Terms of Service

Worksights Ltd, trading as RateMyShift Company number: 16058573 | Registered office: The Bakehouse, Blagdon Hill, Taunton, Somerset, TA3 7SF

1. About These Terms and Order of Precedence

These Terms of Service ("Terms") govern access to and use of the website at www.ratemyshift.app and the application at https://my.ratemyshift.app (together, the "Site"), and the use of the RateMyShift services (the "Services") provided by Worksights Ltd ("we", "us", "our", or the "Provider").

Order of Precedence: These Terms, together with the applicable Order Form, our Privacy Policy, and Acceptable Use Policy, constitute the entire agreement between the parties. In the event of any conflict or inconsistency between these Terms and an Order Form, the provisions of the Order Form shall prevail to the extent of such conflict.

2. Eligibility and Account Registration

You must be at least 18 years old to create an Account. You must provide accurate, current, and complete information when registering. You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your Account. We may suspend or close an Account where we reasonably believe these Terms or our Acceptable Use Policy have been breached.

3. Fees and Payment

  1. Payment Methods: The Customer shall pay the Subscription Fees in accordance with the billing frequency and payment method selected in the applicable Order Form. Where the Customer selects payment by credit or debit card, the Customer authorises the Provider (via its third-party payment processor) to charge the card on a recurring basis. Where the Customer selects payment by invoice (subject to the Provider's prior approval and credit check), the Provider shall issue invoices in advance, and the Customer must pay such invoices within 30 days of the invoice date. Late payments may be subject to interest at the rate of 8% per annum above the Bank of England base rate. All fees are exclusive of VAT.

  2. Adding or Removing Users and Tier Changes:

  • Adding Users: The Customer may add additional users to their Account at any time during the Subscription Period. Additional users will be billed immediately at a prorated rate for the remainder of the current Subscription Period, ensuring all user licenses co-term and renew on the exact same date.

  • Tier Upgrades: If the addition of users causes the Customer's total user count to exceed the maximum limit of their current Plan tier, the Account will automatically be upgraded to the applicable higher tier. The new tier's per-user pricing will apply to the prorated new users immediately, and will apply to all existing users starting from the Customer’s next billing cycle.

    • Example: If you are on the Team plan (1-50 users) and add your 51st user halfway through your billing cycle, you will immediately be billed for just that 51st user at a prorated amount based on the lower Mid-size rate. On your next scheduled renewal date, all 51 of your users will renew together at the lower Mid-size rate.

  • Removing Users (Downgrades): The Customer may remove active users at any time. We do not provide prorated refunds or credits for users removed mid-cycle. The reduced user count and any resulting drop back into a lower-volume tier will automatically take effect at the Customer's next scheduled renewal date.

    • Example: If you remove 5 users halfway through your billing cycle, no mid-cycle refund is issued, but you will not be billed for those seats at your next renewal. If removing those users drops your total count from 55 back down to 45, your entire account will renew at the standard Team rate rather than the Mid-size rate

4. Term and Renewal

The initial Subscription Period shall be as set out in the applicable Order Form. The Subscription shall automatically renew for successive periods equal in length to the initial Subscription Period. To prevent auto-renewal, the Customer must provide written notice of cancellation: (a) at least 30 days prior to the end of the current term for monthly Subscriptions; or (b) at least 60 days prior to the end of the current term for annual Subscriptions.

5. Service Availability and Support

  1. The Provider will use reasonable endeavours to maintain the availability of the Hosted Services. Technical responsibility for service restoration sits with our core engineering team.

  2. We operate a multi-channel support model to ensure rapid incident reporting and resolution. Support Services for the Platform are provided in accordance with the Customer's chosen Plan.

  3. For the Community Plan, we provide email and community forum support.

  4. For Team, Mid-size Orgs, and Enterprise Plans, we provide online, live chat, and telephone support. Our developers provide live chat and telephone support from 06:00 to 22:00 UK time.

  5. We provide an enterprise-level Support Hub for logging and tracking tickets, providing a transparent audit trail of all reported issues.

  6. Professional Services: Any management coaching, advanced culture transformation training, or bespoke implementation packages are available for separate purchase. These services fall outside the scope of these Terms (which strictly govern software access) and will be subject to a separate agreement, Order Form, or Statement of Work.

6. Data Security

The Provider shall implement and maintain appropriate technical and organisational measures to protect Customer Data and Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. Specifically, the Hosted Services shall maintain compliance with the Open Web Application Security Project® (OWASP) Application Security Verification Standard (ASVS) Level 2. These security measures include:

  • Enforcing a password policy requiring a minimum of 8 characters, including at least 1 symbol, 1 uppercase letter, 1 lowercase letter, and 1 digit.

  • Prohibiting the use of common passwords.

  • Ensuring no passwords are stored in plain text.

  • Providing Multifactor Authentication (MFA), which is optionally enforceable at the tenant (Customer) level.

  • Ensuring Customer Data is accessible only through the protected API endpoints of the application.

7. Intellectual Property and Customer Data

We and our licensors own all intellectual property rights in the Platform, the Site, and the Services, including all software, design, trademarks, and underlying technology. We grant you a non-exclusive, non-transferable licence to access and use the Services during your Subscription. As between you and us, you own all right, title, and interest in Customer Data. You grant us a non-exclusive licence to host, copy, store, transmit, and process Customer Data to the extent reasonably necessary to provide the Services.

8. Limitation of Liability

Our total liability to you arising out of or in connection with these Terms, whether in contract, tort (including negligence) or otherwise, shall not exceed the total Subscription Fees paid by you in the 12 months preceding the event giving rise to the claim. If the Customer is on a free plan, trial, or has otherwise paid no fees in the preceding 12 months, the Provider's total aggregate liability shall not exceed £100. We shall not be liable for any indirect or consequential loss, or for loss of profits, revenue, business opportunity, or data. Nothing in these Terms excludes or limits liability for fraud, or for death or personal injury caused by negligence.

9. Suspension and Termination

We may suspend or terminate your Account with notice if you breach these Terms, the Acceptable Use Policy, or fail to pay Subscription Fees when due. Upon termination, your right to access the Services will immediately cease.

10. General Provisions

  • Confidentiality: Each party will keep confidential any non-public information disclosed by the other party and will only use it for the purposes of these Terms.

  • Assignment: You may not assign or transfer your rights under these Terms without our prior written consent.

  • Force Majeure: Neither party is liable for any failure or delay in performance caused by circumstances beyond its reasonable control.

  • Governing Law: These Terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute.

Schedule 1: Data Protection and Retention

1. Roles and ComplianceThe Customer is the controller of any Personal Data submitted through the Services, and the Provider acts as a processor. Both parties shall comply with the Data Protection Laws (including the UK GDPR).

2. Scope of Processing

  • Categories of Data Subject: Employees of the Customer for whom accounts have been created.

  • Types of Personal Data: Full names and email addresses.

3. Infrastructure and Management
Data retained on our Google Cloud Platform (GCP) infrastructure is managed through a formal Data Retention Schedule. We do not use archiving in the sense of long-term offline storage. Data is either active, pseudonymised for longitudinal analytics, or permanently destroyed.

4. Destruction Process
When data reaches its retention limit (such as 12 months for chat logs or 24 months of inactivity for account profile data) it is destroyed via a two-stage process. Logical Deletion involves our application-level scripts removing the data records from the production database to ensure the data is immediately inaccessible to users and the application. Infrastructure Purge follows logical deletion where we rely on the GCP standard deletion pipeline. Google marks the underlying storage space as available and overwrites it over time. This includes the expiration of data from daily and weekly backup snapshots which typically completes within 180 days.

5. Cryptographic ErasureFor data stored in GCP Cloud Storage or persistent disks, destruction is further ensured via cryptographic erasure. By deleting the unique encryption keys associated with that specific data block, the information is rendered instantly unrecoverable even before the physical storage is overwritten.

6. Archiving and PseudonymisationWe do not archive identifiable personal data. For the purposes of long-term workforce analytics with a 10-year retention, shift-related data is pseudonymised. This involves the permanent destruction of primary identifiers (such as Name and NHS Email) whilst retaining professional context (like Job Role and Team). This severed data is stored within the same encrypted production environment but can no longer be linked to a living individual.

7. Verification
Deletion processes are automated via scheduled tasks to ensure consistent application of the retention policy without requiring manual intervention. We perform quarterly internal audits to verify that automated purge scripts have executed successfully.

Contact Us

Got questions or concerns? We're listening.
Email: hello@ratemyshift.app
Web: www.ratemyshift.app

Thanks for reading and welcome to the RateMyShift community.