Privacy Policy

Fire Safety Tactics LLC / ShiftLinked Platform — Effective Date: July 10, 2026

Important Notice: ShiftLinked collects sensitive personal information including government-issued identification, Social Security numbers, biometric face-analysis data, precise location data, and criminal background check information. Please read this policy carefully before using our Platform.

1. Introduction

Fire Safety Tactics LLC ("we," "us," or "our") operates the ShiftLinked staffing platform (the "Platform"), which connects licensed security guards, fire guards, fire safety directors, and concierge workers ("Workers") with businesses ("Companies") in the New York metropolitan area. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our Platform, website, and related mobile applications.

By creating an account or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please do not use the Platform.

2. Information We Collect

2a. Information You Provide

  • Account Information: Full name, email address, phone number, and password.
  • Worker Profile: Professional biography, years of experience, skills, certifications (including DCJS security guard licenses and FDNY Certificates of Fitness), and availability.
  • Government-Issued Identification: We collect copies of government-issued IDs (such as driver's licenses or state IDs) for identity verification and employment eligibility compliance.
  • Social Security Number (SSN): Workers must provide their SSN for tax documentation (W-9/1099 or W-4) and payment processing through our payment partner, Stripe.
  • Financial Information: Bank account and routing numbers provided during Stripe payment onboarding for payroll disbursement. This data is processed and stored by Stripe, Inc., and is subject to Stripe's Privacy Policy.
  • Company Information: Business name, industry, contact details, and billing information for employer accounts.

2b. Biometric and Facial Analysis Data

  • Profile Photo: Workers are required to submit a profile photo captured live via the Platform's in-app camera. Gallery/photo library uploads are not permitted.
  • Automated Face Analysis: Your submitted photo is transmitted to our third-party vendor, Sightengine, which performs automated facial detection and analysis. This includes detecting the number of faces present, facial landmark positions (eyes, nose, mouth corners), obstruction level, image quality, presence of sunglasses, and whether a digital filter has been applied.
  • Purpose limitation: This analysis is used solely to confirm that your photo shows a single, clearly visible, unaltered face suitable for a professional profile. We do not use this data for facial recognition, identity matching, or to identify you against any other photo or database.
  • Legal classification: Depending on your jurisdiction, facial landmark and geometry data of this kind may be classified as biometric information under applicable law, including the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, Washington's biometric privacy law, and New York City's biometric identifier ordinance (NYC Admin. Code §22-1202). We process this data only with your consent, obtained at the time of photo capture, and as described in this section.

2c. Location Data

  • Precise GPS Location: With your permission, we collect your precise geographic location at the moment you clock in or out of a shift, to verify physical presence at a work site. Location is not tracked continuously and is not collected in the background.
  • General Location: City or borough information you provide in your worker profile for shift-matching purposes.

2d. Professional License & Certification Verification

ShiftLinked verifies that all Workers hold a current, valid state or municipal license or certification required for their role prior to activation. This includes verification of NYS Division of Criminal Justice Services (DCJS) Security Guard licenses and FDNY Certificates of Fitness (F-01, F-03, F-04, F-58, F-89). These state and municipal licensing processes include their own background screening requirements, which Workers must satisfy independently as a condition of licensure. ShiftLinked does not currently conduct independent third-party criminal background checks as part of its onboarding process. Certain enterprise clients or specific role requirements may require additional background screening in the future, in which case this policy will be updated accordingly and Workers will be notified prior to any such check being initiated.

2e. Automatically Collected Data

  • Device and Usage Data: IP address, browser type, operating system, device identifiers, pages visited, and time spent on the Platform.
  • Camera Access: The Platform requests access to your device camera solely to capture a profile photo. Camera access is requested only at the moment of photo capture and is never used to record video or capture images at any other time.
  • Push Notification Tokens: If you enable notifications, we collect a device token to deliver shift alerts and platform updates.

2f. Communications

  • SMS / WhatsApp: If you opt in, we collect your phone number and maintain delivery records of messages sent, via our messaging provider, Twilio.
  • In-Platform Messaging: Messages exchanged between Workers and Companies through the Platform's chat system.
  • Call Data: When you call our business phone line, we may collect your phone number and any voicemail messages left.

3. How We Use Your Information

  • Platform Operations: To create and manage accounts, match Workers with shifts, process applications, and facilitate Worker–Company communications.
  • Identity and Compliance Verification: To verify Worker identities, validate professional licenses and certifications (DCJS Security Guard licenses, FDNY Certificates of Fitness), and confirm employment eligibility in compliance with applicable law.
  • Profile Photo Validation: To confirm a clear, single, unaltered face is visible in each profile photo, using automated analysis as described in Section 2b. Photos that fail automated checks for reasons that may reflect a medical or religious accommodation are routed to manual human review rather than automatically rejected.
  • Location Verification: To confirm a Worker's physical presence at a work site during clock-in and clock-out, supporting accurate time tracking and payroll.
  • Payments and Payroll: To process Company payments, calculate platform fees, and disburse wages to Workers via Stripe Connect.
  • Notifications: To send shift reminders, application status updates, and other Platform communications via email, SMS, push notification, and in-app messages, where you have opted in.
  • Safety and Security: To detect fraud, prevent unauthorized access, and enforce our Terms of Service.
  • Legal Compliance: To comply with applicable laws, respond to lawful requests, and protect the rights and safety of our users and company.

4. How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances:

  • Companies: Your Worker profile (name, photo, certifications, experience, ratings, and completed-shift count) is visible to Companies on the Platform for shift matching and hiring decisions.
  • Sightengine: Your profile photo is transmitted to Sightengine's API for automated face detection and quality analysis. Sightengine processes this image under its own privacy policy, available at sightengine.com/privacy-policy. Sightengine does not retain submitted images beyond the time needed to return analysis results, per their stated data handling practices; we encourage you to review their policy directly for current retention terms.
  • Stripe, Inc.: Financial and identity information necessary for payment processing and payroll is shared with Stripe. See Stripe's Privacy Policy at stripe.com/privacy.
  • Twilio: Phone numbers and message content are shared with Twilio solely for SMS and WhatsApp notification delivery. This information is never sold, rented, or shared with any other third party or affiliate for marketing or promotional purposes.
  • Legal Requirements: We may disclose information if required by law, court order, or government authority, or to protect the safety of our users or the public.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to equivalent privacy protections.

5. Device Permissions

Our Platform requests the following device permissions:

  • Camera: Required to capture your profile photo during onboarding. Accessed only when you initiate the photo capture step. We do not record video or access the camera at any other time.
  • Location (Precise GPS): Required to verify your physical presence at a work site during shift clock-in and clock-out. Captured only at the moment you tap to clock in or out and is not tracked in the background.
  • Notifications: Used to deliver shift alerts, application updates, and account notifications. You may disable these at any time in your device or Platform settings.

You may revoke any of these permissions at any time through your device settings. Revoking camera access will prevent you from updating your profile photo; revoking location access will prevent GPS-based shift check-in; revoking notification permissions will stop push alerts but will not affect your ability to use the Platform.

6. SMS and WhatsApp Messaging

We only send SMS or WhatsApp messages to individuals who have explicitly opted in. Message frequency varies depending on your shift activity, notification preferences, and platform usage. Message and data rates may apply. You may opt out at any time by replying STOP to any message, or HELP for help, or by updating your notification preferences in the Platform settings. We do not sell, rent, or share your mobile phone number or SMS opt-in consent with any third party or affiliate for their own marketing or promotional purposes. Your mobile information is used solely to deliver the notifications described in this Policy and is shared only with our messaging service provider, Twilio, strictly to enable message delivery.

7. Data Retention

We retain personal information for as long as your account is active or as needed to provide services and comply with our legal obligations. Upon account deletion:

  • Profile data (bio, availability, photo) is deleted from our systems within 30 days.
  • Payment and tax records are retained for 7 years as required by applicable tax law.
  • Profile photos submitted for facial analysis are deleted from our systems upon account deletion or photo replacement; Sightengine's processing of the image during the validation call is governed by their separate retention practices, described in their privacy policy.
  • Location data from shift clock-in/clock-out is retained for the duration required for payroll, dispute resolution, and compliance recordkeeping, then deleted or anonymized.

8. Data Security

We implement administrative, technical, and physical safeguards designed to protect your information, including encrypted data transmission (TLS), access controls limiting internal access to sensitive data on a need-to-know basis, and secure third-party infrastructure for payment and background check processing. However, no method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

9. Data Breach Notification

In the event of a security breach that compromises your personal information, we will notify affected users and, where required, relevant regulators in accordance with the New York SHIELD Act and other applicable state and federal breach notification laws. Notification will be provided without unreasonable delay and will describe the nature of the breach, the categories of information involved, and steps you can take to protect yourself.

10. Age Requirements and Children's Privacy

ShiftLinked is intended solely for users who are 18 years of age or older. All Workers must be legally eligible to work in the United States and hold any required state or local licensure for their role. We do not knowingly collect personal information from anyone under the age of 13, and our Platform is not directed to children. If we learn that a user under 18 has created an account, or that we have inadvertently collected personal information from a child under 13 without parental consent, we will promptly delete the associated account and data. If you believe a minor has provided us with personal information, please contact us using the information in Section 14.

11. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements described in Section 7.
  • Opt-Out: Opt out of non-essential communications at any time.
  • Biometric Data Rights: Where applicable law provides specific rights regarding biometric data (such as a written release prior to collection, or a publicly posted retention schedule), we will provide the required notices and obtain the required consent separately from this Policy.

To exercise any of these rights, contact us using the information in Section 14. We will respond within 30 days.

12. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information (we do not sell or share personal information as defined under the CCPA), and the right to non-discrimination for exercising your privacy rights. To submit a CCPA/CPRA request, contact us using the information in Section 14.

13. International Users and Data Transfers

The Platform is designed for use by Workers and Companies located in the United States, currently operating in the New York metropolitan area. We do not currently support or knowingly collect information from users located outside the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those of your country of residence.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform at least 14 days before they take effect. Continued use of the Platform after the effective date of an updated policy constitutes acceptance of the changes.

15. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to report a concern, please contact us:

Fire Safety Tactics LLC / ShiftLinked

Phone: +1 (646) 798-9024

Email: info@firesafetytactics.com

Attorney review recommended: This policy has been prepared for informational purposes based on the data practices described to us. Given the sensitive categories of data collected — biometric facial analysis, Social Security numbers, government-issued IDs, criminal background checks, and precise location — we strongly recommend review by a qualified attorney licensed in New York before app store submission or any expansion of the user base, particularly to confirm compliance with NYC Local Law 3/2021 (biometric identifier information), the FCRA, and any state-specific biometric privacy statutes applicable to future expansion markets (e.g., Illinois BIPA, Texas CUBI, Washington HB 1493).