Last updated: July 21, 2026

Privacy Policy

This policy explains the information Medestra processes to provide scheduling, messaging, and shift-trade tools to doctors and hospitals.

Who controls your information

Your hospital controls the workforce and scheduling information it provides to Medestra. Medestra processes that information to operate the service and is responsible for account, support, security, and product-operation information it collects directly.

Information we process

  • Account and profile information, including name, work email, hospital, role, language, employment status, and account-claim records.
  • Scheduling information, including shifts, eligibility, allocations, time off, availability, and scheduling preferences.
  • Doctor-to-hospital message threads and links you choose to send.
  • Trade listings, requests, policy checks, approvals, and audit records.
  • Device and service information needed for authentication, push notifications, security, diagnostics, and support. Backup claim codes are stored only as hashes.

How we use information

  • Authenticate users, map them to the correct hospital and doctor profile, and prevent unauthorized access.
  • Display schedules and profile information, save doctor inputs, support hospital messaging, and execute approved shift trades.
  • Deliver requested email and push notifications, investigate failures, protect the service, and meet legal obligations.
  • Improve reliability using redacted diagnostics. Medestra does not sell personal information or use doctor data for third-party advertising.

Service providers and disclosure

Medestra uses contracted infrastructure and delivery providers, including Supabase for application infrastructure and Expo for mobile notification delivery. Information may also be disclosed to your hospital’s authorized administrators, when required by law, or to protect users and the service. Doctors cannot use Medestra messaging to contact other doctors directly.

Retention and security

We retain information while needed to provide the service, preserve scheduling and trade history, meet hospital instructions, resolve disputes, and comply with law. Access is restricted by hospital and role, privileged operations are audited, messages are immutable, and account-claim codes expire and are protected against repeated guessing. No system can guarantee absolute security.

Your choices and rights

You can change your app language and notification permission at any time. Contact your hospital to correct administrator-managed profile or scheduling records. Contact Medestra to request access to, correction of, or deletion of information where applicable. Some records may need to be retained for legal, security, or scheduling-integrity reasons.

Children, changes, and jurisdiction

The service is for authorized healthcare professionals and administrators, not children. We may update this policy as the service changes and will post the revised date here. Medestra is operated from Canada; information may be processed where contracted providers operate, subject to appropriate safeguards.

Contact us

Questions, privacy requests, or support: contact@medestra.com