ShiftDove Inc. ("ShiftDove," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our workforce and care management platform, website, and related services (collectively, the "Service").
This policy applies to all users of the Service, including healthcare organizations, their staff, administrators, and website visitors. We operate in the United States and Canada and comply with applicable privacy laws in both jurisdictions.
1. Introduction
ShiftDove provides a cloud-based platform for workforce scheduling, client management, GPS attendance tracking, timesheet processing, and care coordination. In delivering these services, we collect and process certain personal information.
This Privacy Policy describes our practices regarding personal information and applies to all personal information we process, regardless of the data subject's location. We adhere to the principles of data protection embedded in applicable privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada and relevant state privacy laws in the United States.
2. Definitions
- Personal Information: Any information that identifies or could reasonably be linked to you or your household, including name, email address, phone number, and online identifiers.
- Protected Health Information (PHI): Individually identifiable health information as defined under the Health Insurance Portability and Accountability Act (HIPAA), including medical records, treatment information, and health status data.
- Customer Data: All data uploaded, entered, or generated by authorized users through the Service, including PHI, client records, schedules, and timesheets.
- Processing: Any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
- Sub-processor: A third-party service provider that processes data on our behalf to support the delivery of the Service.
3. Information We Collect
3.1 Account Information
When you register for the Service, we collect:
- Full name and job title
- Email address and phone number
- Organization name and role
- Login credentials (passwords are stored in encrypted form)
- Payment and billing information (processed by our payment processor)
3.2 Healthcare & Operational Data
When the Service is used for care management, the following types of data may be processed:
- Client and patient records (names, contact information, care plans)
- Staff schedules, shift assignments, and attendance records
- GPS location data collected during clock-in/clock-out for electronic visit verification (EVV)
- Timesheet and payroll data
- Incident reports
- Notes and documentation entered by authorized users
Where this data constitutes PHI, it is handled under a BAA and is not governed by this Privacy Policy.
3.3 Usage & Technical Data
We automatically collect certain information when you use the Service:
- Device information (browser type, operating system, device identifiers)
- Log data (IP address, access times, pages viewed, features used)
- Usage patterns and preferences within the Service
- Error and performance data
3.4 Cookies & Similar Technologies
We use cookies and similar tracking technologies to collect usage data and improve the Service. For full details, see Section 13 (Cookies & Tracking).
4. How We Collect Information
We collect information through the following means:
- Directly from you: When you create an account, fill out forms, enter data into the Service, or communicate with us.
- From your organization: Your employer or organization administrator may provide account and operational data on your behalf.
- Automatically: Through cookies, server logs, and similar technologies when you access or use the Service.
- From third parties: Payment processors for billing, analytics providers for usage insights, and integration partners when you connect third-party services.
5. How We Use Information
We use personal information for the following purposes:
- Providing the Service: Scheduling, attendance tracking, timesheet processing, care coordination, and reporting
- Account management: Creating accounts, authenticating users, providing customer support
- Service improvement: Analyzing usage patterns, troubleshooting issues, developing new features
- Communication: Sending service-related notices, responding to inquiries, and (with your consent) sending marketing communications
- Security: Detecting fraud, unauthorized access, and other suspicious activity
- Legal compliance: Meeting regulatory obligations, responding to legal requests, and enforcing our terms
6. Legal Bases for Processing
We process personal information on the following legal bases:
- Consent: Where you have given explicit consent for specific processing activities (e.g., marketing emails, non-essential cookies)
- Contract performance: Where processing is necessary to fulfill our contractual obligations to you or your organization
- Legal obligation: Where processing is required to comply with applicable laws, regulations, or court orders (e.g., EVV data retention requirements)
- Legitimate interests: Where processing is necessary for our legitimate business interests (e.g., service improvement, security, fraud prevention), provided those interests are not overridden by your rights
Under PIPEDA, we comply with the 10 Fair Information Principles, including obtaining meaningful consent at or before the point of collection. You may withdraw your consent at any time, subject to legal or contractual restrictions.
7. Information Sharing & Disclosure
We may share personal information in the following circumstances:
- Service providers (sub-processors): We share data with third-party vendors who provide infrastructure, hosting, analytics, payment processing, and other services that support the delivery of the Service. All sub-processors are bound by contractual obligations to protect your data and may only process it on our instructions.
- Your organization:Data generated within an organization's account is accessible to authorized administrators and members of that organization.
- Legal requirements: We may disclose information if required by law, regulation, subpoena, court order, or other legal process.
- Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of the transaction. We will notify you of any change in ownership or use of your personal information.
- With your consent: We may share information for purposes not described in this policy only with your explicit consent.
8. HIPAA Disclosures (United States)
For healthcare organizations in the United States, ShiftDove may act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
Key points:
- We execute a Business Associate Agreement (BAA) with each healthcare organization customer that requires us to process PHI
- We implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule
- We follow the minimum necessary standard — access to PHI is limited to the minimum necessary to accomplish the intended purpose
- We report security incidents and breaches as required by the BAA and HIPAA, including breach notification within 60 days of discovery
- We do not use or disclose PHI for marketing or purposes unrelated to the Service without authorization
Patients and care recipients should contact their healthcare provider directly for information about how their health data is handled.
9. PIPEDA Disclosures (Canada)
ShiftDove complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Our practices are guided by PIPEDA's 10 Fair Information Principles:
- Accountability: We have designated a Privacy Officer responsible for compliance with this policy and applicable privacy laws.
- Identifying Purposes: We identify the purposes for which personal information is collected at or before the time of collection.
- Consent: We obtain meaningful consent before collecting, using, or disclosing personal information. Consent may be express or implied depending on the sensitivity of the data.
- Limiting Collection: We collect only the personal information necessary for the identified purposes. We do not collect information indiscriminately.
- Limiting Use, Disclosure, and Retention: We use and disclose personal information only for the purposes for which it was collected, unless you consent otherwise or as required by law. We retain information only as long as necessary.
- Accuracy: We take reasonable steps to ensure personal information is accurate, complete, and up to date.
- Safeguards: We protect personal information with appropriate physical, organizational, and technological security measures.
- Openness: We make information about our privacy policies and practices readily available.
- Individual Access: You have the right to access the personal information we hold about you and to request corrections. We will respond to access requests within 30 days.
- Challenging Compliance: You may challenge our compliance with this policy by contacting our Privacy Officer. We will investigate all complaints.
Provincial Privacy Laws
Depending on your province of residence, additional privacy legislation may apply, including:
- Ontario PHIPA: Personal Health Information Protection Act — governs the collection, use, and disclosure of personal health information in Ontario
- BC PIPA: Personal Information Protection Act — governs private sector collection, use, and disclosure of personal information in British Columbia
- Alberta PIPA: Personal Information Protection Act — governs private sector collection, use, and disclosure of personal information in Alberta
- Quebec Law 25: An Act to modernize legislative provisions as regards the protection of personal information — introduces enhanced requirements including data portability, Privacy Impact Assessments, and mandatory incident reporting
We comply with the applicable requirements of these provincial laws where they apply to our processing activities.
Cross-Border Data Transfers
ShiftDove operates infrastructure in both the United States and Canada. Where personal information is transferred across borders, we ensure comparable protection through contractual safeguards, including data processing agreements and standard contractual clauses, as required by PIPEDA and applicable provincial laws.
10. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete personal information
- Deletion: Request deletion of your personal information, subject to legal and contractual retention obligations
- Portability: Request your data in a structured, commonly used, machine-readable format
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time (this will not affect the lawfulness of processing before withdrawal)
- Opt out of marketing:Unsubscribe from marketing communications at any time by clicking "unsubscribe" in any email or contacting us
To exercise any of these rights, contact us at privacy@shiftdove.com. We will respond to your request within 30 days, as required by PIPEDA, or within the time frame required by applicable law.
If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC) or the relevant provincial privacy commissioner.
11. Data Security
We implement comprehensive technical and organizational measures to protect personal information against unauthorized access, disclosure, alteration, and destruction:
- Encryption: Data is encrypted at rest using AES-256 and in transit using TLS 1.3
- Access controls: Role-based access control (RBAC) with the minimum necessary principle. Multi-factor authentication (MFA) is available for all accounts
- Audit logging: Comprehensive, centralized audit logging of all data access and modifications
- Infrastructure: Cloud infrastructure hosted on AWS (us-east-2 and ca-central-1) with built-in security controls
- Employee training: All employees with access to personal information receive regular privacy and security training
- Incident response: Documented incident response procedures including breach notification as required by HIPAA and PIPEDA
While we take every reasonable precaution, no method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please report it to security@shiftdove.com.
12. Data Retention
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by law:
- Account data: Retained for the duration of your account and for 30 days following termination, after which it is deleted
- Operational data: Customer Data (including PHI under BAA) is retained according to the terms of the applicable subscription agreement and BAA
- Usage data: Anonymized and aggregated after 12 months; fully deleted after 24 months
- Breach logs: Retained for a minimum of 24 months as required by PIPEDA
- Financial records: Retained for 7 years as required by tax and accounting regulations
13. Cookies & Tracking Technologies
We use the following types of cookies:
- Strictly necessary cookies: Required for the Service to function (e.g., authentication, session management, security). These cannot be disabled.
- Analytics cookies: Help us understand how users interact with the Service (e.g., Google Analytics). We use this data to improve the Service.
- Preference cookies: Remember your settings and preferences to provide a personalized experience.
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.
We do not use cookies for cross-site tracking or behavioral advertising. We do not sell information collected through cookies.
14. Children's Privacy
The Service is not directed at children under 13 years of age (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will delete it promptly.
If you are a parent or guardian and believe your child has provided personal information to us, please contact us at privacy@shiftdove.com.
15. Third-Party Links
The Service may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party service before providing your personal information. We are not responsible for the privacy practices of third parties.
16. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. ShiftDove primarily operates in the United States and Canada. When we transfer personal information across borders, we implement appropriate safeguards, including:
- Data processing agreements with all sub-processors
- Standard contractual clauses where required by applicable law
- Verification that receiving jurisdictions provide comparable data protection
By using the Service, you consent to the transfer of your personal information to countries outside your country of residence, subject to the safeguards described in this policy.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. For material changes, we will:
- Provide at least 30 days' notice before the changes take effect
- Notify you by email and by posting a prominent notice on the Service
- Where required by law, obtain your consent to the changes
We encourage you to review this policy periodically. The "Last Updated" date at the top of this page indicates when this policy was last revised.
18. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact our Privacy Officer:
ShiftDove
Email: privacy@shiftdove.com
General inquiries: info@shiftdove.com
Miami, Florida, United States (US Headquarters)
Ontario, Canada (Canada Office)
If you are not satisfied with our response, you may file a complaint with:
- Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca or call 1-800-282-1376
- Relevant provincial privacy commissioner (e.g., Information and Privacy Commissioner of Ontario)