Privacy Policy

Three60 Health · a product of Zenith Elevation LLC · Effective September 17, 2026

Who we are. Three60 Health is operated by Zenith Elevation LLC, 8101 S Elder Ave, Broken Arrow, Oklahoma 74011. This policy explains what information the platform holds, why, who can see it, and how we protect it. Most of the information in the system is put there by the organization that invited you (a provider group, staffing agency, or facility), and that organization decides how it is used. We process it on their behalf to run the service.

What we collect. Account information (name, work email, phone, role, and login and security events). Professional records that you or your organization's staff add: specialty, NPI, licenses, board certifications, DEA and state registrations (we keep only the last four digits of those numbers), life-support cards, malpractice certificates, background check status, CVs, W-9s, and the document images or PDFs behind them. Workforce records your organization needs for credentialing, such as immunization and health screening dates, signed agreements, and policy acknowledgments. Operational records: availability, time off, shifts, assignments, timesheets, rates, and billing batches. Messages sent to you through the system and any replies you send. If your organization pays by card or bank debit, billing contact and payment details are collected by our payment processor, not stored by us. We intentionally do not collect patient information, and the system is not designed to hold it.

How it is used. Only to run staffing operations for your organization: scheduling and matching, credentialing record-keeping and expiry reminders, onboarding, messaging, timesheets, billing handoff, and the audit trail that shows who changed what. We do not sell personal information, do not use it for advertising, and do not use it to train AI models.

AI processing. Three features send data to Anthropic, our AI model provider, under commercial terms that do not allow it to use the data to train its models and that provide for deletion after processing. When someone uploads a credential document through Smart Document Import, the content of that document is sent so the fields printed on it can be suggested for a person to confirm. When someone imports a spreadsheet, the column headers and a few sample rows are sent so columns can be mapped for confirmation. When a scheduler asks the matching advisor for suggestions, provider names, fit scores, conflict flags, and one shift's facility, time, type, and specialty are sent so candidates can be suggested with reasons. Nothing is sent unless a person starts one of these actions, and nothing the AI suggests is saved until a person confirms it. The document reader is instructed not to return Social Security numbers, dates of birth, home addresses, or any patient information.

Who can see it. Access is role-based and enforced at the database layer, so a user only reaches records inside their own organization and role. Providers see their own records, schedule, offers, and messages. Facility users see their own facility's requests and confirmed coverage plus a status-only readiness summary, never provider documents or rates. Staffing partners see only the providers allocated to them. Staff see the records their role needs for operations, and administrators manage accounts and roles. Zenith staff access records only to provide and support the service, to investigate security or technical issues, at an organization's request, or when the law requires it.

Documents. Uploaded documents live in private storage and are served only through short-lived signed links generated for authorized users. They are never publicly accessible. Views and downloads of provider documents are recorded in the audit trail.

Notifications and messages. We send operational emails (offers, confirmations, document review results, reminders, digests) and optional push notifications through delivery providers. Their content is intentionally minimal; details stay behind your login. Organizations can send email messages to their providers through the system, and can email a link to a document for electronic signature. The system does not receive inbound email: if you reply to one of these messages, your reply is not delivered into the system and is not filed to your provider record. Where more than one email address is held for a provider, each address can be switched off individually, and reminder cadence can be set, from the provider record.

Text messages

What we text about. When your organization turns on text messaging and you have opted in, Three60 Health may text you about your work: shift reminders, credential expiration notices, coverage offers, and replies from your scheduling office. We do not send marketing texts.

How you opt in. We only text a number after you have agreed to receive texts, and we keep a record of when you agreed and how, either from your provider account or from your scheduling office recording your consent. A phone number on file is not consent. You can also opt in at three60health.app/text-consent, or on the printed consent form your office can give you.

Frequency and cost. Message frequency varies with your schedule and your organization's settings. Message and data rates may apply.

How you stop. Reply STOP to any message to stop receiving texts. Reply HELP for help, or contact us at chris@zenithelevation.com. Stopping texts does not stop email or in-app notices; those are controlled from your provider record.

Sharing. Your mobile number and your texting consent are not shared with or sold to anyone for their marketing or promotional purposes.

Provider. Texts are delivered by Twilio, which processes your number and the message content in order to deliver it.

Service providers. The system runs on established providers, each processing data only to provide its service: Supabase (database, authentication, and document storage, hosted on Amazon Web Services in the United States), Vercel (application hosting), Cloudflare (network protection and encrypted off-site backup storage), Resend (email delivery), Twilio (text message delivery), Anthropic (AI processing described above), GitHub (source control and the scheduled backup job), Stripe (payments, only if your organization pays through it), Google (Android app distribution and push delivery), and Apple (iOS app distribution through the App Store and TestFlight, and push delivery through APNs). All data is stored in the United States.

Backups and retention. Records are kept while your organization's subscription is active and while your organization keeps them; your organization controls retention of its own records. Error logs purge automatically after 30 days. Nightly encrypted backups are kept for 30 days. When a subscription ends, the organization has 60 days to export its data, after which we delete it from the live service within 30 days and backup copies age out within a further 30 days, except where the law requires us to keep something longer.

Security. Encrypted connections, encryption at rest, row-level database security for tenant isolation, role-based access, two-factor authentication and passwordless sign-in, sign-out of all other devices, private document storage with signed links, audit logging of sensitive actions, automated tests before every deployment, and daily backups with a nightly copy held by an independent provider. No system is perfectly secure. If you believe your account or data has been accessed without authorization, tell your administrator and contact us right away. If we confirm a security incident affecting your organization's data, we notify that organization promptly.

Your choices and requests. To see, correct, or delete information about you, or to close your account, start with your organization's administrator, because they control the records in their tenant and we act on their instructions. You can also contact us directly and we will help route the request. You can adjust notification preferences and two-factor settings from your profile at any time.

Children. The service is for working professionals and is not directed to anyone under 18. We do not knowingly collect information from children.

Changes. We may update this policy as the product changes. We will post the new effective date here and, for material changes, show a notice in the app.

Contact. Privacy questions or requests: chris@zenithelevation.com, or write to Zenith Elevation LLC, 8101 S Elder Ave, Broken Arrow, OK 74011.

Back to sign in · Terms of Service