← Back to Home

Privacy Policy

Last updated: September 14, 2026

1. Introduction

ShiftPilot ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our scheduling platform and services (collectively, the "Service"). By accessing or using ShiftPilot, you agree to the collection and use of information in accordance with this policy.

This Privacy Policy is written to meet the requirements of the Personal Information Protection and Electronic Documents Act (Canada) and, because our customers include health information custodians, the Personal Health Information Protection Act, 2004(Ontario) and comparable provincial and territorial legislation. Where the customer organization that has given you access to the Service is accountable for your personal information under that legislation, this Privacy Policy describes what we do as that organization's agent and service provider (see section 8).

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us, including:

  • Name, email address, and contact information
  • Account credentials and authentication information
  • Professional information related to your role and responsibilities
  • Schedule preferences and availability data
  • Communication preferences and correspondence

2.2 Automatically Collected Information

When you use our Service, we automatically collect certain information, including:

  • Device information, including IP address, browser type, and operating system
  • Usage data, including pages visited, features used, and time spent on the Service
  • Log files and analytics data
  • Cookies and similar tracking technologies

2.3 Third-Party Information

If you choose to integrate your Google Calendar account, we may access and store calendar-related information in accordance with your authorization and Google's privacy policies.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve our Service
  • To create and manage your account and user profile
  • To generate, manage, and optimize work schedules
  • To facilitate communication between users and administrators
  • To sync schedule information with integrated calendar services
  • To send administrative information, updates, and notifications
  • To respond to your inquiries, comments, and support requests
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations and enforce our terms of service
  • To analyze usage patterns and improve user experience

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:

4.1 Within Your Organization

Schedule information, assignments, and related data may be visible to authorized administrators and relevant personnel within your organization as necessary to perform scheduling functions.

4.2 Service Providers

We may share information with third-party service providers who perform services on our behalf, such as hosting, data analytics, email delivery, and customer support. These providers are contractually obligated to protect your information and use it only for specified purposes.

4.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a legal process.

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to the same privacy protections.

5. Security Safeguards

We maintain administrative, technical and physical safeguards that are appropriate to the sensitivity of the information we hold, as required by the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA"), Principle 7 (Safeguards) of Schedule 1 to that Act, and section 12 of the Personal Health Information Protection Act, 2004(Ontario) ("PHIPA"). Those safeguards include the following.

5.1 Encryption

  • All data in transit between your device and the Service, and between the Service and our infrastructure providers, is encrypted using Transport Layer Security (TLS 1.2 or higher).
  • All Customer Data at rest, including database records, file storage, search indexes and backup copies, is encrypted using 256-bit AES.
  • Account passwords are never stored in plain text. They are hashed using an adaptive, salted one-way algorithm (bcrypt).

5.2 Access Control

  • Access to Customer Data within the Service is governed by role-based permissions assigned by your organization's administrators. Schedule members see their own information and the information their organization has chosen to share with them; administrative functions are restricted to designated administrators; hospital site logins see only the sites to which they are assigned.
  • Every request to our backend is authenticated and is scoped to the requesting user's organization. No query or mutation returns data belonging to another organization.
  • Access by ShiftPilot personnel to production systems is limited to named individuals who require it to operate and support the Service, is protected by multi-factor authentication at the infrastructure-provider level, and is used only to the extent necessary to provide the Service, resolve an incident or comply with a legal obligation.

5.3 Audit and Monitoring

  • Changes to schedules, assignments, user roles and organization settings are recorded in an immutable audit log that identifies the actor, the time and the change, and that log is available to your administrators within the Service.
  • Every notification the Service sends (email, SMS or WhatsApp) is logged with its delivery outcome.
  • Application errors and security-relevant events are monitored continuously and reviewed by our engineering team.

5.4 Infrastructure

The Service is operated on infrastructure provided by Vercel, Inc. and Convex, Inc., the latter running on Amazon Web Services. Each of those providers maintains a current SOC 2 Type II attestation and contractual obligations to us regarding confidentiality and security. ShiftPilot itself has not obtained an independent SOC 2 report; we will state clearly when that changes. Production data is stored in data centres located in the United States; see section 16 (International Data Transfers).

5.5 Security Incident Response

If we become aware of any unauthorized access to, or loss, theft or unauthorized use or disclosure of, Customer Data in our custody or control (a "Security Incident"), we will (a) notify the affected customer's designated contact without undue delay and in any event within seventy-two (72) hours of confirming the Security Incident, (b) provide the information reasonably required by the customer to meet its own notification obligations to affected individuals and to the Information and Privacy Commissioner of Ontario or other applicable regulator, and (c) take reasonable steps to contain, investigate and remediate the Security Incident. Nothing in this section limits any shorter notification period required by applicable law or by a written agreement with a customer.

No method of transmission over the Internet or of electronic storage is completely secure. We do not represent that the Service is immune from compromise, and our obligations in respect of a Security Incident are as set out in this Privacy Policy and in any written agreement between us and the customer.

6. Backup, Business Continuity and Recovery

We maintain the following backup program for Customer Data. The measures described in this section are commitments, not aspirations, and are reflected in section 12 of our Terms of Service.

6.1 Layers of Protection

  • Continuous replication. Every write to the production database is durably replicated across multiple availability zones by our database provider before it is acknowledged. A single hardware or zone failure does not result in data loss.
  • Daily full backups. A complete export of every production table is taken automatically once every twenty-four (24) hours and stored, encrypted at rest, in a system separate from the production database and separate from the database provider. Each daily export is retained for ninety (90) days.
  • Schedule version history. Independently of the backups above, every publication, import, generation or manual edit of a schedule creates a point-in-time version of that schedule within the Service. Versions are retained for the life of the customer account and may be restored by an administrator from within the Service without engineering involvement.
  • Application code and configuration. All application code is kept in version control with full history, and every production deployment is immutable and may be rolled back to any earlier deployment.

6.2 Recovery Objectives

  • Recovery Point Objective (RPO). For a full restoration of the production database from a daily backup, no more than twenty-four (24) hours of data. For schedule data restored from version history, no data loss beyond the specific change being reversed.
  • Recovery Time Objective (RTO).Restoration of a schedule from version history: minutes, performed by the customer's administrator. Full restoration of the production database from a daily backup: four (4) hours from the decision to restore.

6.3 Testing

The integrity of the daily export is verified automatically on each run. We perform a restoration exercise of a daily backup into a non-production environment at least once every six (6) months and record the outcome.

6.4 Backup Copies and Deletion

Backup copies are subject to the same encryption, access controls and confidentiality obligations as production data. When Customer Data is deleted from production systems under section 7 (Data Retention), copies of that data persist in backups only until those backups expire under section 6.1, after which they are unrecoverable. Backup copies are used solely for recovery and are not accessed for any other purpose.

6.5 Customer Export

Independently of our backups, administrators may at any time export their organization's schedules from the Service in spreadsheet form, and may request a complete machine-readable export of their organization's data by contacting us. We encourage customers to retain their own copies of information that is critical to their operations.

7. Data Retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, to provide the Service to the customer organization, and to meet our legal and contractual obligations, consistent with Principle 5 (Limiting Use, Disclosure and Retention) of Schedule 1 to PIPEDA. Specifically:

  • Account and profile informationis retained for the duration of the customer organization's subscription.
  • Schedules, assignments, availability, version history and audit logs are retained for the duration of the subscription because they constitute the customer's operational record.
  • Notification and message logs are retained for the duration of the subscription to support delivery verification and dispute resolution.
  • Following termination of a subscription, Customer Data is retained for ninety (90) days so that the customer may export it, and is then deleted from production systems within a further thirty (30) days. Backup copies expire in accordance with section 6.4. A customer may request earlier deletion in writing.
  • Aggregated or de-identified information that cannot reasonably be used to identify an individual may be retained without time limit.

Where a longer retention period is required by applicable law, a court order or a written agreement with the customer, that longer period governs.

8. Health Privacy Legislation and Our Role

8.1 Applicable Legislation

Our customers are principally hospitals, imaging groups and physician practices in Canada. In providing the Service we act in a manner consistent with PIPEDA and, where a customer is a health information custodian or equivalent, with the health privacy legislation that applies to that customer, including PHIPA (Ontario), the Health Information Act (Alberta), the Health Information Privacy and Management Act (Yukon), the Health Information Act (Northwest Territories) and any comparable provincial or territorial statute.

8.2 ShiftPilot as Agent and Service Provider

As between ShiftPilot and a customer, the customer is the organization accountable for the personal information it places in the Service and, where applicable, the health information custodian. ShiftPilot acts as the customer's agent within the meaning of section 17 of PHIPA (and as an information manager, service provider or processor under comparable legislation) and as such:

  • we collect, use and disclose personal information in our custody only for the purpose of providing the Service to the customer and in accordance with the customer's instructions, and not for any purpose of our own except as expressly permitted by law;
  • we do not sell personal information, use it for advertising, or use it to train machine-learning models;
  • we notify the customer at the first reasonable opportunity if personal information in our custody is stolen, lost or accessed by unauthorized persons, as required by section 17(3) of PHIPA and section 5.5 of this Privacy Policy;
  • we will enter into a written agency, data processing or information-manager agreement with any customer that requires one to satisfy its obligations under applicable legislation, on request.

8.3 Nature of the Information Processed

The Service is a workforce-scheduling platform. The information it processes consists principally of the personal information of the customer's physicians, staff and administrators (names, contact details, credentials, availability, assignments and related communications) together with operational information about the customer's sites. The Service is not designed to receive patient records, images or reports, and customers agree in our Terms of Service not to enter individually identifying patient information into it. Where a customer records aggregate operational figures (for example, the number of studies read during a shift), those figures contain no patient identifiers.

8.4 Openness and Accountability

We have designated an individual who is accountable for our compliance with this Privacy Policy and applicable privacy legislation and who may be reached at the address in section 18. Individuals may challenge our compliance by contacting that person, and, if unsatisfied, may complain to the Office of the Privacy Commissioner of Canada or to the Information and Privacy Commissioner of the province or territory in which they reside.

9. Automated Assistant and AI Processing

The Service includes an assistant ("Avery") that answers questions and carries out scheduling tasks in response to messages sent through the web application, SMS or WhatsApp. When a user interacts with the assistant, the content of that user's messages, together with the scheduling information reasonably needed to respond, is transmitted to a large-language-model provider through an API gateway operated by Vercel, Inc. The following terms apply to that processing:

  • the model provider is contractually prohibited from using the content to train or improve its models and from retaining it beyond the period required to generate a response;
  • any change the assistant proposes to a schedule, an availability record or a setting takes effect only after the user expressly confirms it; the assistant does not act on its own initiative;
  • transcripts of assistant conversations are retained within the Service as part of the customer's operational record and are visible to the customer's administrators;
  • a customer may disable the assistant, or any channel through which it is reached, for its organization or for individual users, under section 13 (Configuration Choices and Opting Out).

10. Subprocessors

We engage the following third parties to process Customer Data on our behalf. Each is bound by written terms that require it to protect the information at a standard no less protective than this Privacy Policy and to use it only to provide its service to us.

  • Vercel, Inc. (United States): application hosting, edge network, file storage and AI API gateway.
  • Convex, Inc. (United States), operating on Amazon Web Services: primary database, file storage and scheduled functions.
  • GitHub, Inc. (United States): source-code repository and encrypted storage of daily database backups.
  • Twilio Inc. (United States): delivery of SMS and WhatsApp messages.
  • Resend, Inc. (United States): delivery of email.
  • Google LLC (United States): Google Sheets, Google Drive and Google Calendar integrations, only where the customer has connected them.
  • OpenAI, L.L.C. (United States), accessed through the Vercel AI gateway: large-language-model inference for the assistant described in section 9.
  • Functional Software, Inc. (Sentry) (United States): application error monitoring.
  • RingCentral, Inc. (United States): telephony presence synchronization, only where the customer has connected its RingCentral account.
  • ClickUp (Mango Technologies, Inc.) (United States): tracking of support requests and product feedback submitted by users.

We will give customers at least thirty (30) days' notice, by updating this section and by email to the customer's designated contact, before engaging a new subprocessor that will process Customer Data. A customer that objects on reasonable privacy grounds may raise the objection with us under section 13.

11. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information, including:

  • Access: Request access to your personal information
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data to another service
  • Objection: Object to certain processing activities
  • Withdrawal: Withdraw consent where processing is based on consent

To exercise these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within a reasonable timeframe and in accordance with applicable law.

12. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Service and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

13. Configuration Choices and Opting Out

Every processing activity described in this Privacy Policy other than those strictly necessary to operate an account is configurable by the customer. A customer organization may, for the organization as a whole or for individual users:

  • disable any notification channel (email, SMS or WhatsApp) or any category of automated message;
  • disable the assistant described in section 9, or restrict it to particular channels or roles;
  • decline or disconnect any integration (Google Sheets, Google Drive, Google Calendar, RingCentral) at any time, whereupon we cease exchanging data with that service;
  • decline the use of error-monitoring session replay for its users;
  • request that particular data fields not be collected or be deleted, or request a shorter retention period than that set out in section 7;
  • request a copy of, or the deletion of, any backup export under section 6, to the extent technically feasible.

Individual users may withdraw from SMS and WhatsApp messages at any time by replying STOP, and may adjust their own notification preferences within the Service. Requests to opt out of any other processing may be made by the customer's administrator in writing to the address in section 18. We will confirm receipt within two (2) business days and give effect to the request within ten (10) business days, or explain in writing why the request cannot be accommodated (for example, because the processing is necessary to provide a feature the customer has asked us to provide).

14. Third-Party Services

Our Service may contain links to third-party websites or integrate with third-party services, such as Google Calendar. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our Service.

15. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately, and we will take steps to delete such information.

16. International Data Transfers

Our production systems and the subprocessors listed in section 10 are located in the United States. Personal information placed in the Service is therefore stored and processed outside Canada, where it is subject to the laws of that jurisdiction, including laws that may permit access by courts, law-enforcement and national-security authorities. We protect information transferred outside Canada through the contractual, technical and organizational safeguards described in sections 5 and 10, which are intended to provide a comparable level of protection to that required under Canadian law. Customers that are health information custodians remain responsible for determining that this arrangement is permitted under the legislation applicable to them; we will provide the information reasonably required for that assessment on request.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

18. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at: