Privacy Policy
1. Data we collect and its sources
Account and profile data you provide (name, date of birth, contact details, preferred language, communication preferences); dependent and representative information you add; insurance information you choose to store; booking details needed for a specific appointment (reason for visit, uploads such as orders or referrals where a provider requires them); payment metadata from our payment processor (never raw card numbers or CVV); technical data necessary to operate and secure the service (device, log, and session information); and location information you enter — precise device location is used only with your permission and is never required when a ZIP-code search is sufficient. Provider directory information comes from public, licensed, and provider-supplied sources with recorded provenance. We apply data minimization: clinical or sensitive information is collected only when a specific booking or workflow requires it.
2. How we use data
To operate search and booking; to communicate confirmations, reminders, and account alerts (transactional communications are separate from marketing, which requires distinct consent you can withdraw); to process payments and refunds; to maintain security, prevent fraud and abuse, and audit access; to meet legal obligations; and to improve the service using privacy-conscious, first-party measurement. We do not sell personal information, and we do not use advertising trackers on authenticated, search, booking, or payment pages.
3. Sharing
With providers you book with or send requests to (only what the provider requires); with service vendors under contracts that restrict use (hosting, communications delivery, payments) — vendors handling protected health information are engaged under Business Associate Agreements where required; with authorized representatives you designate; and where required by law. A current vendor register with PHI status, security review, and agreement status is maintained internally.
4. Cookies and analytics
Spot Now uses first-party, privacy-conscious analytics with consent management. No advertising pixels, session-replay tools, third-party marketing trackers, or unapproved chat widgets run on authenticated pages, symptom or provider searches, booking pages, payment pages, or patient dashboards. Personal health details never appear in URLs, referrers, analytics events, page titles, or error payloads. Essential cookies maintain sessions and security; you can manage optional cookies through the consent banner in production.
5. This Privacy Policy vs. the Notice of Privacy Practices
This Privacy Policy describes how the Platform handles data generally. Where Spot Now or a participating provider acts as a HIPAA covered entity or business associate, the applicable Notice of Privacy Practices describes HIPAA-specific uses, disclosures, and individual rights for protected health information. If the two documents differ for PHI, the Notice of Privacy Practices controls to the extent HIPAA applies.
6. Consumer health data notice
[FOR COUNSEL REVIEW] Certain states (for example Washington's My Health My Data Act and similar laws) require specific notices and consent for consumer health data. This section is a placeholder for the state-specific consumer health data privacy notice(s), including categories collected, purposes, sharing, and the rights to access, delete, and withdraw consent.
7. Retention and deletion
Retention periods are configured by record type (profiles, appointments, payments, consents, communications, audit logs, uploaded documents, backups) and approved by legal and compliance personnel. You may request account deletion; some records must be retained after account closure — for example appointment, payment, consent, and audit records required by law — and we explain this at the time of your request.
8. Security
Encryption in transit and at rest, managed keys with rotation, role-based and attribute-based access controls, multifactor authentication for privileged access, audit logging of sensitive access, environment isolation, and an incident-response and breach-notification process. No system is perfectly secure; report concerns via Responsible Disclosure.
9. Children
Accounts are created by adults. Care for minors is managed through parent, guardian, or authorized-representative access with verification, and adolescent records receive additional protection where state law requires. The Platform is not directed at children and does not knowingly collect data directly from children.
10. Your state privacy rights
[FOR COUNSEL REVIEW] Depending on your state, you may have rights to access, correct, delete, or export personal information; to opt out of sale, sharing, or targeted advertising; and to limit use of sensitive personal information. Spot Now does not sell or share personal information for cross-context behavioral advertising; the "Do Not Sell or Share My Personal Information" and "Limit Use of Sensitive Personal Information" controls will be provided here as required. Submit requests to privacy@getmyspotnow.com; we verify requests and respond within the periods state law requires, and you may appeal a refusal.
11. International visitors
The Platform is operated from the United States for services delivered in the United States. If you access it from elsewhere, your information is processed in the United States. [FOR COUNSEL REVIEW: add GDPR/UK sections only if the service is offered in those markets.]
12. Changes and contact
Material changes are versioned, dated, and notified. Privacy office: privacy@getmyspotnow.com — also the channel for privacy complaints, which you may raise without retaliation.