← Back to Infini HealthCare

Privacy Policy

Last updated: February 2026 · Applies to Infini HealthCare and its d/b/a CareCo 24.

1. Who we are

Infini HealthCare (“we”, “us”, “CareCo 24”) operates a healthcare staffing marketplace connecting private-pay families with independently vetted RNs, LPNs, CNAs, and HHAs. Our headquarters is in the United States and our services are directed at U.S. residents.

2. What we collect

Account data: name, email, phone, password (hashed with bcrypt), role, credential (RN/LPN/CNA/HHA), state, home ZIP, willing ZIPs, agency name, EIN.

Health-adjacent data: care recipient name (family-provided), high-level service categories, shift addresses, incident reports. We do not collect medical diagnoses, medication lists, or clinical records unless a family explicitly uploads them to their care plan.

Payment data: processed exclusively by Stripe, Inc. We never see or store raw card numbers. We store only the Stripe customer/account IDs, payment method status, and payout preferences (cadence, ACH/debit/check).

Communications: shift-blast responses (yes/no), preference choices (keep in / snooze / opt out), notification logs (email/SMS status), audit-log entries for administrative actions.

Automatically collected: IP address (for rate limiting + audit), user agent, request timestamps, session tokens.

3. Third parties we share with

  • Stripe (payments & Connect payouts) — privacy policy
  • Resend (transactional email) — privacy policy
  • Twilio (SMS, when enabled) — privacy policy
  • MongoDB Atlas (database) — privacy policy
  • Apollo.io (admin-only B2B lead search — never receives caregiver or family data)
  • Emergent (hosting), PostHog (product analytics)

4. Health information (HIPAA)

We take the position that some of the data we handle constitutes Protected Health Information under HIPAA. We have executed (or are executing) Business Associate Agreements with our primary vendors (Stripe, Resend, MongoDB Atlas). Employees with access to PHI receive annual HIPAA training. Full details available in our Data Practices disclosure.

5. Your rights (GDPR + CCPA/CPRA)

You have the right to (a) know what personal data we hold, (b) receive a copy in machine-readable format, (c) correct inaccuracies, (d) delete your account and personal data, (e) opt out of marketing communications at any time. To exercise these rights, log into your dashboard → Settings → Privacy, or email privacy@careco24.com. We respond within 30 days.

6. Data retention

Active account data is retained for as long as your account is open. After account deletion, we retain audit logs and financial records for 7 years to satisfy tax and healthcare reporting obligations. Shift-blast recipient records are archived 90 days after the shift date. Backup snapshots roll off after 14 days.

7. Cookies & tracking

We use strictly necessary cookies for authentication and session management, plus optional analytics cookies (PostHog) that you can opt out of via the cookie banner or Settings → Privacy. We do not sell your personal information.

8. Security

Passwords are bcrypt-hashed. TLS in transit for every request. Rate limiting and brute-force lockout enforced. Administrative actions are audit-logged with IP address. Third-party payments handled by PCI-DSS Level 1 providers (Stripe).

9. Contact

Data protection officer: privacy@careco24.com. General: hello@careco24.com. Mail: Infini HealthCare LLC (mailing address to be updated).

This document is a working template drafted by our platform. Have an attorney familiar with U.S. healthcare privacy law review it before you launch publicly.

Press on me and ask me a question
Voice or text — I know the app inside out.