Privacy Policy
Last updated: August 12, 2026 · Effective: August 12, 2026
Enacare is a per-diem nursing shift marketplace with built-in training, operated in the United States. This policy says exactly what we collect, why, who processes it for us, and how to exercise your rights. We wrote it to match what the product actually does — nothing here is aspirational.
What we collect, and why
- Account basics — your name, email address, and password (stored only as a one-way hash). Why: signing you in and contacting you about your shifts and account.
- Professional credentials — your license type and state, and the credential documents you upload (nursing license, CPR/BLS, TB screening, and similar), including document images and expiry dates. Why: facilities can only be staffed by verified professionals; verification is the core of the product. Credential documents are encrypted at rest (AES-256-GCM) and every access to them is logged.
- Profile photo — if you add one. Why: facilities see who is arriving for a shift.
- Location, two narrow uses — (1) when you clock in or out of a shift, we record your location at that moment to verify you're at the facility (geofencing); it is stored on that shift's timecard. (2) When you browse shifts, the app can use your device's location to show how far each facility is — that calculation happens on your phone; your browsing location is never sent to our servers. We do not track your location in the background, ever.
- Device & notification data — a push-notification token for your device and your notification preferences. Why: shift reminders and decisions that affect you.
- Activity on the platform — shifts you claim and work, timecards, earnings, messages you send in shift and support chat, ratings, and referrals. Why: this is the product working.
- Usage and security logs — IP addresses and authentication events (sign-ins, failures, rate limiting). Why: keeping accounts safe and abuse out.
Payment and identity data go to Stripe, not us
Payouts run on Stripe Connect. When you set up payouts, the identity and banking details Stripe requires (such as date of birth, the last four digits of your SSN, and bank account numbers) are entered on Stripe-hosted pages and go directly to Stripe. They never touch Enacare's servers. We store only an identifier for your Stripe payout account and its status (for example "active"). Stripe's handling of that data is governed by Stripe's privacy policy.
Who processes data for us
We don't sell your data, and we don't share it with anyone except the service providers that run the platform:
| Processor | What they receive | Why |
|---|---|---|
| Stripe | Payout account identity/banking details (entered directly with Stripe), payout amounts | Payouts and required identity verification |
| Railway | Our application and database run on Railway's infrastructure | Hosting |
| Cloudflare | Network traffic to our services (IP addresses, requests) | Security, performance, and access control |
| Resend | Your email address and the transactional emails we send you | Sign-in codes, password resets, notifications |
| Expo | Your device push token and notification content | Delivering push notifications |
| Sentry | Error reports from our software — configured to strip request bodies, headers, and query strings before anything is sent | Crash and error monitoring |
How long we keep things
- Account and credential data — for as long as your account is active. Deleting your account removes it (see below).
- Financial records — timecards, earnings, and payout records are retained as required for tax and legal purposes even after account deletion, in anonymized form (they no longer identify you).
- Security logs — retained for a limited period for abuse prevention and audit.
Your rights
- Access and correction — your profile, credentials, and history are visible and editable in the app.
- Deletion — nurses can delete their account in the app: Profile → Settings → Delete my account. This permanently deletes your credential documents and photos, removes your personal information, and signs you out everywhere. Financial records are kept in anonymized form as described above. Facility manager accounts are deleted by emailing [email protected].
- Questions or requests — email [email protected] for anything this page doesn't answer, including access or deletion requests you'd rather make by email.
Security
Credential documents are encrypted at rest with AES-256-GCM. All traffic to and from Enacare uses TLS. Passwords are stored only as one-way hashes. Access to credential documents is authenticated and logged. Administrative surfaces sit behind additional access controls.
Children
Enacare is for licensed and licensure-track professionals aged 18 and over. We do not knowingly collect information from anyone under 18; if we learn we have, we will delete it.
Changes
If we change this policy, we'll update the date at the top and, for meaningful changes, tell you in the app or by email before they take effect.
Contact
Enacare · [email protected]