Last updated: July 21, 2026
Privacy Policy
This policy explains the information Medestra processes to provide scheduling, messaging, and shift-trade tools to doctors and hospitals.
Who controls your information
Your hospital controls the workforce and scheduling information it provides to Medestra. Medestra processes that information to operate the service and is responsible for account, support, security, and product-operation information it collects directly.
Information we process
- Account and profile information, including name, work email, hospital, role, language, employment status, and account-claim records.
- Scheduling information, including shifts, eligibility, allocations, time off, availability, and scheduling preferences.
- Doctor-to-hospital message threads and links you choose to send.
- Trade listings, requests, policy checks, approvals, and audit records.
- Device and service information needed for authentication, push notifications, security, diagnostics, and support. Backup claim codes are stored only as hashes.
How we use information
- Authenticate users, map them to the correct hospital and doctor profile, and prevent unauthorized access.
- Display schedules and profile information, save doctor inputs, support hospital messaging, and execute approved shift trades.
- Deliver requested email and push notifications, investigate failures, protect the service, and meet legal obligations.
- Improve reliability using redacted diagnostics. Medestra does not sell personal information or use doctor data for third-party advertising.
Service providers and disclosure
Medestra uses contracted infrastructure and delivery providers, including Supabase for application infrastructure and Expo for mobile notification delivery. Information may also be disclosed to your hospital’s authorized administrators, when required by law, or to protect users and the service. Doctors cannot use Medestra messaging to contact other doctors directly.
Retention and security
We retain information while needed to provide the service, preserve scheduling and trade history, meet hospital instructions, resolve disputes, and comply with law. Access is restricted by hospital and role, privileged operations are audited, messages are immutable, and account-claim codes expire and are protected against repeated guessing. No system can guarantee absolute security.
Your choices and rights
You can change your app language and notification permission at any time. Contact your hospital to correct administrator-managed profile or scheduling records. Contact Medestra to request access to, correction of, or deletion of information where applicable. Some records may need to be retained for legal, security, or scheduling-integrity reasons.
Children, changes, and jurisdiction
The service is for authorized healthcare professionals and administrators, not children. We may update this policy as the service changes and will post the revised date here. Medestra is operated from Canada; information may be processed where contracted providers operate, subject to appropriate safeguards.
Contact us
Questions, privacy requests, or support: contact@medestra.com
