Privacy Policy – PatientsArchive | How We Collect, Use & Protect Your Information
Legal · Privacy

Privacy Policy

This policy explains what information PatientsArchive collects from patients and providers, how we use and share it, and the privacy rights you have — wherever you live in the United States.

Applies to: All U.S. users Coverage: 50 states + D.C.

What we collect

Patient contact and care-interest details, provider practice information, payment data (via Stripe), and standard website/usage data.

How we share it

Patient inquiries are shared with the providers you choose so they can respond. We don’t sell your personal information for money.

Your choices

You can access, correct, delete, and opt out of certain uses. We honor these rights for residents of every U.S. state.

How we protect it

We use reasonable safeguards, limit access, and work only with vendors bound to protect your information.

This summary is for convenience only and does not replace the full policy below. If there’s any conflict, the full policy controls.

1 Scope of this policy

This Privacy Policy (“Policy“) describes how PatientsArchive (“PatientsArchive,” “we,” “us,” or “our“) collects, uses, shares, and protects personal information when you use our website, platform, dashboards, and related services (the “Services“). It applies to patients, caregivers, healthcare providers, and website visitors in the United States. It forms part of, and should be read together with, our Terms & Conditions.

By using the Services, you agree to the practices described here. If you do not agree, please do not use the Services.

2 Information we collect

We collect the categories of information below. The exact information depends on whether you are a patient, a provider, or a visitor, and how you interact with the Services.

CategoryExamples
Identifiers & contactName, email address, phone number, ZIP code, and account login details.
Patient care-interest dataThe condition, symptom, specialty, care type, or provider you search for or inquire about, and location/care preferences you enter.
Provider practice dataCredentials, specialties, license/registration details, accepted insurance, locations, hours, availability, and profile content.
Payment informationSubscription plan, billing details, and transaction records. Card details are processed by our payment processor (Stripe) — we do not store full card numbers.
Usage & device dataIP address, browser and device type, pages viewed, referring links, and interactions, collected via cookies and similar technologies.
CommunicationsMessages, inquiries, demo requests, and support correspondence you send us or send through the Services.
Aggregated/derived dataZIP-level population and demand estimates generated by our calculator using public data sources (see Section 6).

We do not require, and ask that you do not submit, detailed medical records or clinical history through the Services. Any health-related detail you choose to share (such as the specialty you’re seeking) is treated as described in Section 11.

3 How we collect information

  • Directly from you — when you create an account, subscribe, complete a form, use the calculator, contact us, or inquire about a provider.
  • Automatically — through cookies and similar technologies as you browse (see Section 7).
  • From third parties — such as our payment processor, analytics and advertising partners, and public data sources (U.S. Census and CDC) used to power estimates.

4 How we use information

We use personal information to:

  • Operate the Services and connect patients with relevant providers;
  • Enable providers to receive, respond to, and manage patient inquiries;
  • Process subscriptions, billing, and renewals;
  • Provide marketing and visibility services to providers (listings, content, social, PR, reviews, retargeting), subject to your choices;
  • Generate estimates, analytics, and dashboards;
  • Communicate with you, including service messages and, where permitted, marketing;
  • Maintain security, prevent fraud and abuse, and comply with legal obligations;
  • Improve and develop the Services.
Legal bases & purpose limitation. We use information only for the purposes described here or compatible purposes disclosed to you, and we process sensitive information only with your consent or as otherwise permitted by law.

5 How we share information

We share personal information in the following ways:

  • With providers you choose. When you inquire about or select a provider, we share your inquiry and contact details with that provider so they can respond to you.
  • With service providers/vendors. Payment processing (Stripe), hosting, analytics, email/SMS delivery, advertising, and marketing vendors that process data on our behalf under contract.
  • For legal reasons. To comply with law, respond to lawful requests, enforce our Terms, or protect rights, safety, and security.
  • In business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction or consent. When you ask us to share information or otherwise agree.
We do not sell your personal information for money. Some sharing for advertising or analytics may be considered a “sale” or “sharing/targeted advertising” under certain state laws. Where it is, we honor your right to opt out — see Sections 8–10. You can opt out using our “Do Not Sell or Share My Personal Information” control and by enabling a recognized universal opt-out signal (such as Global Privacy Control).

6 The patient potential calculator

Our calculator estimates local patient potential using a ZIP code and specialty you enter. It queries public, third-party data sources — including Zippopotam.us for city/state lookup, the U.S. Census (ACS) for population and demographic data, and the CDC’s Chronic Disease Indicators for prevalence data — and applies our internal marketing model.

The ZIP code and specialty you enter are used to generate the estimate and may be logged to operate and improve the Services. The outputs are modeled estimates, not guarantees, as explained in our Terms. The public data sources have their own terms and privacy practices.

7 Cookies & tracking technologies

We and our partners use cookies, pixels, and similar technologies to run the site, remember preferences, measure performance, and support advertising. Categories include:

  • Essential — required for the site and account to function;
  • Analytics — help us understand usage and improve the Services;
  • Advertising — support marketing and retargeting, and may involve sharing with ad partners.

You can control cookies through your browser settings and, where offered, our cookie banner or preference center. To opt out of advertising-related uses, you can also use a recognized universal opt-out signal such as Global Privacy Control (GPC), which we honor where required by law. Disabling some cookies may affect how the Services work.

8 Your privacy rights (all states)

Depending on where you live, you may have some or all of the rights below. As a matter of practice, PatientsArchive extends these core rights to residents of all 50 states and the District of Columbia, even where not strictly required, applying the strictest applicable standard across our operations.

Right to know / access

Request the categories and specific pieces of personal information we hold about you.

Right to correct

Ask us to fix inaccurate personal information.

Right to delete

Request deletion of personal information, subject to legal exceptions.

Right to portability

Receive a copy of your information in a portable format.

Right to opt out

Opt out of any “sale,” “sharing,” or targeted advertising, and of certain profiling.

Right to limit sensitive data

Limit the use and disclosure of sensitive personal information.

Right to non-discrimination

We will not discriminate against you for exercising your rights.

Right to appeal

Where offered by your state, appeal a decision on your request.

9 How to exercise your rights

To exercise any right, contact us at support@patientsarchive.com with the request and the state you reside in. You may also use any privacy control or preference center we make available.

  • Verification. To protect you, we may need to verify your identity before acting on a request. We will only use information provided for verification to verify the request.
  • Authorized agents. You may use an authorized agent to submit a request where permitted by your state’s law, with proof of authorization.
  • Response time. We respond within the timeframe your state’s law requires (generally 45 days, extendable where permitted).
  • No fee. Requests are generally free, unless excessive or repetitive as permitted by law.
  • Opt-out signals. We honor recognized universal opt-out mechanisms (e.g., Global Privacy Control) where required.

10 State-specific disclosures

The United States has a growing patchwork of state privacy laws. As of 2026, comprehensive consumer privacy laws are in effect in a number of states, and more are being added. Rather than provide a different experience in each state, we apply a single, high baseline nationally and honor the specific rights your state grants.

10.1 California (CCPA/CPRA)

California residents have rights to know, access, correct, delete, and port personal information; to opt out of the “sale” or “sharing” of personal information (including cross-context behavioral advertising); to limit the use of sensitive personal information; and to non-discrimination. We honor Global Privacy Control as a valid opt-out of sale/sharing. To exercise the opt-out, use our “Do Not Sell or Share My Personal Information” control or contact us. California’s “Shine the Light” law also allows residents to request information about disclosures to third parties for their direct marketing; we do not share personal information for third parties’ own direct marketing.

10.2 Virginia, Colorado, Connecticut, Utah & similar-model states

Residents of states following the Virginia model — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon, Montana, Texas, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and Florida — have rights to access, correct, delete, and port their data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. These states require opt-in consent before processing sensitive data. Several (including Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, Maryland, Minnesota, Nebraska, and New Hampshire) require honoring universal opt-out mechanisms such as GPC, which we do. Where your state provides an appeal process for privacy requests, you may appeal our decision by replying to our response or contacting us.

10.3 All other states & the District of Columbia

If your state has not yet enacted a comprehensive privacy law, we still extend the core rights described in Section 8 to you as a matter of policy, and we comply with your state’s data-breach notification and other applicable consumer-protection laws. The following jurisdictions’ residents are covered by this Policy, and each resident’s applicable state protections apply:

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado
  • Connecticut
  • Delaware
  • Florida
  • Georgia
  • Hawaii
  • Idaho
  • Illinois
  • Indiana
  • Iowa
  • Kansas
  • Kentucky
  • Louisiana
  • Maine
  • Maryland
  • Massachusetts
  • Michigan
  • Minnesota
  • Mississippi
  • Missouri
  • Montana
  • Nebraska
  • Nevada
  • New Hampshire
  • New Jersey
  • New Mexico
  • New York
  • North Carolina
  • North Dakota
  • Ohio
  • Oklahoma
  • Oregon
  • Pennsylvania
  • Rhode Island
  • South Carolina
  • South Dakota
  • Tennessee
  • Texas
  • Utah
  • Vermont
  • Virginia
  • Washington
  • West Virginia
  • Wisconsin
  • Wyoming
  • District of Columbia
Nevada & Washington notes. Nevada residents may opt out of the sale of certain covered information; contact us to do so. Washington’s My Health My Data Act and similar consumer-health-data laws may give residents of some states additional rights over health-related data — where they apply, we honor them, including obtaining consent before collecting or sharing consumer health data as required.

11 Sensitive & health-related data

Some information you provide — such as the medical specialty, condition, or care type you’re interested in — may be considered “sensitive” or “consumer health data” under certain state laws. We treat this information carefully:

  • We collect it only to connect you with relevant providers and operate the Services;
  • Where your state requires opt-in consent or separate authorization to process consumer health data, we obtain it;
  • We do not use sensitive information to infer characteristics for unrelated purposes;
  • You may limit the use of sensitive information as described in Sections 8–9.

12 HIPAA & provider relationships

PatientsArchive is generally a marketing and connection platform, not a HIPAA “covered entity.” Information you submit to find care is collected under this Policy, not as protected health information (PHI) under HIPAA.

When a patient connects with a provider, that provider is an independent covered entity responsible for its own HIPAA compliance and privacy notices. Where PatientsArchive processes PHI on a provider’s behalf in a way that makes us a “business associate,” we do so under a separate Business Associate Agreement (BAA) that governs that processing. This Policy governs information we collect and process in our own right as a platform.

13 Data retention

We keep personal information only as long as needed for the purposes described in this Policy — to provide the Services, maintain your account, meet legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and context. When information is no longer needed, we delete or de-identify it. Providers may retain patient inquiry data they receive under their own policies and obligations, over which we have no control.

14 Data security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit where appropriate, and vendor due diligence. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for the security of information you share directly with providers.

If a breach affecting your information occurs, we will notify affected individuals and authorities as required by the data-breach notification laws of every applicable state.

15 Children’s privacy

The Services are intended for adults (18+) and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it. Where a patient seeks care for a minor, the responsible adult is expected to provide and manage that information.

16 Third-party links & services

The Services link to and rely on third-party websites and services (including provider websites, payment processors, data APIs, and social and advertising platforms). We are not responsible for their privacy practices. Review their policies before providing information to them.

17 Changes to this policy

We may update this Policy from time to time. When we make material changes, we will post the revised Policy here and, where required, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance, except where your state’s law requires your affirmative consent, in which case we will obtain it.

18 Contact us

Questions about this Policy, or to exercise your privacy rights, contact:

PatientsArchive
Email: support@patientsarchive.com
Web: www.patientsarchive.com

Please include the state you reside in so we can apply the rights available to you.

This Privacy Policy is provided as a general template for the PatientsArchive platform and does not constitute legal advice. Privacy laws vary by state and change frequently. PatientsArchive should have this document reviewed by qualified privacy counsel and confirm the specific disclosures, opt-out mechanisms, and consent flows its business requires before publication.

Your privacy, handled with care

Have a question about your data or want to exercise a privacy right? We’re here to help — and we honor these rights in every U.S. state.

Scroll to Top