Privacy
What we store about people, who else can see it, how long it is kept, and what you can ask us to do with it.
Last updated: 21 September 2026
Who is responsible
Us, or your employer, depending on whose data it is.
Shoreleave is a trade name of a sole trader registered in the Netherlands at Smakkelaarsveld 79, 3511 EB Utrecht. Chamber of Commerce 50812904, VAT NL001124200B52. You can reach us through the contact form or at [email protected].
Two different roles
Shoreleave handles personal data in two ways, and the difference decides who you ask about what.
For visitors to this site, people who write in, and the person who signs a company up and pays for it, we decide what is collected and why. We are the controller, and this page is your notice.
For the people in a company's account, their leave, their sickness and everything else recorded about them, the company decides what is recorded and why. It is the controller and we only act on its instructions. If your employer uses Shoreleave, ask them about your records first. What we commit to as their processor is written into the terms.
No cookies, no third party
What we keep in your browser, what we count, and who else is told.
Shoreleave sets no cookies at all. There is no advertising, no tracking pixel, no social button and no third party script anywhere on this site or in the app. The fonts are served by us. Nobody outside Shoreleave is told that you were here, and there is no consent banner because there is nothing to consent to.
We do count page views on this site, ourselves. When you open one of these pages, your browser tells our own server which page it was, which site you followed a link from if you came from one, and which browser you are using. We look at it to see which pages people read and which ones are not worth keeping.
If you got here by clicking one of our ads, the address you arrived on carries a number for the ad campaign, and we keep that number as well, so that we can see which ads are worth paying for. It is the same number for everybody who clicked the same ad, so it says nothing about you. Google puts other things on that address too, which are different for every single click. We do not read those and we do not store them.
Nothing in that record names you. So that we can tell one person reading three pages from three people reading one, we turn your IP address, your browser and today's date into a single short code. The date is part of it, so the code is a different one tomorrow and today's reading cannot be joined to any other day's. We erase the IP address after thirty days.
This covers the public side of the site, including the sign in and sign up pages. Nothing inside the app is counted, and none of these records holds your name, your email address, or anything else that points at your account.
Signing in stores a few things in your own browser, in local storage rather than in a cookie: a session token, the name and role we show in the corner of the screen, the language you picked, and small preferences such as how you like a list laid out. They are needed for the app to work as you left it, the token only ever leaves your device on requests you make, and signing out removes it. While you are signing in with Google or Microsoft, or connecting Slack or Teams, the tab also holds a random code for a few moments, so that the answer coming back can be matched to the tab that asked. It is gone when you close the tab.
A company can put the wallchart on a screen on a wall and lock it. The screen then keeps drawing the chart without being signed in: the session exists only in that open page and nothing is stored on the device.
What we hold
It depends on how you came to use Shoreleave.
If you write in
The contact form takes your name, your email address, your company if you fill it in, and your message. We store it and email it to ourselves so we can answer. We also record the IP address the message came from, to stop the form being used to send junk.
If you sign a company up
Your name, email address, the name of your company, the country it is in and its time zone, which decides what "today" is for every date in the account. When you put a card on the account we hold the billing details you type, including your VAT number, invoice address and any billing email, and a reference from our payment provider. We never receive your card number.
If your employer added you
What your employer entered: your name, email address, role, team, start date, the days you work, your allowance and which public holiday calendar applies to you. We also keep the language you last used the app in, so the emails you get are in it, and when you were last active.
Your leave: what kind it is, which days, whether it was asked for, approved, declined or cancelled, who answered and when, and the note or reason anybody wrote on it. A kind of leave can be sickness, which is information about your health. Shoreleave records that you were off sick and on which days, and asks nothing about why. Anything typed in a note is kept as it was typed, so a note is not the place for a diagnosis. Your employer can also record days added to or taken off your allowance, with a reason, and the days you carried over from one year to the next.
Who can see what inside the company is decided by the company's own settings and by roles. The people who answer your requests see everything about your leave. Everybody else in the company sees when you are away, and sees why only where your company has chosen to show it.
If you sign in with Google or Microsoft
The code that identifies your account there, the email address Google or Microsoft confirmed, and a key that lets us ask, about once an hour while you use the app, whether that account is still active. That is how a company switching off your work account also takes you out of Shoreleave. We are never given your Google or Microsoft password.
If your company connects Slack or Teams
Which workspace or organization it is, the channel the daily message goes to if one was picked, and the keys to post there. To reach you directly we match your Slack or Teams account to you by email address and keep its id. If you switch on your status, we set it to away while you are on approved leave and clear it when you are back.
If you use a calendar link
A company can let its people subscribe their own calendar to their leave, their team's or the whole company's. Each link is a secret address that works for anybody who has it. The link for your own leave names the kind of leave, and the team and company links say who is away and never why. Switching calendar links off deletes every one of them.
The emails we send
We email the people in an account when there is something for them to know: an invitation, a password reset, a request to answer, an answer, a cancellation, the week ahead on Monday mornings, and to owners, invoices and notices about the account. We send no marketing email and nothing to anybody outside an account except a reply to somebody who wrote in.
Whenever anything is used
Our server keeps ordinary technical records of requests, and a log of what was changed in an account and by whom. We record IP addresses against a small number of events, such as a failed sign in, a sign up or a password reset request, so that somebody trying addresses one after another can be slowed down. When something breaks, a report of the request it broke on goes to our error tracker, named below.
Who else touches it
Four companies each doing one job, and the tools a company chooses to connect.
We do not sell personal data, we do not share it for advertising, and we do not use it to train anything. These are the only companies involved in running Shoreleave:
- DigitalOcean hosts the site, the API and the database, in Amsterdam.
- Bird, formerly SparkPost, delivers the email we send, and passes contact messages on to us.
- Mollie takes payment. Card details are typed on Mollie's own page and never reach us. Mollie decides for itself what it needs to hold to run a payment business, so for that part it is not acting on our instructions.
- Sentry receives a report when something goes wrong in our server, so that we can fix it. A report describes the request that failed, which can include who was signed in and what they sent. It is held in Germany.
Everything is held inside the European Economic Area. If that ever has to change we will say so here and tell account owners first.
Google, Microsoft, Slack and Teams are only involved when a company turns them on, and they are the company's own suppliers rather than ours. Signing in with Google or Microsoft tells that company you signed in to Shoreleave. A connected Slack workspace or Teams organization receives the messages Shoreleave posts there: the daily message in a channel says who is away and never why, and a request sent to whoever answers it names the kind of leave. What those companies do with it is covered by the company's own agreement with them.
The public holidays come from a public list of holidays by country. We ask it for a country's days and send it nothing about anybody.
We will hand something over to an authority if the law obliges us to, and we will tell the account owner first unless we are forbidden to.
How long it is kept
And how it is protected while we have it.
A company's records are kept while its account is open, including the leave of people who have left and been archived, because a company's reports and payroll need them. When an account closes we keep it for ninety days in case the company comes back, then delete it, and an owner can ask us to delete it immediately instead.
A sign in lasts ninety days from the last time it was used. An invitation link stops working after three days, and a password reset link after 24 hours. IP addresses are erased after thirty days: the ones recorded against events, the ones contact messages came from, and the ones behind page views on this site. Invoices and the figures behind them are kept for seven years, because Dutch tax law requires it, and that obligation outlasts a request to delete an account.
Names, email addresses, contact messages, invoice details and the keys to a Google, Microsoft, Slack or Teams connection are encrypted before they are written to the database. Everything travels over an encrypted connection. Passwords are stored in a form nobody can read back, including us, which is why a forgotten password is reset rather than looked up.
What you can ask for
Your rights, and where to complain if we handle a request badly.
You can ask us for a copy of what we hold about you, to correct it, to delete it, to give it to you in a portable form, or to stop using it in a particular way. Get in touch and we will answer within a month, free of charge.
If your employer gave you an account, the decisions about your leave records are theirs and not ours, so ask them first. Most of what is held about you is on your own page in the app already. If you ask us, we will pass it on and help them answer, but we are not allowed to change or delete their records for you.
If you think we have handled your data badly, tell us and we will try to put it right. You also have the right to complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens, and you can go to the one where you live or work instead.
When this page changes we move the date at the top, and we email account owners when the change matters.