Effective August 26, 2026
ScrubPay ("ScrubPay," "we," "us," or "our") operates a software platform that connects healthcare facilities with clinicians for permanent and travel staffing, and provides participating facilities with tools to manage job postings, applicants, employee records, and payroll. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have, when you use our website and application (together, the "Service").
This Policy applies to everyone who uses the Service: clinicians creating a professional profile and applying to jobs, and facility staff managing job postings, applicants, employees, and payroll on behalf of their organization. By using the Service, you agree to the collection and use of information described here.
We collect information in three ways: what you give us directly, what we collect automatically as you use the Service, and what we receive from third parties involved in providing the Service.
Name, email address, phone number, password (stored in encrypted/hashed form, never in plain text), and account type (clinician or facility).
If you create a clinician profile, we collect the professional information you choose to add: discipline and specialties, years of experience, work history, education, professional references and their contact information, state licenses and license numbers, certifications, a resume, and a profile photo if you upload one. We also collect the content of job applications you submit and messages you exchange with facilities through the Service.
If you create a facility account, we collect your organization's name, Employer Identification Number (EIN), location, website, logo, and the details of the jobs you post (pay, shift, requirements, and similar). We use your EIN to confirm your organization isn't already registered on the Service under a different account, which helps prevent duplicate or fraudulent facility accounts.
Facilities that use our payroll features may add records for their own employees, which can include the employee's name, date of birth, home address, Social Security number, bank routing and account numbers, tax withholding elections, and emergency contact information. This is the most sensitive category of information the Service handles. Social Security numbers and bank account/ routing numbers are encrypted before they are stored, and are never displayed in full in the application after they're entered. Facilities are responsible for the accuracy of the employee information they enter and for having the appropriate authorization from their employees to provide it to us.
Resumes, professional licenses, certifications, and other documents that clinicians or facilities upload. These are stored in private, access-controlled storage and are never publicly accessible — viewing or downloading a document requires a valid, time-limited link generated only for someone authorized to see it.
Like most web applications, we automatically collect some technical information when you use the Service: IP address, browser and device type, pages visited, and general usage patterns. We use this information to keep the Service secure (for example, to detect and slow down automated abuse like repeated failed login attempts) and to understand how the Service is used so we can improve it.
We use cookies and similar technologies for two purposes: keeping you signed in (these are required for the Service to function and can't be turned off), and, where you've consented, analytics that help us understand how the Service is used. See Section 8, Cookies below for details and how to manage your preferences.
The Service includes optional AI-assisted features — for example, extracting structured information from an uploaded resume or job posting document, drafting a job description from the details you provide, and generating plain-language reports from a facility's own data. These features send the relevant text or document to Anthropic (the maker of the Claude AI model) for processing via its API. We do not use these AI features to make employment or hiring decisions on anyone's behalf — every AI-assisted result is shown to the user for review before it is saved or acted on, and nothing is submitted or published automatically.
We use technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encrypting the most sensitive data (like Social Security numbers and bank account details) both in transit and at rest, restricting document access to short-lived, individually-generated links rather than public URLs, enforcing that users can only access their own data or data explicitly shared with them through the Service, and monitoring for and rate-limiting suspicious activity like repeated login attempts.
No system is completely secure, and we can't guarantee absolute security. If we become aware of a breach affecting your information, we'll notify you and any applicable authorities as required by law.
We retain information for as long as your account is active and as needed to provide the Service. When you delete your account, or when a facility removes an employee or candidate record, we delete or de-identify the associated information within a reasonable period, except where we're required to keep it longer — for example, payroll and tax-related records that facilities are legally required to retain, or information we need to keep to resolve disputes, enforce our agreements, or comply with legal obligations.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain uses of it. You can update most of your own account and profile information directly within the Service. For anything else — including a full deletion request — contact us using the information in Section 12.
California residents: the California Consumer Privacy Act (CCPA), as amended, gives California residents specific rights over their personal information, including the right to know what we collect, the right to delete it, and the right to opt out of its sale — we don't sell personal information, so there's nothing to opt out of on that front. You can exercise your other rights by contacting us.
Other states: residents of certain other states have similar rights under their own state privacy laws. We honor applicable requests regardless of which state you live in.
The Service is intended for use by adults in a professional context and is not directed at, and should not be used by, anyone under 18. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. If we make material changes, we'll provide notice — such as by email or a notice within the Service — before the changes take effect. The "Effective" date at the top of this page reflects the most recent update.
Questions about this Privacy Policy or how we handle your information can be sent to privacy@scrubpay.app.
ScrubPay · Lincoln, Nebraska