Privacy Policy
Effective July 14, 2026
This Privacy Policy explains how HIPAA Binder(“we”, “us”) collects, uses, and protects information in connection with the HIPAA Binderwebsite and the compliance documents and related materials it provides (together, the “Service”). By using the Service, you agree to the practices described here. This policy is part of, and should be read together with, our Terms of Use.
Important: we do not collect, request, or store any patient or client health information (PHI). HIPAA Binder is a document layer for your practice. You enter only your own contact and practice details so we can prepare your documents, never information about your patients or clients. The Service is not designed to receive PHI, and you must not submit it.
1. Scope
This policy applies to information we collect through the HIPAA Binder website, when you request a sample or preview, when you join our interest list, when you place an order, and through our own usage analytics. It does not apply to third-party websites or services we link to, which have their own privacy practices.
2. Information we collect
We collect only what we need to operate the Service:
- Email address: the email you give us to request a sample or preview, to be notified at launch, or to place an order.
- Practice details: information about your practice (such as your profession, practice type, address, phone, and Privacy Officer) that you provide, for example through the document generator or an order intake, so we can prepare and customize your documents and support your order. These are details about your own practice, not about any patient or client.
- Practice logo (optional): if you upload a logo for your document letterhead, we store the image file solely to render it on your documents. We use it for nothing else, and you can ask us to replace or delete it at any time.
- Payment information: when you place an order, your payment is processed by Stripe. We receive a confirmation of the purchase (such as the email associated with it, the offer purchased, the amount, and a Stripe reference) but we never receive or store your card number.
- Basic usage data: first-party analytics such as page views and interactions (for example, which offer you clicked), recorded in our own database to help us understand and improve the Service. This may include a randomly generated session identifier and the page or offer involved, but is not used to identify you personally.
We do not ask you to create a password-protected account, and we do not knowingly collect any special categories of personal data beyond the limited practice details described above.
3. How we use information
We use the information we collect to:
- prepare, customize, and deliver the documents you request or purchase;
- send transactional messages, such as order confirmations and delivery;
- respond to your requests, questions, and refund requests;
- send launch and product updates if you asked to be notified (you can opt out at any time);
- understand how the Service is used so we can measure and improve it;
- protect the Service, prevent abuse, and comply with our legal obligations.
4. Cookies & tracking
We keep tracking to a minimum. We use the storage necessary to operate the site and to record first-party usage analytics (for example, a session identifier used to understand page views and interactions within our own database).
We also use Google Ads conversion measurement (Google’s “gtag”) so we can tell whether our advertising works. It measures page views and purchase conversions, and it involves cookies set by Google. It never involves any patient information (we hold none), and we do not use it to build advertising profiles or sell your information to advertisers. You can control or clear cookies and browser storage through your browser settings, and you can manage how Google personalizes ads at adssettings.google.com; doing either will not prevent you from using the Service.
5. Third-party services / sub-processors
We rely on a small number of trusted service providers to operate the Service. They process information only on our behalf and only as needed to provide their service:
- Stripe: payment processing for orders. Stripe handles your card details directly; we do not store them.
- Resend: delivery of transactional email, such as order confirmations.
- Convex: our database and file storage, where we store emails, practice details, uploaded practice logos, usage analytics, and purchase records.
- Vercel: website hosting and delivery.
- Google: advertising conversion measurement (Google Ads), which tells us whether a visit or purchase came from one of our ads, as described in the Cookies & tracking section above.
6. How we share information
We do not sell your personal data. We share information only with the sub-processors listed above so they can provide their service to us, and when we are required to do so by law or valid legal process, to protect our rights or the safety of others, or in connection with a business transfer (such as a merger or acquisition), in which case we will continue to protect the information consistent with this policy.
7. Data retention
We keep information only as long as we need it for the purposes described in this policy, for example, to deliver your documents, support your order, meet legal or accounting obligations, and understand how the Service is used. When we no longer need information, we delete it or retain it in a de-identified form. You may ask us to delete your information sooner, as described below.
8. Your rights
Depending on where you live, you may have rights over your personal information, including under the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA). These can include the right to access the information we hold about you, to correct it, to request its deletion, and to opt out of marketing or the “sale” or “sharing” of personal information (we do not sell personal information, and our only advertising-related use is the Google conversion measurement described in the Cookies & tracking section). We will not discriminate against you for exercising these rights.
To make a request, email us at support@hipaabinder.com and we will respond within the time required by applicable law. To unsubscribe from product or launch updates, use the unsubscribe option in any such email or contact us at the same address.
9. Security
We take reasonable administrative and technical measures to protect the information we hold, including processing payments through Stripe (so we never handle card numbers) and limiting the data we collect in the first place. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; we encourage you to never send us sensitive information we do not request, and in particular never any patient or client information (PHI).
10. Children’s privacy
The Service is intended for healthcare practices and the professionals who run them. It is not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us and we will delete it.
11. International users
We operate in, and process information in, the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country.
12. Changes
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, provide notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact
Questions about this Privacy Policy or your information? support@hipaabinder.com.