Privacy Policy

Last updated: May 5, 2026

Notice: This Privacy Policy is currently a draft pending legal review. The terms below describe our intended practices; please contact us at contact@nextoncall.com for any specific privacy questions while review is in progress.

NextOnCall (“we,” “us,” “the Service”) is operated by Next on Call, LLC (“the Company”). This Privacy Policy explains what personal information the Service collects, how we use it, who we share it with, and the choices and rights you have. By using NextOnCall you accept this Policy. If you don’t agree, please don’t use the Service.

If you have questions, contact us at contact@nextoncall.com.

1. Who is covered

NextOnCall is a B2B SaaS platform. Two kinds of people interact with us:

This Policy covers both groups. Where we say “you,” we mean either group unless we specify.

NextOnCall is currently offered as a general-purpose call-routing and scheduling service. It is not currently offered as a HIPAA Business Associate service, and we do not enter into Business Associate Agreements (BAAs) at this time. Organizations subject to HIPAA are responsible for evaluating whether their intended use requires a BAA before transmitting Protected Health Information (PHI) through the Service. See Section 10.

2. What we collect

2.1 Information you provide

2.2 Information collected automatically

2.3 We do not record call audio

NextOnCall does not record the content of voice calls. We log that a call happened and how long it was. The audio is brokered by Twilio in real time and we do not store it.

2.4 Children

NextOnCall is not intended for use by anyone under 16 years of age, and we do not knowingly collect data from anyone under that age.

3. How we use the information

We use what we collect to:

We do not use your personal data to train any AI model. We do not sell your personal data. We do not share data with advertisers.

4. Who we share information with

We share data only with the following categories of recipients, only to the extent each one needs to do their job:

Recipient What they receive Why
Twilio Inc. Phone numbers, call status, SMS contents (one-time code messages) Voice routing and SMS delivery
Expo / Apple Push (APNs) / Google FCM Push notification tokens, the notification payload (alert title and body — kept minimal, never PHI) Push delivery to your device
Stripe (paying accounts) Billing email, address, payment method Subscription billing
Our hosting provider All application data at rest Hosting and database
Lawful authorities Whatever a valid court order or subpoena compels Legal compliance

We require each of these to handle data appropriately and, where applicable, we have signed standard data processing addenda with them.

5. How long we keep it

After the retention window, we either delete the data or de-identify it so it can no longer be tied to you.

6. Your rights

Subject to applicable law, you can ask us to:

To exercise any of these, email contact@nextoncall.com. We aim to respond within 30 days.

7. Push notifications

The mobile app uses push notifications to deliver shift-start alerts and incoming-call escalations. You control these in two places:

  1. Your device’s system settings — turn off “Allow notifications” for the NextOnCall app at any time.
  2. In-app preferences — the app’s Settings screen has toggles for Push Notifications, Override Volume, Dark Mode, and shift-start lead time.

On iOS, NextOnCall delivers alerts as standard push notifications, which follow your device’s sound and Focus settings. On Android, on-call alerts use a high-priority notification channel that can bypass Do Not Disturb where your device settings allow it. While you are on call, please make sure your notification settings allow NextOnCall alerts to be audible.

8. Security

We use industry-standard measures to protect your data, including:

No system is perfectly secure. If we ever experience a data breach that affects you, we’ll notify you and the relevant authorities as required by law.

9. Cookies and similar technologies

The web dashboard uses session cookies (PHPSESSID) to keep you logged in. We do not use third-party advertising or tracking cookies. The mobile app does not use cookies.

10. HIPAA and Business Associate Agreements

NextOnCall does not currently offer Business Associate Agreements, and the Service is not currently offered for uses that require one. If your organization is a HIPAA-Covered Entity, do not use the Service to transmit Protected Health Information (PHI) — for example, in caller notes — unless and until a BAA is in place between your organization and the Company.

The Service is designed to minimize the sensitive data it handles: we do not record call audio, and push notification payloads include only the alert type and shift identifier — never patient identifiers or call content.

HIPAA/BAA support is planned for a future release. If your organization requires a BAA, contact us at contact@nextoncall.com and we will notify you when it becomes available.

11. Changes to this Policy

We’ll update this Policy as the Service changes. The “Last updated” date at the top reflects the most recent change. If we make a material change, we’ll notify you via email (for administrators) and an in-app banner (for providers) at least 14 days before it takes effect.

12. Contact

If you have any questions about this Policy or want to exercise your rights: