Privacy Policy

Last updated: August 11, 2026

Pelican Sport Center Inc. (“Plantilla,” “we,” “us,” or “our”) operates the Plantilla workforce management application, available on the web at www.useplantilla.com and as native mobile applications on iOS and Android (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your information.

The Service is a private workforce management tool intended for employees of organizations that have signed up to use it. Access requires an account created on behalf of an employee by an authorized manager or administrator within their organization.

1. Information We Collect

Account Information

When you are added to the system by your employer or accept an invitation, we collect:

  • Full name
  • Email address
  • Phone number (optional)
  • Date of birth (used to determine minor-labor protections)
  • Password (stored only as a one-way cryptographic hash)
  • Optional two-factor authentication secret

Authentication via Third-Party Providers

If you choose to sign in using “Sign in with Google” or “Sign in with Apple,” we receive a limited set of information from those providers to identify your account:

  • Your name (as it appears on your Google or Apple ID)
  • Your email address — or, in the case of Sign in with Apple, a private relay email if you choose to hide your real address
  • A unique account identifier issued by the provider

We do not receive your password, your contacts, your photos, or any data outside the items listed above. We use this information only to create or log you into your Plantilla account. The authentication transaction is performed by Google or Apple directly; we never see your credentials.

Profile Picture

You may optionally upload a profile picture, which appears in the application next to your name on the schedule, in chat, and in other surfaces where co-workers within your organization can see it. Profile pictures are stored on our servers as ordinary image files and are accessible only to authenticated members of your organization. You can change or remove your profile picture at any time from the Profile page.

Biometric Authentication

If you enable biometric sign-in (Face ID or Touch ID on iOS, fingerprint or face unlock on Android), your biometric data never leaves your device. The biometric check is performed entirely by your device’s operating system, which only returns a pass-or-fail result to the application. We do not receive, store, or have access to any image, scan, or other biometric data associated with your face or fingerprint.

Passkeys

You may optionally enroll one or more passkeys to sign in to the Service without a password. A passkey is a public/private key pair generated and stored on your device by your operating system’s credential manager (iCloud Keychain on iOS and macOS, Google Password Manager on Android and Chrome, and the equivalent on Windows and Linux). The private half of the key never leaves your device or your trusted synchronized device set. We store only the public half of the key plus a usage counter and a label you choose, and the unlocking step (Face ID, Touch ID, fingerprint, device PIN, etc.) is performed entirely by your operating system — we do not see or store the biometric or PIN used to unlock the passkey. You can view, rename, or revoke any enrolled passkey at any time from the Profile page; revoked passkeys are immediately unable to sign in to the Service.

Employment Information

Information needed to manage your work:

  • Position(s) and department(s)
  • Work location(s)
  • Hourly wage or pay rate (visible only to authorized managers)
  • Employment status (full-time, part-time, active, inactive)
  • Weekly hours cap, if any

Schedule and Time Data

  • Shifts you are scheduled to work, including any swaps or coverage requests
  • Time-off requests, approvals, and balances
  • Availability windows you submit
  • Time clock entries — clock-in / clock-out timestamps and break durations
  • Attendance points and any related forgiveness records

Location Information

When the time clock feature is enabled by your employer and you tap “Clock In,” the application may request access to your device’s GPS coordinates. We use these coordinates only to verify that you are physically at the location of your scheduled shift (a “geofence” check). Coordinates are not retained after the verification is performed; only a record of whether the clock-in succeeded and at what time is stored. Location is not tracked continuously and is not shared with other users.

Communications

Messages you send through the in-app messaging feature, including text content and any attachments such as photos, documents, or other files; announcements you post or read; time-off request notes; shift handoff notes; and other communications you choose to share with co-workers within your organization. Attachments you upload are stored on our servers and are accessible only to other authenticated members of your organization who are participants in the relevant conversation or recipients of the relevant message.

Customer Booking Information

If your employer enables the Appointments feature, your organization may collect contact information for the customers who book appointments — typically the customer’s name, phone number, email address, and any notes the booking employee records. This information is collected from the customer (over the phone or in person) by an employee using the Service, not directly from you, and is used to (i) schedule the appointment in the Service, (ii) send a confirmation email to the customer at the email address they provide, and (iii) allow the customer to call back to cancel or reschedule. Customer confirmation emails are sent via Resend (see Service Providers below). Customer information is visible within the Service only to the assigned employee and the managers responsible for that position’s bookings.

Audit Logs

We maintain audit logs of significant actions taken within the system — for example, shift edits, employee changes, schedule publishes, wage updates — for compliance and dispute resolution purposes. Logs include the action taken, who performed it, when it was performed, and what was changed.

Operating-System Integration Features

The mobile applications integrate with several operating-system surfaces. None of these surfaces collect additional personal information beyond what is described elsewhere in this Policy; they display or make searchable information that the Service already holds about you.

  • iOS Widgets and Live Activities — if you add the Plantilla widget to your home screen or Lock Screen, or if you start a shift while a Live Activity is supported, the widget displays your next or current shift and is periodically refreshed by iOS from the Service. The data shown is the same shift data visible inside the app. The widget reads from a sandboxed App Group shared with the main application; nothing is sent to third parties.
  • iOS Quick Actions and Spotlight Search — long-pressing the app icon surfaces shortcut entries (Schedule, Plantilla Assistant, Coverage and Trades, Open Messages) that deep-link into the app. The Spotlight index also makes your next shift and today’s schedule searchable from your device’s system-wide search. These indices are written to the on-device system index by iOS and are not transmitted to us or to third parties; they are visible only on your device while you are signed in.
  • Siri Shortcuts and App Intents — if you say “Hey Siri, clock me in” or trigger a similar app-intent shortcut, your spoken command is processed by Apple (see Service Providers) and the resulting action is executed in the Service exactly as if you had tapped the corresponding button inside the app.
  • Universal Links and Android App Links — tapping a Plantilla link (for example, the meeting/invite link your manager texts you) opens directly in the installed app rather than the browser. No additional data is collected by this routing.

Device and Usage Information

Standard technical information collected automatically:

  • IP address
  • Device type and operating system
  • Browser type and version
  • Application version
  • Date and time of access; pages or features accessed

Push Notification Tokens

If you grant push-notification permission on your mobile device, your device’s operating system generates an opaque token that we store on our servers and use to deliver notifications to you — for example, schedule changes, new messages, shift reminders, or time-off responses. The token does not identify you beyond what is needed to route notifications to your device, and is transmitted only to the operating system’s push notification service (Apple Push Notification service on iOS, Firebase Cloud Messaging on Android) when we send you a notification. You can revoke push-notification permission at any time from your device’s system settings; doing so does not affect any other functionality of the Service.

2. How We Use Your Information

We use your information to:

  • Provide scheduling, time-off, and time-tracking functionality
  • Authenticate your access to the Service
  • Verify your physical location at clock-in, when the geofence feature is enabled
  • Send notifications about your schedule, time-off status, announcements, and other workplace matters
  • Maintain compliance with applicable labor laws, including protections for minor employees
  • Generate payroll-related reports for your employer
  • Investigate and resolve disputes
  • Protect the security and integrity of the Service

3. Information Sharing

We do not sell your personal information to third parties. We share information only as described below.

Within Your Organization

Your employer (Pelican Sport Center Inc., or another organization using the Service) has access to your information for legitimate business purposes. Managers and administrators within your organization can see your schedule, hours worked, contact information, and other employment-related data based on their role and scope.

Service Providers

We use the following third-party services to operate the Service. Each is contractually bound to handle your information in accordance with this policy:

  • Render, Inc. — hosts the web servers and database that power the Service
  • Resend — sends transactional emails such as password resets and notifications
  • Google LLC — (i) distributes the Android application via Google Play Store and may collect crash reports and device-compatibility metrics; (ii) when you choose “Sign in with Google,” authenticates your identity and returns your name, email address, and a unique identifier as described in the Authentication via Third-Party Providers section above; (iii) delivers push notifications on Android devices via Firebase Cloud Messaging when you have notifications enabled
  • Apple Inc. — (i) distributes the iOS application via the App Store and may collect crash reports; (ii) when you choose “Sign in with Apple,” authenticates your identity and returns your name, an email address or private relay email, and a unique identifier as described in the Authentication via Third-Party Providers section above; (iii) delivers push notifications on iOS devices via the Apple Push Notification service when you have notifications enabled
  • OpenAI, L.L.C. — powers the in-app AI assistant and message auto-translation. When you send a message to the assistant or use the voice input feature, your message text (and, in the case of voice, the audio recording) is transmitted to OpenAI’s API for processing. OpenAI returns a generated response and, for voice input, a text transcript of what you said. When you tap the “Translate” button on a chat message, shift note, or handoff note, the text of that item is transmitted to OpenAI’s API and a translation in your preferred language is returned; the translation is cached on our servers so subsequent viewers of the same item don’t re-transmit it. Per OpenAI’s API data policy, customer data submitted through their API is not used to train their models. The assistant can also read data from the Service (your schedule, time-off balance, etc.) and, in some cases, perform actions on your behalf (such as submitting a time-off request) — it does so under your existing permissions and only after you explicitly confirm the action.
  • OpenStreetMap Foundation— provides the map tiles displayed on the “On the floor now” live roster map. When a manager opens the map, the application requests tile images directly from OpenStreetMap’s public tile servers (subdomains of tile.openstreetmap.org); as part of that request the tile servers see the requester’s IP address and the coordinates of the map area being viewed. We do not send any account or employee data to OpenStreetMap. The map is opt-in behind a “Show map” button and is not shown to employees.
  • Functional Software, Inc. (Sentry) — provides error monitoring and session-replay services that help us diagnose bugs and improve reliability. When the application encounters an error, a crash report is sent to Sentry that includes the error message, a stack trace, the application version, the device and operating system, your user identifier within the Service, and the recent in-app actions (“breadcrumbs”) that led up to the error. We also use Sentry’s Session Replay feature, which records a privacy-safe playback of UI interactions (clicks, page navigations, network requests) on a sampled basis so we can reconstruct what was happening on screen when an error occurred. The replay does not record audio, camera, microphone, or text you type into password fields or other masked inputs. We use Sentry data solely to diagnose and fix defects in the Service and to monitor its operational health.

Legal Requirements

We may disclose information if required to do so by law, valid legal process (subpoena, court order, etc.), or to protect our rights, your safety, or the safety of others.

4. Data Retention

  • Active employees: we retain your information for as long as you have an active account
  • Former employees: after your employment ends, your account is deactivated. Historical records (shifts worked, time entries, audit logs) are retained as required by labor law and your employer’s record-keeping obligations, typically a minimum of three years for payroll records
  • Audit logs: retained for compliance purposes, typically seven years
  • Deletion requests: you may request deletion of your personal information at any time. From inside the mobile or web application, open Account Settings and tap “Delete my account” to submit a deletion request that removes your personal information and deactivates your account. You may also contact your manager or email us at the address below. Information that we are legally required to retain (typically payroll records under wage-and-hour law and certain audit records) is preserved for the mandated period and then deleted; all other personal information is removed within 30 days of the request

5. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your information (subject to legal retention obligations)
  • Restrict or object to processing
  • Data portability — receive a copy of your information in a machine-readable format
  • Withdraw consent where consent is the legal basis for processing

California Residents

California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what categories of personal information are collected, the right to delete, and the right not to be discriminated against for exercising these rights. We do not sell personal information.

European Economic Area Residents

Residents of the EEA, the United Kingdom, and Switzerland have rights under the General Data Protection Regulation (GDPR). Our legal bases for processing are: (1) performance of a contract relating to your employment, (2) our legitimate interests in operating a workforce management service, and (3) compliance with legal obligations.

6. Security

We use industry-standard security measures to protect your information:

  • All connections to the Service are encrypted using HTTPS / TLS
  • Passwords are stored as one-way cryptographic hashes; we never have access to plain-text passwords
  • Authentication tokens are cryptographically signed and have a limited lifetime
  • Database backups are encrypted at rest
  • Access to production systems is limited to authorized personnel

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Children’s Privacy

The Service is not directed to children under 13 and does not knowingly collect personal information from them. Employees who are minors (typically ages 14 to 17 in the United States, depending on state law) may use the Service only when added by an employer in accordance with applicable child labor laws and with parental or guardian consent where required.

8. International Data Transfers

We are based in the United States and process information on servers located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated through the Service or by email to the address associated with your account. Your continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.

10. Contact Us

For questions about this Privacy Policy, or to exercise any of your rights under it, please contact:

Pelican Sport Center Inc.2980 State Route 10, Ste 2Morris Plains, NJ 07950-9923United StatesEmail: mgmt@useplantilla.com