Privacy Policy
Last updated: July 26, 2026
Nexora Staffing by Aurelius Compliance Group (“Nexora,” “we,” “us”) operates a healthcare workforce marketplace that connects healthcare facilities with independent, credentialed professionals. This policy explains what we collect, how we use it, and the choices you have. It applies to our website and mobile applications (the “Service”).
Information we collect
- Account information — name, email, phone, role, and password (stored only as a salted hash).
- Professional credentials and identity — licenses, certifications, government-issued identifiers, and related documents you upload to verify eligibility to work. Sensitive identifiers are encrypted at rest.
- Location — precise device location at the moment you clock in or out of a shift, used to confirm you are at the facility. We do not track your location in the background.
- Shift and work activity — shifts claimed, timesheets, ratings, messages, disputes, and payments.
- Device and usage data — IP address, device and browser characteristics, and log data, used for security and to operate the Service.
- Payment information — facility payment card and billing details are collected and processed by our payment processor (Stripe); we do not store full card numbers.
How we use information
- To operate the marketplace — match professionals to shifts, verify credentials, and record work.
- To process facility payments and professional earnings.
- To confirm attendance via location at clock-in/out and to detect fraud or misuse.
- To communicate with you about shifts, your account, and support requests.
- To meet legal, regulatory, and compliance obligations (including audit logging).
How we share information
We do not sell your personal information. We share it only as needed to run the Service:
- With facilities — a professional’s relevant credential status and shift activity are shared with facilities they engage with. Facilities do not receive raw sensitive identifiers.
- With service providers — payment processing (Stripe), hosting, and infrastructure vendors bound by confidentiality obligations.
- For legal reasons — to comply with law, enforce our terms, or protect rights and safety.
Data security
We apply defense-in-depth safeguards including encryption of sensitive identifiers at rest, encrypted transport (HTTPS), access controls, and an immutable audit log of sensitive access. No method of transmission or storage is completely secure, but we work to protect your data.
Data retention
We retain information for as long as your account is active and as required to meet legal, tax, and compliance obligations, after which it is deleted or de-identified.
Your choices and rights
- Access, correct, or update your account information from within the app.
- Request deletion of your account, subject to records we must retain by law.
- Control device location permission through your device settings; note that clock-in/out requires location.
Children
The Service is for users 18 and older and is not directed to children.
Changes to this policy
We may update this policy and will revise the “Last updated” date above. Material changes will be communicated in-app.
Contact
Questions about this policy or your data can be submitted through the in-app support ticket system, which routes to our privacy team.

