Privacy Policy
Last updated 13 July 2026.
1. Who we are
Stafflo is a trading name of Thryve Apps Ltd (registered in England & Wales, Company No. 94208378) ("Stafflo", "we", "us"). Thryve Apps Ltd is the data controller for personal data collected via the Stafflo workforce-management platform when used directly, and the data processor for personal data uploaded into the platform by our customers ("Tenants") about their own staff and applicants. Contact: privacy@stafflo.co.uk.
2. What we collect
Information you give us directly
- Account details — name, email, password, role.
- Profile details — date of birth, address, phone number, next-of-kin / emergency contact, profile photo.
- Right-to-work and identity documents — passport, visa, share-code response, driving licence, SIA licence, training certificates and other workforce documents you or your employer upload.
- Payroll details — bank account number, sort code, National Insurance number (where collected for payroll processing by your employer).
- Workforce records — staff profiles, recruitment applications, shift schedules, time records (including clock-in / clock-out times and location), availability, absences.
- Recruitment vetting results — outcome of background, sanctions and right-to-work checks initiated by the employer (see section 7 for the providers used).
- Criminal-records data — where your employer's vetting process requires it (e.g. BS7858 screening), DBS certificates you or your employer upload and related vetting declarations. This is criminal-offence data under Article 10 UK GDPR; we process it only on the employer's documented instructions, and the employer is responsible for having a lawful basis and an appropriate policy document for it.
- Communications — messages and emails sent through the platform.
Information collected automatically
- Usage data — pages visited, actions taken, device + browser type.
- Log data — IP address, request timestamps, authentication events.
- Mobile device identifiers — push notification tokens (Apple Push Notification service or Firebase Cloud Messaging) used solely to deliver shift, schedule and safety notifications. We do not use advertising identifiers (IDFA / Android Advertising ID).
Information from third-party integrations
If you connect a third-party service (e.g. Google Calendar), we access only the data needed to provide that integration. See section 5.
3. Mobile app & device permissions
The Stafflo mobile app (iOS and Android) requests the following device permissions. Each is only used for the purpose stated, and only when you trigger the corresponding feature.
- Camera — to scan QR codes (clock-in, document verification) and to capture sign-in photos or photos attached to incident reports, vetting documents and chat messages. Photos taken in the app are uploaded to your tenant's storage on Supabase; QR scans are processed locally on the device.
- Photo library — to let you attach existing images (e.g. a photo of an ID document) to your profile, vetting record or a chat message. Stafflo only reads files you explicitly pick.
- Precise location — when you clock in to a shift, the app reads your current location to confirm you are at the venue, and when you trigger the in-app safety beacon, it broadcasts your live location to your employer's safety controllers. Location is not collected in the background or when the app is closed.
- Biometric authentication (Face ID, Touch ID, Android biometrics) — used only to unlock the app on your device. The biometric data itself is processed by your device's secure enclave and is never transmitted to or stored on Stafflo's servers.
- Push notifications — to deliver shift offers, schedule changes, chat messages and safety alerts. You can opt out at any time from your device settings or from inside the app.
4. How we use your data
- To operate the platform (creating accounts, scheduling shifts, managing recruitment, sending operational emails).
- To secure the platform (audit logs, fraud detection, abuse prevention).
- To support customers when they contact us.
- To improve the platform — aggregate, de-identified usage analytics only.
We do not sell personal data, share it with advertisers, or use it to train AI/ML models without explicit consent.
5. Legal basis (UK GDPR Article 6)
- Contract — operating the service under our customer agreement (Articles 6(1)(b)).
- Legitimate interest — security, fraud prevention, product improvement (Article 6(1)(f)).
- Consent — third-party integrations you connect yourself (Article 6(1)(a)). Withdrawable at any time from Settings.
- Legal obligation — retention periods required by law (Article 6(1)(c)).
6. Google API user data
If you connect your Google Calendar to Stafflo via the "Connect Google Calendar" button in Settings, Stafflo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access
https://www.googleapis.com/auth/calendar.events.owned— to create and manage the interview events (with Google Meet links) that Stafflo itself adds to your calendar when you schedule recruitment interviews. This scope is limited to events you own.https://www.googleapis.com/auth/userinfo.email— your Google account email address, displayed in Settings so you can tell which account is connected.
What we do with it
- Create one calendar event per interview you schedule, containing the recruit's name, time, and a Meet link.
- Read back and update those events — for example to add the recruit as an attendee once they confirm attendance, or to change the time of an event we created.
- Delete the event we created if the interview is cancelled in Stafflo.
- Nothing else. We only ever access the interview events Stafflo itself creates on your calendar. We do not browse, read or list any of your other calendar events, and we never share Google user data with third parties.
How long we keep it
Stafflo stores a refresh token tied to your account so it can create events on your behalf. You can disconnect at any time from Settings → Preferences, which deletes the token immediately. Revoking access at myaccount.google.com/permissions has the same effect at Google's end. Calendar events created on your behalf remain on your Google Calendar after disconnection — Stafflo does not delete them.
Human access
Stafflo does not allow humans to read your Google data except: (a) with your explicit consent, (b) for security investigations, or (c) when required by law. We do not use Google user data for advertising, sell it to third parties, or use it to train AI/ML models.
7. Sharing
We share personal data only with:
- Sub-processors — Supabase (database, auth and file storage), Vercel (web hosting), Resend (transactional email), Twilio (SMS and WhatsApp message delivery), Anthropic (AI processing for the optional WhatsApp assistant — message content only, not used to train AI models), Google Cloud (Calendar API), Apple Push Notification service and Firebase Cloud Messaging (mobile push delivery), Capgo (mobile app over-the-air updates). A current list is available on request.
- Recruitment vetting providers — when a tenant initiates a check on an applicant: Experian (UK identity, address history, financial-sanctions screening), OpenSanctions (global sanctions and politically-exposed-persons screening), and HMRC's Employer Checking Service (right-to-work verification). These services return a pass / fail / referral outcome plus the underlying matching records, which we store against the applicant's profile as the legal record of the check.
- Authorities — when legally compelled (subpoena, court order, statutory request).
- Successors — in the event of a merger, acquisition, or sale of assets, with notice to customers in advance.
We do not share data with advertisers, data brokers, or third-party analytics or attribution services.
8. International transfers
Stafflo operates primarily on UK and EU infrastructure. Where data crosses borders, we rely on UK adequacy decisions, Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework as appropriate.
9. Retention
- Workforce records — for the duration of the tenant's subscription plus 30 days, or longer if required by law (e.g. SIA / right-to-work record-keeping).
- Authentication logs — 90 days.
- Google Calendar refresh tokens — until you disconnect or revoke.
- Closed account data — fully deleted within 30 days unless retention is required by law.
10. Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct it if inaccurate.
- Request deletion (subject to legal retention requirements).
- Object to processing for legitimate-interest reasons.
- Withdraw consent for any consent-based processing (e.g. Google Calendar integration).
- Lodge a complaint with the Information Commissioner's Office (ICO).
Email privacy@stafflo.co.uk to exercise any of these rights. We respond within 30 days.
Deleting your account and data
To delete your Stafflo account and the personal data associated with it, email privacy@stafflo.co.uk from the address on your account, or write to the postal address in section 14. We will confirm and complete deletion within 30 days, except for data we are legally required to retain (for example SIA / right-to-work records, payroll records, or audit logs required by HMRC and the Security Industry Authority). Where retention applies, the underlying records remain restricted to compliance use only and are deleted as soon as the legal retention period ends.
If you only use Stafflo as part of your employer's workforce (a "Tenant" deployment), your employer is the data controller for your workforce records. Contact them first; we will assist them on request.
11. Security
We use industry-standard measures including encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, multi-tenant isolation, and audit logging. We follow the principle of least privilege for sub-processor access. Refresh tokens for third-party integrations are stored with strict row-level access controls — only the connecting user (or service-role administrators acting on documented requests) can read them.
12. Children
Stafflo is not intended for users under 16. We do not knowingly collect data from anyone under 16. Where a tenant operates an 18+ age-gated vacancy, the date-of-birth check is performed by the tenant during recruitment and we do not solicit data from minors via the app.
13. Changes to this policy
We may update this policy from time to time. Material changes will be notified to administrators by email at least 14 days in advance. The "last updated" date at the top of this page tracks all revisions.
14. Contact
Privacy queries: privacy@stafflo.co.uk
Data Protection Officer: dpo@stafflo.co.uk
Postal: Thryve Apps Ltd (trading as Stafflo), Connaught House, Padholme Road East, Peterborough PE1 5XL, United Kingdom.