Shift Health, Inc
Privacy Policy
Effective 11-29-2021 · Last updated 09-30-2026
1. Introduction
Shift Health, Inc (“we,” “our,” or “us”) operates the Shift Health platform, a healthcare AI platform that uses intelligent agents and agentic workflows to automate repetitive tasks for healthcare organizations. This Privacy Policy describes how we collect, use, disclose, and protect your information when you access or use our platform, website (www.shifthealth.io), and related services (collectively, the “Services”).
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.
2. Information We Collect
2.1 Information You Provide to Us
- Account Information: When you register for an account, we collect your name, email address, organization name, job title, and contact information.
- Client Data: Information and data you or your organization provide to enable the operation of our AI agents and agentic workflows, which may include healthcare-related data and documents.
- Communications: When you contact us for support or other inquiries, we collect the content of those communications.
2.2 Information Collected Through Google APIs
When you connect your Google account to our Services, we may access the following information with your explicit authorization:
- Google Account Profile Information: Your name, email address, and profile photo, used to create and manage your account.
- Gmail Data: Email content and metadata as necessary to perform automated tasks you configure through our AI agents. We access only the emails and data required to execute the specific workflows you authorize.
- Google Drive Files: Documents and files you explicitly grant access to, as needed to perform automated tasks through our AI agents.
2.3 Information Collected Automatically
- Usage Data: Information about how you interact with our Services, including features used, pages visited, and actions taken.
- Device and Log Information: IP address, browser type, operating system, device identifiers, and access timestamps.
- Cookies and Similar Technologies: We use cookies and similar tracking technologies to maintain sessions and improve user experience.
2.4 Our Website
When you visit www.shifthealth.io (the “Website”):
- Analytics: We use Plausible Analytics to count visits and see which pages are useful. Plausible does not use cookies and does not collect personal information; visits are counted in aggregate.
- Booking a demo: Demo requests are scheduled through Google Calendar appointment scheduling, embedded on our Website. When you book, Google collects your name, email address and any answers you give, and shares them with us so we can hold the meeting. Google’s privacy policy applies to the booking calendar, which may set Google’s own cookies.
- Hosting: The Website is hosted by Cloudflare, which processes standard request information (such as IP address and browser type) to deliver and protect the Website.
- No patient information: The Website is not designed to receive Protected Health Information. Please do not include patient information when booking a demo or contacting us.
We do not set cookies on the Website ourselves.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain our Services, including executing AI agent workflows you configure.
- To authenticate your identity and manage your account.
- To process transactions and manage your credit-based service usage.
- To communicate with you about your account, provide customer support, and respond to inquiries.
- To improve and enhance our Services, including analyzing usage patterns and developing new features.
- To comply with legal obligations, including healthcare regulations such as HIPAA.
- To detect, prevent, and address technical issues, fraud, or security concerns.
- To generate aggregated, de-identified analytics and benchmarking data to improve our platform.
4. Google API Services – Limited Use Disclosure
Important: Shift Health, Inc’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we commit to the following:
- We will only use access to Google user data to provide or improve user-facing features that are prominent in our application’s user interface.
- We will not transfer Google user data to third parties unless necessary to provide or improve user-facing features, required for compliance with applicable laws, or as part of a merger, acquisition, or asset sale with prior notice to users.
- We will not use Google user data for serving advertisements.
- We will not allow humans to read Google user data unless we have your affirmative agreement for specific content, it is necessary for security purposes (such as investigating abuse), it is necessary to comply with applicable law, or the data has been aggregated and anonymized and is used for internal operations.
5. HIPAA Compliance and Protected Health Information
As a healthcare AI platform, we understand and take seriously our obligations regarding Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA).
- Business Associate Agreements: We enter into Business Associate Agreements (BAAs) with our healthcare clients as required by HIPAA before accessing, processing, or storing any PHI on their behalf.
- Safeguards: We implement administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule.
- Minimum Necessary Standard: We limit the use and disclosure of PHI to the minimum necessary to accomplish the intended purpose of the use or disclosure.
- Breach Notification: In the event of a breach of unsecured PHI, we will notify affected clients and individuals in accordance with the HIPAA Breach Notification Rule.
- Workforce Training: Our team members who may have access to PHI receive appropriate training on HIPAA requirements and our privacy and security policies.
6. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following limited circumstances:
- Service Providers: We share data with trusted third-party vendors who assist us in operating our platform (e.g., cloud hosting on Amazon Web Services), subject to confidentiality obligations and data processing agreements.
- Legal Compliance: We may disclose information if required to do so by law, regulation, legal process, or governmental request.
- Protection of Rights: We may disclose information to enforce our agreements, protect the rights, property, or safety of our company, our users, or others.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will provide notice before your information becomes subject to a different privacy policy.
- With Your Consent: We may share information with third parties when you have given us explicit consent to do so.
- Aggregated or De-identified Data: We may share aggregated or de-identified data that cannot reasonably be used to identify you for analytics, benchmarking, and marketing purposes.
7. Data Security
We implement and maintain commercially reasonable security measures designed to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Access controls and authentication mechanisms.
- Regular security assessments and vulnerability scanning.
- Infrastructure hosted on Amazon Web Services (AWS) with data stored and processed exclusively within the United States.
- Incident response procedures in the event of a data breach.
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Services. We may also retain and use your information as necessary to comply with legal obligations, resolve disputes, enforce our agreements, and as permitted by applicable law.
When you or your organization request deletion of your data, we will delete or de-identify your information within a reasonable timeframe, unless retention is required by law or for legitimate business purposes. Data obtained through Google APIs will be deleted promptly upon your revocation of access or account deletion.
9. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access and Portability: You may request a copy of the personal information we hold about you.
- Correction: You may request that we correct inaccurate or incomplete personal information.
- Deletion: You may request that we delete your personal information, subject to certain legal exceptions.
- Revoke Google Access: You can revoke our access to your Google data at any time through your Google Account settings at https://myaccount.google.com/permissions or by contacting us at support@shifthealth.io
- Opt-Out of Communications: You may opt out of receiving promotional communications from us by following the unsubscribe instructions in those messages.
To exercise any of these rights, please contact us at support@shifthealth.io. We will respond to your request within 30 days or as required by applicable law.
10. Children’s Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information promptly.
11. Third-Party Links and Services
Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services before providing them with your information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the updated Privacy Policy on our website and updating the “Last Updated” date above. Your continued use of our Services after such changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Shift Health, Inc
Attn: Privacy Officer
Email: support@shifthealth.io
Website: www.shifthealth.io