PRIVACY POLICY
SHFT LLC - ReflectEQ
Last Updated: February 2, 20261.
INTRODUCTION
SHFT LLC ("SHFT," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use ReflectEQ, including our physical NFC card and mobile application (collectively, the "Service"). Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this Privacy Policy, please do not use the Service.
2. INFORMATION WE COLLECT
We collect several types of information to provide and improve our Service.2.1 Personal Information You Provide Account Information includes your name, email address, password (encrypted), and profile preferences (chosen icon, display settings). Purchase Information includes billing name and address, shipping address, and payment information (processed through Stripe - we do not store complete payment card details). Communications includes messages you send us, feedback and survey responses, and support requests.2.2 Usage and Behavioral Data. ReflectEQ Interaction Data includes tap frequency and timing patterns (when you use your NFC card), ratings you provide (1-5 stars) on prompts, engagement patterns (how often you interact, session duration), prompt response patterns, and check-in history and timing. brittAlgo Data - Our proprietary personalization algorithm (brittAlgo) collects and analyzes observable behavioral patterns from your card usage, rating patterns over time, engagement consistency and frequency, temporal patterns (time of day, day of week usage), and response velocity (how quickly you respond to prompts). Important Note: brittAlgo uses Hidden Markov Models to infer patterns from your observable behaviors. It does NOT record your thoughts, feelings, or journal entries. We maintain a "no journaling" design principle - we only collect structured data points (ratings, taps, timing) to personalize your experience.2.3 Device and Technical Information Mobile Device Data includes device type and model, operating system and version, unique device identifiers, mobile network information, and NFC reader capability information.App Usage Data includes app version, features accessed, error logs and crash reports, and performance data.2.4 Location Information. We may collect approximate location data based on your IP address to determine appropriate shipping costs, provide region-specific content, and comply with regional legal requirements. We do NOT collect precise GPS location data unless you explicitly enable location services for specific features (currently not implemented).2.5 Cookies and Tracking Technologies Website Cookies - Our website (shftexperience.com) may use cookies and similar tracking technologies to remember your preferences, analyze site traffic and usage patterns, enable payment processing, and improve user experience.Types of Cookies include Essential Cookies (required for the website to function - login sessions, shopping cart), Analytics Cookies (help us understand how visitors use our site), and Marketing Cookies (may be used for advertising if applicable). You can control cookies through your browser settings, but disabling certain cookies may limit functionality.
3. HOW WE USE YOUR INFORMATION
We use your information for the following purposes:3.1 To Provide the Service - We use your information to create and manage your account, process your purchase and deliver your ReflectEQ card, deliver personalized daily prompts through brittAlgo, enable NFC card functionality, and provide customer support.3.2 To Personalize Your Experience - We use brittAlgo to analyze your behavioral patterns and infer emotional awareness needs, tailor prompts to your engagement patterns, adapt content based on your usage history, and improve the accuracy of personalization over time.3.3 To Improve Our Service - We analyze aggregated, anonymized usage data to improve ReflectEQ, identify bugs, errors, and technical issues, develop new features and functionality, enhance brittAlgo's algorithms, and conduct research on emotional intelligence tools (using de-identified data).3.4 To Communicate With You - We send order confirmations and shipping updates, provide important Service updates and changes, respond to your inquiries and support requests, send you tips for using ReflectEQ effectively, and request feedback and reviews (you can opt out).3.5 Marketing (If You Opt In) - We may send promotional emails about new features or products, share content about emotional intelligence and personal development, and notify you of special offers or updates to the SHFT ecosystem. You can unsubscribe from marketing emails at any time using the link in the email.3.6 Legal and Safety Purposes - We use information to comply with legal obligations, enforce our Terms and Conditions, protect our rights, property, and safety, prevent fraud and abuse, and respond to legal requests from authorities.
4. brittAlgo PERSONALIZATION ALGORITHM
4.1 How brittAlgo Works- brittAlgo is our proprietary personalization engine that uses machine learning (specifically Hidden Markov Models and Expectation-Maximization algorithms) to analyze your behavioral patterns and infer underlying emotional awareness needs.What brittAlgo Analyzes: your rating patterns (how you rate prompts over time), engagement frequency (how often you use your card), temporal patterns (when you tend to reflect), consistency patterns (regularity of usage), and response patterns (which types of prompts you engage with). What brittAlgo Does: infers hidden emotional states from observable behaviors, selects prompts likely to be relevant to your current needs, adapts to your evolving patterns over time, and learns from your engagement to improve personalization.4.2 What brittAlgo Does NOT DobrittAlgo does not record your thoughts or feelings in text form, share your individual patterns with others, diagnose mental health conditions, make medical or clinical assessments, or predict specific emotional states with certainty. brittAlgo is a computational tool for personalization, not a diagnostic or therapeutic tool.4.3 Data Used by brittAlgo. All data processed by brittAlgo is stored securely on our servers, used only to personalize your individual experience, not sold to third parties, and aggregated and anonymized if used for research or algorithm improvement. You can request deletion of your brittAlgo data at any time.
5. HOW WE SHARE YOUR INFORMATION
We do not sell your personal information to third parties. We may share your information in the following circumstances:5.1 Service Providers. We share data with trusted third-party service providers who help us operate the Service:Firebase (Google) provides cloud database and back-end services, stores user data, interaction history, and brittAlgo data, and is subject to Google's privacy practices. Learn more at firebase.google.com/support/privacy.Stripe processes payment transactions securely. We do not store complete payment card information. Stripe is subject to its own privacy policy. Learn more at stripe.com/privacy.Hosting and Infrastructure Providers host our website and deliver the Service.Analytics Providers help us understand usage patterns using aggregated, anonymized data.These service providers are contractually obligated to protect your data and use it only for the purposes we specify.5.2 Business Transfers - If SHFT is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.5.3 Legal Requirements - We may disclose your information if required to do so by law or in response to court orders or legal process, requests from government authorities, protection of our rights, property, or safety, prevention of fraud or illegal activity, or emergency situations involving danger to any person.5.4 With Your Consent - We may share your information for purposes not described in this policy with your explicit consent.5.5 Aggregated and Anonymized Data - We may share aggregated, anonymized data that cannot identify you individually for research on emotional intelligence tools, to publish insights about usage patterns, to improve our algorithms, or for business analytics.
6. DATA SECURITY
6.1 Security Measures. We implement industry-standard security measures to protect your information: encryption of data transmitted between your device and our servers using SSL/TLS, secure storage with data at rest encrypted using Firebase's security protocols, access controls with limited employee access to personal data on a need-to-know basis, authentication through password-protected accounts with secure login, and regular security audits to review our security practices.6.2 Security Limitations - No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.6.3 Breach Notification - In the event of a data breach that affects your personal information, we will notify you as required by applicable law, typically within 72 hours of discovering the breach.
7. DATA RETENTION
7.1 How Long We Keep Your Data Active Accounts - We retain your data for as long as your account is active and you continue using the Service. brittAlgo data is continuously updated based on your usage.Inactive Accounts - If you stop using the Service but don't delete your account, we may retain your data for up to 2 years. After 2 years of inactivity, we may delete your account and associated data.Deleted Accounts - When you request account deletion, we delete your personal data within 30 days. Some data may be retained longer if required for legal, accounting, or security purposes. Aggregated, anonymized data may be retained indefinitely for research.Purchase Records - We retain purchase and transaction records for 7 years for accounting and tax purposes.Backup Data - Deleted data may remain in backup systems for up to 90 days before permanent deletion.7.2 Legal Retention - We may retain certain information longer if required by law, regulation, or legal proceedings.
8. YOUR PRIVACY RIGHTS
Depending on your location, you may have certain rights regarding your personal information:8.1 Access - You have the right to request confirmation of whether we process your personal data, a copy of your personal data, and information about how we use your data.8.2 Correction - You have the right to correct inaccurate personal data, update incomplete information, and modify your profile and preferences. You can update most information directly through the ReflectEQ app settings.8.3 Deletion - You have the right to request deletion of your personal data ("right to be forgotten"). We will delete your data unless we have a legal reason to retain it. To delete your account, go to Settings in the ReflectEQ app, select "Delete Account," and confirm your decision. Or email us at info@shftexperience.com.8.4 Data Portability - You have the right to receive your personal data in a structured, machine-readable format and to transmit it to another service. To request your data, email privacy@shftexperience.com. We'll provide your data within 30 days in JSON or CSV format.8.5 Opt-Out Rights - You have the right to opt out of marketing emails (click "unsubscribe" in any email), certain data processing activities (contact us), and sale of personal information (we don't sell data, but you can confirm this with us).8.6 Do Not Track - Some browsers support "Do Not Track" signals. Currently, we do not respond to Do Not Track signals, but we do not track users across third-party websites.8.7 Exercising Your Rights - To exercise any of these rights, contact us at info@shftexperience.com. Include your account email and specify your request. We'll respond within 30 days. We may request additional information to verify your identity before processing requests.
9. STATE-SPECIFIC PRIVACY RIGHTS
9.1 California Residents (CCPA/CPRA)If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):Right to Know includes categories of personal information collected, sources of personal information, business purposes for collection, and categories of third parties we share with.Right to Delete allows you to request deletion of your personal information (with exceptions for legal obligations).Right to Opt-Out means we do not sell or share personal information for cross-context behavioral advertising.Right to Non-Discrimination means we will not discriminate against you for exercising your privacy rights.Sensitive Personal Information - We collect behavioral and emotional data through ReflectEQ. This data is used solely to provide and personalize the Service. You can limit the use of this data by deleting your account.To exercise these rights, email info@shftexperience.com.California "Shine the Light" Law - We do not share personal information with third parties for their direct marketing purposes.9.2 Virginia Residents (VCDPA) - Virginia residents have rights similar to those under CCPA, including rights to access, correct, delete, and obtain a copy of personal data.9.3 Other State Privacy Laws - If you reside in a state with privacy laws (Colorado, Connecticut, Utah, etc.), you may have similar rights. Contact us to exercise those rights.
10. INTERNATIONAL USERS
10.1 United States-Based Service - SHFT LLC is based in the United States, and our servers are located in the United States. Your information will be processed and stored in the United States.10.2 International Data Transfers - If you are accessing the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer and processing.10.3 GDPR (European Users) - If you are in the European Economic Area (EEA), we process your data under the following legal bases: Contract Performance (to provide the Service you purchased), Legitimate Interest (to improve the Service and communicate with you), and Consent (for marketing communications where required). You have additional rights under GDPR, including the right to lodge a complaint with your local data protection authority.
11. CHILDREN'S PRIVACY
11.1 Age Restriction - ReflectEQ is not intended for children under 18 years of age. We do not knowingly collect personal information from anyone under 18.11.2 Parental Notice - If we discover that we have collected information from a child under 18, we will delete it immediately. If you believe we have collected information from a child, please contact us at info@shftexperience.com.11.3 Future Products - While SHFT's long-term vision includes emotional intelligence tools for children, any such products will have separate age-appropriate privacy practices and parental consent mechanisms.
12. THIRD-PARTY LINKS AND SERVICES12.1 External Links - The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.12.2 Third-Party Integrations - If we integrate with third-party services in the future (e.g., calendar apps, health apps), we will update this policy and obtain your consent before sharing data with those services.
13. CHANGES TO THIS PRIVACY POLICY13.1 Updates - We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.13.2 Notification - When we make changes, we will update the "Last Updated" date at the top, notify you via email if the changes are material, post a notice in the app if changes significantly affect your rights, and provide at least 30 days' notice for material changes.13.3 Continued Use - Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.
14. CONTACT US
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: SHFT LLC
General Privacy Inquiries: info@shftexperience.comData Rights Requests: info@shftexperience.com (Subject Line: "Privacy Rights Request")Response Time: We aim to respond to all privacy inquiries within 30 days.
15. SPECIFIC DISCLOSURES
For compliance with state privacy laws, here is a summary of personal information categories we collect:Identifiers (Name, email, account ID) - Collected: Yes
Payment Information (Billing address, payment method) - Collected: Yes (via Stripe)
Device Information (Device type, OS, app version) - Collected: Yes
Usage Data (Tap frequency, ratings, engagement) - Collected: Yes
Behavioral Data (Patterns analyzed by brittAlgo) - Collected: Yes
Location Data (Approximate location, IP-based) - Collected: Yes
Biometric Information - Collected: No
Audio/Visual Information - Collected: No
Professional Information - Collected: No
Education Information - Collected: No
Business Purposes for Collection: We collect and use personal information for providing and maintaining the Service, processing transactions, personalizing your experience via brittAlgo, improving our Service and algorithms, communicating with you, customer support, and legal compliance and safety.Sharing Practices: We share personal information with service providers (Firebase, Stripe, hosting providers), professional advisors (lawyers, accountants), and authorities when legally required. We do NOT sell personal information, share data for third-party advertising, or use data for purposes unrelated to the Service.
ACKNOWLEDGMENT
By using ReflectEQ, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.If you do not agree with this Privacy Policy, please do not use the Service and contact us to delete any data we may have collected.Effective Date: February 2, 2026This Privacy Policy is part of our Terms and Conditions and should be read in conjunction with those terms.