Privacy Policy

Last updated: August 20, 2026 · Applies to the ClinCover platform and clincover.com

1. Overview

This Privacy Policy explains how ClinCover Solutions (“ClinCover,” “we,” “us”) collects, uses, shares, and protects information in connection with the ClinCover physician scheduling platform and our website (together, the “Platform”). It applies to the clinicians, schedulers, and administrators who use the Platform (“Users”), and to visitors to our website.

ClinCover is business-to-business software. We license the Platform to hospitals, physician groups, and similar healthcare organizations (each, a “Customer Organization”), and the people who sign in are staff and providers of those organizations. That relationship shapes everything below. Most importantly, the information in the Platform belongs to your organization, not to us.

2. Our Role and Your Organization’s Data

Your organization decides what goes into ClinCover; we process it on their behalf. A Customer Organization determines who appears on its roster, which facilities and shifts exist, what credential records are maintained, and who is granted administrator access. We handle that information under our written agreement with the organization and under its instructions. We do not decide, on our own, to use it for some other purpose.

In the vocabulary of most privacy laws, the Customer Organization is the controller (or business) of that information and ClinCover is a service provider (or processor) acting for it. Practically, this means that if you are a provider or scheduler asking to see, correct, or remove your information, your organization is usually the right first stop. Section 10 explains how we help.

We act as the controller of a small amount of information in our own right: the technical and account records we need to operate the Platform securely, and any message you send us directly (for example, a demo request emailed to us).

3. Information We Collect

Information your organization provides

  • Roster information: provider and staff names, work email addresses, and whether an account carries administrator permissions.
  • Schedule information: shift assignments recording who is working, at which facility, on which date, in which shift type (for example day, night, call, or backup).
  • Facility and shift definitions: the campuses, sites, and shift templates your organization schedules against.
  • Credential information: the records your organization maintains about where a provider is credentialed and eligible to work, used to determine which open shifts that provider may claim.

Information imported from your scheduling system of record

  • ClinCover synchronizes automatically, normally nightly, with the scheduling system your organization already uses as its system of record, at your organization’s direction. That import brings across the schedule and roster information described above. We keep a record of each import run (when it ran, what changed, whether it succeeded) so the schedule’s accuracy can be audited.

Information you provide directly

  • The work email address you enter to request a sign-in link, and the actions you take in the Platform, such as claiming an open shift, or an administrator approving or declining a claim.
  • Anything you choose to write to us, such as a demo or support request.

Information collected automatically

  • Basic technical information needed to operate and secure the Platform, such as IP address, browser type, and pages requested, together with the functional cookies that keep you signed in. We do not run third-party advertising trackers, and we do not sell or share personal information for targeted advertising.

Payment information

  • The Platform does not process payments and does not collect card or bank details from Users. Fees are handled directly between ClinCover Solutions and the Customer Organization outside the Platform. Where the Platform displays an incentive amount attached to an open shift, that is scheduling information, a figure your organization published. Any actual payment is made by your organization through its own payroll process, not by us.

4. Patient Information

ClinCover schedules clinicians, not patients. The Platform is designed to hold workforce information: who is working where and when. It is not designed to receive, and should not be used to store, patient records or protected health information (PHI).

Please do not enter patient names, medical record numbers, diagnoses, or any other patient information into free-text fields such as shift labels or notes. If your organization believes PHI has been entered into the Platform, contact us at the address in Section 14 so it can be removed.

Where a Customer Organization requires a Business Associate Agreement or other specific healthcare data terms, those are addressed in the written agreement between that organization and ClinCover Solutions, and that agreement controls over this policy to the extent of any conflict.

5. How We Use Information

  • To display the schedule to the people your organization has authorized to see it;
  • To keep that schedule current by importing from your system of record, and to detect and halt an import that looks anomalous rather than publishing bad data;
  • To operate the open shift board by showing which extra shifts are available, determining eligibility from the credential records your organization maintains, and routing claims to an administrator for approval;
  • To authenticate you, by emailing a one-time sign-in link to a work email address on your organization’s roster;
  • To provide administrative tools to the administrators your organization designates;
  • To operate, secure, debug, and improve the Platform, and to prevent fraud and abuse;
  • To communicate with your organization about the service;
  • To comply with legal obligations.

We do not use your personal information for third-party advertising, we do not sell it, and we do not use the contents of a Customer Organization’s data to build products for anyone else.

6. How We Share Information

We share personal information only as described here:

  • Within your organization. The Platform is a shared schedule by design: colleagues at your organization can see who is covering which facility and shift, and administrators can additionally see roster, credential, and open-shift claim information. What each person can see is governed by the permissions your organization sets.
  • With service providers that help us run the Platform, under obligations to use the information only to provide those services. Today this includes our database and authentication provider, Supabase (which hosts the application database and delivers sign-in link emails), and our application hosting provider. We do not permit these providers to use your information for their own purposes.
  • With your scheduling system of record, to the extent your organization directs us to connect to it. That connection is read-oriented: we import your organization’s schedule into ClinCover.
  • For legal reasons. To comply with law, enforce our Terms of Use, or protect the rights, safety, and property of ClinCover Solutions, our Customer Organizations, or others.
  • In a business transfer. If ClinCover Solutions is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this policy.

We do not sell personal information, and we have not sold it in the preceding 12 months.

7. Cookies & Sign-In Sessions

We use strictly functional cookies: a session cookie that keeps you signed in, and technical cookies required for the site to work. We do not use advertising cookies or cross-site tracking. Because we do not track you across other sites, the Platform does not respond differently to browser “Do Not Track” signals. There is nothing to turn off. If we ever introduce analytics or advertising technologies, we will update this policy and provide appropriate choices first.

8. How We Protect Information

  • All traffic between your browser and the Platform is encrypted in transit (HTTPS).
  • Sign-in uses one-time emailed links, so there are no passwords to steal, reuse, or leak. A link is only sent to an email address already on your organization’s roster, and a signed-in person who is not on that roster is not granted access.
  • Access checks run on the server on every request, so a page cannot be reached by guessing its address, and administrative functions are limited to the accounts your organization has designated as administrators.
  • Our database and hosting providers maintain their own physical, network, and encryption-at-rest safeguards for the infrastructure they operate.

No method of transmission or storage is 100% secure, but we design the Platform so that each person can only reach what they legitimately need. If you believe an account has been compromised, tell your organization’s administrator and contact us at the address in Section 14.

9. Data Retention

We retain the information described in Section 3 for as long as your organization’s agreement with us is in effect, because a schedule is a record your organization relies on historically as well as day to day. Your organization controls what is kept in its own account and may correct or remove records at any time.

After that agreement ends, we delete or de-identify the organization’s data on the schedule set out in that written agreement, except where we must retain something to comply with a legal, tax, or dispute-resolution obligation. We also keep limited operational logs for a short period for security and troubleshooting purposes. If you need a copy of records before an agreement ends, request it through your organization.

10. Your Choices & Rights

Because the information in the Platform belongs to your organization, requests about your own information are usually fastest through your organization’s administrator, who can correct a roster entry or a credential record directly. Where the law gives you rights we can act on, or where your organization asks us to assist, you may contact us to:

  • Request a copy of the personal information we hold about you;
  • Correct inaccurate information;
  • Request deletion of your information (subject to records we or your organization must keep for legal, tax, employment, or dispute reasons);
  • Ask questions about this policy or our practices.

To make a request, email us at the address in Section 14 from the work email address associated with your Platform account. That is how we verify the request is really yours. We respond within 45 days. Where we act as a service provider for your organization, we will forward your request to them and support their response. We will never discriminate against you for exercising privacy rights.

11. State-Specific Disclosures

We are based in Florida and operate in the United States. As we expand, this section will carry any additional disclosures required by the privacy laws of states where we operate or serve residents (such as the California Consumer Privacy Act, the Colorado Privacy Act, the Texas Data Privacy and Security Act, and similar laws). Two standing commitments apply in every state: we do not sell personal information, and we do not process personal information for targeted advertising, which means the opt-out rights those laws center on are satisfied by default. Residents of states with comprehensive privacy laws may exercise the access, correction, deletion, and portability rights described in Section 10, and may appeal a refused request by replying to our decision; where state law provides, you may also contact your state Attorney General. Note that several of these laws treat information processed purely in an employment or business-to-business context differently, but we apply the rights above regardless, to the extent we are able to act on them.

12. Children’s Privacy

The Platform is workforce software intended for adults. Accounts are created only for people on a Customer Organization’s staff roster, and you must be at least 18 to use the Platform. We do not knowingly collect personal information from children under 13 (consistent with the federal COPPA statute). If you believe a child has provided us personal information, contact us and we will delete it.

13. Changes to This Policy

When we make material changes, we will update the date at the top of this page and, where appropriate, notify Customer Organizations by email or a notice on the Platform before the change takes effect. Continued use of the Platform after a change means the updated policy applies.

14. Contact Us

ClinCover Solutions Privacy Team
Email: contact@clincover.com
Florida, United States

This policy describes our practices in plain language on purpose. If anything is unclear, ask us. We would rather explain it than have you guess.