Privacy Policy
Last updated: July 3, 2026
Summary: Senzii collects scheduling data — staff names, contact information, certifications, availability, and shift assignments. We do not collect payment card information (Stripe handles that). We do not store protected health information (PHI). This policy describes what we collect, how we use it, and your rights.
1. Who We Are
REPL Made LLC ("we," "us," or "our") operates the web application at senzii.com, including the admin dashboard, staff portal, and client portal (collectively, the "Service"). Senzii is a workforce scheduling platform that matches staff to shifts based on skills, proximity, and availability.
For questions about this Privacy Policy, contact us at support@senzii.com.
2. Data We Collect
2.1 Data You Provide
When you create an account and use the Service, you or your organization's admin may enter the following personal data:
- Admin/organization data: Your name, email address, phone number, organization name, and password (stored as a bcrypt hash)
- Staff data: Staff names, email addresses, phone numbers, home addresses (used for proximity matching), certifications and expiration dates, availability windows, and timezone
- Client data: Client or customer names, email addresses, phone numbers, and work site addresses
- Shift data: Shift times, work site locations, required skills, assignment status, and match scores
- Checkout data: Name, email, phone, organization name, and number of seats — passed to Stripe to create a checkout session
2.2 Data Collected Automatically
When you visit the landing page, we collect limited analytics data via a first-party beacon:
- Page URL, referrer, and section visibility (which parts of the page you scrolled to)
- UTM parameters (source, medium, campaign, content, term) if present in the URL
- Screen dimensions and browser language
- A daily-rotating, one-way hash of your IP address (cannot be reversed to identify you, and rotates daily so the same visitor cannot be tracked across days)
We do not use third-party analytics tools (Google Analytics, Mixpanel, etc.), advertising pixels, or cross-site tracking cookies.
2.3 Data We Do Not Collect
- Payment card information: All payment processing is handled by Stripe. We never see or store your card number, CVC, or expiry date.
- Protected Health Information (PHI): Senzii is not HIPAA-compliant. Do not enter diagnoses, treatment notes, or any medical records.
- Sensitive personal data: We do not collect race, ethnicity, religious beliefs, sexual orientation, or genetic data.
3. How We Use Your Data
- To provide the Service: Match staff to shifts, calculate proximity scores, manage availability, and display schedules
- To communicate with you: Send magic link login emails, password reset emails, and service notifications via Resend (our email provider)
- To process payments: Pass checkout information to Stripe to create subscription billing. Stripe processes and stores all card data — we only store your email and subscription status
- To improve the Service: Aggregate, anonymized analytics on landing page visits help us understand which features and content are useful
- To send transactional emails: Staff and client magic link emails, password resets, and shift notifications
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Data Storage and Security
4.1 Where Data Is Stored
Your data is stored in a PostgreSQL database hosted by Neon (neon.tech), which holds SOC 2 Type 2, ISO 27001, and GDPR compliance certifications. Data is stored in the United States.
The application itself runs on servers hosted by Linode (Akamai), also in the United States.
Email delivery is handled by Resend (resend.com). Payment processing is handled by Stripe (stripe.com).
4.2 Encryption
- In transit: All connections use TLS (HTTPS). The server enforces HTTPS via Caddy with automatic TLS certificates.
- At rest: The database provider encrypts data at rest. Passwords are hashed with bcrypt (12 rounds) — they are never stored in plain text.
4.3 Data Breach Response
If we become aware of a data breach affecting your personal data, we will notify affected users by email within a reasonable timeframe and take steps to mitigate the breach. However, as stated in our Terms of Service, we are not liable for data breaches beyond the limitations described there.
5. Third-Party Services
We use the following third-party services that may process your data:
- Stripe — Payment processing. Stripe handles all card data and is PCI-DSS compliant. See Stripe's Privacy Policy
- Neon — Database hosting. See Neon's Privacy Policy
- Linode / Akamai — Server hosting. See Akamai's Privacy Policy
- Resend — Transactional email delivery. See Resend's Privacy Policy
- OpenStreetMap / Nominatim — Address geocoding (converting addresses to coordinates for proximity matching). No personal data is sent — only the address string you enter
When you connect a third-party AI assistant (such as ChatGPT or Claude) to your Senzii account, that assistant's provider may process data you share. We are not responsible for how third-party AI providers handle your data — review their privacy policies before connecting.
6. Cookies and Sessions
Senzii uses a single session cookie to keep you logged in. The cookie contains a session ID — no personal data is stored in the cookie itself. Session data is stored server-side in our PostgreSQL database.
We do not use tracking cookies, advertising cookies, or third-party cookie-based analytics.
7. Data Retention
- Active accounts: Your data is retained as long as your account is active
- After cancellation: We retain your data for 30 days in case you change your mind, then permanently delete it
- Analytics data: Daily visitor hashes are not retained beyond 90 days. Aggregate page view counts may be retained longer
- Email logs: Magic link and notification emails are sent via Resend. We do not retain the content of sent emails beyond what Resend's own retention policy specifies
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request that we correct inaccurate or incomplete data
- Deletion: Request that we delete your personal data (subject to legal retention requirements)
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to certain processing of your data
- Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at support@senzii.com. We will respond within 30 days.
If you are a resident of California (CCPA) or the European Economic Area / UK (GDPR), you have additional rights under those regulations. We do not sell personal data, and we do not process data for direct marketing without consent.
9. International Data Transfers
Your data is stored and processed in the United States. If you are accessing the Service from outside the United States, your data will be transferred to the United States. By using the Service, you consent to this transfer. Our database provider (Neon) and email provider (Resend) also process data in the United States.
For users in the European Economic Area, United Kingdom, or Switzerland: We process personal data on the basis of the GDPR's legitimate interest and contractual necessity provisions, as the data is required to provide the scheduling Service you requested.
10. Children's Privacy
The Service is intended for businesses and workforce management. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Data Processing by You (For Admins)
If you are an organization admin, you are responsible for ensuring that you have the legal right to enter your staff members' and clients' personal data into the Service. This includes obtaining any necessary consents required under applicable data protection laws (GDPR, CCPA, or others).
You are the data controller for the staff and client data you enter. REPL Made LLC acts as a data processor on your behalf, processing that data only to provide the Service to you. You are responsible for informing your staff and clients about how their data is used, and for handling any data subject requests they send to you.
12. Changes to This Policy
We may update this Privacy Policy at any time. We will notify active users by email of material changes. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
← Back to Senzii