Privacy Policy
For VectorCare's No-Code SMART on FHIR App Builder
Last Updated: December 2024
1. Overview
This Privacy Policy describes how VectorCare, Inc. ("VectorCare," "we," "our," or "us") collects, uses, stores, shares, and protects information when Customers and users access the SMART on FHIR App Builder platform ("Service").
This policy applies to:
- Platform users
- Workflow administrators
- Third parties interacting with apps built on the Service
- Website visitors for this product
2. Information We Collect
2.1 Customer-Submitted Data
This includes:
- Workflow configurations
- Application logic
- Forms, rules, automations
- Any data transmitted by Customer systems
- FHIR resources (if integrated and authorized)
If PHI is processed, it is handled pursuant to a Business Associate Agreement.
2.2 Usage Data
We collect usage analytics, such as:
- Login timestamps
- Feature usage patterns
- System performance logs
- Integration request metadata
- Device/browser information
This data does not include PHI.
2.3 Account Information
Name, email, organization, role, and authentication credentials.
2.4 Cookies & Website Tracking
When using the landing page or dashboard, we may use cookies, log files, or analytics tools to monitor usage and improve experience.
3. How We Use Information
We use Customer Data and platform usage data to:
- Provide and maintain the Service
- Enable FHIR data exchange and SMART on FHIR app functionality
- Improve platform performance
- Support security, auditing, and fraud detection
- Develop enhancements and new features
- Comply with legal and regulatory obligations
Customer Data is never sold or used for advertising.
4. How We Share Information
VectorCare may share data only in the following circumstances:
4.1 With Customer-Authorized Entities
Apps built on the platform may retrieve or transmit data to Epic or other EHRs at Customer direction.
4.2 With Service Providers
Cloud hosting providers, analytics vendors (non-PHI), security tools, and infrastructure partners.
4.3 For Legal or Compliance Reasons
If required to comply with law, a court order, or regulatory obligation.
4.4 De-Identified or Aggregated Data
We may use aggregated or de-identified system usage patterns to improve the Service.
VectorCare does not share PHI unless authorized by a BAA.
5. Data Retention
We retain Customer Data for the duration of the Customer relationship and as required for compliance or auditing. Upon termination, Customers may request their data be exported or deleted in accordance with applicable law and contractual terms.
6. Security Measures
VectorCare uses administrative, physical, and technical safeguards designed to protect Customer Data, including:
- Encryption at rest and in transit
- Access controls
- Audit trails
- Vulnerability management
- OAuth2.0 and industry-standard authorization protocols
If handling PHI, security measures adhere to HIPAA requirements.
7. Customer Rights
Depending on jurisdiction (e.g., CCPA, GDPR), Customers may have rights to:
- Access their data
- Correct inaccurate information
- Request deletion where legally permissible
- Restrict or object to certain processing
- Export or transfer their data
Requests can be sent to privacy@vectorcare.com
8. Children's Privacy
The Service is not intended for individuals under 18 and does not knowingly collect data from minors.
9. Changes to This Policy
VectorCare may update this Privacy Policy periodically. Changes will be posted on the landing page and, where appropriate, communicated to Customers.
10. Contact
For privacy questions or requests:
VectorCare, Inc.
San Francisco, CA