Skip to content

Legal

Privacy notice

Effective 28 September 2026

In short: we collect what we need to verify people and run bookings, share contact details only once a shift is booked, never store your ID images, never sell your data, and let you delete your account from the app at any time.

1. Who we are

MedSkift is operated by Attribute AI, LLC, a United States limited liability company (“MedSkift”, “we”, “us”). We are the data controller for the personal information described in this notice. For people using MedSkift in Zimbabwe we process it under the Cyber and Data Protection Act [Chapter 12:07] and the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, Statutory Instrument 155 of 2024.

You can reach our Data Protection Officer at privacy@medskift.com.

2. What we collect

  • Account details: your email address, name and, if you add it, your phone number.
  • Health worker profile: profession, council and registration number, experience, skills, languages, town and, if you choose to share it, your approximate location for nearby shifts.
  • Identity verification results from our partner Didit: your verified legal name, date of birth, nationality, document type and issuing country, and the last four digits of your document number (the full number is stored only as a one-way hash). The photos of your ID and your selfie stay with Didit.
  • Documents you upload: practising and registration certificates, qualifications, CVs, police clearances, business registrations, operating licences and tax clearances, with their numbers and expiry dates.
  • Organization details: name, type, registration number, contact details, sites and team members.
  • Marketplace activity: shifts, applications, bookings, cancellations, reviews and messages.
  • Payments: top-up amounts, Linkwa payment references and receipts. We never receive card numbers or mobile money PINs.
  • Technical information: IP address, browser and device type, push notification tokens and security logs.

3. How and why we use it

  • To provide MedSkift (performing our contract with you): accounts, shift listings, applications, bookings, messaging, notifications, credit and receipts.
  • To verify people and organizations (our legitimate interest in patient safety and a trustworthy marketplace, and your consent to identity checks): identity checks, credential and business document reviews, and expiry reminders.
  • To keep the platform safe (legitimate interests): masking contact details before a booking, investigating reports, preventing fraud and abuse, and rate-limiting sign-in attempts.
  • To meet legal obligations: financial records, responding to lawful requests from authorities.
  • Optional messages (your consent, which you can withdraw in Settings): shift alerts and product news.

We do not sell personal information, and we do not use it for advertising.

4. Sensitive information

Identity document data and health professional registration records are sensitive. We collect only what verification needs, restrict access to trained verification staff who sign in with two-factor authentication, and record every time a document is reviewed. Documents are kept in private storage and can only be opened through links that expire after five minutes.

5. Who can see your information

  • Other users, only as needed. Employers see a health worker’s profile, verified badges, experience and reviews when they apply, but not their phone number or email. Once a shift is booked, both sides see each other’s contact details and the site address. Families’ home addresses stay hidden until they book.
  • Our service providers (listed below), who process data for us under contract and only on our instructions.
  • Authorities, when the law requires it, or to protect someone’s safety.

6. Processing outside Zimbabwe

Attribute AI, LLC is based in the United States, and some of our providers store or process data in other countries, so information you give MedSkift is processed outside Zimbabwe. We notify POTRAZ of these transfers as the Act requires and use contracts that require providers to protect your information to an adequate standard.

ProviderPurposeWhere
NeonDatabase hosting and sign-in (accounts, profiles, bookings, messages)United Kingdom (London)
CloudflareWebsite and API hosting, private document storage, securityGlobal network; storage outside Zimbabwe
DiditIdentity verification (ID document and live selfie)European Union
Google FirebasePush notifications to the mobile appUnited States
ResendSending account and booking emailsUnited States
LinkwaPayment checkout for employer creditZimbabwe

7. How long we keep it

InformationKept for
Account, profile and organization detailsWhile your account is open; removed or pseudonymised when you delete it
Identity verification results (verified name, date of birth, document type and country, last four digits and a one-way hash of the document number)While your account is open. ID images are never stored by MedSkift
Credential and business documentsWhile your account is open, so expiry can be tracked; deleted with your account
Files uploaded but never attached to a documentDeleted automatically after 24 hours
Bookings, reviews and messagesWhile either party’s account is open; your name is removed from them when you delete your account
Top-ups, receipts and the credit ledgerAs long as Zimbabwean tax and accounting law requires, with personal details pseudonymised after deletion
Audit records of staff and security actionsKept permanently for accountability, with personal details pseudonymised after deletion
Server logsShort periods (typically under 90 days) for security and fault-finding

8. Your rights

Under the Cyber and Data Protection Act you can:

  • ask for a copy of the personal information we hold about you;
  • ask us to correct information that is wrong or incomplete;
  • ask us to delete your information, subject to the records the law requires us to keep;
  • object to processing based on our legitimate interests, and withdraw consent at any time;
  • complain to the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).

Email privacy@medskift.com from the address on your account. We may ask you to confirm your identity before acting on a request.

9. Deleting your account

You can delete your account at any time in Settings → Delete account in the web app or the mobile app, or by emailing support@medskift.com.

When you do, we remove your sign-in identity so the account can no longer be used, and delete or pseudonymise your personal details: your name, contact details, profile, documents and verification results. Records the law or basic accountability requires us to keep, such as the credit ledger, receipts and audit records, stay but no longer identify you. Unused organization credit cannot be paid out (see our credit terms).

10. How we protect it

All traffic is encrypted in transit. Sessions use secure, HTTP-only cookies; documents sit in private storage; staff access uses two-factor authentication and least-privilege roles; financial and audit records cannot be edited after they are written. No system is perfectly secure; if a breach affects you, we will tell you and POTRAZ as the law requires.

11. Children

MedSkift is for adults. You must be 18 or older to create an account.

12. Changes to this notice

We will post any update here with a new effective date, and tell you by email or in the app before significant changes take effect.