Ops Pulse Privacy Policy
Ops Pulse is coverage scheduling software for organizations that send clinical staff to customer sites. It is operated by Case Creative LLC ("we", "us"). This policy explains what the service collects, why, who it is shared with, and how to get it removed.
Ops Pulse is sold to organizations, not to individuals. If you use Ops Pulse because your employer does, your employer controls your account and the data in it, and their own policies apply alongside this one.
1. Who this policy covers
- Customer administrators and coordinators who sign in to schedule work.
- Clinical staff whose shifts, availability and time off are scheduled.
- Customer site contacts whose names and business contact details are stored so staff know who to ask for on arrival.
2. What we collect
Information your organization gives us
- Names, work email addresses and work phone numbers.
- Job roles, credentials, competencies and sign-off records used to decide who is qualified for which work.
- Schedules, shift assignments, time off requests and their approval status.
- Customer site names, addresses, phone numbers and operational notes.
- Billing codes and rates used to produce invoices.
Information collected automatically
- Sign-in events and the account identifier they belong to.
- Application logs and error reports used to keep the service working.
We do not use advertising trackers, we do not run third party analytics that profile individuals, and we do not sell personal information.
3. Google user data
Connecting a Google account is optional and is done by an administrator on behalf of the organization. If nobody connects one, Ops Pulse works without any Google access at all.
When an administrator connects a Google Workspace or Google account, Ops Pulse asks for exactly the scopes below and nothing else. Each one is requested because a specific feature cannot work without it.
| Scope | What Ops Pulse does with it |
|---|---|
https://www.googleapis.com/auth/calendar |
Creates calendars that Ops Pulse owns, one per person or customer site, and writes the published schedule into them as events. It also shares those calendars with the individual they belong to, and removes that access when somebody leaves. Ops Pulse writes events; it does not read the contents of unrelated calendars for any purpose other than confirming the calendars it created still exist. |
https://www.googleapis.com/auth/userinfo.email |
Reads the email address of the connecting account so the application can show which account is connected, and record which account owns the calendars it created. |
https://www.googleapis.com/auth/gmail.send |
Sends notification email from the connected account: schedule changes to the person affected, time off decisions to the requester, coverage gap alerts to the operations mailbox, and sign-in invitations to newly added users. This scope is send only. Ops Pulse cannot read, search or delete mail in the connected mailbox. |
https://www.googleapis.com/auth/drive.readonly |
Lets an administrator browse their Drive to pick reference documents (site instructions, protocols, forms) and attaches links to them so staff can open them from a shift. Ops Pulse reads file names and links to display and attach them. It does not modify, delete or create anything in Drive. |
Limited Use disclosure. Ops Pulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not use Google user data to serve advertising, we do not sell it, we do not transfer it except as needed to provide the features described above or where required by law, and we do not allow humans to read it except with the affected user's explicit consent, to resolve a specific support issue they have raised, for security purposes such as investigating abuse, or where required by law.
What we store from Google
- An OAuth refresh token for the connected account, so the features above keep working without asking somebody to sign in every day.
- The connected account's email address.
- Identifiers for the calendars and events Ops Pulse created, so it can update and clean up its own work.
- Links and file names for documents an administrator chose to attach.
We do not copy mailbox contents, Drive file contents, or events from calendars Ops Pulse did not create.
Disconnecting
An administrator can disconnect the Google account at any time in the application's settings, which deletes the stored refresh token and stops all Google access. You can also revoke access directly at myaccount.google.com/permissions. Calendars that Ops Pulse created remain in the Google account that created them until somebody deletes them, because they belong to that account and not to us.
4. How we use information
- To build, publish and change work schedules.
- To check that the person assigned is qualified for the work.
- To tell people about shifts, changes, time off decisions and coverage gaps.
- To produce invoices and operational reports for the organization.
- To keep the service secure, available and working, and to investigate problems.
We do not use this information to build advertising profiles, and we do not use customer data to train machine learning models.
5. Sharing
We share personal information only in these situations:
- Within your organization, according to the roles and permissions your administrators configure.
- With the customer sites your organization serves, limited to the coverage information your organization chooses to publish to them.
- With service providers that host and run the software on our behalf, listed below.
- Where the law requires it, or to protect rights and safety.
We do not sell personal information and we do not share it with advertisers.
Service providers
| Provider | Purpose |
|---|---|
| Google Cloud Platform | Application hosting, database hosting and file storage. |
| Firebase Authentication (Google) | Sign-in and identity. |
| Google Workspace APIs | Calendar, mail sending and Drive access, as described above. |
6. Health information
Ops Pulse schedules clinical work. It is designed so that the schedule records who is working, where and when, rather than information about patients. Where an organization's use of Ops Pulse involves protected health information under HIPAA, we act as a business associate and enter into a Business Associate Agreement with that organization, and we handle that information under the terms of that agreement.
Do not enter patient names, diagnoses or other patient information into free text fields such as notes. Those fields are for operational instructions.
7. Where data is stored, and for how long
Data is stored in Google Cloud data centers in the United States. We keep information for as long as your organization's account is active. When an organization ends its subscription, we delete or return its data within 90 days, except where we are required to keep it longer by law.
Individuals whose data appears in Ops Pulse because their employer put it there should contact their employer to correct or remove it. If you contact us directly, we will refer you to them and help them act on it.
8. Security
- Traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting provider.
- OAuth tokens and other secrets are held in a managed secret store, not in application code.
- Access is controlled by role, and administrative actions that change who can see what are recorded.
- Access to production systems is limited to personnel who need it.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify the affected organization without undue delay and in line with applicable law and any agreement in place.
9. Your choices
- Disconnect Google access at any time, in settings or through your Google account.
- Ask your organization's administrator to correct or delete information about you.
- Depending on where you live, you may have rights to access, correct, delete or port your personal information, or to object to certain processing. Contact us and we will route the request to the organization that controls the data and support them in answering it.
10. Children
Ops Pulse is workplace software and is not directed to children. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
If we make a material change we will update the effective date above and notify customer administrators before the change takes effect.
12. Contact
Case Creative LLC
Email: privacy@casecreative.com