Higher Calling logoHigher Calling

Legal

Privacy Policy

Higher Calling, Arizona. This policy explains what we collect, why we collect it, who we share it with, how long we keep it and how you can request access or deletion.

1. Who this policy covers

This policy applies to job applicants, employees and contract staff, client facility contacts, and visitors to our public website and staff portal. Where we handle protected health information on behalf of a client facility, we do so as a business associate under a signed Business Associate Agreement, and that agreement — together with HIPAA — controls how that information may be used. See our HIPAA readiness notice for detail on when HIPAA applies.

2. What we collect

Applicants & employees

  • Name, email, phone, mailing address and emergency contact
  • Discipline, work history, resume and application answers, and where you heard about us
  • Credential and clearance records: licence numbers, background and fingerprint clearance, I-9 / E-Verify, OIG and SAM checks
  • Health-related employment records where required for the role: TB test, drug screen, immunisation and fitness-for-duty results
  • Government identifiers required for hiring and payroll, including Social Security number and tax withholding elections
  • Schedules, shift assignments, time punches, break records and geolocation captured at clock-in and clock-out
  • Pay rates, timesheets, payroll and pay-stub records
  • Messages, notifications and documents you upload to the platform

Client facilities & site visitors

  • Business contact details, facility locations, staffing requests and credential requirements
  • Contract, rate sheet, agreement signature and billing records
  • Demo request form submissions (name, agency, email, phone, message)
  • Basic technical data needed to run and secure the site, such as sign-in attempts and security event logs

We collect this data directly from you, from your employer or the facility you work with, and from verification services you authorise during hiring. We do not buy personal data from data brokers.

3. How we use it

  • Recruiting, hiring and onboarding — reviewing applications, verifying credentials and tracking clearance
  • Scheduling and staffing — matching cleared workers to shifts and confirming coverage
  • Time and attendance — verifying worked time, including location at clock-in and clock-out to confirm on-site presence
  • Payroll and billing — calculating pay, producing pay stubs, exporting payroll and invoicing clients
  • Communication — shift alerts, credential expiration reminders, onboarding reminders and secure messaging
  • Compliance, safety and audit — meeting licensing, employment, wage-and-hour and healthcare requirements, and maintaining tamper-evident audit trails
  • Security — authenticating accounts, enforcing multi-factor authentication and detecting abuse

We do not sell personal or health information, and we do not use employee, applicant or client records for advertising or profiling.

4. Who we share it with

  • Client facilities, limited to what they need to accept a placement (for example name, discipline and clearance status)
  • Background check, credential verification and E-Verify providers
  • Payroll, tax and accounting providers
  • Infrastructure providers that host the database, files, email and SMS delivery on our behalf
  • Government agencies, regulators, auditors or courts where the law requires it

Service providers may only use the data to perform the service we asked for. Inside the platform, access is limited by role: recruiters do not see Social Security numbers, schedulers do not see medical documents, and administrative staff see clearance statuses rather than the underlying documents.

5. How we protect it

Accounts are invite-only and protected by a passcode with optional Face ID or Touch ID unlock; administrators must use multi-factor authentication. Data is encrypted in transit and at rest, every table enforces row-level security, sensitive fields are masked from roles that do not need them, and access to sensitive records is logged with who read what and when. Onboarding, clearance and payroll audit trails are hash-chained so entries cannot be altered.

6. How long we keep it

  • Audit and compliance records: six years.
  • Employment, payroll and tax records: for the period required by federal and Arizona law.
  • Internal messages: deleted automatically once the configured retention window closes.
  • Applications that do not result in hire: kept for the period required for equal opportunity recordkeeping, then deleted.

7. Cookies, consent and tracking

We use three categories of cookies and similar local storage, and your consent controls what runs beyond the first one:

  • Essential — sign-in session, passcode unlock state, multifactor and security checks, and protection against abuse. These cannot be switched off, because the portal cannot keep you signed in safely without them.
  • Preferences — remembering choices such as saved filters and the view you last used. Optional.
  • Measurement — anonymous, aggregated usage counts that tell us which screens are used. Optional, and off until you opt in.

If you choose essential only, or never answer the banner, no preference or measurement storage is written and no usage measurement is collected — we do not fall back to “legitimate interest” tracking. We do not use advertising cookies, cross-site trackers, social pixels or third-party profiling on this site, and we never place measurement or advertising technology inside the staff portal areas that contain employment, clearance or health records. You can change or withdraw your choice at any time on the cookie preferences page; withdrawing takes effect immediately and clears the optional storage. We also honour your browser’s Global Privacy Control or Do Not Track signal by treating optional categories as declined.

8. When HIPAA applies

Most of what we hold is employment data, not protected health information — an applicant’s resume, a licence number or a timesheet is governed by employment and privacy law rather than HIPAA. HIPAA applies when we handle patient information on behalf of a client facility that is a covered entity. In that case we act as a business associate under a signed Business Associate Agreement, and the following applies:

  • Patient information stays inside the platform and is never sent through personal email or texts.
  • Access is least-privilege by role: schedulers and business development staff see operational statuses such as VERIFIED or CLEARED, never the underlying documents.
  • Every read of a sensitive record is logged with who accessed it, when and from where, and those logs are hash-chained so they cannot be altered.
  • Retention follows the six-year HIPAA documentation standard; internal messages are purged automatically once the configured retention window closes.
  • A patient wishing to exercise HIPAA rights should contact the facility that provided their care; we forward any request we receive to that facility and assist it in responding.
  • We notify the affected facility without unreasonable delay if we discover unauthorised access to information we hold for it.

Your own employment health records — TB tests, drug screens, fitness-for-duty — are kept separately from your general personnel file and visible only to the compliance roles that must verify them.

9. Your choices and how to request deletion

  • Ask what personal data we hold about you and request a copy
  • Ask us to correct information that is inaccurate or incomplete
  • Ask us to delete information we are not required to keep
  • Withdraw consent for optional messages, and set channel preferences in the staff portal
  • Ask a question or raise a concern about how your data is handled

To make a request, email Rayiyi@calledtocareaz.com with the subject “Privacy request” and tell us what you would like us to do. We verify your identity before acting and respond within 30 days. We will delete what we can, and we will tell you in writing what we must keep and why — employment, payroll, tax, clearance and audit records generally cannot be deleted before their retention period ends. If we hold information as a business associate for a client facility, we forward your request to that facility, which is responsible for responding.

10. Changes and contact

We update this policy as the platform changes and will note the new effective date here. Questions? Email Rayiyi@calledtocareaz.com.

This policy is provided for transparency and is not legal advice.

Back to home