Privacy
Privacy Policy for Zchedule

This explains what we collect, why we collect it, and the choices you have.

Firebase (Auth + Firestore)We never sell your data for moneyCPRA rights supported
Effective Date:
20 Jul 2026
Last Updated:
22 Aug 2026
Company:
Lazy Leaf LLC, a California Limited Liability Company

1. Overview

This Privacy Policy describes how Lazy Leaf LLC (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use Zchedule (the “Service”). It applies to all of the ways you interact with Zchedule, including our iOS app, our website and marketing pages at zchedule.app, and the account, scheduling, and billing features available through them.

This is a single, unified policy that covers both our mobile app and our web experience. Where a practice applies only to one surface (for example, App Store purchases on iOS or advertising cookies on the web), we say so.

This Privacy Policy explains our practices regarding personal information when you use the Service. Where consent or device permission is required, we request it separately as required by applicable law and platform rules.

2. Information We Collect

We collect the following categories of information:

  • Account information: name (if provided), email address, team/organization membership, and role.
  • Service data: schedules, shifts, assignments, swap requests, and related activity within your teams.
  • Location and attendance information: if your organization enables location-based attendance features, Zchedule may collect your device's location when you use a location-dependent attendance action such as clocking in or clocking out. This may include latitude and longitude coordinates, location accuracy, the work location or clock-in zone associated with the event, approximate distance from that zone, whether the event occurred inside or outside the configured geofence, and related attendance flags, alerts, review status, or approval requests.
  • Device and usage data: IP address, device type, operating system, app version, and basic usage logs.
  • Notifications data: push notification tokens used to deliver alerts to your device.
  • Payments: on iOS, purchases are processed by the Apple App Store and our subscription providers (such as RevenueCat). On the web, subscriptions are processed by Stripe. In all cases, payment card details are handled by these processors — we do not store full payment card numbers.
  • Advertising & measurement data (web): when you visit or use our website, we and our advertising partner (Meta) may collect cookies and identifiers — such as Meta’s _fbp and _fbc cookies — and event data about actions such as viewing pages or pricing information, creating an account, starting a trial, publishing a schedule, beginning checkout, or activating a paid subscription. See Section 5 for full detail.

3. Location Services & GPS Attendance

Organizations using Zchedule may configure physical work locations and geofenced clock-in zones. When a team member uses a GPS-enabled attendance feature, such as clocking in or clocking out, Zchedule may request the device's current location and compare it with the selected or applicable work location.

Depending on the organization's settings, location information may be used to:

  • determine whether a clock-in or clock-out occurred within a configured work zone;
  • calculate the approximate distance between the device and the applicable work location;
  • identify or flag potentially off-site clock events for manager review;
  • require manager approval before certain out-of-area clock-ins are completed; and
  • create attendance alerts or records associated with the clock event.

Authorized owners and managers within the applicable Zchedule team may be able to view information associated with these attendance events, including the work location, whether the event occurred within a configured zone, distance-related information, attendance alerts, and information needed to review or resolve an attendance issue.

Zchedule does not use attendance location information to build advertising profiles or provide attendance location information to Meta for advertising measurement or targeting.

Zchedule's GPS attendance features are designed to obtain location when needed for a location-based attendance action. Zchedule does not use these features to create continuous background location histories or continuously monitor a worker's movements.

Your device operating system may ask for permission before Zchedule can access location information. You can manage location permissions through your device settings, but disabling location access may prevent GPS-based attendance features from working.

4. How We Use Information

We use information to:

  • Provide, maintain, and improve the Service;
  • provide GPS-based attendance features, verify clock events against configured work locations, identify out-of-area punches, and support manager review or approval workflows;
  • Authenticate users and secure accounts;
  • Deliver notifications you request or enable;
  • Process subscriptions and verify entitlements;
  • Provide customer support;
  • Send account, verification, and notification emails (delivered through our email provider, Resend);
  • Measure and improve our advertising and understand how visitors find and sign up for Zchedule, including sharing certain web activity with Meta as described in Sections 4 and 5;
  • Detect, prevent, and address fraud or misuse;
  • Comply with legal obligations.

We do not sell your personal information for money. We do, however, share limited web activity with Meta for advertising measurement and matching, which California law treats as “sharing.” See Sections 5, 6, and 10 for details and your opt-out choices.

5. Cookies & Tracking Technologies

On our website at zchedule.app, we use cookies and similar technologies for essential functionality (such as keeping you signed in), analytics, and advertising measurement. Our mobile app does not use the advertising cookies described below. You can control cookies through your browser settings; blocking some cookies may affect how parts of the website work.

Meta Pixel (client-side). Our website uses the Meta (Facebook) Pixel, ID 914329748387383. As you use the website, the Pixel may send event data to Meta from your browser. Depending on how you interact with Zchedule, this may include events relating to:

  • page views and navigation;
  • viewing pricing information;
  • clicking links or calls to action;
  • beginning and progressing through the signup process;
  • completing account registration;
  • creating a first shift;
  • publishing a first schedule; and
  • beginning the checkout process.

Some of these events may include limited context about the action, such as the location of a button, signup step, selected plan, billing interval, or transaction value and currency.

The Meta Pixel may also read Meta identifiers such as the _fbp and _fbc cookies so that Meta can attribute website activity to advertising.

Meta Conversions API (server-side). In addition to browser-based Pixel events, Zchedule uses Meta's Conversions API to send certain events directly from our servers to Meta. Depending on the event, these may include:

  • CompleteRegistration — when a new account is successfully created;
  • StartTrial — when a user's Zchedule trial actually begins after their first shift is created;
  • InitiateCheckout — after a Stripe Checkout Session is successfully created; and
  • Purchase — after our billing system confirms that a paid subscription has become active.

For events that are sent through both the browser Pixel and the Conversions API, such as CompleteRegistration and InitiateCheckout, we use event identifiers designed to allow Meta to recognize the browser and server copies as the same action and avoid counting the conversion twice.

StartTrial and Purchase may be sent only through the server-side Conversions API because they depend on actions confirmed by our backend systems.

Depending on the event and information available, server-side events may include:

  • your email address, hashed using SHA-256 before being sent to Meta;
  • your first name, when available, hashed using SHA-256 before being sent to Meta;
  • your Zchedule account identifier as an external identifier;
  • Meta advertising identifiers such as _fbp and _fbc, when available;
  • your IP address and browser user-agent when available to the server handling the event; and
  • event-related information such as the selected plan, billing interval, transaction value, and currency.

We use this information for advertising attribution, measurement, and matching, including understanding the effectiveness of our advertising. We do not send Meta your payment card number through the Meta Pixel or Conversions API. We also do not deliberately send Meta your phone number, date of birth, gender, or postal address through the Conversions API.

Information received by Meta is handled according to Meta's own data and privacy policies, which we do not control.

6. Sharing & Disclosures

We may share information with:

  • Your organization and authorized team administrators — information you create or generate within a Zchedule team may be available to authorized owners, managers, and other permitted team members as necessary to provide the Service. This may include schedules, attendance records, GPS attendance results, work-zone information, attendance alerts, and review or approval status.
  • Service providers who help us operate the Service — for example, Google Firebase for authentication and database hosting, and Resend to deliver account, verification, and notification emails (your email address and message content pass through Resend for delivery).
  • Payment and subscription processors — Apple App Store and RevenueCat for purchases made in our iOS app, and Stripe for subscriptions purchased on the web — to process payments and manage subscription status.
  • Our advertising partner (Meta) — as described in Section 5, we share certain website activity and identifiers with Meta through the Meta Pixel and Conversions API for advertising measurement and matching. Under the California Consumer Privacy Act, as amended by the CPRA, this may be considered “sharing” of personal information for cross-context behavioral advertising.
  • Legal and safety disclosures if required by law or to protect rights, safety, and security.

We do not sell your personal information in exchange for money. Aside from the advertising sharing with Meta described above, we do not share your personal information with third-party advertisers. You can limit the Meta advertising sharing as described in Section 9.

7. Data Retention

We retain personal information for as long as reasonably necessary to provide the Service and for legitimate business purposes, including security, fraud prevention, customer support, compliance, accounting, and dispute resolution.

Attendance and location information may be retained as part of an organization's historical workforce and attendance records for as long as reasonably necessary to provide those records, support attendance review, comply with applicable obligations, resolve disputes, prevent misuse, and enforce our agreements.

If you request deletion, or if an organization deletes its account, we will delete or de-identify applicable personal information within a reasonable timeframe, subject to legal, security, accounting, backup, and other legitimate operational retention requirements.

Advertising event data shared with Meta through the Meta Pixel and Conversions API (Section 4) is retained by Meta according to Meta’s own data retention policies, which we do not control.

8. Security

We use reasonable administrative, technical, and physical safeguards designed to protect your information. However, no method of transmission or storage is 100% secure.

9. California Privacy Rights (CPRA)

If you are a California resident, you may have rights to request:

  • Access to your personal information;
  • Correction of inaccurate personal information;
  • Deletion of personal information;
  • Information about categories of personal information collected and disclosed;
  • To opt out of the “sharing” of your personal information for cross-context behavioral advertising (see Section 10).

To submit a request, contact us at support@zchedule.app. We may need to verify your identity before fulfilling your request. We do not discriminate against users who exercise privacy rights.

Sale/Sharing: We do not sell personal information for money as defined by California law. We do “share” certain website activity with Meta for cross-context behavioral advertising, as described in Sections 5 and 6. You can opt out of this sharing — see Section 10.

Sensitive Personal Information: certain location information collected through Zchedule's GPS attendance features may constitute sensitive personal information, including precise geolocation, under California law. We use this information only for the location-based attendance, security, operational, and related purposes described in this Privacy Policy.

10. Do Not Sell or Share My Personal Information

We do not sell your personal information in exchange for money. However, our use of the Meta Pixel and Meta Conversions API on our website (Section 5) may be considered “sharing” of personal information for cross-context behavioral advertising under California law. You have the right to opt out of this sharing, and we will not discriminate against you for doing so.

You can opt out in any of these ways:

  • Email us: send a request to support@zchedule.app with the subject “Do Not Share My Personal Information.” This uses the same request process described in Section 9, and we will apply your opt-out to the advertising sharing described above.
  • Control cookies in your browser: block or clear cookies for zchedule.app, which prevents the Meta Pixel and its _fbp/_fbc cookies from operating.
  • Adjust your Meta ad settings: you can manage ad personalization directly in your Facebook and Instagram account settings.

Because advertising cookies apply only to our website, this section does not affect our mobile app, which does not use them.

11. Children

The Service is not intended for individuals under 18. We do not knowingly collect personal information from minors.

12. International Users

The Service is operated from the United States. If you access the Service from outside the United States, you understand that your information may be transferred to and stored in the United States.

13. Changes

We may update this Privacy Policy from time to time. If changes are material, we will provide notice as required by law. Continued use of the Service after changes become effective means you accept the updated Policy.

14. Contact

Lazy Leaf LLC
Support: support@zchedule.app

Zchedule logo© 2026 Zchedule