Trust

Data governance

The practical rules behind My Shift health data.

Current scope

Shift processes account data and, where a member explicitly chooses the feature, optional health-tracking information used for progress, Health MOT, check-ins, Fit/Grub personalisation and related member tools.

Data map

DataPurposeControl
Identity/accountAccount access, security and supportAccount settings, rights request, account deletion
Measurements/check-insProgress history and personalisationExplicit health-tracking consent, export, erase history
Progress photosUser-requested progress record/illustrationSeparate photo consent, delete photo/history
Fit/Grub preferences and plansGenerate and save member plansSave/swap/delete through member journey
Security/privacy logsSecurity, fraud prevention and accountabilityRestricted operational access; retention limited to need

Governance rules

  • Collect the minimum needed for the feature.
  • Separate optional health tracking from basic account access.
  • Do not use health tracking to make automated clinical/prescribing decisions.
  • Assess new health-data uses and processors before launch.
  • Keep processor/controller roles clear.
  • Provide export, deletion and consent controls.
  • Review retention and security controls when the product changes.

Regulated healthcare

Shift does not diagnose, prescribe or supply medication. If a separate regulated provider processes clinical data, that role and privacy information must be identified before the data is shared.