StaffWeaverLog inSign up

Privacy Policy

Effective August 21, 2026

This policy explains what information StaffWeaver collects, how we use it, and the choices you have. We wrote it in plain English on purpose — if anything here is unclear, email us at support@staffweaver.com.

Data we collect

Account information. When you create a StaffWeaver account, we collect your email address, first and last name, and an optional company name.

Content you create. The scores you compose or edit in StaffWeaver are stored in your account on our servers, so they're available whenever you sign back in. Deleting your account deletes the scores stored under it.

Technical information. Like most web services, our servers keep standard logs (such as IP address, browser type, and request timestamps) to operate and secure the service. We also store a record of each signed-in session — see Authentication below for exactly what those records contain.

How we use it

We use the information above to:

  • Provide and operate the StaffWeaver service, including storing the scores you create so they're available across sessions and devices.
  • Send transactional email, such as account verification and password-reset messages. We do not send marketing email.
  • Maintain the security and integrity of the service, including detecting abuse.

What we don't do

  • We do not sell your data to anyone.
  • We do not use advertising cookies or ad-tracking pixels, and we do not build advertising profiles.

Storage & security

StaffWeaver runs on Amazon Web Services in the US East (Ohio) region (us-east-2). Data is encrypted in transit using TLS. Passwords are never stored in plain text — we hash them with bcrypt before they touch our database.

Authentication

When you sign in, StaffWeaver stores a bearer token in your browser's local storage to keep you signed in. We do not use advertising or tracking cookies for authentication or anything else.

Sign-in session records. So that signing out genuinely ends a session, and so that one seat stays one person, we keep a record on our servers for every signed-in session. Each record holds an identifier for the session, a random device identifier your browser generates on first sign-in (stored in local storage as sw_device_id), a one-way keyed hash of the IP address the sign-in came from, and the times the session was created, last used, and ended. We do not store the IP address itself in these records — only the hash, which we can compare for equality but cannot turn back into an address. The device identifier is a random value that contains no personal information; it is not a browsing fingerprint, is never shared with third parties, and stays in your browser after you sign out so that signing back in on the same machine is recognized as the same device rather than a new one.

One browser has one device identifier, so if more than one StaffWeaver account is signed in from the same browser, those accounts' session records will each carry that same value. We do not use it to link accounts to one another, and it plays no part in any of the decisions above: each account's sign-in limits are worked out only against that same account's own sessions. You can clear it at any time by clearing your browser's local storage for this site; the only effect is that your next sign-in looks like a new device.

Because of these records, signing in on a different device can end an earlier session for the same account. When that happens, the earlier session is told why rather than being shown a generic timeout.

Unsaved edits kept on your device. The score editor keeps a copy of unsaved edits in your browser's local storage so your work isn't lost if a session ends unexpectedly. That copy stays on your device until you choose to restore it. If a session ends without you asking it to — it times out, or you are signed out because the account was signed in elsewhere — the copy is deliberately kept so the work is still there when you sign back in. Choosing Log out yourself clears it, so nothing of yours is left behind on a shared computer.

Third parties

We work with a small number of third-party services to run StaffWeaver:

  • Google reCAPTCHA protects our signup form from automated abuse. Google's use of information collected by reCAPTCHA is governed by the Google Privacy Policy and Google Terms of Service .
  • Email delivery provider. We use a transactional email provider to send account verification and password-reset messages on our behalf.
  • Stripe. When paid plans launch, we will use Stripe to process payments. We do not currently share any data with Stripe because StaffWeaver does not yet process payments.

Data retention & deletion

We keep your account information and content for as long as your account is active. If you would like your account and data deleted, email support@staffweaver.com and we will process the request.

An account whose email address is never verified cannot be used and holds no content. 30 days after signup we email that address once with a fresh verification link; if it is still unverified 7 days later, the account is deleted, so a mistyped address is released for whoever meant to use it.

Children's privacy

StaffWeaver is not directed at children under 13, and we do not knowingly collect personal information from children under 13.

Changes to this policy

If we make material changes to this policy, we will update the effective date above and, where appropriate, notify account holders by email.

Contact

Questions about this policy? Email support@staffweaver.com.