← Back to DubGrid

Privacy Policy

Last updated: May 2026

1. Introduction

DubGrid LLC (“DubGrid,” “we,” “our,” or “us”) operates a multi-tenant staff scheduling platform for care facilities. This Privacy Policy explains how we collect, use, store, and protect information when you use our web and mobile applications and related services (the “Service”). By using DubGrid, you agree to the practices described in this policy.

The Service is intended for organizations and staff located in the United States. We are not directed at, and do not knowingly offer the Service to, individuals in the European Union or United Kingdom.

2. Information We Collect

We collect information necessary to provide the Service and to manage your organization's schedules and staff.

  • Account and authentication. When you sign up or sign in, we collect your email address and password (stored in encrypted form). We may also store your first and last name when you provide it or when it is derived from your account profile.
  • Profile and role data. We store your association with an organization, your role (e.g., admin, scheduler, supervisor, or staff), and platform-level role if applicable. This allows us to enforce access control and show you the appropriate features and data.
  • Organization data. For each organization (tenant), we store the organization name, subdomain identifier, and optional contact information such as address and phone number that administrators may configure.
  • Employee roster data. Organizations use DubGrid to manage staff rosters. This may include employee names, designations, roles, focus area assignments, seniority, FTE weight, and optional contact information (phone, email, contact notes) that your organization chooses to store in the system.
  • Schedule and shift data. We store shift assignments (which employee is assigned which shift and job on which date), draft and published schedule states, and any schedule or shift notes (e.g., readings, shower notes) that authorized users add.
  • Invitation data.When an administrator invites a user to join an organization, we store the invitee's email address, the role to be assigned, and the invitation status and expiry.
  • Technical and usage data. Our infrastructure (including authentication and database hosting) may log technical data such as IP address, browser type, and request metadata to operate and secure the Service.
  • Analytics data (with consent). If you accept analytics cookies, we use PostHog and Vercel Analytics to collect anonymized usage data such as page views and performance metrics. This data is not collected until you provide consent. See our Cookie Policy for details.
  • Error reports. We use Sentry for error monitoring. When an error occurs, technical context (stack traces, request metadata) is captured to help us diagnose issues. Personally identifiable information is not included in error reports. Sentry also offers session replay, which we enable only with your analytics consent.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the scheduling and roster features of the Service.
  • Authenticate you and enforce role-based access so that users only see and edit data they are permitted to access.
  • Isolate each organization's data (multi-tenant isolation) so that one organization cannot access another's data.
  • Send transactional email such as invitations, email verification, password resets, and account notifications.
  • Process subscription payments and manage billing for paid plans.
  • Protect the security and integrity of the Service, including rate limiting, abuse prevention, and maintaining audit logs of sensitive actions.
  • Comply with legal obligations.

4. Data Storage, Security, and PHI Prohibition

Your data is stored on secure servers provided by our infrastructure and database provider, encrypted in transit and at rest. We use row-level security and role-based access control so that access to data is restricted by organization and by your role. Passwords are managed by our authentication provider and are never stored in plain text, and we support multi-factor authentication. We track active sessions, rate-limit sensitive endpoints, and keep audit logs of role changes and schedule publishing. We do not sell your personal information to third parties. No method of transmission or storage is completely secure; if we become aware of a security incident affecting your personal information, we will notify affected users and authorities as required by applicable law.

PROHIBITION OF PROTECTED HEALTH INFORMATION (PHI)

DubGrid is designed for operational staff scheduling and is nota HIPAA-compliant platform. The Service is not intended for the storage, transmission, or processing of Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA). Users are strictly prohibited from entering resident or patient names, medical records, diagnoses, or any clinical health data into employee records, schedules, or free-form notes fields. Notes must be limited to operational scheduling coordination (for example, "day shift needs coverage in Wing A").

5. Data Retention

We retain your account and profile data for as long as your account is active and as needed to provide the Service. Organization data, employee rosters, shifts, and notes are retained while the organization uses the Service; archived records are retained according to each organization's configurable retention setting (365 days by default) before being purged. Cookie consent records are kept as an append-only compliance log and are not deleted with your account. We keep routine encrypted backups for disaster recovery, and these may persist for a limited period after deletion.

You can request a copy of your personal data (data export) or its deletion at any time. Account deletion removes your profile, memberships, sessions, and preferences, and either deletes or anonymizes the personal data associated with your account, subject to records we must keep by law. See Your California Privacy Rights below for how to make a request.

6. Your California Privacy Rights

This section describes the categories of personal information we handle and the rights available to California residents under the California Consumer Privacy Act, as amended (CCPA/CPRA). We extend the core choices below to all of our users.

In the past twelve months we have collected these categories of personal information, used for the business purposes described in this policy and disclosed only to the service providers listed below:

  • Identifiers (name, email address, phone number, account and organization identifiers).
  • Professional or employment information (role, designation, focus areas, seniority, FTE weight, schedule and shift assignments).
  • Internet or network activity (IP address, browser type, request metadata, and, with consent, analytics about how you use the Service).
  • Commercial information (subscription and billing status; payment details are handled directly by our payment processor).
  • Geographic information (only an organization address that an administrator chooses to enter).

We do not sell or share your personal information, and we have not done so in the past twelve months. We do not use sensitive personal information for purposes that would require a right to limit. We do not knowingly collect personal information from minors.

Subject to applicable law, you have the right to:

  • Know and access the personal information we hold about you and request a portable copy.
  • Correct inaccurate personal information.
  • Delete your personal information, subject to records we must retain by law.
  • Opt out of any sale or sharing of personal information (not applicable, as we do neither).

You can update profile details directly in the Service, and request a data export or account deletion from your profile settings. To make any other request, email us at support@dubgrid.com. We will verify your identity using your account before acting on a request, and you may use an authorized agent where the law permits. We will not discriminate against you for exercising these rights. Because the Service is provided to organizations, some requests about organization or roster data may be directed to your organization's administrators.

7. Third-Party Service Providers

We use the following US-based service providers to operate and improve DubGrid. Each processes data on our behalf under data processing terms and in accordance with its own privacy policy:

  • Supabase (authentication and database hosting): account, profile, organization, roster, and schedule data.
  • Vercel (application hosting and web performance analytics, analytics consent required): request and performance metadata.
  • PostHog (product analytics, consent required): page views and feature-usage events, using localStorage and cookies.
  • Sentry (error monitoring, always on; session replay, analytics consent required): stack traces and request context. No personally identifiable information is sent.
  • Stripe (payment processing): billing contact and payment metadata, shared only during checkout and billing.
  • Resend (transactional email delivery): recipient email address and message content for invitations, verification, password resets, and notifications.
  • Upstash (rate limiting): a hashed identifier and request counts, used to protect the Service from abuse.
  • Google Maps Platform (address autocomplete): address text you type when configuring an organization, sent to Google to return address suggestions.
  • Expo, Apple Push Notification service, and Firebase Cloud Messaging (mobile push notifications): a device push token, used to deliver notifications to the mobile app.

Our web fonts are self-hosted, so loading the Service does not contact a third-party font provider.

For a full list of cookies and how to manage them, see our Cookie Policy.

8. Children's Privacy

DubGrid is a business tool intended for use by adult employees and administrators. The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us and we will delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date, and we will provide notice of material changes by email or within the Service where appropriate. Continued use of the Service after changes constitutes acceptance of the revised policy.

10. Contact Us

If you have questions about this Privacy Policy or our data practices, or wish to exercise a privacy right, contact us at:

DubGrid LLC
[REGISTERED ADDRESS]
support@dubgrid.com