Privacy Policy

For VectorCare's No-Code SMART on FHIR App Builder

Last Updated: December 2024

1. Overview

This Privacy Policy describes how VectorCare, Inc. ("VectorCare," "we," "our," or "us") collects, uses, stores, shares, and protects information when Customers and users access the SMART on FHIR App Builder platform ("Service").

This policy applies to:

  • Platform users
  • Workflow administrators
  • Third parties interacting with apps built on the Service
  • Website visitors for this product

2. Information We Collect

2.1 Customer-Submitted Data

This includes:

  • Workflow configurations
  • Application logic
  • Forms, rules, automations
  • Any data transmitted by Customer systems
  • FHIR resources (if integrated and authorized)

If PHI is processed, it is handled pursuant to a Business Associate Agreement.

2.2 Usage Data

We collect usage analytics, such as:

  • Login timestamps
  • Feature usage patterns
  • System performance logs
  • Integration request metadata
  • Device/browser information

This data does not include PHI.

2.3 Account Information

Name, email, organization, role, and authentication credentials.

2.4 Cookies & Website Tracking

When using the landing page or dashboard, we may use cookies, log files, or analytics tools to monitor usage and improve experience.

3. How We Use Information

We use Customer Data and platform usage data to:

  • Provide and maintain the Service
  • Enable FHIR data exchange and SMART on FHIR app functionality
  • Improve platform performance
  • Support security, auditing, and fraud detection
  • Develop enhancements and new features
  • Comply with legal and regulatory obligations

Customer Data is never sold or used for advertising.

4. How We Share Information

VectorCare may share data only in the following circumstances:

4.1 With Customer-Authorized Entities

Apps built on the platform may retrieve or transmit data to Epic or other EHRs at Customer direction.

4.2 With Service Providers

Cloud hosting providers, analytics vendors (non-PHI), security tools, and infrastructure partners.

4.3 For Legal or Compliance Reasons

If required to comply with law, a court order, or regulatory obligation.

4.4 De-Identified or Aggregated Data

We may use aggregated or de-identified system usage patterns to improve the Service.

VectorCare does not share PHI unless authorized by a BAA.

5. Data Retention

We retain Customer Data for the duration of the Customer relationship and as required for compliance or auditing. Upon termination, Customers may request their data be exported or deleted in accordance with applicable law and contractual terms.

6. Security Measures

VectorCare uses administrative, physical, and technical safeguards designed to protect Customer Data, including:

  • Encryption at rest and in transit
  • Access controls
  • Audit trails
  • Vulnerability management
  • OAuth2.0 and industry-standard authorization protocols

If handling PHI, security measures adhere to HIPAA requirements.

7. Customer Rights

Depending on jurisdiction (e.g., CCPA, GDPR), Customers may have rights to:

  • Access their data
  • Correct inaccurate information
  • Request deletion where legally permissible
  • Restrict or object to certain processing
  • Export or transfer their data

Requests can be sent to privacy@vectorcare.com

8. Children's Privacy

The Service is not intended for individuals under 18 and does not knowingly collect data from minors.

9. Changes to This Policy

VectorCare may update this Privacy Policy periodically. Changes will be posted on the landing page and, where appropriate, communicated to Customers.

10. Contact

For privacy questions or requests:

privacy@vectorcare.com

VectorCare, Inc.
San Francisco, CA