Privacy Policy
This policy explains what information Daybook Health collects through its website and its product, how we use it, who helps us handle it, and the choices you have.
1. Who we are and what this covers
"Daybook," "we," "us," and "our" mean Daybook Health, based in New York, New York. This policy covers our website at daybookhealthcare.com and the Daybook product at app.daybookhealthcare.com, where our customers sign in. Our Terms of Service govern use of the website; a separate written agreement governs use of the product.
2. Two roles: our own data and our customers' data
For information about website visitors and the people who hold accounts in the product, Daybook decides how the information is used, and this policy describes those uses.
Our customers are billing companies, plan administrators, practices and other organizations. The claims, remittances, eligibility responses, patient and member details and other records a customer uploads or connects to Daybook are that customer's data. When that data includes protected health information under HIPAA, Daybook handles it as the customer's business associate, under a Business Associate Agreement signed before any protected health information is processed. For that data, the customer agreement and the Business Associate Agreement control, and this policy does not expand what we may do with it.
3. Information from the website
- What you give us. When you enter your email address to book a call, we receive that address and the page you sent it from, and your browser opens our scheduling page with the address filled in. If you write to us, we receive what you write.
- Technical information. Like most websites, the servers that deliver the site record standard request information, such as your IP address, browser type, the page requested and the time.
- On your device. The site remembers which of its audience pages you last visited (for TPAs, billers, practices or dental) in your browser's local storage, so the terms page can show the note for your side. It stays on your device. The site sets no advertising or analytics cookies.
Please do not send protected health information or other sensitive personal data through the website or in an unsolicited message.
4. Account information in the product
When your organization gives you an account, we hold your name, work email address, organization and role, and records of your sign-ins and sessions. If you sign in with Google, Google tells us your name and email address; we use Google for sign-in only. We send account email, such as sign-in links, invitations and account notices, to the address on your account. For an order, we also hold the billing contact details on the order form and invoices.
5. Customer data and health information
We use and disclose customer data only to provide the Daybook services to the customer that supplied it, and only as its customer agreement and Business Associate Agreement allow. Each customer's data is stored in a database of its own, separate from every other customer's. We do not sell customer data, and we do not use it for advertising.
If you are a patient or a plan member and your information reached Daybook through one of our customers, that customer is the right place to start for questions or requests about it. We will help the customer respond, as our agreement with it requires.
6. How we use information
We use website and account information to respond to you and schedule the calls you ask for, to provide and secure the product, to send account email, to keep the site and the product working and improve them, to invoice for the services, and to meet our legal obligations. We do not sell personal information, and we do not share it for targeted advertising.
7. Service providers
These companies process information on our behalf, under their own terms and our instructions:
- Cloudflare delivers the website and hosts the product, including the databases that store customer data. We have signed a Business Associate Agreement with Cloudflare.
- Fly.io hosts the database that holds accounts and sign-in records. We have signed a Business Associate Agreement with Fly.io.
- Resend sends account email only: sign-in links, invitations and account notices. That email never contains patient data or other protected health information.
- Google provides sign-in only, for people who choose to sign in with their Google account. No customer data is sent to Google.
On the website only:
- Cal.com schedules the calls you book.
- Web3Forms delivers the email address you enter to book a call to our inbox.
- Unsplash serves one photograph on the practices page, so it receives the standard request information your browser sends when it loads that image.
8. When we share information
Apart from the service providers above, we share personal information only when the law requires it, to protect the rights, safety or property of Daybook, our customers or others, or as part of a merger, acquisition or sale of assets, in which case this policy and our customer agreements continue to apply to the information transferred.
9. How long we keep it
We keep website messages and booking details as long as we need them to respond and follow up, and we delete them when you ask. We keep account information while the account is open and for a reasonable period afterward for records and security. We keep customer data for as long as the customer agreement and the Business Associate Agreement provide, and return or destroy it as they require when the agreement ends.
10. Security
Our Security page describes how we protect information, in plain terms. No system is perfectly secure, and we will notify customers of security incidents as our agreements and the law require.
11. Your choices and rights
You can ask us to stop contacting you at any time by replying to any message or writing to us. You can ask us what personal information we hold about you, and ask us to correct or delete it. Depending on your state or country, the law may give you further rights, and we will honor them. For customer data, we will pass your request to the customer it belongs to and help it respond.
12. Children and changes to this policy
The website and the product are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 18 through the website. We may update this policy as the product and the company grow. When we do, we will change the date at the top of this page, and for material changes we will make the update easy to notice.
13. Contact
Questions about this policy, or requests about your information, can be sent to:
Daybook Health · New York, NY
brian@daybook.healthcare