ShiftPilot ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our scheduling platform and services (collectively, the "Service"). By accessing or using ShiftPilot, you agree to the collection and use of information in accordance with this policy.
This Privacy Policy is written to meet the requirements of the Personal Information Protection and Electronic Documents Act (Canada) and, because our customers include health information custodians, the Personal Health Information Protection Act, 2004(Ontario) and comparable provincial and territorial legislation. Where the customer organization that has given you access to the Service is accountable for your personal information under that legislation, this Privacy Policy describes what we do as that organization's agent and service provider (see section 8).
We collect information that you provide directly to us, including:
When you use our Service, we automatically collect certain information, including:
If you choose to integrate your Google Calendar account, we may access and store calendar-related information in accordance with your authorization and Google's privacy policies.
We use the information we collect for the following purposes:
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:
Schedule information, assignments, and related data may be visible to authorized administrators and relevant personnel within your organization as necessary to perform scheduling functions.
We may share information with third-party service providers who perform services on our behalf, such as hosting, data analytics, email delivery, and customer support. These providers are contractually obligated to protect your information and use it only for specified purposes.
We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a legal process.
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to the same privacy protections.
We maintain administrative, technical and physical safeguards that are appropriate to the sensitivity of the information we hold, as required by the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA"), Principle 7 (Safeguards) of Schedule 1 to that Act, and section 12 of the Personal Health Information Protection Act, 2004(Ontario) ("PHIPA"). Those safeguards include the following.
The Service is operated on infrastructure provided by Vercel, Inc. and Convex, Inc., the latter running on Amazon Web Services. Each of those providers maintains a current SOC 2 Type II attestation and contractual obligations to us regarding confidentiality and security. ShiftPilot itself has not obtained an independent SOC 2 report; we will state clearly when that changes. Production data is stored in data centres located in the United States; see section 16 (International Data Transfers).
If we become aware of any unauthorized access to, or loss, theft or unauthorized use or disclosure of, Customer Data in our custody or control (a "Security Incident"), we will (a) notify the affected customer's designated contact without undue delay and in any event within seventy-two (72) hours of confirming the Security Incident, (b) provide the information reasonably required by the customer to meet its own notification obligations to affected individuals and to the Information and Privacy Commissioner of Ontario or other applicable regulator, and (c) take reasonable steps to contain, investigate and remediate the Security Incident. Nothing in this section limits any shorter notification period required by applicable law or by a written agreement with a customer.
No method of transmission over the Internet or of electronic storage is completely secure. We do not represent that the Service is immune from compromise, and our obligations in respect of a Security Incident are as set out in this Privacy Policy and in any written agreement between us and the customer.
We maintain the following backup program for Customer Data. The measures described in this section are commitments, not aspirations, and are reflected in section 12 of our Terms of Service.
The integrity of the daily export is verified automatically on each run. We perform a restoration exercise of a daily backup into a non-production environment at least once every six (6) months and record the outcome.
Backup copies are subject to the same encryption, access controls and confidentiality obligations as production data. When Customer Data is deleted from production systems under section 7 (Data Retention), copies of that data persist in backups only until those backups expire under section 6.1, after which they are unrecoverable. Backup copies are used solely for recovery and are not accessed for any other purpose.
Independently of our backups, administrators may at any time export their organization's schedules from the Service in spreadsheet form, and may request a complete machine-readable export of their organization's data by contacting us. We encourage customers to retain their own copies of information that is critical to their operations.
We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, to provide the Service to the customer organization, and to meet our legal and contractual obligations, consistent with Principle 5 (Limiting Use, Disclosure and Retention) of Schedule 1 to PIPEDA. Specifically:
Where a longer retention period is required by applicable law, a court order or a written agreement with the customer, that longer period governs.
Our customers are principally hospitals, imaging groups and physician practices in Canada. In providing the Service we act in a manner consistent with PIPEDA and, where a customer is a health information custodian or equivalent, with the health privacy legislation that applies to that customer, including PHIPA (Ontario), the Health Information Act (Alberta), the Health Information Privacy and Management Act (Yukon), the Health Information Act (Northwest Territories) and any comparable provincial or territorial statute.
As between ShiftPilot and a customer, the customer is the organization accountable for the personal information it places in the Service and, where applicable, the health information custodian. ShiftPilot acts as the customer's agent within the meaning of section 17 of PHIPA (and as an information manager, service provider or processor under comparable legislation) and as such:
The Service is a workforce-scheduling platform. The information it processes consists principally of the personal information of the customer's physicians, staff and administrators (names, contact details, credentials, availability, assignments and related communications) together with operational information about the customer's sites. The Service is not designed to receive patient records, images or reports, and customers agree in our Terms of Service not to enter individually identifying patient information into it. Where a customer records aggregate operational figures (for example, the number of studies read during a shift), those figures contain no patient identifiers.
We have designated an individual who is accountable for our compliance with this Privacy Policy and applicable privacy legislation and who may be reached at the address in section 18. Individuals may challenge our compliance by contacting that person, and, if unsatisfied, may complain to the Office of the Privacy Commissioner of Canada or to the Information and Privacy Commissioner of the province or territory in which they reside.
The Service includes an assistant ("Avery") that answers questions and carries out scheduling tasks in response to messages sent through the web application, SMS or WhatsApp. When a user interacts with the assistant, the content of that user's messages, together with the scheduling information reasonably needed to respond, is transmitted to a large-language-model provider through an API gateway operated by Vercel, Inc. The following terms apply to that processing:
We engage the following third parties to process Customer Data on our behalf. Each is bound by written terms that require it to protect the information at a standard no less protective than this Privacy Policy and to use it only to provide its service to us.
We will give customers at least thirty (30) days' notice, by updating this section and by email to the customer's designated contact, before engaging a new subprocessor that will process Customer Data. A customer that objects on reasonable privacy grounds may raise the objection with us under section 13.
Depending on your location, you may have certain rights regarding your personal information, including:
To exercise these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within a reasonable timeframe and in accordance with applicable law.
We use cookies and similar tracking technologies to track activity on our Service and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
Every processing activity described in this Privacy Policy other than those strictly necessary to operate an account is configurable by the customer. A customer organization may, for the organization as a whole or for individual users:
Individual users may withdraw from SMS and WhatsApp messages at any time by replying STOP, and may adjust their own notification preferences within the Service. Requests to opt out of any other processing may be made by the customer's administrator in writing to the address in section 18. We will confirm receipt within two (2) business days and give effect to the request within ten (10) business days, or explain in writing why the request cannot be accommodated (for example, because the processing is necessary to provide a feature the customer has asked us to provide).
Our Service may contain links to third-party websites or integrate with third-party services, such as Google Calendar. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our Service.
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately, and we will take steps to delete such information.
Our production systems and the subprocessors listed in section 10 are located in the United States. Personal information placed in the Service is therefore stored and processed outside Canada, where it is subject to the laws of that jurisdiction, including laws that may permit access by courts, law-enforcement and national-security authorities. We protect information transferred outside Canada through the contractual, technical and organizational safeguards described in sections 5 and 10, which are intended to provide a comparable level of protection to that required under Canadian law. Customers that are health information custodians remain responsible for determining that this arrangement is permitted under the legislation applicable to them; we will provide the information reasonably required for that assessment on request.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy or our privacy practices, please contact us at: