Legal

Privacy Policy

Effective date: January 1, 2026 · Last updated: January 1, 2026

Our Privacy Commitment

  • ✓ We never sell your data or patient data to third parties
  • ✓ Protected Health Information (PHI) is handled under our HIPAA Business Associate Agreement
  • ✓ California residents have full CCPA/CPRA rights over their personal data
  • ✓ You own your data and can export or delete it at any time

1. Overview

CareOps Technologies, Inc. ("CareOps," "we," "us," or "our") operates the CareOps platform, a HIPAA-compliant medication management and care operations solution for licensed California healthcare facilities. This Privacy Policy explains how we collect, use, disclose, and protect information about our customers, their employees, and where applicable, the residents in their care.

This policy applies to: (a) information collected through our website (careops.ai and subdomains); (b) information collected through the CareOps web application; and (c) information processed on behalf of healthcare facilities as their Business Associate under HIPAA.

This Privacy Policy does not apply to third-party websites or services linked from our platform. We encourage you to review the privacy policies of any third-party services you access through CareOps.

2. Information We Collect

We collect the following categories of information:

CategoryExamplesSource
Account DataName, email, phone, role, job titleYou, during registration
Organization DataFacility name, address, license number, NPI, subscription tierYou, during onboarding
Payment DataBilling address, last 4 digits of card (stored by Stripe)You, via Stripe
Usage DataFeature usage, login events, error logs, API callsAutomatically collected
Device/Technical DataIP address, browser type, OS, session durationAutomatically collected
PHI (on behalf of facilities)Resident names, diagnoses, medications, care notesEntered by facility staff

3. Protected Health Information (PHI) and HIPAA

When healthcare facilities use CareOps to manage resident health records, medications, and care documentation, CareOps acts as a Business Associate under HIPAA (45 CFR Parts 160 and 164). This means:

  • We process PHI only as directed by and on behalf of the healthcare facility (the Covered Entity)
  • We do not use PHI for our own commercial purposes
  • We do not sell PHI or use it for targeted advertising
  • We maintain appropriate safeguards required under the HIPAA Security Rule
  • We report suspected breaches of PHI to the relevant facility within 60 days of discovery, in accordance with the HIPAA Breach Notification Rule

A Business Associate Agreement (BAA) is required for all CareOps customers and is incorporated into the CareOps Terms of Service. The full BAA text is available at careops.ai/hipaa.

Residents' rights to access and control their PHI are managed through the healthcare facility, which serves as the Covered Entity under HIPAA. Residents should contact their care facility directly to exercise HIPAA rights.

4. How We Use Information

We use account, organization, and usage data for:

  • Service delivery: Providing, operating, and maintaining the CareOps platform
  • Account management: Managing your subscription, authentication, and access controls
  • Customer support: Responding to inquiries, troubleshooting, and providing technical assistance
  • Billing: Processing payments and managing subscriptions through Stripe
  • Communications: Sending service notifications, security alerts, product updates, and transactional emails
  • Compliance: Maintaining audit logs required by HIPAA and applicable regulations
  • Product improvement: Analyzing aggregated, de-identified usage patterns to improve features and performance
  • Security: Detecting fraud, unauthorized access, and security threats
  • Legal obligations: Complying with applicable laws, court orders, and regulatory requirements

We will not use your information for purposes materially different from those listed above without providing advance notice and, where required, obtaining your consent.

5. Information Sharing and Disclosure

We do not sell personal information. We share information only as follows:

  • Service Providers (Sub-processors): We engage trusted third-party vendors who process data on our behalf, listed below. Each sub-processor is bound by data processing agreements.
  • Legal Requirements: We may disclose information when required by law, legal process, or governmental authority, or to protect the rights, property, or safety of CareOps, our customers, or the public.
  • Business Transfers: In connection with a merger, acquisition, financing, or sale of assets, information may be transferred to the successor entity. We will notify you via email and in-app notice.
  • With Your Consent: We may share information with third parties when you explicitly authorize us to do so.

Sub-processors

VendorPurposeData Type
SupabaseAuthentication and databaseAccount data, PHI
StripePayment processingBilling data (no PHI)
ResendTransactional email deliveryEmail address, notification content
TwilioSMS notificationsPhone number, notification content
SentryError monitoringError logs, stack traces (PHI scrubbed)
DeepSeekAI clinical assistance featuresAnonymized query context

6. Data Security

CareOps implements security safeguards aligned with HIPAA Security Rule requirements and industry best practices:

  • Encryption: AES-256 encryption for data at rest; TLS 1.2 or higher for all data in transit
  • Access Controls: Role-based access control (RBAC) with principle of least privilege; MFA support
  • Audit Logging: Comprehensive audit trails for all data access and modifications
  • Backups: Automated daily backups with point-in-time recovery capability
  • Vulnerability Management: Regular security assessments and dependency updates
  • Incident Response: Documented breach response procedures with notification timelines

Despite our safeguards, no system is 100% secure. If you suspect unauthorized access to your account, contact us immediately at security@careops.ai.

7. Data Retention

We retain information for as long as necessary to provide the Service and comply with legal obligations:

  • Account data: Retained for the duration of the subscription plus 30 days after termination
  • PHI (clinical records): Retained as required by California law (minimum 7 years for adult records; 7 years after age 18 for minors) or as directed by the facility
  • Audit logs: Retained for 6 years per HIPAA requirements
  • Payment records: Retained for 7 years per financial regulations
  • Usage/analytics data: Retained in aggregated form for up to 3 years

After the retention period, data is securely deleted using industry-standard data sanitization methods.

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of personal information we have collected about you and the categories, sources, and purposes of collection
  • Right to Delete: Request deletion of personal information we hold about you (subject to legal exceptions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale: We do not sell personal information. No opt-out is necessary.
  • Right to Limit Use of Sensitive Data: Request that we limit our use of sensitive personal information
  • Right to Non-Discrimination: You will not be discriminated against for exercising your privacy rights

To exercise these rights, contact us at privacy@careops.ai. We will respond within 45 days and may verify your identity before processing the request.

Note: CCPA rights apply to personal information about California consumers in their individual capacity. PHI about facility residents is governed by HIPAA, not CCPA. Residents should contact their care facility directly.

9. Cookies and Tracking

CareOps uses only essential cookies required for platform operation. We do not use advertising cookies or cross-site tracking technologies.

  • Authentication cookies: Required to maintain your login session (Supabase Auth)
  • CSRF protection tokens: Required for security against cross-site request forgery
  • Preference cookies: Remember your UI settings (e.g., dark mode, timezone)

We do not use Google Analytics, Meta Pixel, or other third-party tracking scripts. No cookie consent banner is required because we only use strictly necessary cookies.

10. Children's Privacy

CareOps is designed for licensed healthcare professionals and organizations. We do not knowingly collect personal information directly from children under 13. If you believe we have inadvertently collected such information, contact us at privacy@careops.ai and we will delete it promptly.

Note: CareOps may process health records for minor residents in care facilities (e.g., ARF). Such processing is performed on behalf of the licensed care facility and is governed by the BAA and applicable healthcare privacy laws.

11. International Data Transfers

CareOps is headquartered in California and processes data primarily within the United States. Our infrastructure is hosted in US-based data centers. If any data processing occurs outside the United States, we will ensure appropriate safeguards are in place (such as Standard Contractual Clauses) to protect your information.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide notice via email and in-app notification at least 30 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy inquiries, data requests, or to report a security concern:

CareOps Technologies, Inc.
Attn: Privacy Officer
Email: privacy@careops.ai
Security incidents: security@careops.ai
Response time: Within 45 days for CCPA requests; within 30 days for general inquiries