Privacy
Last updated 6 September 2026
What we collect, why, who else touches it, and how long it stays. Short, because the list is short.
This is a working draft. The policies described are the ones the product actually enforces today, written in plain language. The sections marked [COUNSEL REVIEW] still need a lawyer before launch, and the whole document will be replaced by counsel’s version.
1. What we collect
Contact details: name, email address, mobile number, and for a practice its business address. For payouts, whatever Stripe needs to pay a professional — we never hold bank details ourselves.
Credentials: the documents a professional uploads for their role, the licence or registration number, and the expiry date. The expiry date is used by the product, not just stored: it decides which shifts you are shown and when a renewal reminder is sent.
Location: a single position fix when a professional clocks in and another when they clock out, used to confirm they were at the practice. We do not track location at any other time, and there is no background tracking of any kind.
Messaging consent: when somebody opts in to text messages we store the exact sentence they were shown alongside the tick, the time, and the page it happened on — not merely a true/false flag. If we ever have to prove what somebody agreed to, the answer should be the words they actually read.
Ordinary service records: shifts posted and worked, timesheets, payments, messages we sent and their delivery status.
2. Why we collect it
To run the marketplace: to match a shift to professionals who are eligible for it, to confirm somebody was where they said they were, to pay people, and to charge practices after work is approved.
To keep it lawful and safe: verifying credentials is the point of the credential file, and it is why a document is reviewed by a person rather than accepted on upload.
To tell you things you need to know: a shift offer, a reminder, a credential about to expire. We do not send marketing texts, and the messages we do send can be stopped by replying STOP.
3. What we do not do
We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is no advertising network on this site and no third-party analytics that follows you off it.
A practice never sees a professional's documents. It sees that somebody is cleared for the role — not the paperwork behind it. Until a shift is assigned, a practice does not see the professional's contact details at all, and a professional does not see the practice's address.
4. Who processes it for us
Stripe — payments to practices and payouts to professionals, including the identity checks a payout account requires.
Twilio — the text messages that carry shift offers, reminders and claim links.
Supabase — the database, authentication, and the private file store credential documents live in.
Vercel — the hosting this site and its API run on.
Each of them processes data on our instructions to run the service. We do not hand your information to anyone else except where the law requires it.
[COUNSEL REVIEW] Sub-processor list, data-processing terms, and the international transfer position if any of these operate outside the US for our data.
5. How credential documents are held
In a private store, never a public URL. When somebody with a reason to see a document opens it, they get a link that stops working after ten minutes. A document is reachable by the professional it belongs to and by the people here who verify it, and by nobody else.
6. Text messages
Shift offers and reminders are sent by SMS to the number you gave us, and message and data rates from your carrier may apply. Reply STOP to any message to end them and HELP for contact details.
Stopping messages stops shift offers too — texting is how offers are delivered — so the account keeps working but goes quiet.
7. How long we keep it
Records of shifts, timesheets and payments are kept while the account is open and afterwards for as long as tax and employment records have to be kept.
Credential documents are kept while they are current and for a period after they are replaced, because a superseded document is part of the record of who was cleared to work a shift that already happened. A rejected upload is kept too, for the same reason.
Location fixes are kept with the timesheet they belong to and are not used for anything else.
Consent records are kept for as long as the law requires us to be able to prove consent, and longer than the account if that is what it takes.
[COUNSEL REVIEW] The actual retention periods, per category, against Nevada and federal requirements. The paragraphs above describe the shape of it, not the number of years.
8. Your choices
You can see and correct your own details in the product, stop text messages at any time, and ask us to delete an account.
Deleting an account does not delete records we are required to keep — the shifts somebody worked and was paid for are part of a financial record, not a profile setting.
[COUNSEL REVIEW] Access, correction, deletion and portability rights as they actually apply here, including Nevada's opt-out of sale statute and California's if we take a professional or practice from there.
9. Children
This service is for people 18 and over. We do not knowingly collect information from anybody younger, and we delete it if we find it.
10. Contact
Questions about any of this, or a request about your own data, go to hello@fillara.co and reach a person.
[COUNSEL REVIEW] Whether a formal privacy contact, postal address or data-protection representative has to be named here.
Questions about any of this? Ask us.