Trust
Data governance
The practical rules behind My Shift health data.
Current scope
Shift processes account data and, where a member explicitly chooses the feature, optional health-tracking information used for progress, Health MOT, check-ins, Fit/Grub personalisation and related member tools.
Data map
| Data | Purpose | Control |
|---|---|---|
| Identity/account | Account access, security and support | Account settings, rights request, account deletion |
| Measurements/check-ins | Progress history and personalisation | Explicit health-tracking consent, export, erase history |
| Progress photos | User-requested progress record/illustration | Separate photo consent, delete photo/history |
| Fit/Grub preferences and plans | Generate and save member plans | Save/swap/delete through member journey |
| Security/privacy logs | Security, fraud prevention and accountability | Restricted operational access; retention limited to need |
Governance rules
- Collect the minimum needed for the feature.
- Separate optional health tracking from basic account access.
- Do not use health tracking to make automated clinical/prescribing decisions.
- Assess new health-data uses and processors before launch.
- Keep processor/controller roles clear.
- Provide export, deletion and consent controls.
- Review retention and security controls when the product changes.
Regulated healthcare
Shift does not diagnose, prescribe or supply medication. If a separate regulated provider processes clinical data, that role and privacy information must be identified before the data is shared.
