Schedulosity · Last Updated: September 14, 2026
Last Updated: September 14, 2026
Strongwork LLC (“Strongwork,” “we,” “us,” or “our”) is a technology company that develops and operates web applications. Schedulosity is Strongwork's workforce scheduling and management software product. This Privacy Policy explains how Strongwork collects, uses, discloses, and retains personal information in connection with the Schedulosity website, mobile applications, and related services (the “Services”).
This Policy covers visitors, account holders, administrators, staff, contractors, applicants, references, invitees, and other individuals whose information is processed through the Services, including people who do not have an account. Features and the information involved vary by organization, subscription, device, and the features used.
This Policy applies to Schedulosity. Other Strongwork products may have separate privacy notices. As described in Sections 3 and 7, Strongwork may use and share certain information within its product portfolio for common administration, security, service delivery, and marketing where permitted. That ownership does not authorize unrestricted use of organization-managed Schedulosity records for another product's independent purposes.
Our Terms of Use and applicable customer agreements govern use of the Services. This Policy provides information about our practices; it does not itself obtain consent for processing that requires a separate choice or waive privacy rights available under law.
When an employer or other organization uses Schedulosity to manage its workforce, recruitment, events, or related records, that organization generally determines why and how its information is used. Strongwork processes personal information in those records on the organization's behalf as a processor or service provider, where those terms apply. We follow the organization's lawful instructions, applicable agreements, and legal requirements. We do not use customer-controlled personal information for unrelated advertising, another Strongwork product's independent purposes, or other purposes prohibited by those agreements or applicable law.
The organization controls its authorized users, settings, submitted information, and permitted disclosures. It is responsible for providing required notices, establishing an appropriate legal basis, obtaining required permissions, and handling its own employment and recordkeeping obligations. Strongwork remains responsible for obligations that apply to our own processing.
Strongwork separately determines the purposes and means of processing information for its own account administration, subscriptions, billing, direct support, security, legal compliance, advertising and permitted marketing. We may use Strongwork-controlled account, business-contact, subscription, support, and preference information across Strongwork products to operate, secure, support, improve, and market those products, subject to applicable law and the choices described in Section 8. We also provide features people use in their individual capacity, including personal invitations, coordination, and My Activity. Our role depends on the particular activity; the fact that information concerns a staff member does not make every use of that information processing on an employer's behalf.
For requests about organization-managed records, contact the relevant organization. You may also contact us using Section 15. We will identify the appropriate route and assist the organization as required, and will address information for which Strongwork is independently responsible.
We receive information directly from individuals; from organizations, administrators, coworkers, organizers, applicants, and references using the Services; from services they connect or use; and automatically from interactions with the Services. An organization may create a record about someone before that person registers.
Depending on the features used, information includes:
Information may be sensitive under applicable law, including account-access credentials, sufficiently precise location or presence information, and sensitive information contained in submitted records. Please provide only information relevant to the intended feature. Do not submit government identity numbers, medical records, or other highly sensitive information unless the particular service and applicable written agreement expressly permit that use. A professional scheduling account is not, by itself, an agreement to handle patient medical records.
Subject to the roles and restrictions described in Section 1, we use information to:
Product improvement does not authorize unrestricted reuse of customer-controlled information. Where we use aggregated or deidentified information for broader reporting or development, it must be processed so that it no longer identifies an individual under the applicable standard. We do not treat identifiable records as anonymous merely because they appear in an aggregate report. We will not attempt to reidentify information maintained as deidentified except as permitted by applicable law, including to test the effectiveness of deidentification safeguards.
Some versions of the Services may offer an optional location-sharing feature for organizations that need to coordinate attendance at configured places. Its availability and controls may vary while it is rolled out. Before enabling the feature for a worker, Strongwork and the relevant organization must provide the applicable feature notice and obtain any required authorization or permission. Device permission alone does not establish an organization's lawful basis for workforce monitoring.
When location sharing is enabled, it may process location or presence information associated with configured places, including entry and exit events, times, device-permission status, and relevant shift associations. These events can reveal a person's presence at a specific place. Location sharing is not required for basic scheduling access. We will update this Policy before materially expanding the feature or using location information for a materially different purpose.
You may change device permissions in device settings and contact us or the relevant organization about location information. Future collection and withdrawal controls will be explained in the feature when it is available to you. Previously received information remains subject to Section 9 and applicable privacy rights.
My Activity is an optional personal feature, currently available only to selected users while it is being tested. A person must turn it on in the Services and authorize the required device permission. When enabled, the iOS application monitors circles around the person's home and the locations of upcoming shifts and reports an entry or exit, the time, and the circle involved. The current implementation does not send continuous device-location coordinates with those crossing reports. It uses the reports to show the person their actual arrival and departure times and travel between home and work.
My Activity is not required for basic scheduling access. Its records are personal to the user and are not available to an employer through My Activity. Turning the feature off stops the application from receiving personal circles for future monitoring; device permissions can also be changed in device settings. We will give separate notice and obtain any required authorization before adding a sharing, employer-access, or materially different use of My Activity information.
Mobile features may use device or installation identifiers and push-notification tokens to deliver alerts and Live Activities. Notification previews and Live Activities may display scheduling information on a device's lock screen. You can manage those displays and permissions in device settings.
If you choose to take or upload a profile photo, the application may request camera or photo access. Optional dictation may use the device's or browser's speech service to convert speech into text; that provider's terms and privacy notice apply to its processing. Text you submit through Schedulosity is treated as submitted content. Permission settings may affect these optional features without preventing unrelated features from working.
Where available, you may choose a writing assistant to turn notes into a referral or reference letter. To provide this feature, we send the submitted notes and relevant context—such as candidate, author, employer, and role names—to Anthropic, our AI service provider. We receive the generated text and may retain the notes and draft with the associated recruitment record.
Use only information you are authorized to provide, and review generated text before sharing it. The writing feature assists the author; it does not itself make a hiring decision. Information from a customer-controlled record remains subject to the applicable processing restrictions. This Policy does not grant permission to train general-purpose models on customer-controlled content. Any permitted provider handling must be governed by the applicable service arrangements and law.
We use cookies, local storage, and similar technologies to maintain sessions, authenticate users, remember preferences, protect the Services, and measure use. Some are temporary; others remain until they expire or are removed. Blocking technologies needed for authentication or security may prevent relevant features from working.
We use Google Analytics to measure website use. Analytics may involve browser and device information, identifiers, page and interaction information, and approximate location information. The underlying information is not necessarily anonymous even when reports are aggregated. Google explains its practices in its Privacy Policy. Its Analytics Opt-out Browser Add-on is available for supported browsers; it does not control every form of collection across devices or services.
We may use campaign landing pages to understand how people find and interact with Schedulosity. Those pages may record campaign attribution and page, click, and video-interaction events. We use IPinfo to obtain IP-based location and network information for those pages. We also use Google address and mapping services to validate or geocode addresses submitted through the Services.
Email and messaging systems may record delivery, bounces, complaints, opens, clicks, and responses where measurement is enabled. These records support communications, troubleshooting, and understanding engagement.
We may display contextual advertising or sponsored content on the Services and in email, including advertising for Schedulosity, other Strongwork products, or third parties. Contextual placement may use the page, feature, message type, broad audience or organization category, and advertising preferences; it does not require disclosure of organization-managed workforce, recruitment, location, payment, SMS-consent, or submitted-content records to an advertiser. We may measure an advertisement or sponsor placement using the technical and engagement information described above. If we introduce cross-context behavioral or targeted advertising, or disclose personal information for it, we will provide the notice, choices, and technical controls required before doing so.
You can use browser and device settings to manage storage and permissions. Where consent or another specific choice is required, we will provide that choice before the relevant processing. Our website does not currently respond to legacy “Do Not Track” signals. Global Privacy Control and other legally recognized opt-out preference signals are distinct; where applicable law requires us to honor such a signal for sale, targeted advertising, or sharing, we will do so.
We disclose information only for the relevant purposes and subject to applicable legal and contractual restrictions:
We do not sell personal information or disclose it for cross-context behavioral advertising or targeted advertising as those activities are defined under applicable US state privacy laws. We do not sell customer content, workforce records, location events, or SMS consent records. Providing a mobile number for operational messages does not authorize disclosure to third parties for their own marketing. If our practices change, we will update this Policy and provide legally required opt-out methods before engaging in the changed practice.
Independent services selected by a user have their own privacy practices. Their notices should be reviewed before using them. This does not remove Strongwork's responsibilities for processing performed on our behalf.
You may unsubscribe from promotional email or sponsor messages using the applicable unsubscribe link or contact us. Sponsor-message preferences are separate from operational scheduling notifications, so opting out of sponsor messages does not stop shift assignments, availability requests, event reminders, account, billing, security, or other service communications that are not marketing. We may retain the minimum information necessary to record and honor an opt-out.
For SMS, follow the opt-out instructions in the message or reply STOP to the sending number where supported. You can also contact us for assistance. A messaging opt-out applies to the relevant channel or program; it does not itself delete an account or workforce record. Organizations using messaging features must provide required notices and obtain and document required permissions. Consent to use Schedulosity is not a substitute for any separate consent required to send a message.
Device settings control push notifications. Available account settings also allow you to manage communication preferences.
We retain personal information for as long as reasonably necessary to provide the Services, fulfill the purposes described in this Policy, and satisfy applicable legal and contractual obligations. Retention periods depend on the information involved and its purpose. We delete or deidentify information when it is no longer needed, subject to applicable exceptions and preservation requirements.
In determining retention, we consider whether an account or customer relationship remains active; whether the information is needed for an ongoing service or a lawful customer instruction; applicable tax, accounting, security, and recordkeeping requirements; the need to establish, exercise, or defend legal claims; and binding return or deletion obligations. Retained information is limited to the purpose supporting its retention. This does not authorize indefinite retention merely because information might be useful in the future.
Closing an account or ending a subscription does not, by itself, require all associated records to be erased immediately or on a single fixed schedule. A paid subscription may end while an individual account or another customer relationship continues. These distinctions do not postpone an applicable statutory deadline or a binding contractual obligation. Where Strongwork processes information on an organization's behalf, we follow its lawful instructions and the applicable processing agreement, including return or deletion requirements when services end.
An account holder may request deletion through the account settings area after confirming the current password. We make the account inaccessible, revoke its active credentials and mobile geofencing credential, and process the request. We delete or deidentify account information and personal content within the request flow, including personal My Activity circles and crossing history. We preserve limited records where necessary, including an organization's workforce, scheduling, attendance, recruitment, compensation, and similar records; financial and tax records; security and deletion-request records; and information subject to a legal hold or another lawful exception. We sever the deleted account's links to organization records where appropriate, rather than changing the organization's records or unassigning its shifts. If a person is an organization's only administrator, the organization must first designate another administrator or contact us for help.
Account holders and organizations should export records they need while authorized access is available and before closing an account. After closure, they may contact us about information still retained. Availability of additional export or recovery assistance depends on the records remaining available, except where assistance or access is required by law or a binding agreement. The Services are not a substitute for an organization's own legally required records or archives.
Backups and provider-held copies are subject to applicable retention and deletion requirements. If immediate removal from backup media is not required, retained copies must remain protected and limited to necessary recovery, security, or legal purposes until removed under the applicable retention process. Applicable deletion requirements must be reapplied if a backup is restored. A legal hold may suspend disposal of affected information for the duration of the hold.
An individual's account and records an organization lawfully maintains about that individual may be subject to different requirements. Deactivating an account or removing a visible record is not the same as completing a deletion request. Requests are handled under Section 10, including any applicable exceptions. Properly deidentified or aggregated information that no longer identifies an individual may be retained for reporting and product improvement, subject to applicable law and agreements.
This Policy does not waive statutory privacy rights or, by itself, retroactively remove an enforceable retention, export, return, or deletion commitment that already applies to particular information or a customer relationship.
You may contact contact@schedulosity.com or write to the address in Section 15 to ask about your information, request access or correction, or request deletion. Please identify the relevant account or organization and describe the request. No particular subject line is required. Do not send a password, full payment-card number, or identity document unless we request an appropriate verification method through a secure channel.
Depending on applicable law and our role, you may have rights to access or know your personal information, obtain a portable copy, correct inaccuracies, delete information, opt out of sale, sharing, targeted advertising or certain profiling, and limit certain uses of sensitive information. Exceptions and verification requirements may apply. We will not unlawfully discriminate or retaliate against you for exercising a privacy right.
We may request information reasonably necessary to confirm identity or authority, using information appropriate to the nature of the request. An authorized agent may submit a request where permitted; we may require evidence of authorization and appropriate verification. We do not require identity verification for an opt-out where applicable law prohibits it.
We will respond within the time required by applicable law, measured from receipt of the request as required, and explain any permitted extension or denial. Where you have a right to appeal a denial, reply to the decision or email us with “Privacy Appeal.” We will review and respond within the applicable period and explain any available regulator complaint route. Organization-managed requests are handled as described in Section 1.
This subsection applies where Strongwork is subject to the California Consumer Privacy Act, as amended (“CCPA”), for the relevant processing. The categories described in Section 2 include identifiers; customer records; commercial information; internet or network activity; professional or employment information; audio, visual, or similar information where submitted; geolocation; inferences from scheduling and interaction records; and sensitive personal information where applicable.
Sources, uses, and recipient categories are described in Sections 2, 3, and 7. For the preceding 12 months, the relevant collection and business-purpose disclosures depend on the features used: account and billing information is disclosed to providers supporting those functions; customer content and workforce, recruitment, location, or event records to the relevant organization, authorized recipients, and feature providers; and technical or interaction records to hosting, security, communications, analytics, address or mapping, and campaign-measurement providers. We do not sell or share personal information for cross-context behavioral advertising.
Sensitive information may include credentials permitting account access and sufficiently precise location information. We use sensitive information for requested services, security, and other purposes permitted without offering a right to limit under the CCPA; we do not use it to infer unrelated sensitive characteristics. Additional notice and any legally required choice must precede a materially different use. Retention criteria are in Section 9.
California rights may include knowing categories and specific pieces of information, deletion, correction, and applicable sale/sharing or sensitive-information choices. Use the request methods above. For applicable access, deletion, and correction requests, we will ordinarily respond within 45 calendar days of receipt; if a lawful extension is necessary, we will notify you within that initial period and explain it. Opt-outs and other requests follow their applicable, potentially shorter, deadlines. This Policy does not restrict legally required request methods or rights.
Where Nevada's online privacy provisions apply, you may direct a verified request concerning sale of covered information to contact@schedulosity.com, our designated request address. We do not sell covered information as defined by those provisions. We will handle applicable requests within the legally required period. Access and correction inquiries may be submitted through the same address.
We operate from the United States and use providers that may process information in other countries. Privacy laws and protections may differ from those in your location. The availability of a website does not by itself determine which laws apply to a particular activity.
Where European, UK, or Swiss data protection law applies and Strongwork acts as controller, we rely on the lawful basis appropriate to the activity: performing a contract with the individual for necessary account or requested-service processing; legitimate interests in administering business relationships, providing support, improving reliability, and preventing abuse, subject to applicable balancing requirements; legal obligations for required records and disclosures; and consent where required for the particular processing. A contract with an organization does not automatically establish contract necessity for every use of its workers' information. Device-storage and marketing rules may require separate consent or another specific condition.
Applicable rights may include access, correction, erasure, restriction, objection, portability, and withdrawal of consent without affecting prior lawful processing. You may object to direct marketing and complain to a competent supervisory authority. Contact us under Section 15 to exercise rights or request information about the lawful basis for a particular activity.
Where we act as a processor, the relevant organization determines its lawful basis, and processing must be covered by the required data processing agreement. Contact us to arrange or obtain the applicable agreement. Transfers requiring safeguards must be supported by an applicable adequacy decision or an appropriate transfer arrangement, including the relevant contractual safeguards and supplementary measures where required. You may request information and a copy of applicable safeguards, subject to necessary redactions. This Policy does not itself execute a data processing agreement or transfer mechanism.
We use reasonable technical and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction. These include access restrictions and safeguards for communications and infrastructure appropriate to the information and processing involved. We use AWS infrastructure and TLS-protected connections for the Services, and Stripe for payment processing.
No method of storage or transmission is completely secure. We cannot guarantee absolute security. If an incident requires notification, we will notify the relevant organizations, individuals, or authorities as required by applicable law and binding agreements. A provider's certification or compliance status does not constitute a certification of all Schedulosity operations.
Authorized users must be at least 18 years old under our Terms. We do not permit a person under 18 to register for or use an account.
Organizations may submit limited information about people who do not have accounts, including a minor competitor's name and competition details. The submitting organization is responsible for the required notices, permissions, and lawful basis for that information. If you believe information about a minor has been submitted improperly, contact us so we can investigate and take appropriate action. An account-age restriction does not eliminate applicable privacy requirements for information submitted about a non-user.
We may update this Policy to reflect changes in the Services, our practices, or legal requirements. We will post the revised version at schedulosity.com/privacy and update the date above. For material changes, we will provide appropriate additional notice, such as an account notice or email, before the change takes effect where required.
Where a change requires consent or another legal authorization, we will obtain it before applying the change to the relevant information. Posting a revised Policy does not override existing contractual commitments or authorize an incompatible use of previously collected information.
Strongwork LLC — Schedulosity Privacy Inquiries
9205 West Russell Road, Suite 240
Las Vegas, NV 89148
Email: contact@schedulosity.com
| Attachment Viewer |