Privacy Policy and Data Protection | CareO’Clock
Privacy & Data Protection

Privacy Policy and Data Protection

Effective date: May 26, 2026

This Privacy Policy explains how CareO’Clock Medical and Staffing Services (“CareO’Clock”, “we”, “our”, “us”) collects, uses, shares, retains, and deletes personal data when you use our website, mobile application, and related services for clients, caregivers, and administrators alike.

PHI Protected Data Never Sold Role-Based Access Fully Audit Logged
What We Collect

1. Information We Collect

We collect only what’s needed to coordinate safe, reliable care and to operate the platform.

Account Information

Name, email address, phone number, account role, and secure login credentials.

Care Coordination Data

Care requests, assignments, schedules, visit records, and related communications needed to deliver services.

Payment & Billing

Transaction references and billing records required for accounting, fraud prevention, and legal compliance.

Device & Technical Data

IP address, device/app data, security logs, and push notification tokens.

Support Information

Details you provide when you contact us for help.

Purpose

2. How We Use Information

Every use ties back to delivering, securing, or improving the CareO’Clock platform.

  • Provide, operate, and improve CareO’Clock services.
  • Authenticate users and secure accounts and sessions.
  • Coordinate care workflows, bookings, communications, and payments.
  • Detect, prevent, and investigate abuse, fraud, and security incidents.
  • Comply with legal, regulatory, and contractual obligations.
Disclosure

3. How We Share Information

We do not sell personal data. We share data only where absolutely necessary to provide services or comply with law.

Authorized Users

Clients, caregivers, and admins access data based on role-based, need-to-know access controls.

Trusted Service Providers

Vendors supporting hosting, authentication, analytics, notifications, and payments bound by confidentiality and security obligations.

Regulators & Authorities

Regulators, public authorities, or law enforcement, only where required by applicable law.

Retention

4. Data Retention

We keep personal data only as long as needed for service delivery, security and legal obligations.

Active
Account data retained while your account is active
1 Week
Data is held then anonymized after a deletion request
7 Years
Max. retention for payment & legally required records
Ongoing
Security & audit logs kept for incident investigation
Your Control

5. Account Deletion and Data Deletion

You can request deletion through in-app account deletion (where available) or by emailing [email protected].

1

Deletion Is Initiated

You’re logged out immediately once the deletion request is received.

2

Access Is Revoked

Active tokens and sessions are revoked immediately across the platform.

3

Data Is Held, Then Anonymized

Your data is held for one week and then anonymized, except for records we must retain by law.

  If legal retention applies, we keep only the minimum necessary information for the required period, then securely delete or anonymize it.
Your Rights

6. Your Privacy Rights

Subject to applicable law, you may exercise the following rights by contacting [email protected].

Access

Request a copy of the personal data we hold about you.

Correction

Ask us to fix inaccurate or incomplete information.

Export

Receive your data in a portable format.

Restriction

Limit how your data is processed in certain cases.

Deletion

Request erasure of your personal data, subject to legal retention.

Security

7. Security

Layered safeguards protect personal data across the platform the same accountability model used across every CareO’Clock visit.

Secure Authentication

Credentials are protected end-to-end at login and throughout every session.

Role-Based Access

Data is visible only to the people who need it to do their job.

Server-Side Validation

Requests are validated on our servers, not just in the app.

Token & Session Controls

Sessions and access tokens are time-limited and revocable.

Monitoring & Audit Logging

Activity is logged with a timestamp, user ID, and IP address for a verifiable record.

On careoclock.ca

8. Cookies, Comments & Embedded Content

These practices apply specifically to browsing careoclock.ca, separate from the CareO’Clock app.

Cookies

Login cookies last two days (two weeks with “Remember Me”); screen-option cookies last a year. Comment cookies, if opted into, last a year.

Comments

Comment forms collect your comment data plus your IP address and browser user agent to help detect spam.

Blog only

Media & Embeds

Embedded content (videos, images, articles) behaves as if you visited the source site directly, and may set its own cookies.

Password Resets

If you request a password reset, your IP address is included in the reset email for security verification.

Spam Detection

Visitor comments may be checked through an automated spam-detection service before publication.

Minors

9. Children

CareO’Clock services are not directed to children. If you believe personal data was provided inappropriately, contact us and we will review and take appropriate action.

Updates

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material updates will be posted on this page with a revised effective date.


FAQ

Common Privacy Questions

Quick answers to what clients and caregivers ask most.

Do you sell my personal data?

No. CareO’Clock does not sell personal data. We only share it where necessary to provide services or comply with the law. See Section 3.

How is my health information protected?

Protected Health Information (PHI) access is time-limited and token-secured, viewable by a caregiver only in a brief window before their scheduled visit, and every access is audit logged.

What happens to my data if I delete my account?

You’re logged out and your sessions revoked immediately. Your data is held for one week and then anonymized, except for records we’re legally required to retain.

Who can see my information within CareO’Clock?

Access is role-based and need-to-know: only the clients, caregivers, and admins directly involved in your care can view relevant records.

How do I exercise my privacy rights?

Email [email protected] to request access, correction, export, restriction, or deletion of your personal data.

11. Contact Us

Have a privacy question or want to exercise your rights? Reach our team directly.

Scroll to Top