Privacy policy

Your information,
handled with
care and clarity.

This policy explains what information Shyft collects, why we use it and the choices and rights available to you.

Read the policy
Last updated14 July 2026
Contactprojects@shyft.build
The short version

We collect only the information needed to respond, deliver the work and operate Shyft properly.

We do not sell personal information or share it with unrelated businesses for their own marketing.

Information may be processed by trusted providers that help us host the website, send emails, measure performance and deliver services.

You can ask us about the information we hold or request that it is corrected, restricted or deleted where the law gives you that right.

Privacy details

How information is collected, used and protected.

Select a section below for more detail. Contact us when something is unclear or you would like to exercise a data protection right.

Who this policy applies to

This policy explains how Shyft handles personal information when you visit our website, contact us, submit a project brief, request an audit, subscribe to updates or work with us as a client.

For the purposes of UK data protection law, Shyft is responsible for deciding how personal information collected through this website and our services is used.

Information we collect

We may collect information you provide directly, including your name, work email address, telephone number, company name, website address and the details of an enquiry, project or business requirement.

Project information may include descriptions of existing systems, operational processes, objectives, budgets, timescales, documents, screenshots, files and other information you choose to share with us.

When you use the website, limited technical information may also be collected, including your IP address, browser type, device type, pages visited and interactions with the site. Non-essential analytics information is collected only where the required permission has been provided.

How we use your information

We may use personal information to:

  • respond to questions and project enquiries;
  • review requirements and determine whether Shyft is a good fit;
  • prepare proposals, estimates and recommendations;
  • deliver and manage projects or Technology Partnerships;
  • create and administer a private Shyft Workspace;
  • provide support and communicate about active work;
  • send requested audit reports or other requested information;
  • maintain appropriate business, financial and legal records;
  • protect our website, systems and services from misuse;
  • understand and improve how the website performs; and
  • send marketing updates where you have asked to receive them or where another lawful basis permits us to do so.

We do not sell personal information or provide it to unrelated third parties for their own marketing.

Our lawful bases

The lawful basis used depends on the reason the information is being processed.

Taking steps before entering a contract

When you ask us to assess a project, prepare a proposal or discuss a potential engagement.

Contractual necessity

When information is required to deliver agreed work, manage a client relationship or provide access to the Workspace.

Legitimate interests

When it is reasonably necessary to operate and improve the business, respond to enquiries, protect our systems or maintain appropriate business records, provided those interests are not overridden by your rights.

Consent

Where you choose to receive marketing communications or accept non-essential cookies and analytics technologies.

Legal obligations

Where information must be retained or disclosed to meet accounting, tax, regulatory or other legal requirements.

Project enquiries and business information

Information submitted through the Start a Project configurator is used to understand the requirement, review whether Shyft can help and recommend an appropriate next step.

You should avoid including personal information that is not relevant to the enquiry. You should also ensure you have permission to share information relating to another person.

Commercial and operational information shared with us is treated as confidential and used only where reasonably necessary to assess, propose or deliver the work, subject to any separate agreement entered into with you.

The Shyft Workspace

When a project or Technology Partnership begins, authorised users may receive access to a private Shyft Workspace.

The Workspace may contain names, work email addresses, messages, requests, comments, files, approvals, time records, project updates and other information required to manage the relationship and deliver the work.

Access is limited to authorised users and the Shyft team members or service providers who need the information to operate the Workspace or deliver the agreed services.

Newsletter and marketing communications

If you subscribe to Shyft updates, we may use your email address to send occasional news, articles and information about our services.

You can unsubscribe at any time using the link included in a marketing email or by contacting us. Unsubscribing does not prevent us from sending service messages relating to an active enquiry, project or client relationship.

Cookies and analytics

The website may use essential cookies or similar technologies where they are needed for security, functionality or to remember choices you have made.

We also use Google Analytics to understand matters such as which pages are visited, how visitors find the website and how the site performs. Analytics technologies are non-essential and should only be activated where the required consent has been provided.

You can change your cookie preferences through the consent controls provided on the website. You may also be able to restrict cookies through your browser, although doing so may affect some website functionality.

Service providers and sharing

We may use trusted service providers to operate the website and deliver our services. These may include:

  • website hosting and infrastructure providers;
  • email delivery and communication providers;
  • analytics and performance services;
  • database, file storage and backup providers;
  • accounting, payment and administrative systems;
  • professional advisers such as accountants or legal advisers;
  • software services used to manage and deliver client work; and
  • contractors or delivery partners involved in an agreed project.

Providers are given access only where reasonably necessary for their role. We may also disclose information where required by law, to protect legal rights or in connection with the sale, restructuring or transfer of a business or its assets.

International data transfers

Some technology providers may store or process information outside the United Kingdom.

Where personal information is transferred internationally, we take reasonable steps to ensure that appropriate safeguards are in place. These may include an adequacy decision, approved contractual protections or another mechanism recognised under applicable data protection law.

How long we keep information

We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected.

Retention is determined by factors including:

  • whether an enquiry develops into an active engagement;
  • the duration of a project or client relationship;
  • the need to provide support or maintain project records;
  • legal, accounting, tax and insurance requirements;
  • the sensitivity and volume of the information;
  • the possibility of a dispute or legal claim; and
  • whether you remain subscribed to marketing communications.

Information that is no longer required is deleted, anonymised or securely archived where continued retention is required by law.

How we protect information

We use reasonable technical and organisational measures intended to protect personal information against unauthorised access, alteration, loss or disclosure.

These measures may include access controls, authentication, encryption where appropriate, secure hosting, restricted administrative access, backups and supplier controls.

No online service can guarantee absolute security. You should contact us promptly if you believe information connected with Shyft has been accessed or used improperly.

Your data protection rights

Depending on the circumstances, you may have the right to:

  • request a copy of personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • request deletion of information in certain circumstances;
  • ask us to restrict how information is used;
  • object to processing based on legitimate interests;
  • withdraw consent where processing is based on consent;
  • receive certain information in a portable format where applicable; and
  • complain to the Information Commissioner’s Office or another relevant supervisory authority.

These rights are not absolute and may not apply in every situation. We may need to confirm your identity before responding to a request.

Children’s information

Shyft’s website and services are intended for businesses and professional users. They are not directed at children, and we do not knowingly collect personal information from children through the website.

Changes to this policy

We may update this privacy policy when our services, website, suppliers or legal obligations change.

The current version will always be published on this page, together with the date it was last updated.

Questions or data requests

Speak directly to us about your information.

Contact Shyft to ask a question, make a data request or raise a concern about how information has been handled.

Email Shyft

You may also raise a concern with the UK Information Commissioner’s Office through its official website.