Back to TipFlowLast updated: July 17, 2026
Privacy Policy
TipFlow helps tipped workers track private shift income and read aggregated local signals when enough workers have contributed. Your exact shift records are private by default.
What We Collect
- Role, broad work area, language, and consent version.
- Private shift records, including date, time window, income amounts, duration, mood, signals, and optional private notes (visible only to you).
- Optional Moment text, mood, signal tags, broad area, moderation status, and share slug.
- Anonymous technical identifiers (device and session codes), pseudonymous Supabase user ID, and display alias.
- Optional email, used only for restoring your history across devices.
- Usage events, such as how long logging a shift takes (record duration), used to verify our 20-second goal and keep the service reliable.
How We Use Data
- Show your private shift history and My Money summaries to you.
- Create aggregated local signals only when enough workers have contributed.
- Keep public surfaces free of email, auth IDs, exact locations, exact restaurants, and private notes.
- Use device and session identifiers for continuity, account recovery support, and abuse prevention. They are not public identity.
Anonymous vs Pseudonymous
TipFlow does not show your identity publicly. Internally, TipFlow uses pseudonymous identifiers such as Supabase user ID, device ID, session ID, and optional email so the service can preserve your private history, support deletion, and reduce abuse.
Local Signals and Low Data
Local signals are aggregated and threshold-protected. When there is not enough data, TipFlow hides income ranges, common signals, and exact counts instead of guessing or exposing small samples. Above the threshold, TipFlow may show a broad sample bucket, never exact counts or individual values. Signals update periodically when snapshots are refreshed, not in real time.
Moments and Moderation
Sharing a Moment is optional. Submitted Moments stay pending until reviewed. Do not include names, exact restaurants, addresses, receipts, faces, license plates, or identifying details.
Deletion
You can request account/data deletion from Profile. A deletion request removes your records from the product and moves them into a purge pipeline. Aggregate updates after that point no longer include your data. Historical aggregate snapshots may be retained under our retention policy only as non-identifying statistics that cannot be traced back to a person or a specific shift.
Contact
For privacy, deletion, safety, or account access issues, contact support@tipflow.online.