Privacy Policy

Effective Date: 2026-04-15 Last Updated: 2026-04-15

This Privacy Policy describes how ShiftMesh (“we”, “us”, “our”, or “ShiftMesh”) collects, uses, shares, and protects information when you use our platform at shiftme.sh, including our web portal, mobile applications, and API services (collectively, the “Service”).

By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.


1. Who We Are

ShiftMesh is a healthcare staffing workforce management platform. We provide software to healthcare staffing agencies (“Agencies”) to manage shifts, credentials, timekeeping, and payroll for healthcare professionals (“Professionals”) serving healthcare facilities (“Facilities”).

Depending on how you use the Service, you may be:

  • An Agency Administrator — an employee of a staffing agency that uses ShiftMesh
  • A Professional — a nurse, CNA, or allied health worker receiving shifts through an Agency
  • A Facility Contact — an employee of a healthcare facility that receives staffing from an Agency

This policy applies to all three roles.


2. Information We Collect

2.1 Information You Provide Directly

Account Information:

  • Name, email address, phone number
  • Password (stored only as a bcrypt hash — we never see your plaintext password)
  • Role (Agency Admin, Professional, Facility Contact)
  • Employment classification (W-2 or 1099, for Professionals)

Professional Profile Information:

  • Professional license numbers, certifications, and expiration dates
  • Photos of credential documents (licenses, BLS, TB tests, immunization records)
  • Home address (used for proximity-based shift matching)
  • Employment history, skills, and preferences

Identity and Payment Information (collected only when required):

  • Social Security Number (for W-2 or 1099 tax reporting) — collected by our payroll provider directly; ShiftMesh never stores raw SSN
  • Bank account and routing numbers (for direct deposit) — collected by our payroll provider directly; ShiftMesh never stores raw bank account numbers
  • Government-issued ID (for identity verification when required by an Agency)

2.2 Information Collected Automatically

Usage Data:

  • Pages viewed, features used, actions taken within the Service
  • Device type, browser, operating system, IP address
  • Timestamps of logins, shift claims, clock-ins, and other actions

Location Data (Professionals only, during active shifts):

  • GPS coordinates when clocking in or clocking out of a shift
  • Used solely to verify geofence compliance (within 200 meters of the Facility)
  • Location is NOT tracked continuously — only at clock-in and clock-out events

Shift and Work History:

  • Shifts claimed, completed, cancelled, or missed
  • Timesheet entries (clock-in, clock-out, breaks)
  • Reliability score components (attendance, punctuality)

2.3 Information From Third Parties

  • Credential verification results from state nursing boards (where integrated)
  • Payroll status and payment confirmations from our payroll provider
  • Background check results (where required by an Agency, via a separate consent)

3. How We Use Your Information

We use your information to:

  1. Provide the Service: Authenticate you, route shifts to eligible Professionals, track credentials, process timesheets, and generate payroll.
  2. Verify geofence compliance: Ensure Professionals are physically at the Facility when clocking in or out.
  3. Prevent fraud and abuse: Detect duplicate accounts, unauthorized access, and policy violations.
  4. Comply with legal obligations: Tax reporting (W-2, 1099), labor law compliance, and response to lawful requests.
  5. Improve the Service: Analyze usage patterns to identify bugs and improve features.
  6. Communicate with you: Send shift notifications, credential expiry reminders, and account-related messages.

We do NOT use your information for:

  • Targeted advertising
  • Selling to data brokers
  • Profiling for purposes unrelated to staffing and workforce management

4. How We Share Your Information

4.1 Between Platform Participants

  • Your Agency sees all information you provide as a Professional: profile, credentials, work history, timesheets, location data at clock-in/out events.
  • Facilities where you work see your name, profession, credential validity status, and arrival/departure times for shifts at their facility.
  • Other Professionals cannot see your information.

4.2 Service Providers

We share information with third parties that provide services on our behalf, under written contracts that require them to protect your information:

ProviderPurposeData Shared
Google Cloud PlatformHosting, storage, database, monitoringAll data (encrypted at rest via CMEK)
Check HQ (when enabled)Payroll processing and Instant Pay disbursementPayroll amounts, tax classification, bank account information (held by Check HQ directly)
StripeSubscription billing for AgenciesBilling contact, payment method (held by Stripe)
SendGridTransactional email deliveryEmail address, message content

If an Agency enables additional services (e.g., SMS notifications via Twilio, KYC verification via Persona), we will disclose those providers at the time the Agency activates them.

We may disclose your information when required by law, subpoena, court order, or to:

  • Comply with labor law or tax reporting obligations
  • Respond to lawful requests from government authorities
  • Protect the rights, property, or safety of ShiftMesh, our users, or the public
  • Investigate fraud, abuse, or policy violations

4.4 Business Transfers

If ShiftMesh is acquired, merged, or sells substantially all assets, your information may be transferred to the acquiring entity under this Privacy Policy or a successor policy of equivalent protection.


5. Data Retention

  • Active account data: Retained while your account is active.
  • Shift and timesheet records: Retained for 7 years after the shift date (payroll, tax, and labor-law requirement).
  • Credential documents: Retained while employment is active plus 7 years.
  • Location data: Retained for 2 years, then deleted.
  • Deleted accounts: Personal identifiers are anonymized within 90 days of account deletion, except where retention is required by law.

6. Your Rights

6.1 All Users

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Correct inaccurate information through your account settings or by contacting us.
  • Deletion: Request deletion of your account. We will comply except where retention is legally required.
  • Portability: Request a machine-readable copy of data you provided.

To exercise any of these rights, email privacy@shiftme.sh.

6.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights:

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of sale or sharing (ShiftMesh does not sell personal information)
  • Right to limit use of sensitive personal information

We do not discriminate against users who exercise these rights.

6.3 EU and UK Residents (GDPR/UK GDPR)

If you are in the EU or UK, your lawful basis for processing is:

  • Contract: Where processing is necessary to provide the Service to you or your Agency
  • Legal obligation: Tax, labor, and employment law compliance
  • Legitimate interest: Fraud prevention, service improvement
  • Consent: Marketing communications (where applicable)

You have the right to object to processing, restrict processing, and lodge a complaint with your data protection authority.


7. Security

We protect your information using:

  • TLS encryption in transit (verify-full in production)
  • Encryption at rest via Google Cloud KMS with customer-managed encryption keys (CMEK)
  • PostgreSQL Row-Level Security (RLS) enforcing tenant isolation
  • Multi-factor authentication for administrative access
  • Audit logs retained for security investigation
  • Regular security scanning (govulncheck, OWASP ZAP baseline)

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and applicable regulators as required by law.


8. Children

The Service is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has provided us information, email privacy@shiftme.sh and we will delete it.


9. International Transfers

ShiftMesh is operated in the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the US. For EU/UK residents, we rely on Standard Contractual Clauses as the lawful basis for transfer.


10. HIPAA

ShiftMesh is not a covered entity or business associate under HIPAA. The Service is used for staffing and workforce management, not for handling Protected Health Information (PHI). We do not intend for PHI to be entered into the Service. If your Agency requires HIPAA coverage, contact us for a Business Associate Agreement.


11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via email to registered users and a banner on the Service at least 30 days before taking effect. Continued use after the effective date constitutes acceptance.


12. Contact Us

ShiftMesh Privacy Email: privacy@shiftme.sh Support: support@shiftme.sh Website: https://shiftme.sh

If you have a privacy complaint and are not satisfied with our response, you may contact your local data protection authority.