← Back to TipFair

Privacy Policy

Effective Date: October 20, 2025

At TipFair, your privacy matters. This policy explains what data we collect, how we use it, and your rights regarding it. By using TipFair, you agree to the practices described here.

1. Information We Collect

We collect only the information you voluntarily provide:

  • Account data (if you register): email address, name, and role.
  • Profile data (optional): phone number, hourly rate, tax bracket preference.
  • Shift data: staff names, hours, roles, tip pool amounts, and calculated payouts that you choose to save.
  • Venue data: names of venues and associated staff lists you save.
  • Usage data: standard server logs (IP address, browser type, pages visited) for security and performance monitoring. We do not use these for advertising.

2. How We Use Your Data

  • To provide and maintain the TipFair service.
  • To sync your saved shifts and venues across your devices (when you are signed in).
  • To process subscription payments via Stripe (we do not store payment card details ourselves).
  • To send transactional emails (e.g., password reset, email verification) via Supabase Auth.
  • To improve TipFair based on aggregate, anonymized usage patterns.

We do not use your data for advertising, sell it to third parties, or share it with data brokers.

3. Data Storage

  • Unauthenticated use: all data is stored only in your browser's local storage. It never leaves your device unless you create an account.
  • Authenticated use: your data is stored in a secure Supabase (PostgreSQL) database with row-level security. Only you can access your own records.
  • Payment processing is handled exclusively by Stripe, which has its own privacy policy and PCI-DSS compliance. TipFair does not store credit card numbers or full payment details.

4. Data Sharing

We share data only in these limited circumstances:

  • Service providers: Supabase (database and auth), Stripe (payments), and Vercel (hosting). Each is bound by data protection agreements.
  • Legal requirements: if required by a valid court order, law enforcement request, or applicable law.
  • Shared links: if you use the Share Shift feature, the shift summary is stored server-side and accessible to anyone with the share link.

5. Your Rights

You have the right to:

  • Access your data by viewing your Profile, History, and Venues tabs.
  • Delete individual shifts or venues directly in the app.
  • Delete your account and all associated data via the Profile tab or by contacting support@tipfair.org.
  • Export your shift data via the CSV export feature (Pro plan).

6. Security

We implement industry-standard security measures including HTTPS, database row-level security, and OAuth 2.0 for authentication. However, no system is perfectly secure. You are responsible for keeping your account credentials safe.

7. Cookies

TipFair uses minimal, strictly necessary cookies for session management (via Supabase Auth). We do not use advertising or analytics cookies. You can disable cookies in your browser, but this will prevent login from working.

8. Children's Privacy

TipFair is intended for adults working in the hospitality industry. We do not knowingly collect personal information from children under 13. If we discover such data, we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy at any time. We will post the revised policy here with an updated effective date. Continued use of TipFair after changes constitutes your acceptance of the updated policy.

Questions? Contact us at support@tipfair.org