our Terms of Service section 4(f) lists what to keep out.


3. Where your data lives, and who can reach it

3.1 Where it lives

In your browser. Weeksolved is a single-page application: the whole program runs in your browser. Your data is stored there, in browser localStorage, which is why the app keeps working when you are offline. That copy is on your device and under your control. Clearing your browser data clears it.

In our database, if you sign in. If you sign in, your data also syncs to our database. That database is in the United States, and only in the United States. We are in the middle of moving it:

Both are listed as subprocessors in section 4 while the transition runs. When it is finished, Firebase comes off that list and this section says so. We are not running two live copies of your data indefinitely: one system is authoritative at a time, and we will tell you when that changes. Nothing about the move sends your data outside the United States, and nothing about it changes who can reach your data or what we may do with it.

In both systems your data is protected in transit and at rest by the platform's encryption, and by per-account rules enforced at the database itself — Firestore security rules today, Postgres row-level security on Supabase — under which an account can read only its own data.

Your password is held hashed by the authentication service — Firebase Authentication today, Supabase Auth after the move. We never see it and cannot recover it; if you lose it, you reset it. If you choose Sign in with Google instead, Google confirms who you are and passes us the name, email address and profile-picture link on your Google account; we use the email address only, and no password is created unless you add one yourself.

Your billing details live with Stripe, in the United States, as set out in section 2.1. They are not in the scheduling database.

3.2 Who can reach it — read this part

Your data is protected from other customers by per-account security rules. Those rules are how accounts are kept apart, and they are enforced by the database provider's infrastructure, not by our application code alone.

They do not, and cannot, keep us out.

We operate the database. Like the operator of any hosted service, we can technically reach it through the provider's console — the Google Firebase console today, the Supabase dashboard after the move. We are telling you this plainly because the alternative — implying that we have made it technically impossible for us to see your data — would not be true. We do not offer customer-managed encryption keys, and we do not hold your data under a key we cannot access. Changing database providers does not change this, and we are not going to present the move as if it did.

What we commit to instead is a rule about when we will look:

Access to the production database — either one, during the transition — is limited to one person, the owner of the business. As the company grows, access will be granted on a need-to-do-the-job basis and removed when the need ends.

If you are a business or agency buyer and you want these commitments as contract terms rather than policy statements, our Data Processing Addendum puts them in writing and is signable.

3.3 What is not encrypted end-to-end

To be clear about what the encryption above does and does not do: your data is encrypted in transit between your browser and the database, and encrypted at rest on the provider's disks. It is not end-to-end encrypted in the sense of being unreadable to us. That is true of Firebase today and it will be true of Supabase. See 3.2.


4. Who else we give data to (subprocessors)

We do not sell your data and we do not share it for advertising. We do use a small number of vendors to run the service. Here is the complete list.

Subprocessor What they do What they get Where Status
Supabase, Inc. Database and authentication — the system your account and your board live in Account information and all customer data you sync; your email address and hashed password United States (region us-west-1) Becoming live. The system we are moving to.
Stripe, Inc. Payments — checkout, the billing portal, invoices and refunds Your billing contact name and email, billing address, card details and billing history. Stripe holds the card number; we never see or store it. No employee information of any kind. United States Not live. Begins when paid plans start.
Google LLC — Firebase / Cloud Firestore and Firebase Authentication Database and sign-in during the transition, while we move to Supabase Account information and all customer data you sync; your email address and hashed password; with Google sign-in, the name, email address and profile-picture link Google provides United States Live during the transition. Comes off this list when the move is complete.
GitHub, Inc. — GitHub Pages Hosting — serving the website and the application file to your browser Your IP address and standard web request information when a page loads. No account data and no employee data: the application runs in your browser and does not send your board to the host. United States Live

That is the whole list. Paddle is no longer on it — we chose Stripe instead, and Weeksolved, not the payment company, is the seller of record for your purchase.

We will update this table before adding a subprocessor, and customers under a Data Processing Addendum get advance notice and a right to object, as set out there.

4.1 About email — how it works today

Right now, Weeksolved sends no email at all.

When you use a feature that emails a staff member, the app opens a pre-filled draft in your own mail client using a mailto: link. The message is composed and sent by you, from your own email account, through your own email provider. It never touches our servers, and we have no copy of it and no record that you sent it.

That means your own email provider's privacy practices apply to those messages, not ours.

This is changing. We plan to add a server-side email sender in January 2027, so that we can send the things a paid service has to send — receipts, renewal reminders, and security notices — from our own systems rather than by hand. When that happens, messages you send through the product will pass through our systems and a third-party sending provider. We will name that provider in the table above at least 30 days before it starts handling anything, and we will tell you before the change takes effect. Billing emails from Stripe (receipts and card-expiry notices) come from Stripe as part of the payment service.

4.2 Other disclosures

We may disclose information:

Any successor takes the data subject to the same commitments. A change of ownership is not permission to start selling data.


5. What we never do


6. Retention and deletion

What How long
Account information While your account is active, then 30 days after termination
Customer data (employee information) While your account is active. On termination, available for export for 30 days, then deleted
Data in your browser Until you clear it. It is on your device; we cannot delete it for you
Billing and transaction records (held by us and by Stripe) 7 years, for tax and accounting law
Card details Held by Stripe for as long as the subscription needs them, then under Stripe's own retention rules. We never hold them at all
The list of devices that have opened your account While the device is signed in. It is removed when you sign that device out, when you use "sign out everywhere else", or when you close the account
Problem reports Up to 24 months
Security and access logs Up to 12 months
Backups Deleted data may persist in routine backups for up to 14 days and is then overwritten. Deleted data is not restored to live systems

Tester accounts. If your tester access expires, your data is retained so you can come back. Ask us and we will delete it. We will contact expired tester accounts before the paid launch to ask whether to keep or delete the data, and we will delete data belonging to any tester who does not respond within 90 days of that notice.

Deletion is real. When we delete, we delete — subject only to the backup window above and to records we are legally required to keep.


7. Your rights

7.1 If you are a Weeksolved account holder

You have the right to:

How to exercise them. Email privacy@weeksolved.com with what you want. You can also export your data yourself from inside the app at any time, and delete your account yourself.

How we verify you. We will ask you to send the request from the email address on the account, and we may ask you to confirm details only the account holder would know. We do this to avoid handing your data to someone pretending to be you. We do not ask for government ID.

How long we take. We confirm receipt within 10 business days and respond within 45 calendar days. If we need more time we will tell you why, and take no more than 90 days total. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you before doing anything.

Authorized agents. You may use an authorized agent. We will ask for written permission signed by you, and we may ask you to confirm directly.

Appeals. If we deny a request, we will tell you why. You may appeal by replying to our decision, and a human being will review it. You may also complain to the California Privacy Protection Agency at cppa.ca.gov or the California Attorney General at oag.ca.gov.

7.2 If you are an employee of a Weeksolved customer

Your employer decided to put your information into Weeksolved. They chose the tool, they chose what to enter, and they control it.

So your request goes to your employer, not to us. Ask your manager, your HR department, or whoever handles privacy at your workplace. Under California law, your employer must give you a notice about the information it collects on you and must honor your privacy rights.

If you contact us instead, we will tell you this, let your employer know you got in touch, and not act on your data ourselves. That is not us brushing you off — we are legally the service provider here, and acting on your data without your employer's instruction would be the wrong thing for us to do.

If your employer will not respond, you can complain to the California Privacy Protection Agency (cppa.ca.gov), the California Attorney General (oag.ca.gov), or the California Civil Rights Department.

7.3 If you are outside California

We extend the access, correction, deletion, and portability rights above to everyone who asks, wherever you are, rather than checking your address first.


8. Automated decision-making

Weeksolved builds draft schedules from rules that the manager sets, and shows warnings. A human manager reviews and publishes every schedule. The software does not assign anyone to a shift on its own, and it does not make hiring, pay, promotion, discipline, or termination decisions.

California's regulations on automated decisionmaking technology take effect January 1, 2027. They apply to businesses that use such technology to make significant employment decisions, including work assignment and compensation. If those rules apply to a use of Weeksolved, the obligations fall on the employer using the tool, not on us as the vendor.

If you are a customer and you need to document how the product works for a risk assessment or a pre-use notice, ask us at privacy@weeksolved.com and we will help.


9. Minors

Weeksolved is not directed to children and is not intended for anyone under 18. Only managers have accounts, and account holders must be 18 or older. Employees, including employees under 18, have no logins and never use the product.

The product lets an employer optionally record an employee's date of birth for one reason: to warn the employer about work-hour limits that apply to workers under 18. That value is entered by the adult employer, about their employee.

The Children's Online Privacy Protection Act does not apply to us. COPPA covers operators of sites and services directed to children under 13 that collect personal information from children. We do not collect information online from children. Information an adult employer enters about a young worker is not information collected from a child, and the FTC's own guidance states that COPPA does not apply to information about children collected from adults. In any event, employees under 13 are not lawfully employable in the settings Weeksolved serves.

Employers remain responsible for handling a minor employee's information under the laws that apply to them.


10. Security

What we actually do:

What we are not claiming: we hold no SOC 2 report, no ISO 27001 certificate, and no third-party penetration test as of this policy's date. If we get them, we will say so here. We would rather tell you that now than have you find out during a security review.

No system is perfectly secure. Anyone who tells you otherwise is selling something. Keep your password strong and unique, do not share accounts, and remove access for people who leave.

10.1 Two controls you have, and what each one actually does

Settings shows every device that has opened your account — a rough label such as "Windows · Chrome", the nearest city from the time zone the browser reports, and when it was last seen. Two things you can do with that, described honestly, because the difference matters:

Signing devices out does not change your password, and no sign-out keeps out somebody who still knows it. We would rather say that here than have you press the reassuring button and think you are finished.

If you believe you have found a vulnerability, email security@weeksolved.com. We will acknowledge within 3 business days. We will not pursue legal action against anyone who reports a vulnerability in good faith, does not access or alter other people's data, and gives us a reasonable chance to fix it before going public.


11. If there is a breach

If personal information is exposed by a security incident, we will:

  1. Tell affected customers without undue delay, and no later than 72 hours after we confirm a breach affecting their data. Customers under a Data Processing Addendum get the same commitment as a contract term.
  2. Tell you what we know: what happened, when, what categories of information and roughly how many people were affected, what we have done, and what we recommend you do.
  3. Keep you updated as we learn more. We would rather send you an incomplete notice on time than a complete one late.
  4. Give you the information you need to make your own notifications. You, as the employer, are the one who must notify your employees and any regulator under California Civil Code sections 1798.29 and 1798.82 and any other law that applies to you. We will support you; we will not do it for you, because they are your employees.
  5. Make our own notifications where the law requires us to.

12. Changes to this policy

What changed on September 12, 2026. The subprocessor list in section 4 changed, and this is the notice of it:

This paragraph is the 30 days' notice that section 5.3 of the Data Processing Addendum requires, and it starts running today. If you are under a Data Processing Addendum and you object on reasonable data-protection grounds, section 5.4 there tells you what happens next, including your right to leave and get your unused fees back.

If we change this policy materially, we will post the new version with a new effective date and notify account holders by email or in the app at least 30 days before it takes effect. Non-material changes take effect when posted.

We keep prior versions available at https://weeksolved.com/privacy.html so you can see what changed.

We will not apply a materially less protective policy to data we already collected without asking you first.


13. Contact

Privacy questions, rights requests, and complaints: privacy@weeksolved.com

Security reports: security@weeksolved.com

Postal: Weeksolved, a California sole proprietorship 2108 N Street, Suite 17551, Sacramento, CA 95816

We are a small company. A person reads these, and it is usually the person who wrote the software.