Updated October 6, 2026
Privacy and your account.
What we collect
Account and early-access forms collect your name, contact email, city, role, work preferences, and the office or professional details you choose to provide. Optional details include your introduction, favorite restaurant, software, office address, team description, and photos. Professional profiles can include a California license number, expiration dates, training readiness, and an uploaded CPR/BLS card. Email/password accounts use our own account storage. Passwords are stored as salted password hashes; session tokens and password-reset tokens are stored as hashes. Passwords are not retained as readable text. Browser sessions use secure HTTP-only cookies; the native app stores its session in device SecureStore. New account email addresses are not automatically verified. Work readiness and private-group access require separate review. Password recovery uses a private link sent to your account email through our email delivery provider, Brevo, when configured. The link expires after 15 minutes and can be used once. Resetting a password ends earlier web and app sessions. Brevo processes the recipient address and email content to deliver the message. Email recovery availability is shown on the login form. Existing accounts may link their previous trusted sign-in to a password account. Do not send patient information, Social Security numbers, government identity documents, or payment details.
Your drafts and uploads
Changes to profile questions are saved as a private draft so you can continue later, including on another device. Completing setup saves your profile. Photos and CPR/BLS cards are saved in file storage linked to your account. Uploads accept JPG, PNG, or WebP photos, and PDF CPR cards, up to 5 MB each. Upload only photos you have permission to use, with the permission of people shown. Do not include patients or patient charts. You can remove or replace an uploaded file in profile setup.
You choose who sees your profile
Your profile page starts private. If you choose “Let signed-in members see my profile and photos,” members who can access this site can open your profile link and see your introduction, photos, city, and work details. A shared office page can include its street address if you add one. Sharing a profile does not change the site’s access settings. Your contact email, private office contact, license details, CPR/BLS card, and unfinished draft are not included on the member profile page. Turn sharing off by editing and saving your profile. CPR/BLS cards are never included on shared profile pages.
Optional homepage office spotlights
Sharing your profile with signed-in members does not put your team on the homepage. From your office account, you can separately submit a team photo, an office logo, an optional office photo, and a caption for an HSSD spotlight. Confirm permission from everyone shown and permission to use the logo. After owner approval, that selected content plus your office name and city can appear to everyone who can visit the homepage, including public visitors if the site becomes public. Contact details and credential documents stay private. You can remove the spotlight from your office account at any time. Replacing a featured image hides it until you submit the new images for review. Removing a spotlight stops future site display; it cannot retrieve copies already saved by visitors.
How we use it
Your profile and draft are associated with your authenticated account so you can return and edit them. Each login can hold a professional profile and an office profile. Early-access inquiries are stored separately for responding to your request. Creating an account or uploading a document does not start billing or complete credential verification. Authorized credential reviewers can access private CPR cards and employer evidence to review readiness. The owner can see account counts, sign-in email addresses, inquiries, billing records, and permission changes. Ordinary members cannot access these records.
Office payroll readiness
Offices can submit their legal employer name, payroll provider and contact, workers' compensation carrier and coverage expiration, plus a private redacted confirmation document. These records are not on shared office pages. Upload only evidence needed for review, never employee W-2, W-4, or I-9 forms, Social Security numbers, bank details, birth dates, or worker tax records. A manual readiness review is not government verification and does not run payroll, verify work authorization, or issue W-2s. Updated details or evidence require another review.
Office membership payments
When billing is connected, Stripe hosts recurring-payment checkout and the billing portal. Card and bank details go to Stripe, not this site's storage. We keep provider customer and subscription identifiers, membership status, invoice receipts, and payment-event references to manage membership. Office membership payments are separate from employee wages; the office pays employees through its payroll provider. An unconnected checkout cannot take payment.
Your pilot days, shifts, and hours
The free pilot stores your participation status and accepted terms, chosen available days, alert cities, shift posts, requests, agreed hourly and travel pay, confirmed driving miles, cancellation reasons, and submitted and reviewed timesheets. Offices and professionals see the requests and booked work they are involved in. Approved pilot participants can see open shifts with office details, software, address, and legal employer. The owner can see pilot participation and all pilot shifts and hours to operate the service. Worker tax and identity documents are not collected. Keep notes free of patient information. Availability and shift agreements are saved on your account, not only your device; private records are not cached for offline access.
Optional device notifications
With your permission, we store your browser’s push endpoint and encryption keys to send shift updates. Your browser’s push provider (such as Google, Mozilla, or Apple) handles device delivery. Lock-screen notifications contain a generic HSSD update; sign in to view shift details. We store inbox notifications even if push is unavailable. We do not collect device location or automatically calculate your commute. Choose alert cities and agree driving miles with the office. Turn off this browser’s subscription in Alerts, or remove permission in device settings. Invalid or expired push subscriptions are removed after a rejected delivery.
Your saved CE calendar
When you save a CE, we store the provider’s public course title, date, link, credits and listing metadata on your account. Saves are private to you and sync across devices. Remove a save from a course card or your CE calendar. Saving is not registration, attendance or proof of earned credit; external providers manage their own accounts and registration data.
Private job messages
Job conversations connect one office and one dental professional around a posting. Message text, timestamps, participant IDs, and read status are stored and returned only to those participants through the app. Owner status does not grant access to another person’s private job messages. New-message inbox alerts use a generic notice, not the message body. Offices can start conversations with matching, reviewed professionals who share their profile or request the job; professionals can contact the office for a matching posting. Messages do not create a booking or change an agreed offer. Keep patient information out of messages.
Member community discussions
Posts, replies, likes and their timestamps are saved in shared storage. Community groups are private: only members approved for that professional role can read or participate. The owner can access every group for moderation. Professional profile review and office employer review determine group access; editing a profile may require review again. Earlier shared discussions are assigned to their author’s role, and earlier replies from other roles are kept out of the group feed. This cannot undo access that existed before groups became private. Your professional display name and role appear beside your posts and replies, even when your full profile is private. Full-profile links appear only if you chose to share your profile. Keep patient-identifying and sensitive personal information out of discussions. Authors can edit or remove posts and remove their replies; removing a post also removes its reply text. The owner can hide, restore, pin and remove discussions, remove replies, review reports, and suspend accounts. Reports and reporter identifiers are private to the owner and are retained for moderation; removing public text does not remove moderation and audit records. New replies may create an inbox update for the author. This member feed is not continuously monitored or an emergency channel.
Who processes it
Authorized HygieneShift SD operators and our hosting, database, and file-storage providers may process information to operate the site and review account submissions. Browser push providers process notification routing when you enable device alerts. We do not sell your profile or application data or use advertising trackers. The main pages load fonts from Google Fonts; your browser connects to that provider when loading them.
Review or remove your information
Log in to your account to review and edit your profile. For deletion or other privacy requests, use the contact form, choose "Privacy request," and enter the email used in your original submission. Ask to review, correct, or delete your information. We may need to confirm your identity before acting on a request. Keep your submission reference for follow-up.
What is open today
Profiles, office payroll-readiness submissions, authorized reviews, and the free pilot workspace are available. Pilot approval and work-readiness checks are required before booking. Availability, shift requests, final offers, bookings, cancellations, hours, and inbox alerts are saved across devices. Browser push is optional on supported devices; delivery is not guaranteed. Homepage sample shifts remain examples. Automatic state-board verification and native app-store releases are not connected. Office membership payments are disabled during this free pilot, and joining does not authorize future billing.
Pay and employment responsibilities
This network requires W-2 employee payroll for booked professionals; 1099 payments are not supported. The office is the employer, not HygieneShift SD, and handles employee onboarding, wages, taxes, coverage, supervision, and expense reimbursements. Hourly rates and travel bonuses must be agreed before work begins. Optional bonuses do not replace legally required payments. Employer costs are not included in the staffing-cost examples.
Create an account
HygieneShift SDHome