Privacy Policy
Effective Date: 2026-04-15 Last Updated: 2026-04-15
This Privacy Policy describes how ShiftMesh (“we”, “us”, “our”, or “ShiftMesh”) collects, uses, shares, and protects information when you use our platform at shiftme.sh, including our web portal, mobile applications, and API services (collectively, the “Service”).
By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
1. Who We Are
ShiftMesh is a healthcare staffing workforce management platform. We provide software to healthcare staffing agencies (“Agencies”) to manage shifts, credentials, timekeeping, and payroll for healthcare professionals (“Professionals”) serving healthcare facilities (“Facilities”).
Depending on how you use the Service, you may be:
- An Agency Administrator — an employee of a staffing agency that uses ShiftMesh
- A Professional — a nurse, CNA, or allied health worker receiving shifts through an Agency
- A Facility Contact — an employee of a healthcare facility that receives staffing from an Agency
This policy applies to all three roles.
2. Information We Collect
2.1 Information You Provide Directly
Account Information:
- Name, email address, phone number
- Password (stored only as a bcrypt hash — we never see your plaintext password)
- Role (Agency Admin, Professional, Facility Contact)
- Employment classification (W-2 or 1099, for Professionals)
Professional Profile Information:
- Professional license numbers, certifications, and expiration dates
- Photos of credential documents (licenses, BLS, TB tests, immunization records)
- Home address (used for proximity-based shift matching)
- Employment history, skills, and preferences
Identity and Payment Information (collected only when required):
- Social Security Number (for W-2 or 1099 tax reporting) — collected by our payroll provider directly; ShiftMesh never stores raw SSN
- Bank account and routing numbers (for direct deposit) — collected by our payroll provider directly; ShiftMesh never stores raw bank account numbers
- Government-issued ID (for identity verification when required by an Agency)
2.2 Information Collected Automatically
Usage Data:
- Pages viewed, features used, actions taken within the Service
- Device type, browser, operating system, IP address
- Timestamps of logins, shift claims, clock-ins, and other actions
Location Data (Professionals only, during active shifts):
- GPS coordinates when clocking in or clocking out of a shift
- Used solely to verify geofence compliance (within 200 meters of the Facility)
- Location is NOT tracked continuously — only at clock-in and clock-out events
Shift and Work History:
- Shifts claimed, completed, cancelled, or missed
- Timesheet entries (clock-in, clock-out, breaks)
- Reliability score components (attendance, punctuality)
2.3 Information From Third Parties
- Credential verification results from state nursing boards (where integrated)
- Payroll status and payment confirmations from our payroll provider
- Background check results (where required by an Agency, via a separate consent)
3. How We Use Your Information
We use your information to:
- Provide the Service: Authenticate you, route shifts to eligible Professionals, track credentials, process timesheets, and generate payroll.
- Verify geofence compliance: Ensure Professionals are physically at the Facility when clocking in or out.
- Prevent fraud and abuse: Detect duplicate accounts, unauthorized access, and policy violations.
- Comply with legal obligations: Tax reporting (W-2, 1099), labor law compliance, and response to lawful requests.
- Improve the Service: Analyze usage patterns to identify bugs and improve features.
- Communicate with you: Send shift notifications, credential expiry reminders, and account-related messages.
We do NOT use your information for:
- Targeted advertising
- Selling to data brokers
- Profiling for purposes unrelated to staffing and workforce management
4. How We Share Your Information
4.1 Between Platform Participants
- Your Agency sees all information you provide as a Professional: profile, credentials, work history, timesheets, location data at clock-in/out events.
- Facilities where you work see your name, profession, credential validity status, and arrival/departure times for shifts at their facility.
- Other Professionals cannot see your information.
4.2 Service Providers
We share information with third parties that provide services on our behalf, under written contracts that require them to protect your information:
| Provider | Purpose | Data Shared |
|---|---|---|
| Google Cloud Platform | Hosting, storage, database, monitoring | All data (encrypted at rest via CMEK) |
| Check HQ (when enabled) | Payroll processing and Instant Pay disbursement | Payroll amounts, tax classification, bank account information (held by Check HQ directly) |
| Stripe | Subscription billing for Agencies | Billing contact, payment method (held by Stripe) |
| SendGrid | Transactional email delivery | Email address, message content |
If an Agency enables additional services (e.g., SMS notifications via Twilio, KYC verification via Persona), we will disclose those providers at the time the Agency activates them.
4.3 Legal Disclosures
We may disclose your information when required by law, subpoena, court order, or to:
- Comply with labor law or tax reporting obligations
- Respond to lawful requests from government authorities
- Protect the rights, property, or safety of ShiftMesh, our users, or the public
- Investigate fraud, abuse, or policy violations
4.4 Business Transfers
If ShiftMesh is acquired, merged, or sells substantially all assets, your information may be transferred to the acquiring entity under this Privacy Policy or a successor policy of equivalent protection.
5. Data Retention
- Active account data: Retained while your account is active.
- Shift and timesheet records: Retained for 7 years after the shift date (payroll, tax, and labor-law requirement).
- Credential documents: Retained while employment is active plus 7 years.
- Location data: Retained for 2 years, then deleted.
- Deleted accounts: Personal identifiers are anonymized within 90 days of account deletion, except where retention is required by law.
6. Your Rights
6.1 All Users
- Access: Request a copy of the personal information we hold about you.
- Correction: Correct inaccurate information through your account settings or by contacting us.
- Deletion: Request deletion of your account. We will comply except where retention is legally required.
- Portability: Request a machine-readable copy of data you provided.
To exercise any of these rights, email privacy@shiftme.sh.
6.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of sale or sharing (ShiftMesh does not sell personal information)
- Right to limit use of sensitive personal information
We do not discriminate against users who exercise these rights.
6.3 EU and UK Residents (GDPR/UK GDPR)
If you are in the EU or UK, your lawful basis for processing is:
- Contract: Where processing is necessary to provide the Service to you or your Agency
- Legal obligation: Tax, labor, and employment law compliance
- Legitimate interest: Fraud prevention, service improvement
- Consent: Marketing communications (where applicable)
You have the right to object to processing, restrict processing, and lodge a complaint with your data protection authority.
7. Security
We protect your information using:
- TLS encryption in transit (verify-full in production)
- Encryption at rest via Google Cloud KMS with customer-managed encryption keys (CMEK)
- PostgreSQL Row-Level Security (RLS) enforcing tenant isolation
- Multi-factor authentication for administrative access
- Audit logs retained for security investigation
- Regular security scanning (govulncheck, OWASP ZAP baseline)
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and applicable regulators as required by law.
8. Children
The Service is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has provided us information, email privacy@shiftme.sh and we will delete it.
9. International Transfers
ShiftMesh is operated in the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the US. For EU/UK residents, we rely on Standard Contractual Clauses as the lawful basis for transfer.
10. HIPAA
ShiftMesh is not a covered entity or business associate under HIPAA. The Service is used for staffing and workforce management, not for handling Protected Health Information (PHI). We do not intend for PHI to be entered into the Service. If your Agency requires HIPAA coverage, contact us for a Business Associate Agreement.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via email to registered users and a banner on the Service at least 30 days before taking effect. Continued use after the effective date constitutes acceptance.
12. Contact Us
ShiftMesh Privacy Email: privacy@shiftme.sh Support: support@shiftme.sh Website: https://shiftme.sh
If you have a privacy complaint and are not satisfied with our response, you may contact your local data protection authority.